Connected Fleets under Siege: The 2026 CSN ICT Cyprus – Greece Satellite and Cyber Security Report

The international maritime sector is operating at an unprecedented intersection of digital acceleration, operational complexity and acute geopolitical exposure. Modern vessels have evolved from isolated steel islands into continuously connected, data-rich nodes integrated directly into corporate IT ecosystems. Yet, as high-speed Low Earth Orbit (LEO) constellations, cloud architecture and automated operational technologies dissolve the traditional physical boundaries between ship and shore, the attack surface has expanded dramatically.
Simultaneously, commercial shipping is navigating an aggressive threat environment marked by widespread electronic warfare, GNSS jamming and spoofing across vital sea lanes, and a tightening regulatory framework that includes IACS Unified Requirements E26 and E27, the EU NIS2 Directive, and IMO Resolution MSC.428(98). Cyber resilience is no longer an isolated technical support function; it has become a fundamental pillar of navigational safety, commercial continuity and board-level risk governance.
To capture the ground-level operational reality across the Cyprus and Greece shipping clusters, Cyprus Shipping News compiled detailed, unvarnished assessments from leading ICT directors, Chief Information Security Officers, and maritime technology executives. Their insights reveal how the premier management companies are defending connected assets under siege.
Geopolitical Cyber Vectors and Evolving Threats
With commercial shipping infrastructure increasingly caught in regional conflicts, the industry has seen a decisive shift from untargeted, opportunistic cybercrime to coordinated, deliberate campaigns directed at both vessels and shoreside offices.
| Threat Category | Primary Attack Vector | Operational & Commercial Impact | Strategic Mitigation Focus |
|---|---|---|---|
| Targeted Espionage & Disruption | AI-crafted spear-phishing referencing real voyages, charter parties, and port calls. | Unauthorised operational visibility, compromised vessel itineraries, and cargo disruption. | Role-specific training, live email threat analysis, and anomaly logging. |
| Business Email Compromise (BEC) | Mailbox interception, domain spoofing, and supplier payment diversion. | Direct multimillion-euro financial fraud and commercial contract manipulation. | Mandatory out-of-band verification and banking change controls. |
| OT & Edge Exploitation | Probing exposed VPN gateways, edge routers, and remote access ports. | Unauthorised access to machinery automation, ballast control, and chart systems. | Hardened DMZs, default-deny firewalls, and least-privilege jump hosts. |
| Indirect Supply Chain Breach | Compromising small maritime suppliers, agents, and riding teams. | Lateral infiltration into core shipboard and corporate networks via trusted paths. | Rigorous vendor risk audits, SBOM tracking, and time-boxed remote access. |

According to Dr. Matthew Maheras, President of AMMITEC and Chief Information Officer of Metrostar Management Corp., the defining change across the sector is one of intent rather than simply volume. Untargeted cybercrime has given way to the deliberate targeting of shipping as critical global infrastructure, with reported maritime incidents roughly doubling through 2025 and 2026. Intrusions touching operational technology (OT) aboard vessels represent the fastest-growing and most dangerous vector. Threat actors increasingly initiate attacks outside the owner’s immediate perimeter by compromising managers, agents, suppliers, remote maintenance portals, or external mailboxes. Furthermore, Business Email Compromise represents an immediate financial peril, as demonstrated in July 2026 when the Hellenic Police investigated a €4 million fraud against a Greek shipping company carried out via lookalike domains. An attacker no longer needs to penetrate the vessel hull directly; compromising someone who talks to the vessel is sufficient to disrupt operations.
This evaporation of the boundary between kinetic conflict and cyber warfare is a daily reality for Dimitris Marinis, ICT Manager at Angelakos (Hellas) S.A. He notes that modern attacks are meticulously shaped around shipping workflows, referencing real charter party agreements, actual vessel positions, and port calls. Rather than spraying generic commodity malware, threat actors are steadily probing remote access points and targeting personnel holding administrative access to operational systems. Angelakos (Hellas) now treats every vessel as a remote branch office, defending ship and shore as a single, continuous attack surface.

Drawing on reports from ENISA and the NATO Shipping Centre, Yiannis Sofianidis, IT Director and CISO at A.M. Nomikos Transworld Maritime Agencies S.A., observes that geopolitical conflicts in the Black Sea, Red Sea, and Eastern Mediterranean have directly exposed commercial shipping to cyber disruption and supply chain sabotage. Sophisticated attackers exploit real-world trade patterns and operational pressures to make social engineering campaigns far more convincing, turning cyber security into an operational resilience priority that links safety, continuous trade, and board-level risk.
The concept of connected fleets under siege is an everyday operating condition. Apostolos Giannetsos, ICT Manager at Cyprus Sea Lines, points to the grounding of MSC Antonia on the Eliza Shoals near Jeddah as a stark reference case for weaponised navigation and deliberate signal interference. With industry research from DNV indicating that 31% of maritime professionals experienced a cyber incident over the past year, Giannetsos argues that defensive strategies must combine active UKMTO threat bulletin tracking with continuous Safety Management System risk updates.

Vlassis Papapanagis, Chief Commercial Officer at Tototheo Global, reinforces this with industry intelligence indicating a 103% year-on-year surge in maritime cyber incidents, with attacks specifically targeting maritime OT jumping by 150%. Average ransomware losses across the sector now exceed $10 million in direct and indirect damages. Threat actors increasingly combine electronic jamming with network intrusion attempts, attacking connectivity, navigation, and corporate ERP systems in tandem. Konstantinos Stais, Head of ICT & Security at Delia Tankers, agrees that while raw breach numbers have not exploded indiscriminately, the persistence, reconnaissance depth, and AI-backed sophistication of adversaries have evolved significantly. Shipping companies must realise they are frequent collateral targets in broader international disputes.

