NATO warns of growing cyber threat to port infrastructure

NATO has issued a warning over the rising cyber threat to maritime port infrastructure, identifying ports as high-value targets for state-linked cyber actors and calling for urgent reforms to address critical gaps in civil-military cybersecurity coordination.

According to a new policy brief from the NATO Cooperative Cyber Defence Centre of Excellence (CCDCOE), nearly all NATO and partner countries surveyed reported cyber-attacks on their port infrastructure in the past five years.

Systems at greatest risk include access control technologies and vessel traffic management systems, which are increasingly interconnected as the maritime industry proceeds with its digitalisation efforts.

The report highlights sustained campaigns by state-sponsored actors from Russia, Iran and China, alongside financially motivated cybercriminals and politically driven hacktivist groups.

Attacks have ranged from ransomware incidents that disrupted oil terminals in Belgium and Germany to coordinated DDoS campaigns against major European ports, including Rotterdam, Gdynia and Felixstowe.

The CCDCOE notes that many ports operate with legacy operational technology not designed for internet connectivity, creating vulnerabilities as these systems are integrated with modern ICT networks.

The 2017 NotPetya malware attack, which caused an estimated $300 million in losses for Maersk and disrupted operations at key global ports, is cited as a key example of the risks posed by poor network segmentation across ICT and OT domains.

Despite the strategic role that commercial ports play in NATO’s defence logistics, the current Alliance Maritime Strategy does not formally integrate port operators into its frameworks. The CCDCOE is calling for a revision of that strategy to incorporate cybersecurity as a core element of maritime security, with defined mechanisms for collaboration between military commands and civilian port stakeholders.

“The maritime sector is undergoing rapid digital transformation, but cybersecurity has not kept pace,” the report states.

“Ports cannot be treated in isolation. Cyber resilience must extend to supporting infrastructure, including power and communications systems.”

The brief recommends the creation of dedicated liaison roles between NATO Maritime Command and national port cybersecurity authorities, formal intelligence-sharing networks tailored to maritime threats, and new working groups under the IMO to align cybersecurity standards across the sector.

Share this story

About the Author

Picture of Rob O'Dwyer
Rob O'Dwyer

Rob is Chief Network Officer and one of the founders of Smart Maritime Network. He also serves as Chairman of the Smart Maritime Council. Rob has worked in the maritime technology sector since 2005, managing editorial for a range of leading publications in the transport and logistics sector. Get in touch by email by clicking here, or on LinkedIn by clicking here.

Further Reading

News Archive