Operational training for enhanced maritime cyber resilience: Bridging safety and security through maritime education and training
Abstract
Modern maritime navigation and operations heavily rely on technology. While this has brought many benefits, it has also introduced new risks, especially in cyber security. This thesis investigates how the maritime industry and maritime education and training institutions can be better prepared against cyber threats. By taking a human-centred design approach, the thesis investigates how qualitative research can be utilized to enhance maritime cyber resilience. This thesis explores how the traditional maritime ship safety transition into an industry which not just need to consider normal accidents, like fire onboard or ship collision avoidance, but also needs to address cyber security aspects. Central to this research is the exploration of the International Maritime Organization's (IMO) Resolution for Maritime Cyber Risk Management in Safety Management Systems (MSC.428(98)), which positioned cyber risk on the global maritime safety agenda. By underscoring the need for heightened awareness and urging the maritime sector to evolve and learn continuously, this Resolution has become a cornerstone in discussions about maritime cyber resilience. As a strategic focus for the IMO, MET's potential to fortify human capacity on ships stands out as a pivotal element in the quest to make humans the strongest link in maritime cyber security. Through a rigorous examination of current research trends, industry initiatives, and the pivotal intersection of automation and human interaction, this thesis underscores the importance of integrating maritime cyber security into MET curricula. To provide a comprehensive perspective, the research methodology encompasses a review of existing literature, an evaluation of the development of maritime cyber security, and a deep dive into how the maritime industry responds to regulations and frameworks. The thesis also assesses the relevance and applicability of concepts like maritime cyber resilience in the context of MET. The research approach includes a look at existing studies, an examination of how maritime cyber security has evolved, and a review of how the maritime sector deals with rules and guidelines. The thesis looks at how resilience applies to cyber issues in the maritime context. Key findings come from four major papers and a workshop. These insights stress the importance of teaching maritime cyber resilience widely. The first two papers address how a navigator’s workday now is affected by cyber risks and how the navigator experience those risks. The final papers present humancentred design approach to developing and conducting maritime cyber resilience training, as well as a novel procedural framework. The final discussions in the thesis link these findings with existing knowledge to suggest how MET can really make a difference in improving cyber security at sea. In conclusion, this thesis offers insights both for researchers and for maritime professionals. As technology keeps advancing, the findings here offer a roadmap for future research and training efforts.
Has parts
Paper 1: Erstad, Erlend; Ostnes, Runar; Lund, Mass Soldal. An Operational Approach to Maritime Cyber Resilience. TransNav, International Journal on Marine Navigation and Safety of Sea Transportation 2021 ;Volum 15.(1) s. 27-34 https://doi.org/10.12716/1001.15.01.01 distributed under the terms of the Creative Commons Attribution License (CC BY-NC)Paper 2: Erstad, Erlend; Lund, Mass Soldal; Ostnes, Runar. Navigating through Cyber Threats, A Maritime Navigator’s Experience. Applied Human Factors and Ergonomics International (AHFE International) 2022 ;Volum 53. s. 84-91 https://doi.org/10.54941/ahfe1002205 distributed under the terms of the Creative Commons Attribution License (CC BY)
Paper 3: Erstad, Erlend; Hopcraft, Rory; Vineetha Harish, Avanthika; Tam, Kimberly. A human-centred design approach for the development and conducting of maritime cyber resilience training. WMU Journal of Maritime Affairs (JoMA) 2023 ;Volum 22. s. 241-266 https://doi.org/10.1007/s13437-023-00304-7 This article is licensed under a Creative Commons Attribution 4.0 International License CC BY
Paper 4: Erstad, Erlend; Hopcraft, R.; Palbar, J.D.; Tam, K.. CERP: A Maritime Cyber Risk Decision Making Tool. TransNav, International Journal on Marine Navigation and Safety of Sea Transportation 2023 ;Volum 17.(2) s. 269-279 https://doi.org/10.12716/1001.17.02.02 distributed under the terms of the Creative Commons Attribution License (CC BY)
Workshop report: Erstad, E., Larsen, M. H., Lund, M. S., & Ostnes, R. (2022). Maritime Cyber Simulator Scenario Workshop report. https://ntnuopen.ntnu.no/ntnu-xmlui/handle/11250/3037765