Intrusions that historically stopped at the enterprise IT perimeter now actively attempt to bridge into vessel OT systems. Alexandros Schizas, ICT Manager at MCT Inc., notes that edge devices such as routers, firewalls, and VPN gateways have become the primary initial point of entry for attackers. Ioannis Rizos, Head of ICT Infrastructure at Dynagas Ltd., points out that adversaries are targeting the wider maritime ecosystem rather than isolated fleets, achieving massive leverage by compromising software vendors and remote maintenance providers. Angelos Demetriou, IT Manager at Raytec Digital Ocean Technologies Ltd, adds that even threat groups with lower technical capabilities are executing highly disruptive attacks by partnering with specialised affiliate networks.
Threats are increasingly entering operations indirectly through compromised vendor accounts, tampered firmware updates, or degraded positioning data. Yvonne Tsanos, General Manager at Azimuth Radio Technologies, stresses that establishing clear escalation channels between bridge teams, shore IT, and certified service partners is essential to prevent secondary disruption. Dimitris A. Makris, IT Manager and CySO at Andriaki Shipping Co. Ltd., highlights that the integration of AI by cybercriminals has accelerated reconnaissance speed, while Melanie Dias, Senior Network & Applications Engineer at KVH, reports that year-over-year GPS spoofing incidents have spiked by approximately 340%. Thodoris Efstathiou, ICT Manager & CISO at Equinox Maritime LTD. confirm a marked rise in phishing campaigns that exploit basic administrative oversights, reinforcing that cyber risk must be embedded directly into operational resilience.

Konstantinos Sakellakos, IT Manager at Navarone, highlights that 2025 showed a dramatic increase in cyber activity against the maritime sector. The interesting qualitative measure, he notes, is that most attacks are not highly sophisticated. They still primarily exploit weak credentials, email phishing, exposed remote access, and vulnerable or unpatched third party software. He also points out that regional tensions have significantly increased GPS disruption and communication interference activity. However, on a positive note, Sakellakos observes that IACS UR 26 and 27 have slowly started influencing the industry, resulting in cyber security experts being included much earlier in project planning and pre deployment discussions.

Marios Ioannou, Business Information Security Officer of Columbia Group, confirms this decisive shift from opportunistic to targeted activity. He observes that maritime themed phishing and social engineering campaigns have become noticeably more tailored, referencing genuine vessel names, port calls, and chartering workflows. This indicates adversaries are investing heavily in sector reconnaissance. Ioannou also highlights a notable increase in identity centric attacks against shoreside offices, such as attempts to compromise cloud accounts and abuse legitimate authentication flows, alongside a sustained rise in GNSS interference. The sophistication, he notes, lies less in novel malware and more in adversaries understanding how shipping companies actually operate, thereby exploiting the trusted relationships between vessels, offices, and third parties.
Satellite Connectivity, LEO Networks and GNSS Vulnerabilities
Widespread GPS and GNSS jamming and spoofing across volatile trading corridors present critical navigation hazards, while high-bandwidth LEO networks introduce complex architectural vulnerabilities.
| Vulnerability Domain | Technical & Operational Risk | Primary Failure Mode | Engineered Countermeasure |
|---|---|---|---|
| GNSS Jamming & Spoofing | Synthetic RF signals displacing true vessel coordinates on bridge consoles. | ECDIS misplacement, false autopilot corrections, and unflagged grounding risks. | Cross-checking radar, visual bearings, depth sounders, and multi-constellation units. |
| LEO Rapid Handovers | Satellite handovers every 5 to 15 minutes requiring constant re-authentication. | Micro-connection gaps vulnerable to session hijacking and packet manipulation. | Cryptographic session pinning, robust tunnel encapsulation, and strict gateway filtering. |
| Orbital & Phased-Array Attack | Embedded software exploits within flat-panel antenna micro-operating systems. | Terminal disabling, firmware bricking, and mid-voyage communications blackouts. | Independent fallback links (GEO/L-band), firmware integrity verification, and air-gapped backups. |
| Geopolitical Constellation Risk | State-driven network control, coverage restrictions, and national firewalls. | Abrupt loss of connectivity coverage or unmanaged data routing in sensitive jurisdictions. | Multi-provider hybrid connectivity architectures (LEO/GEO/4G) and sovereign routing policies. |

Katerina Raptaki, Digital Transformation & Cyber Security Specialist at Navios Group, highlights the specific, often overlooked risks of LEO networks. Unlike geostationary satellites with fixed dishes, LEO satellites move rapidly across the sky, forcing flat-panel antennas to switch satellites every 5 to 15 minutes. These rapid handovers require constant session re-authentication, creating brief micro-gaps that sophisticated attackers can exploit for session hijacking. Furthermore, orbital vulnerabilities via inter-satellite space lasers and the risk of malware infecting the antenna’s micro-operating systems present severe threats.
To mitigate these connectivity risks, Apostolos Giannetsos enforces default-deny firewalls and shapes bandwidth to guarantee operational traffic always takes priority over recreational use. He notes that high bandwidth is an open door if not properly controlled, citing documented cases of crew purchasing retail satellite dishes and connecting them directly into vessel networks to bypass corporate controls. Furthermore, Giannetsos highlights the geopolitical fragmentation of LEO providers across American, European, Chinese, and Russian constellations, urging managers to evaluate data jurisdiction.
Dr. Matthew Maheras argues that GNSS must now be treated as an untrusted input, requiring disciplined cross-checking against radar, visual fixes, and gyro logs. He also warns that AIS identity manipulation by sanctioned fleets creates severe commercial exposure, making behavioural analytics platforms vital for due diligence. LEO constellations did not create a new attack surface so much as remove the bandwidth scarcity that previously limited poor cyber practices.
Dimitris Marinis treats the satellite terminal as an untrusted edge, ensuring critical systems are strictly isolated from crew networks, and notes that deliberate jamming of LEO terminals has already been observed in volatile corridors. Yiannis Sofianidis stresses the need for bridge teams to look for subtle indicators of GNSS spoofing, such as sudden position jumps and discrepancies between echo sounder readings and charted depths. Alexandros Schizas briefs masters transiting high-risk corridors to expect continuous interference, maintaining procedures to revert instantly to traditional passage planning and paper chart plotting, pairing multi-constellation receivers with inertial navigation systems.

