Maritime Cyber Security for Port and Shipping Operations Training Course

5 days Cyber Security Certificate on completion
Course codeSD-CS-055
Duration5 days
LevelFoundation to Intermediate
CategoryCyber Security
DeliveryClassroom or live online
LanguageEnglish
CertificateCertificate of completion

Course overview

Port authorities, terminal operators, ship managers and logistics providers now depend on connected operational technology and digital exchanges to move vessels and cargo. A ransomware incident in a terminal operating system, compromise of an EDI gateway, malware on a vessel network, or loss of availability in port community systems can delay berthing, disrupt cargo release, create safety exposure and trigger contractual claims. Professionals responsible for these environments need to understand cyber risk in operational terms, not only IT terminology.

This course equips participants to identify and protect critical maritime assets across ports, terminals, vessels and shore-side operations. Participants map IT and OT dependencies; assess threats to terminal operating systems, vessel networks, industrial control systems and third-party interfaces; apply the NIST Cybersecurity Framework 2.0; and interpret IMO cyber risk management expectations. They practise network traffic analysis with Wireshark, develop incident escalation paths, assess supplier controls, and build cyber recovery measures for operational disruption.

Teaching combines instructor-led explanation with maritime incident cases, guided risk workshops and hands-on analysis of realistic port and vessel scenarios. Each participant develops a Maritime Cyber Risk Treatment Plan for a selected port, terminal, fleet or shipping business process. The plan includes an asset and dependency map, prioritised risk register, control recommendations, incident roles, recovery actions and a practical 90-day implementation roadmap that can be used in internal discussions after the course.

The course is suited to operational, technology, security and assurance professionals who must coordinate cyber security decisions across shipboard, port and corporate environments. It is designed for foundation-to-intermediate participants who need a structured way to connect technical cyber controls with safe, reliable maritime operations.

Course objectives

By the end of this course, participants will be able to:

  • Map critical IT, OT, vessel and port-system dependencies using an operational asset inventory
  • Assess cyber threats and vulnerabilities through a maritime-specific risk register and likelihood-impact scoring method
  • Apply NIST Cybersecurity Framework 2.0 functions to port, terminal and shipping control environments
  • Analyse packet captures in Wireshark to identify suspicious maritime network communications
  • Evaluate supplier and third-party cyber controls for EDI, port community system and remote-access connections
  • Design an incident response escalation workflow for ransomware, network compromise and operational technology disruption
  • Develop recovery priorities and manual-workaround procedures for disrupted port and shipping operations
  • Produce a Maritime Cyber Risk Treatment Plan with prioritised controls, owners and a 90-day action roadmap

Benefits of attending

For you

  • Gain the ability to translate cyber incidents into berth, cargo, vessel-schedule and safety consequences
  • Build credible working knowledge of IMO cyber risk management expectations and NIST CSF 2.0 application
  • Learn to challenge weak remote-access, supplier-interface and backup arrangements in maritime operations
  • Create a portfolio-quality Maritime Cyber Risk Treatment Plan relevant to a current operational responsibility
  • Strengthen readiness for cyber, digital resilience, marine assurance and operational risk leadership roles

For your organisation

  • Improve visibility of critical dependencies between terminal systems, vessel technology, corporate IT and third parties
  • Reduce the likelihood of uncontrolled operational outages through clearer incident escalation and recovery priorities
  • Establish a repeatable method for assessing cyber risks affecting cargo, berthing, navigation-support and fleet processes
  • Strengthen supplier assurance for EDI links, port community systems, remote maintenance and managed service providers
  • Generate a practical 90-day cyber improvement roadmap that can feed into operational resilience and investment planning

Target competencies

Maritime cyber riskOT asset mappingNetwork traffic analysisIncident response designSupplier assurance reviewsOperational recovery planning

