33
cyber threats of all aspects of maritime cyber systems
and the reduction of the consequences of cyber-attacks
on maritime operations. In order to apply resilient
attributes to the nautical operations, the people
undertaking such operations must be able to protect
the ongoing operations from a potential cyber threats
and risks, as well as constantly expect the unexpected,
evolving and learning from own operations.
“Maritime Cyber Resilience” has been defined as a
nautical system’s ability to learn how to maintain and
evolve a normal operation, as well as anticipate,
withstand, recover and evolve from a cyber threat in
the minimum amount of time possible. The authors
have also argued for why the navigator should be the
focus of study when considering maritime cyber
resilience, as the navigator is at the sharp edge of the
operation, maybe being the only agent able of
detecting an unwanted variation to a situation.
Furthermore, the navigator is expected to take the
wheel when the technology fails. One assumption
when considering maritime cyber resilience is that the
navigator needs to accept that the safety of the
situation can, and eventually will be, compromised.
This article has discussed that robust systems can
fail, and even technical resilient systems can fail. In
this case, the navigator, who is a major decision maker
onboard needs to take command to take control over
the situation. The article mentions that there are many
types of cyber-attacks and many of them are not yet
known. A cyber-attack can be lurking in the system,
not to cause any trouble, before a given time or
position. This means that the navigator and the
human aspect is key, when considering Maritime
Cyber Resilience.
ACKNOWLEDGEMENT
This paper is part of the research project MarCy (Maritime
Cyber Resilience). The MarCy project has received funding
from the Research Council of Norway, with project number
295077. Contents reflects only the authors’ views, and the
Research Council of Norway, nor the project partners, are
not responsible for any use may be made of the information
it contains.
REFERENCES
1. Anholt, R., Boersma, F.K.: From security to resilience:
New vistas for international responses to protracted
crises. In: Linkov, I., Florin, M.-V., and Trump, B.D.
(eds.) Resilience (Volume 2, 2018). pp. 25–32
International Risk Governance Center (2018).
https://doi.org/10.5075/epfl-irgc-262527.
2. Awan, M.S., Al Ghamdi, M.A.: Understanding the
Vulnerabilities in Digital Components of an Integrated
Bridge System (IBS). Journal of Marine Science and
Engineering. 7, 10, (2019).
https://doi.org/10.3390/jmse7100350.
3. Bainbridge, L.: Ironies of automation. Automatica. 19, 6,
775–779 (1983). https://doi.org/10.1016/0005-
1098(83)90046-8.
4. Barrett, M.: Framework for Improving Critical
Infrastructure Cybersecurity Version 1.1,
https://doi.org/10.6028/NIST.CSWP.04162018, (2018).
5. Bimco, Clia, ICS, Intercargo, Intermanager, Intertanko,
IUMI, OCIMF and World Shipping Council: The
Guidelines on Cyber Security onboard Ships. BIMCO
(ed.) Version 4.0 (2020).
6. Bodeau, D.J., Graubart, R.D., Picciotto, J., McQuaid, R.:
Cyber Resiliency Engineering Framework. The MITRE
Corporation (2011).
7. Bowditch, N.: The American practical navigator : an
epitome of navigation. National Imagery and Mapping
Agency (2002).
8. Boyes, H., Isbell, R.: Code of Practice: Cyber Security for
Ships. Institution of Engineering and Technology,
London, United Kingdom (2017).
9. Cambridge Online Dictionary: Maritime. Cambridge
Univeristy Press (2021).
10. Cambridge Online Dictionary: Operation. Cambridge
Univeristy Press (2021).
11. da Conceição, V.P., Dahlman, J., Navarro, A.: What is
maritime navigation? Unfolding the complexity of a
Sociotechnical System. Proceedings of the Human
Factors and Ergonomics Society Annual Meeting. 61, 1,
267–271 (2017).
https://doi.org/10.1177/1541931213601549.
12. Cutler, T.J.: Dutton’s Nautical Navigation. Naval
Institute Press; (2004).
13. Daum, O.: Cyber Security in the Maritime Sector. J. Mar.
L. & Com. 50, 1–19 (2019).
14. DiRenzo, J., Goward, D.A., Roberts, F.S.: The little-
known challenge of maritime cyber security. In: 2015 6th
International Conference on Information, Intelligence,
Systems and Applications (IISA). pp. 1–5 (2015).
https://doi.org/10.1109/IISA.2015.7388071.
15. DNV: Cyber security resilience management for ships
and mobile offshore units in operation,
https://www.dnv.com/maritime/dnvgl-rp-0496-
recommended-practice-cyber-security-download.html,
last accessed 2021/04/15.
16. Fitton, O., Prince, D., Germond, B., Lacy, M.: The future
of maritime cyber security. Lancaster University (2015).
17. Giacomello, G., Pescaroli, G.: Managing Human Factors.
In: Kott, A. and Linkov, I. (eds.) Cyber Resilience of
Systems and Networks. pp. 247–263 Springer
International Publishing, Cham (2019).
https://doi.org/10.1007/978-3-319-77492-3_11.
18. Haimes, Y.Y.: On the Definition of Resilience in Systems.
Risk Analysis. 29, 4, 498–501 (2009).
https://doi.org/10.1111/j.1539-6924.2009.01216.x.
19. Hareide, O.S.: Podkast: Teknologi og mennesket som
“sensor,”
https://www.kystverket.no/Nyheter/2021/januar/ny-
podkast-teknologi-og-mennesket-som-sensor/, last
accessed 2021/04/16.
20. Hareide, O.S., Jøsok, Ø., Lund, M.S., Ostnes, R., Helkala,
K.: Enhancing Navigator Competence by Demonstrating
Maritime Cyber Security. Journal of Navigation. 71, 5,
1025–1039 (2018).
https://doi.org/10.1017/S0373463318000164.
21. Hollnagel, E.: Resilience engineering and the built
environment. null. 42, 2, 221–228 (2014).
https://doi.org/10.1080/09613218.2014.862607.
22. Hollnagel, E., Pariès, J., Woods, D., Wreathall, J.:
Epilogue: RAG – The Resilience Analysis Grid. In:
Resilience Engineering in Practice. pp. 275–296 CRC
Press, London, United Kingdom (2011).
https://doi.org/10.1201/9781317065265-19.
23. Hollnagel, E., Woods, D.D., Leveson, N.: Resilience
Engineering: Concepts and Precepts. CRC Press (2006).
24. Hollnagel, Erik: How resilient is your organisation? In:
An Introduction to the Resilience Analysis Grid (RAG). ,
Toronto, Canada (2010).
25. Hopcraft, R., Martin, K.M.: Effective maritime
cybersecurity regulation – the case for a cyber code. null.
14, 3, 354–366 (2018).
https://doi.org/10.1080/19480881.2018.1519056.
26. IACS: Rec 166 - Recommendation on Cyber Resilience,
http://www.iacs.org.uk/publications/recommendations/1
61-180/, last accessed 2021/04/15.