Konstantinos Stais builds resilience through layered communication services and urges the maritime industry to present unified technical standards to satellite providers. Vlassis Papapanagis advocates for multi-orbit connectivity built on top of segmented network architectures from initial commissioning. Ioannis Rizos warns that satellite dishes installed outside traditional firewall architectures create unmanaged backdoors, meaning operators must invest as heavily in segmentation and identity controls as they do in bandwidth.

Dr. Kyriakos P. Mahos, HSQE & Energy Efficiency Director at Levante Ferries, notes that LEO high-speed links require disciplined network architecture to prevent exposure. Yvonne Tsanos stresses that high bandwidth must never equate to open access, and every remote session running over LEO must be authenticated and time-limited. Melanie Dias recommends hybrid network links running satellite alongside cellular and shore Wi-Fi to prevent vessels from being completely cut off if a primary frequency is jammed. Angelos Demetriou evaluates dual LEO installations for complete physical isolation, while Thodoris Efstathiou ensures higher bandwidth is matched with strong governance. Konstantinos Sakellakos completes this picture by deploying SD-WAN architectures with automated failover channels to maintain connectivity under pressure.
Addressing these exact GNSS vulnerabilities, Marios Ioannou of Columbia Group builds resilience through layered navigation and communications capabilities rather than relying on any single system. By coordinating closely between marine, fleet, and IT teams, he ensures vessels can maintain safe operations, situational awareness, and uninterrupted shore communication even during spoofing events. Regarding LEO networks, Ioannou notes that while the operational benefits are undeniable, Columbia Group deliberately treats connectivity as an enabler rather than a trusted environment. He advocates for a media agnostic network architecture where security controls, segmentation, and access management remain consistent whether using GEO, LEO, MEO, or terrestrial communications. This strategy guarantees that the expanded attack surface introduced by high bandwidth never translates into expanded corporate risk.
Securing the Ship-to-Shore Bridge and IT/OT Convergence
As vessels become interconnected nodes within corporate networks, enforcing strict network segmentation and zero trust access control is vital to prevent cross-contamination during a breach.
| Operational Layer | Defensive Security Mandate | Technical Architecture | Data Flow Restrictions |
|---|---|---|---|
| Bridge & Navigation (OT) | Total air-gapping / strictly controlled DMZ | Read-only data diodes, zero direct internet access, segregated VLANs. | Outgoing telemetry only; zero incoming connections permitted. |
| Machinery & Propulsion (OT) | Controlled maintenance access | Time-boxed remote support windows, multi-factor jump hosts, session logging. | Brokered access via secure jump host; automatic session termination. |
| Corporate Vessel IT | Secure administrative operations | Identity validation via Zero Trust, endpoint detection (EDR), centralised patching. | Enterprise-managed tunnels with least-privilege role-based access. |
| Crew Welfare Network | Isolated personal connectivity | Dedicated physical or virtual LANs, bandwidth shaping, captive portals. | Absolute logical isolation; zero routing pathways into core networks. |

Polykarpos Yiannoudes, General Manager at UiBS, stresses that for years the industry over-invested in perimeter firewalls while ignoring access control. Identity is the new perimeter. He advocates for passwordless authentication and a Zero Trust model powered by Microsoft Entra ID, arguing that human memory was never designed to be a security control. Every access request from ship or shore must be evaluated in real time. AI platforms like Microsoft Sentinel and Defender Copilot can contain threats in seconds, but Yiannoudes warns that AI cannot fix poor governance, excessive admin rights, or unmanaged devices.
Dimitris Marinis highlights the practical application of this by establishing a Demilitarised Zone with brokered data flows, ensuring remote access is granted strictly through jump hosts with least-privilege permissions. Yiannis Sofianidis aligns with this by establishing explicit zoning based on IACS UR E26 and E27 standards, rejecting flat network topologies across the fleet.
Apostolos Giannetsos goes further, using one-way data diodes for telemetry analysed ashore, preventing shoreside analytics platforms from transmitting back into vessel control machinery. Konstantinos Stais notes that establishing clear cross-departmental ownership between ICT, Technical, and Marine departments ensures fast, decisive action during incidents. Thodoris Efstathiou isolates business networks and critical navigation systems behind layered controls to ensure that an infection in a crew laptop cannot threaten ship stability.