Who should attend

  • Port and Terminal Operations Managers — who must maintain safe vessel and cargo flows during technology disruption
  • Shipping Company IT and Cyber Security Managers — who protect shore-side systems and vessel-to-shore connectivity
  • Marine Superintendents and Fleet Managers — who oversee vessel operational resilience and cyber risk management
  • Terminal Operating System and Port Community System Administrators — who manage high-value operational platforms and interfaces
  • OT, Automation and Engineering Managers — who support industrial control systems, gate systems, cranes and networked equipment
  • Risk, Compliance and Internal Audit Professionals — who need to test maritime cyber controls against operational and regulatory expectations

Requirements and prerequisites

Participants should be comfortable discussing basic IT concepts such as networks, user accounts, access permissions, malware, backups and incident reporting. Experience in a port, terminal, vessel operator, shipping line, maritime logistics provider or marine technology environment is strongly beneficial because exercises use operational scenarios and terminology. No programming, penetration-testing experience, security certification or prior use of Wireshark or Microsoft Sentinel is required. Complete beginners in cyber security can attend, but should expect to work with risk scoring, network diagrams and operational-control concepts from the first day.

Training methodology

The five-day programme uses short instructor-led briefings to establish maritime cyber concepts, followed by applied work on port, terminal and vessel scenarios. Participants map a cargo-handling or ship-to-shore process, review sample network evidence in Wireshark, score risks using a structured register and test response decisions against ransomware and OT disruption cases. Small-group workshops compare operational, technical and assurance perspectives. Each day adds a component to the participant’s Maritime Cyber Risk Treatment Plan, culminating in peer review and a manager-ready implementation briefing.

Course outline

Day 1: Maritime cyber risk landscape and critical asset mapping

  • Cyber threat pathways across ports, terminals, vessels and shore-side offices
  • IT, OT and maritime operational technology distinctions
  • Critical maritime assets including terminal operating systems, ECDIS and port community systems
  • Business-impact analysis for berthing, cargo release, gate operations and vessel turnaround
  • Asset ownership, data flows and trust boundaries
  • NIST Cybersecurity Framework 2.0 functions and profiles
  • IMO MSC-FAL.1/Circ.3 cyber risk management expectations

Workshop: Participants create a critical-asset and dependency map for a selected terminal, port process or vessel-to-shore operation.

Day 2: Threat assessment and protective controls

  • Maritime ransomware, phishing, credential theft and business email compromise scenarios
  • Threat modelling with attack paths and operational consequences
  • Risk-register construction using likelihood, impact, control effectiveness and risk owners
  • Network segmentation for corporate IT, terminal OT and vessel environments
  • Identity and access management for privileged and remote-access accounts
  • Backup, restoration and immutable-copy requirements for operational systems
  • IACS UR E26 and UR E27 principles for cyber resilience of onboard systems

Workshop: Participants build and prioritise a maritime cyber risk register for a simulated terminal operating system disruption.

Day 3: Network monitoring and incident detection

  • Maritime network architecture, VLANs, firewalls and remote-maintenance pathways
  • Wireshark capture filters and display filters for network investigation
  • DNS, HTTP, SMB and remote desktop protocol indicators of compromise
  • Baseline traffic patterns for terminal and vessel-connected networks
  • Log sources from firewalls, endpoints, identity platforms and OT gateways
  • Microsoft Sentinel incident queues, analytics rules and investigation views
  • Triage criteria for cyber events with potential operational impact

Workshop: Participants inspect a Wireshark packet capture and produce an evidence summary identifying suspicious communications and recommended containment actions.

Day 4: Response, recovery and third-party assurance

  • Incident command roles across operations, IT, OT, legal, communications and vessel management
  • Containment decisions when safety, availability and forensic preservation conflict
  • Ransomware response playbooks for terminal, shipping and port community systems
  • Operational recovery sequencing and manual-workaround design
  • Cyber tabletop exercise methods and decision logging
  • Supplier due diligence for EDI, cloud, remote support and managed security services
  • Contractual security clauses, notification requirements and access-control evidence

Workshop: Teams run a ransomware tabletop involving terminal gate outages and produce an incident escalation, continuity and supplier-notification plan.

