Digital

Recovery vs. Protection in Cyber Defence

By Joshua Kantner · April 2026 · OceanSphere Consulting

Why Protection Does Not Solve Everything

No system can be fully isolated. Recovery is decisive.

What Recovery Means in a Maritime Context

Restoring critical functions in an orderly manner or continuing operations safely.

Free Initial Consultation Independent marine engineering consulting. We find a solution.
Contact

Why Recovery Is Often Neglected

Protective measures are more visible and easier to communicate.

How Operators Make Recovery Robust

Inventory, prioritisation, tested procedures and defined roles.

Technical Deep-Dive: What Recovery on Board Actually Involves

Maritime recovery goes well beyond restoring a backup. Modern vessels operate numerous interconnected systems: ECDIS (Electronic Chart Display), AIS (Automatic Identification System), GMDSS (Global Maritime Distress and Safety System), engine controls, ballast water management, cargo control and communication systems. A cyber attack can affect several of these systems simultaneously.

The IACS Unified Requirements UR E26 and E27 — mandatory for newbuilds since July 2024 — define minimum requirements for cyber resilience for the first time. UR E26 addresses the vessel as a system and requires, among other things, an inventory of all Computer-Based Systems (CBS), network segmentation and the capability for controlled shutdown and restart. UR E27 addresses system suppliers and mandates security-by-design.

For recovery, this means concretely: every critical system must have a documented restart procedure that the crew can execute without external support — at least for basic operations. This presupposes that backup media are available on board, configuration data have been saved and the crew knows the sequence of system starts.

A frequently overlooked point is the dependency between OT (Operational Technology) and IT (Information Technology). If the IT network is compromised, the OT network — which controls machinery and safety systems — must not be dragged down with it. Network segmentation is not an optional measure here but a fundamental architectural decision that must be taken during vessel design.

Practical Implications: Recovery Planning for Existing Fleets

For existing vessels not covered by UR E26/E27, the starting position is often worse. Many older systems were designed without cybersecurity in mind — default passwords, absent network segmentation and no documented recovery procedures are common.

The pragmatic approach begins with a system inventory: which CBS are on board, which are networked, which are safety-relevant? This yields a prioritisation: navigation systems and engine controls take highest priority, followed by communications and cargo control. For each priority level, a recovery procedure is defined — from a simple restart to a complete system rebuild.

Testing is decisive. A recovery procedure that has never been rehearsed is worthless in an actual incident. Tabletop exercises — where the crew works through a cyber scenario without actually shutting down systems — are a practicable first step. Full drills, where systems are actually shut down and restarted, should take place at least annually.

Case Context: Maersk and NotPetya — The Most Expensive Lesson

The NotPetya attack on Maersk in June 2017 remains the most impactful case study for maritime cyber recovery. Within hours, 49,000 laptops, 3,500 servers and the entire network infrastructure were disabled. Total costs were estimated at 300 million USD.

The decisive insight was not the weakness of protection but the initial absence of recovery capability. Maersk had no isolated backup of the Active Directory — the central authentication infrastructure. A single domain controller in Ghana that happened to be offline at the time of the attack saved the restoration. Without this coincidence, the rebuild would have taken weeks longer.

For vessel operators, the lesson is clear: if the world's largest container shipping line takes weeks to restore its IT infrastructure, a smaller operator without a recovery plan cannot expect to be operational again within days.

Decision Framework: Assessing Recovery Maturity

Operators can assess their recovery maturity against five levels. Level 1: no documented inventory of critical systems. Level 2: inventory exists but no recovery procedures. Level 3: procedures documented but never tested. Level 4: regularly tested procedures with defined roles. Level 5: integrated recovery capability with automated monitoring and regular drills.

Most operators sit at Level 2 or 3. The jump from 3 to 4 — actually testing the documented procedures — delivers the greatest security gain at comparatively modest effort.

Key Takeaways

Related Articles and Services

FAQ

Why is recovery so important in shipping?
Because critical functions cannot simply be suspended.
Are strong protective measures sufficient?
No. Without recovery, the organisation remains unprepared in a disruption.
First step towards better recovery?
Prioritise critical systems and establish realistic restart procedures.

Ready for a solution?

Free initial consultation – we analyze your situation and find the best path forward.

Request Consulting