Dr. Kyriakos P. Mahos integrates IT and OT management within the Safety Management System for passenger ferries to protect passenger safety and operational punctuality. Alexandros Schizas treats the ship-to-shore link as a boundary to be controlled, not a pipe to be trusted, while Angelos Demetriou relies on physical isolation and one-way data diodes to block incoming network traffic.
Ioannis Rizos builds architectures that limit lateral movement and preserve operational independence. Yvonne Tsanos ensures remote access is granted strictly to designated systems for specified time windows. Melanie Dias deploys secure gateways like CommBox to enforce separation based on real traffic monitoring rather than assumptions. Vlassis Papapanagis advocates for continuous threat detection across the entire fleet ecosystem, and Konstantinos Sakellakos treats the vessel as an extension of the corporate network to deploy enterprise-grade access management directly on board.
Marios Ioannou details that Columbia Group treats the vessel as an untrusted network segment by design. Onboard IT and OT are separated into distinct zones aligned with the IACS UR E26/E27 framework, and the ship to shore link is treated as a monitored boundary rather than an extension of the corporate LAN. All vessel to shore traffic traverses inspected, authenticated channels following strict least privilege principles. Crucially, Ioannou ensures that segmentation is validated continuously through monitoring and detection coverage on both sides of the bridge, guaranteeing that if a vessel is compromised, the blast radius is contained and the breach never becomes a fleet wide event.
Regulatory Compliance and Infrastructure Stress-Testing
Meeting the standards set by IMO Resolution MSC.428(98), IACS UR E26/E27, and the EU NIS2 Directive requires continuous operational validation rather than static, paper-based audits.
| Regulatory Standard | Governance Scope | Mandatory Technical Obligation | Practical Audit Evidence |
|---|---|---|---|
| IACS UR E26 / E27 | Newbuild design & onboard integrated equipment security. | Hardware-level zone segmentation, encrypted internal comms, and system hardening. | Yard design approvals, Class survey verifications, and penetration test reports. |
| EU NIS2 Directive | Critical maritime transport & essential supply chain entities. | Strict 24h early warning / 72h incident reporting, and board-level legal liability. | Dynamic risk registers, supply-chain cyber audits, and logged incident playbooks. |
| IMO MSC.428(98) | Fleetwide operational safety management. | Incorporating cyber risk assessment directly into the ISM Safety Management System. | Documented onboard cyber drills, emergency failover plans, and master training logs. |
| EU AI Act & ISO 42001 | Algorithmic transparency & automated decision-making. | Governance over operational AI models, data privacy controls, and human oversight. | Shadow AI acceptable-use policies, AI model risk inventories, and bias audits. |
Apostolos Giannetsos notes that regulatory oversight has developed real enforcement power, with surveyors now inspecting live asset inventories and active configuration backups. He conducts live failover tests, bandwidth saturation drills, and scenario-based tabletops. Dr. Matthew Maheras advises shipowners to purchase verification by applying the Cyber Secure class notation to all newbuildings, ensuring security is built in at the shipyard and verified by class surveyors under real operating conditions.
Dimitris A. Makris uses automated Governance, Risk, and Compliance platforms for continuous risk assessments, maintaining real-time visibility across ship and shore infrastructure. Yiannis Sofianidis runs automated vulnerability scanning tools and maintains dynamic network asset inventories, shifting the focus from policy creation to proving operations will continue during an active attack. Alexandros Schizas integrates vulnerability scanning and incident response exercises into everyday operations, noting that with NIS2 establishing personal executive liability, compliance must be woven into the daily operating rhythm.

Melanie Dias connects onboard monitoring tools directly into central compliance platforms to automate evidence collection. Konstantinos Stais stresses that mature security programmes continuously adapt to new operational realities. Thodoris Efstathiou conducts continuous risk reviews and independent cyber security assessments to uncover technical weaknesses before they cause operational disruptions.
Dr. Kyriakos P. Mahos embeds cyber risk directly into internal audits and Safety Management Systems, treating cyber preparedness with the same discipline as traditional maritime emergency drills. Yvonne Tsanos notes that meaningful compliance proves that configurations are backed up and systems can be restored. Ioannis Rizos validates recovery capabilities under realistic operational conditions, arguing that passing an audit does not guarantee resilience during an incident.
Angelos Demetriou uses comprehensive monitoring platforms to validate network security posture. Vlassis Papapanagis embeds proactive monitoring throughout the lifecycle of connected systems, and Konstantinos Sakellakos conducts annual disaster recovery exercises across the fleet to verify operational resilience standards are met in practice.
Marios Ioannou takes a highly proactive stance, deliberately treating IMO MSC.428(98), IACS E26/E27, NIS2, and the incoming EU requirements as a floor rather than a ceiling. He emphasises that compliance artefacts are simply outputs of an operational security programme, not the programme itself. By incorporating cyber acceptance criteria into newbuild and retrofit projects, Columbia Group ensures resilience is engineered in from the start. Success, Ioannou notes, is never measured by a completed checklist, but by demonstrable detection, containment, and recovery capability proven through recurring vulnerability assessments and technical validation exercises.
The Human Defence Layer, Security Culture and Seafarer Literacy
Technology alone cannot secure a fleet if human literacy lags behind. The human element represents both the most targeted vulnerability and the most adaptable line of defence when supported by a no-blame culture.
| Training Element | Traditional Compliance Method | Modern Operational Approach | Practical Outcome |
|---|---|---|---|
| Delivery Cadence | Annual classroom or e-learning module. | Short, monthly scenario drills on board during rotation. | Continuous retention unaffected by crew change schedules. |
| Phishing Preparation | Generic office-based email templates. | Realistic maritime lures (fake port agent, bunkering, crewing). | Sharp reduction in credential harvesting and malicious clicks. |
| Financial Controls | Email confirmation of payment requests. | Mandatory out-of-band telephone verification protocols. | Elimination of CEO fraud and Business Email Compromise. |
| Incident Reporting | Punitive response to user errors. | Transparent, blame-free reporting culture with crew praise. | Rapid early-stage containment of active cyber security events. |
Dr. Matthew Maheras advocates for short, frequent, monthly scenario training for crews, noting that annual training fails when it collides with crew rotation schedules. Because threat actors now use synthetic voice and deepfake video in payment fraud, security must rely on strict procedural rules, such as mandatory out-of-band phone verification for any change in bank details, regardless of perceived urgency or seniority. Industry associations like AMMITEC collaborate with training bodies like HELMEPA to raise awareness across the shipping cluster.
Dimitris Marinis uses realistic maritime scenarios for training, such as fake messages from port agents, and stresses that shipping companies must build a blame-free reporting culture where crew members are praised for reporting mistakes or suspicious emails immediately. Apostolos Giannetsos delivers scenario-based training on board during routine drills and enforces strict rules on removable media, ensuring contractor USBs are scanned on isolated terminals.
Yiannis Sofianidis tailors training to maritime-specific workflows and conducts unannounced phishing simulations twice a year to build crew confidence. Konstantinos Stais leverages direct communication to foster an open reporting environment where reporting mistakes is actively supported. Alexandros Schizas replaces annual briefings with frequent phishing simulations and coaching, focusing on removing the fear of reporting.