Day 5: Cyber governance and implementation planning

  • Cyber governance structures for port authorities, terminal operators and shipping companies
  • Risk appetite, control ownership and executive reporting metrics
  • Control prioritisation using risk reduction, cost, operational feasibility and dependency criteria
  • Security awareness requirements for crews, operators, contractors and administrators
  • Audit evidence for access reviews, backups, incident drills and supplier assurance
  • NIST CSF 2.0 target-profile and gap-assessment development
  • Ninety-day maritime cyber improvement roadmap design

Workshop: Participants complete and present a Maritime Cyber Risk Treatment Plan with prioritised actions, accountable owners, milestones and success measures.

Tools & standards covered

NIST Cybersecurity Framework (CSF) 2.0, IMO MSC-FAL.1/Circ.3, Wireshark, Microsoft Sentinel

A typical training day

08:30 – 10:30First session
10:30 – 10:45Refreshment break
10:45 – 12:30Second session
12:30 – 13:30Lunch and networking
13:30 – 15:00Third session
15:00 – 15:15Refreshment break
15:15 – 16:30Workshop and daily review

Live online deliveries follow the same structure in the East Africa Time zone, with shorter screen blocks and longer breaks.

What the fee includes

  • Instruction by a practitioner facilitator
  • Full course workbook and materials
  • Exercise files, templates and case studies
  • Certificate of completion
  • Refreshments and lunch (classroom deliveries)
  • Post-course application plan
  • Facilitator follow-up on request
  • Group rates from five participants

How you can take this course

Classroom

Scheduled sessions in Nairobi, Mombasa, Kigali, Dar es Salaam, Dubai and Cape Town.

Live online

The same facilitator and materials, delivered live for distributed teams and individuals.

In-house

Delivered privately for your team, at your offices or a venue of your choice, tailored to your context. Request a proposal.

Certification

Participants who complete the full five days receive the Skillset Development Certificate of Completion, stating the course title, course code, dates and delivery format — suitable for professional-development records and employer reimbursement.

Frequently asked questions

No. The course begins with core cyber and network concepts, then applies them to maritime operations. Familiarity with your organisation’s port, vessel or shipping processes is more valuable than prior security-tool experience.

A laptop is recommended for the Wireshark analysis and planning exercises in classroom delivery, and required for live online delivery. Course materials and access instructions are provided; participants do not need to purchase or pre-install enterprise security software.

Yes. It addresses shipboard, shore-side, terminal and port-community dependencies, with emphasis on where those environments connect. Participants can focus their final plan on a vessel, fleet, terminal, port authority or shipping business process.

This programme concentrates on operational consequences: vessel turnaround, cargo release, berth planning, gate operations, remote maintenance and recovery from OT disruption. It uses maritime standards, sector-specific cases and a risk-treatment deliverable rather than generic awareness content.

You can use the asset-mapping, risk-register and supplier-assurance templates to review a live operational dependency or upcoming technology change. The incident and recovery methods can also be incorporated into a cyber tabletop exercise with operations, IT and external providers.

You leave with a Maritime Cyber Risk Treatment Plan tailored to a selected operational environment. It includes a dependency map, prioritised risks, recommended controls, response roles, recovery actions and a 90-day implementation roadmap.

Upcoming sessions

New dates are being scheduled. Ask us about the next session or an in-house delivery for your team.

Ask about dates

Group of 5+?

Request in-house delivery or group rates →

Related courses in Cyber Security

5 Days Certificate

Microsoft Sentinel Threat Detection Training Course

Security operations teams often collect more telemetry than they can investigate effectively. Microsoft Sentinel can centralise alerts, inci…

5 Days Certificate

MITRE ATT&CK Threat Detection Engineering Training Course

Security operations teams often collect more telemetry than they can investigate, yet still lack reliable detections for the techniques most…

5 Days Certificate

CIS Controls v8 Implementation and Assessment Training Course

Security teams are often asked to demonstrate that their controls are effective, prioritised and connected to business risk, yet their evide…

5 Days Certificate

Wireshark Network Packet Analysis Training Course

Network incidents, intermittent application failures and suspected data exfiltration are often hidden in packet captures that are too large …