
Maritime Vessel Cybersecurity
A Complete Course and Operational Textbook
Shipboard OT, bridge navigation and autonomous ships
Rahimeh Neamatian Monemi, Ph.D. · Shahin Gelareh, Ph.D.
Maritime Vessel Cybersecurity is a complete course for the people who defend the navigation, propulsion and control systems of a commercial vessel: bridge officers, marine engineers, DPAs, and the shore-side IT/OT security teams who support them.
Across 40 chapters in six parts, the book moves from maritime cyber risk foundations through navigation-system security (GNSS jamming and spoofing, AIS, ECDIS chart integrity, VDR forensics), vessel OT and control-system security, IT, identity and connectivity, threat detection and incident response, and compliance and governance under IMO MSC.428(98), IACS UR E26/E27 and IEC 62443.
Every chapter follows the same structure: learning objectives, key terminology, a documented incident or a clearly labelled illustrative scenario, a safety warning, a step-by-step technical runbook, a mapping to the relevant regulatory and industry frameworks, and a Platform Lab Session that readers can optionally run hands-on on the Maritime Cyber Range platform. The book is complete on its own; the platform is an optional companion, and worked lab solutions are supplied to adopting instructors.
Six parts, one platform lab per chapter
PART IFoundations of Maritime Cyber RiskCh. 1–5
- 1The Maritime Cyber Threat Landscape
- 2Regulatory Framework: IMO, STCW, BIMCO, NIS2, ISPS
- 3Vessel System Architecture: IT, OT, and Navigation
- 4Attack Surfaces on a Modern Vessel
- 5Human Factors and the Insider Threat
PART IINavigation System SecurityCh. 6–12
- 6GNSS Architecture and Vulnerability
- 7GNSS Jamming: Detection and Safe Procedures
- 8GNSS Spoofing: Detection and Anti-Spoofing
- 9AIS: Architecture, Attacks, and Phantom Vessel Detection
- 10ECDIS and ENC Chart Integrity Validation
- 11VDR Forensics and Tamper Detection
- 12GMDSS and SAR Communication Security
PART IIIVessel OT and Control System SecurityCh. 13–20
- 13Vessel OT Architecture
- 14IEC 62443 Zones and Conduits on a Vessel
- 15PLC/RTU Process Value Validation
- 16Firmware and Logic Tamper Detection
- 17Modbus, DNP3 and PROFINET Anomaly Detection
- 18OT Network Traffic Analysis
- 19Safety-Instrumented Systems and ESD Protection
- 20IT-to-OT Lateral Movement Detection and Containment
PART IVIT, Identity, and Connectivity SecurityCh. 21–27
- 21Vessel Network Architecture: Satcom, VSAT, and LTE
- 22Phishing, BEC and Social Engineering at Sea
- 23Remote Access Security for Vessels
- 24Endpoint Detection and Response on Maritime Assets
- 25Identity and Access Management Aboard
- 26Cloud-Connected Fleet Systems Security
- 27Vulnerability and Patch Management Under Operational Constraints
PART VThreat Detection and Incident ResponseCh. 28–35
- 28Detection Engineering for Maritime Networks
- 29Cyber Threat Intelligence in the Maritime Domain
- 30Threat Hunting on Vessel Networks
- 31RF and SDR Signal Threat Analysis
- 32Vessel Incident Response: Procedure and Playbooks
- 33Ransomware Recovery and Safe Restoration
- 34Multi-System Cascade Failure Management
- 35Crisis Communications and Stakeholder Coordination
PART VICompliance, Audit, and GovernanceCh. 36–40
- 36Maritime Cyber Risk Assessment: ISM/SMS Integration
- 37IMO MSC.428(98): Implementation and Evidence
- 38STCW VI/6: Curriculum Design and Competency Evidence
- 39Flag State Reporting and Audit Evidence
- 40Post-Incident Lessons Learned: SIRE 2.0 and TMSA
BACK MATTERAppendices and references
- ISM Code Cybersecurity Verification Checklist (Good Practice Model)
- Maritime Industrial Protocol Technical Reference
- Maritime Cyber Range Vessel Scenario Catalog
- MITRE ATT&CK for ICS: Maritime Vessel Technique Mapping
- Proposed Maritime Cyber Competency Framework (Non-Normative Crosswalk)
- Glossary of Maritime Cyber Terms
Everything to teach the course
The teaching materials follow the textbook chapter by chapter. They are supplied to instructors who adopt the book and are not distributed to students.
Lecture slides
One deck for the volume, organised as 90-minute sessions (one per chapter), with speaker notes and ready to adapt to your course.
Instructor guide and solutions manual
For every chapter: a session plan, key messages and common misconceptions, a slide map, model answers to every review question with marking points, and a walkthrough of the platform lab with debrief answers.
Practise every chapter on Predictim Maritime Cyber Range
Each of the 40 labs in this volume maps to a guided-simulation exercise on the platform, so readers move from the page to hands-on practice within the same framework.
- 01Every chapter ends with a guided Platform Lab Session, identified by its platform exercise ID.
- 02Readers request access, and we open the labs for the volume or volumes they use.
- 03On the platform, open the chapter under My Books and select Open Lab Terminal.
Platform access is governed by its own terms of service and may require separate registration or a subscription; buying the book does not guarantee access for any particular period.
Review copy or institutional licence
Instructors and reviewers can request a review copy. Academies, universities, and operators can license the books for their learners, together with access to the Maritime Cyber Range.
First Edition, 2026 — available now in paperback on Amazon. Request a review copy or an institutional licence below.
Ready to optimize your operations?
Talk to our research team about your operational challenge. Receive a tailored technical proposal within 72 hours.