Dimitris A. Makris delivers continuous security training both on board and ashore, supported by regular security bulletins. Thodoris Efstathiou focuses on practical guidance and open engagement with shipboard personnel, emphasising that reporting a false alarm is far better than ignoring an active threat. Dr. Kyriakos P. Mahos ensures every crew member understands that maintaining cyber hygiene contributes directly to safe navigation.
Yvonne Tsanos empowers personnel to pause and verify unexpected requests, such as an unfamiliar USB connection or conflicting ECDIS readings. Ioannis Rizos notes that cyber awareness must be embedded into daily operations through practical decision-making. Melanie Dias recommends embedding cyber training into standard compliance platforms, while Angelos Demetriou combines computer-based training and targeted phishing simulations. Konstantinos Sakellakos builds trust and open collaboration with users based on the Technology, Organisation, and People framework.
Marios Ioannou clearly views the crew as vital sensors, not vulnerabilities. He has transitioned Columbia Group’s training away from generic annual modules toward continuous, role based education that reflects the maritime themed phishing and fraudulent chartering threats crews actually face. With the expansion of onboard connectivity, Ioannou points out that crews now possess office grade access and therefore face office grade threats. By reinforcing realistic simulation exercises and a blame free reporting channel, he embeds cyber security directly into the existing safety culture, observing that a crew member reporting a suspicious email within minutes is worth far more than any single technical control.
Vendor and Third-Party Supply Chain Risk Management
Modern shipmanagement depends on an interconnected web of external software vendors, equipment OEMs, and satellite service providers. Managing third-party risk requires strict contractual governance, time-boxed remote access, and continuous verification.
| Third-Party Category | Inherent Risk Exposure | Governance & Contractual Control | Access Management Protocol |
|---|---|---|---|
| OEM Equipment Providers | Unmonitored remote diagnostic access into main engines and automation. | Mandatory contractual incident notification clauses and right-to-audit terms. | Brokered jump hosts, time-limited access windows, and full session recording. |
| Maritime Software & PMS | Supply chain vulnerabilities and unvetted software patches. | Software Bill of Materials (SBOM) tracking and pre-deployment vulnerability scans. | Dedicated DMZ staging servers; zero direct database or network integration. |
| Port Agents & Chandlers | Low cyber maturity leading to compromised email accounts and payment fraud. | Multi-factor supplier portals and out-of-band verification for bank details. | Strict file filtering, anti-spoofing DMARC/DKIM checks, and sandboxed attachments. |
| External IT / Riding Teams | Introduction of infected service laptops, USB drives, and diagnostic tools. | Physical hardware hygiene protocols and mandatory terminal sanitisation. | Air-gapped scanning kiosks before connection; isolated temporary service VLANs. |
Dr. Matthew Maheras highlights that remote maintenance access is the widest and least guarded door in the maritime industry. Shipowners must maintain an accurate register of all vendors holding remote access, require multi-factor authentication, grant access strictly for defined time windows, and enforce full session logging. Furthermore, cyber security provisions must be embedded directly into standard shipmanagement contracts, establishing mandatory incident notification timelines and audit rights. AMMITEC works to establish common baseline supplier standards across the Greek and Cypriot shipping clusters.
Dimitris Marinis points out that a vendor’s security posture is part of the shipmanager’s security perimeter, requiring rigorous pre-contract assessments and eliminating permanent, open vendor tunnels into the fleet. Yiannis Sofianidis maps critical business processes to specific vendors, noting that smaller marine suppliers often lack dedicated IT security teams, making them attractive footholds for attackers.
Apostolos Giannetsos notes that under the EU NIS2 Directive, shipowners are legally accountable for supply chain security. Cyprus Sea Lines requires vendors to provide architecture documentation aligned with IACS UR E27 and maintains Software Bill of Materials visibility. Konstantinos Stais ensures security requirements are included during initial procurement discussions and applies strict least-privilege access for remote maintenance

