A Verified Identity, Not Verified Intent: How PoisonX Blinds a Control Maritime Cyber Compliance Requires

Maritime Cyber Threat Briefing #13 A Trusted Signature Proves Origin—Not Intent Briefing #12 examined what happens when the network perimeter fails. When an edge device that was supposed to keep…

Continue ReadingA Verified Identity, Not Verified Intent: How PoisonX Blinds a Control Maritime Cyber Compliance Requires

What are IMO Resolution MSC.428(98) and the IMO Guidelines on Maritime Cyber Risk Management?

Maritime Cyber Insights #4 Cyber resilience begins beyond compliance. Many shipping companies state that they "comply with MSC.428(98)." That shorthand is understandable, but technically incomplete. International Maritime Organization Resolution MSC.428(98)…

Continue ReadingWhat are IMO Resolution MSC.428(98) and the IMO Guidelines on Maritime Cyber Risk Management?

When the Shore Side Falls: Dissecting the Anubis Ransomware Attack on the Adriatic Port Authority

Maritime Threat Craft #2 The Anubis ransomware group's attack on the Adriatic Port Authority, the "AutoritĂ  di Sistema Portuale del Mare Adriatico Centrale" [operator of the Port of Ancona], was…

Continue ReadingWhen the Shore Side Falls: Dissecting the Anubis Ransomware Attack on the Adriatic Port Authority

The Invisible Occupation: Volt Typhoon and the Strategic Pre-Positioning of Maritime Infrastructure

Maritime Cyber Threat Briefing #11 From Quiet Access to Crisis-Time Disruption In December 2024, something remarkable happened in a meeting room in Geneva. Senior Chinese officials reportedly signaled in a…

Continue ReadingThe Invisible Occupation: Volt Typhoon and the Strategic Pre-Positioning of Maritime Infrastructure