Search

Search across services, blog posts, and R&D projects.

MARITIME CYBERSECURITYSeptember 17, 2026 · 8 min read

OT/IT Convergence in Ports: Why Maritime Cyber Risk Is Now an Operational Risk

A crane scheduling system and a corporate email server used to live on separate networks with separate risk owners. In a modern port, they're often the same network — and the same incident.

Rahimeh Monemi, PhD
Author
Rahimeh Monemi, PhD
All articles
Port control room operator monitoring crane telemetry and network security dashboards with illuminated container cranes visible through the windows behind them

For most of the last two decades, a port's operational technology — crane PLCs, terminal operating system servers, AIS receivers — sat on a network that had little reason to talk to the corporate network running email, finance, and HR. The two systems had separate owners, separate risk registers, and separate incident-response plans, and that separation was, for a long time, a reasonably accurate description of the actual attack surface.

It no longer is. Terminal operating systems now pull live AIS and GPS feeds for berth-allocation optimization, crane scheduling systems expose APIs to yard-management software running on standard corporate infrastructure, and vendors maintain remote access into OT equipment for predictive-maintenance contracts. The result is a single, converged attack surface with two risk owners who were never asked to coordinate — and an incident that starts in either system can now end in the other.

A crane scheduling system and a corporate email server used to live on separate networks with separate risk owners. In a modern port, they're often the same network — and the same incident.

§ 02Where the Convergence Actually Happens

The integration points are specific and growing, not hypothetical: a TOS that ingests real-time vessel position data to re-sequence berth assignments; crane and yard equipment that reports telemetry into the same analytics platform used for corporate reporting dashboards; and remote diagnostic access granted to equipment vendors for predictive maintenance, which is functionally a permanent third-party VPN into OT, often provisioned years before anyone reviews it against current security policy. None of these integrations are mistakes — each one is there because it makes the port measurably more efficient. That is precisely why segmentation can't simply be reversed.

§ 03Why a Ransomware Incident Becomes a Berth-Allocation Problem

The pattern seen across several major port disruptions in recent years follows a consistent shape: a ransomware or intrusion event on the IT side forces a precautionary shutdown of OT systems that share any network path with the compromised environment, even when the OT systems themselves were never directly infected. Cranes stop scheduling against live vessel data, berth allocation reverts to manual coordination over phone and radio, and a security incident that started as a corporate data-exfiltration problem becomes, within hours, a physical queue of vessels with nowhere confirmed to dock. The financial exposure of that cascade routinely exceeds the direct cost of the original breach by an order of magnitude.

§ 04Segmentation Is Necessary but Not Sufficient

Network segmentation between IT and OT is table stakes, not a solved problem once implemented — because the optimization systems that make a modern port competitive depend on a continuous flow of OT data (vessel position, crane status, yard occupancy) into IT-side analytics, which means a hard air gap simply isn't compatible with how the port actually operates. What segmentation buys is a defensible boundary with monitored, whitelisted data flows crossing it — anomaly detection specifically tuned to that boundary, rather than a general-purpose IT security stack that has no model of what normal OT-to-IT traffic looks like and therefore can't tell a legitimate telemetry spike from an attacker pivoting across the boundary.

§ 05Building Response Capability Before the Incident: The Case for Cyber Range Training

Because the real failure mode spans both domains, the response capability has to as well — and that's the gap most port cybersecurity programs still have. IT security teams drill IT incidents; terminal operations teams drill equipment failures; the two groups rarely drill the scenario that actually happens, where an IT compromise forces an OT shutdown decision under time pressure and incomplete information. Cyber range exercises that put both groups through a joint OT-spoofing or cascading-shutdown scenario — not a tabletop read-through, but a simulated live decision with a clock running — are what actually surface the coordination gaps (who has authority to order an OT shutdown, how fast can berth allocation genuinely revert to manual) before a real incident tests them for the first time.

Engage

Ready to optimize your operations?

Talk to our research team about your operational challenge. Receive a tailored technical proposal within 72 hours.