Alexandros Schizas requires suppliers to demonstrate security standards prior to onboarding, while Ioannis Rizos enforces continuous, evidence-based vendor governance supported by technical controls that minimise trust by default. Yvonne Tsanos requires remote maintenance to be governed by defined scopes, named personnel, and explicit approval. Thodoris Efstathiou requires all vendor access to be justified, approved, and periodically reviewed. Melanie Dias recommends regular external penetration testing for third-party integrations, Angelos Demetriou audits equipment providers via HSSQE procedures, and Konstantinos Sakellakos actively monitors privileged vendor sessions.
Marios Ioannou identifies third party access as one of the most significant risk vectors in modern ship management. At Columbia Group, every vendor connection is subject to a defined lifecycle involving security due diligence before onboarding and contractual incident notification obligations. Remote maintenance access to vessels is brokered through controlled gateways, ensuring it is time bound, monitored, and logged end to end rather than standing open. Furthermore, Ioannou views the EU Cyber Resilience Act as a highly positive development, shifting a meaningful share of the security burden to product manufacturers and giving ship managers a stronger regulatory basis to demand secure by design software.
Artificial Intelligence, Shadow IT and Automation
Artificial intelligence is transforming maritime operations and cyber defence, but the unchecked spread of unapproved consumer AI tools introduces significant governance and data confidentiality risks.
| AI Application Domain | Defensive Operational Benefit | Adversarial Cyber Risk | Governance Requirement |
|---|---|---|---|
| Threat Detection & SOC | Real-time log analysis, automated incident triaging, and fast containment. | AI-automated reconnaissance and high-speed vulnerability scanning. | Continuous human-in-the-loop oversight and automated alert validation. |
| Voyage & Engine Optimisation | Predictive machinery maintenance, fuel analytics, and route efficiency. | Poisoning of operational telemetry data leading to flawed engine decisions. | Explainable AI models, data integrity verification, and KPI cross-checks. |
| Communications & Email | Natural language processing to detect nuanced phishing and BEC attempts. | Generative AI creating flawless multilingual social engineering lures. | Advanced behavioural email filtering and strict verification protocols. |
| Enterprise Data Management | Rapid search across fleet manuals, maintenance logs, and ERP databases. | Shadow AI leakage of confidential charter party terms and crew personal data. | Sanctioned enterprise AI platforms and strict data loss prevention rules. |
Dr. Matthew Maheras warns that the most urgent near-term challenge is Shadow AI: employees and senior executives pasting commercially sensitive charter party terms, personal data, and technical manuals into unapproved public AI tools. Companies must establish governance before buying tools, define acceptable use policies, classify sensitive data, and provide sanctioned enterprise platforms. Dr. Maheras points to the proposed Article 5B in the Greek Constitution as an excellent guiding principle for maritime boards, noting that AMMITEC is currently developing MAP-AI (Maritime AI Playbook) in partnership with AI Catalyst Greece.
Polykarpos Yiannoudes warns that AI will not compensate for poor governance, excessive administrative privileges, or weak identity controls; deploying AI without strong fundamentals simply automates organisational weaknesses. Dimitris Marinis focuses on practical applications within internal testing labs, leveraging AI for rapid data retrieval across ERPs and maintenance logs to support fast decision-making.
Konstantinos Stais approaches AI from the board level, using it to streamline workflows, improve reporting, and empower lean IT teams without replacing human accountability. Vlassis Papapanagis advocates for common maritime data frameworks and API standards, noting that platforms like TM Synergia and EchoVerse connect fragmented operational data to provide real-time analytics and intelligent 3D vessel models.

Apostolos Giannetsos deploys AI for anomaly detection across network telemetry and predictive maintenance on engine machinery while bringing all AI models under formal governance aligned with the EU AI Act. Yiannis Sofianidis targets AI investments toward email threat detection, automated phishing analysis, and predictive machinery analytics. Dimitris A. Makris adopts a controlled approach, assessing data privacy, storage locations, and shadow AI risks before deployment.
Alexandros Schizas uses AI-driven anomaly detection to identify network deviations while maintaining human oversight over all navigation and machinery decisions. Dr. Kyriakos P. Mahos integrates AI tools for decarbonisation and predictive maintenance through EU innovation initiatives like ELEMED, e-SHyIPS, and FIT-HORIZONS. Yvonne Tsanos focuses on operationally useful AI to flag equipment alarms and prioritise security events. Ioannis Rizos stresses that AI should augment skilled professionals rather than replace them, Melanie Dias helps operators integrate compliant AI detection tools, Angelos Demetriou uses AI-assisted monitoring tools, Thodoris Efstathiou leverages AI for threat visibility, and Konstantinos Sakellakos prioritises controlled AI adoption under strict governance.
Marios Ioannou directs Columbia Group’s AI investments along a dual track of security operations and business enablement. On the security side, AI driven network detection and behavioural analytics surface anomalies at machine speed, a crucial capability when adversaries are themselves using automation to compress their attack timelines. On the business side, AI assistants streamline workflows under a governed framework with clear data handling boundaries, ensuring that adoption does not become a new exposure. Ioannou stresses that every AI deployment must be explainable, governed, and measurably reduce risk or manual effort, ensuring the company invests in outcomes rather than hype.
Disaster Recovery, Decoupled Navigation and Operational Resilience
In the event of a total communications blackout, severe GNSS spoofing, or a major ransomware deployment affecting shipboard systems, maintaining decoupled fallback procedures guarantees the continuity of navigation and the safety of life at sea.
| Operational Domain | Primary Connected Capability | Degraded / Disconnected Fallback Mode | Verification & Drill Cadence |
|---|---|---|---|
| Vessel Navigation | Dual ECDIS integrated with multi-constellation GNSS. | Radar plotting, visual bearings, depth sounder contours, and paper charts. | Monthly bridge limited-GNSS and manual plotting drills. |
| Fleet Communications | Multi-orbit high-speed LEO / GEO broadband uplink. | Standalone GMDSS, MF/HF, and VHF radio with prioritised MRCC contact lines. | Quarterly communications failover exercises. |
| Operational Data & SMS | Cloud-hosted Microsoft Azure / SaaS platforms ashore. | Encrypted, air-gapped local backups and printed offline operational playbooks. | Semi-annual disaster recovery restore validation. |
| Machinery Control | Automated power management & remote telemetry. | Local manual engine room overrides and physical mechanical control. | Scheduled auxiliary equipment emergency override tests. |
Apostolos Giannetsos ensures bridge teams routinely rehearse manual navigation using paper charts, radar, and visual bearings under SOLAS Chapter V carriage requirements. Operational playbooks are maintained in printed and offline formats on board, and communications fall back from high-speed LEO to standalone MF/HF and VHF radio with prioritised emergency contacts.
Dimitris Marinis stresses that safety of navigation must remain strictly segregated from corporate IT networks. Mandated SOLAS, GMDSS, and core navigation equipment operate independently so that a vessel can navigate safely even if administrative systems are offline. Angelakos maintains offline data backups, isolated network segments, and rehearsed incident plans to ensure a cyber incident never becomes a safety-of-life emergency.
Konstantinos Stais designs corporate ICT infrastructure on Microsoft Azure, allowing shore teams to operate seamlessly regardless of physical office access. On board, vessels maintain multiple independent satellite links across different technologies, paired with simple, regularly rehearsed manual fallback procedures.

Ioannis Rizos stresses that vessels must retain the independent capability to navigate safely and make decisions when primary digital services are unavailable. Alexandros Schizas designs systems around complete operational decoupling, protecting critical data from ransomware with air-gapped backups. Angelos Demetriou uses automated, encrypted backups stored on isolated hardware checked weekly to guarantee rapid recovery.
Yvonne Tsanos requires offline operating capability, manual override procedures, and empowered bridge teams. Thodoris Efstathiou maintains documented incident response procedures, alternative communication paths, and regular recovery drills. Melanie Dias recommends maintaining an independent, logically and physically decoupled communications path, such as an isolated email-only channel. Konstantinos Sakellakos ensures business continuity through offline backups and regular drills, keeping critical vessel operations functional even during corporate network failures.
Marios Ioannou bases resilience planning on the assumption that connectivity and shoreside systems can be lost entirely. He ensures vessels retain the ability to navigate safely without any shore link, supported by documented fallback procedures and independent communication paths. On the shore side, Columbia Group maintains segregated, immutable backups with recovery priorities driven by business impact analysis rather than convenience. Crucially, these procedures are rigorously exercised through scenario based drills that simulate full communication blackouts and ransomware conditions, allowing IT and marine departments to practice decision making under genuinely degraded conditions.
The Next 18 to 24 Months: Strategic Outlook and Regional Leadership
The maritime ICT landscape across the Cyprus and Greece shipping clusters will be defined by the convergence of tighter regulatory supervision, sophisticated AI threats, expanding vessel connectivity, and geopolitical instability.
| Strategic Priority | Key Industry Challenge | Practical Action Plan for Shipping Companies |
|---|---|---|
| Regulatory Supervision | NIS2 national enforcement and mandatory IACS E26/E27 surveys. | Consolidate compliance evidence platforms and assign named board risk owners. |
| AI Governance & Control | Uncontrolled Shadow AI usage risking commercial data leakage. | Implement clear acceptable-use policies and deploy sanctioned enterprise AI tools. |
| Supply Chain Assurance | Cascading breaches via unmonitored vendor remote access. | Enforce strict time-boxed MFA jump hosts and contractual cyber clauses. |
| Regional Collaboration | Lean internal IT resources managing complex cyber operations. | Leverage cluster initiatives like AMMITEC and regional cybersecurity centres. |
Apostolos Giannetsos highlights the compression of regulatory enforcement with executive liability, cyber-physical threats reaching the navigation bridge, rapid AI deployment outrunning governance, and satellite connectivity entangled in geopolitics. Shipping companies must focus on foundational excellence: robust OT/IT segmentation, verified asset inventories, strict identity controls, and supply chain resilience.
Dr. Matthew Maheras advises companies to appoint a named cyber risk owner with board access, conduct annual cross-departmental crisis exercises, maintain accurate vendor access registers, and adopt class cyber notations on newbuildings. Regional associations like AMMITEC provide essential shared frameworks and threat intelligence so smaller owners do not have to address these challenges alone.
Katerina Raptaki stresses balancing the pressure to adopt AI with the industry’s traditional strengths: seamanship, practical experience, and human judgement (ναυτοσύνη). Companies must establish clear AI governance, evaluate vendor data risks, and maintain meaningful human oversight over all operational and safety decisions.

Dimitris Marinis focuses on closing the gap between new regulations and the operational reality of managing mixed fleets with older tonnage. Yiannis Sofianidis maps critical processes, identifies dependencies on OT and satellite links, and integrates cyber risk directly into safety management and fleet operations. Polykarpos Yiannoudes emphasises disciplined, identity-first security architectures powered by Zero Trust models.
Alexandros Schizas calls for active regional collaboration to share threat intelligence, pointing to planned regional cybersecurity centres. Konstantinos Stais notes that leadership agility and governance will be the key differentiators over technology budgets. Dr. Kyriakos P. Mahos sees success for European shipping depending on successfully navigating decarbonisation, digitalisation, and cyber resilience simultaneously.
Vlassis Papapanagis requires integrating connectivity and compliance mandates into unified platforms. Dimitris A. Makris prioritises building cyber security and governance into technology adoption from the outset. Yvonne Tsanos stresses clear ownership and live compliance registers across the maritime hubs.

Thodoris Efstathiou requires strong cross-departmental collaboration, treating cyber risk as a business and safety imperative. Angelos Demetriou notes the EU NIS2 Directive will require operators to elevate their compliance capabilities from recommendations to strict legal requirements. Melanie Dias advises consolidating compliance strategies to address overlapping IMO, IACS, and EU requirements simultaneously. Konstantinos Sakellakos focuses on managing digital complexity through strict governance, standardisation, security-by-design, and investment in skilled personnel.
Marios Ioannou anticipates that the greatest challenge over the coming months will be managing the convergence of increasing regulatory obligations with the rapid digitalisation of vessel operations. As the widespread adoption of LEO and high bandwidth connectivity accelerates the integration of ships into corporate processes, the digital footprint on board expands significantly. To manage this complexity, Ioannou urges organisations to prepare by investing in scalable governance frameworks and ensuring that security, compliance, and operational technology strategies evolve together rather than independently.
Executive Action Matrix for Maritime Boards
To translate technical and regulatory requirements into board-level strategy, executive leadership should execute the following actionable priorities:
-
Deploy Zero Trust Identity Architecture: Replace legacy network perimeters with identity-first access management, mandatory multi-factor authentication, and Conditional Access across all shipboard and shoreside systems.
-
Enforce Complete OT/IT Hardware Segmentation: Isolate bridge navigation, propulsion controls, corporate administrative IT, and crew welfare Wi-Fi using monitored DMZs and one-way data diodes.
-
Establish Rigorous AI Governance: Implement acceptable-use policies to eliminate Shadow AI, prevent confidential charter party data leakage, and align operations with the EU AI Act.
-
Transition to Continuous Operational Stress-Testing: Move beyond paper compliance by conducting unannounced failover drills, dynamic vulnerability scanning, and Class-certified cyber surveys.
-
Cultivate a Blame-Free Human Defence Layer: Deliver frequent, role-specific scenario training tailored to real shipping workflows and actively reward personnel for reporting suspicious activities.
-
Strictly Audit Third-Party Supply Chains: Maintain a live register of all external remote connections, enforcing time-boxed access windows, session logging, and contractual cyber liability clauses.
-
Preserve Decoupled Navigational Independence: Ensure bridge teams maintain the capability to navigate safely using traditional methods, independent radars, and standalone GMDSS radio during complete network blackouts.
Conclusion
The consensus of the 2026 CSN ICT Cyprus, Greece, Satellite and Cyber Security Report is absolute. Cyber resilience has outgrown its legacy status as a technical support function and now represents a fundamental pillar of modern seamanship, operational safety, and commercial viability. As cyber threats become more targeted and regional conflicts disrupt electronic navigation, shipping companies across Cyprus and Greece can no longer rely on paper compliance. Long-term resilience depends on disciplined governance, secure network architecture, close vendor oversight, and an open safety culture that empowers personnel both ashore and at sea.
Related News.
Top News,Cyprus,Digitalisation
August 31, 2026
Cyprus’s next big opportunity is at Sea: How AI can transform shipping into a pillar of the new economy
An exclusive CSN interview by Adonis Violaris with Demetris Skourides, Chief Scientist for Research, Innovation and Technology, and Chairman of the…
August 31, 2026
Women in shipping do not need to become better jugglers
Women are often praised for being good at juggling, but I am not convinced that this is always the compliment it is meant to be. More often than not,…
August 31, 2026
Cybersecurity and resilience in the maritime sector
Digital systems have become critical to core operations across the maritime sector. Ports, terminals, shipping companies and logistics operators…
August 31, 2026
Export disruptions increasingly hurting tanker demand: BIMCO’s Tanker Shipping Market Overview & Outlook August 2026 is out
Tanker Shipping Market Overview & Outlook Export disruptions increasingly hurting tanker demand "Tanker markets are facing mounting pressure…
August 31, 2026
NGOs call on IMO Member States to ignore Dangerous Distractions En Route to Net Zero
Ahead of next week’s key meeting of the International Maritime Organization , the Clean Shipping Coalition is calling on member states to hold firm…
August 31, 2026
DORIC MONTHLY – BRAZIL BAROMETER AUGUST 2026
Kindly find below the DORIC latest publication, the "BRAZIL BAROMETER," which delves into the key macroeconomic and trade variables shaping the…
August 31, 2026
Iran says the U.S. is standing in the way of Hormuz deal amid talks with Oman
The U.S. is obstructing an agreement between Iran and Oman to secure a safe transit route through the Strait of Hormuz, the Islamic Republic’s…
August 31, 2026
RINA unveils Mermaid, a future-ready ship design for an uncertain decarbonisation future
RINA has unveiled Mermaid, a future-ready ship propulsion concept designed to help shipowners reduce fuel consumption, lower emissions, improve…
August 31, 2026
Auramarine strengthens business development and lifecycle services leadership with two senior appointments
Auramarine, a leading fuel supply systems expert, has appointed Lauri Helkkula as Business Development & Key Account Director, and Aki Sand as…
August 31, 2026
DNV: Regulatory uncertainty demands fleet strategies built for multiple futures
Regulatory uncertainty is increasing pressure on shipowners to make investment decisions that remain viable across multiple future scenarios.…
Subscribe to our newsletter!
if you dont want to swim alone in the ocean of news, sign up for the newsletter, and you will receive daily all the important news of world shipping!
Design & Development by P.KAN.DESIGNER
© 2026 Cyprus Shipping News. All rights reserved
Design & Development by P.KAN.DESIGNER
© 2026 Cyprus Shipping News. All rights reserved






















