In late August, the United States Coast Guard boarded two foreign-flagged commercial vessels in the Gulf of Mexico after indications that both ships’ operational and information-technology networks had been compromised. Federal agencies are now reported to be tracking cyber threats against nearly 20 vessels worldwide, with the Coast Guard requesting advance notice before any of them enters a US port. No injuries, no grounding, no spill, . . . this time. Maritime cyber risk is “a thing”.
Strip away the geopolitics and the methods are mundane. CyberOwl, a maritime-security firm that monitors vessel networks, reports that in more than half the intrusions it detected this year, malware reached the ship the oldest way there is: a USB stick or other removable device carried aboard. Most of the rest arrived through an internet download or a phishing email. These are not exotic weapons. They are the same vectors that have plagued shoreside business for two decades, now afloat.
The reason they work at sea is structural. As DNV’s cyber-research lead has noted, shipboard operational technology is frequently old equipment that cannot easily be patched — systems designed when an attack on a vessel was barely conceivable. Add always-on satellite connectivity, crews rotating through unfamiliar systems, and technicians plugging laptops into bridge equipment in port, and you have an attack surface no modern IT department would tolerate ashore.
Here the conversation gets uncomfortable for our industry — and where owners deserve candor rather than a sales pitch. The incidents generating the headlines are, in large part, the incidents marine insurance is least able to pay. European investigators suspected Russian military hackers behind the immobilization of an MSC ferry in a French port last December. A hacking group disrupted communications on more than 100 Iranian tankers in early 2025. A DNV expert described this activity plainly as “part of the warfare” — as much about sowing instability as causing damage.
State-sponsored and warlike cyber operations sit squarely inside the war exclusion that runs through virtually every marine wording (CL380 and its successors) and they are, for the most part, uninsurable by any private carrier. That is not a gap a clever endorsement closes; it is a deliberate boundary the market draws because nation-state accumulation risk cannot be priced or diversified like ordinary loss. An owner who believes a cyber policy will answer an act of cyber warfare has misread the product, and any underwriter who implies otherwise is selling something they cannot deliver.
So the right question for a shipowner is not “am I covered if a state actor attacks my fleet?” It is narrower and more useful: am I covered for the other half of the risk, i.e., the criminal, the negligent, and the accidental. The ransomware crew that encrypts a cargo system for money. The contractor’s infected USB drive. The phishing email a tired officer clicks at 0300. Those are insurable losses, and they are the bulk of what CyberOwl is actually counting.
What makes that half insurable is discipline — and this is where underwriting and risk management stop being separate conversations. Segregation between OT and crew networks. Multi-factor authentication on every remote connection. Prompt patching of what can be patched, and compensating controls for what cannot. A removable-media policy that treats every USB device as hostile until scanned. Weekly, isolated backups that ransomware cannot reach. None of this is novel; it is the substance of the BIMCO Guidelines on Cyber Security Onboard Ships. It is also the difference between a vessel that shrugs off a phishing attempt and one that ends up boarded in the Gulf of Mexico. For a carrier, these controls are not box-ticking — they are the conditions that make the risk assumable at a rational price, which is precisely why a serious wording is built around them rather than around them being ignored.
Our view at Janus is that marine cyber is underwritten honestly only when the wording says plainly what it covers and what it does not: a real, bounded response to criminal and accidental cyber loss, and no pretense of covering acts of war. That candor protects the owner, who then knows what they are holding, and the carrier, which knows what it has assumed. A policy that gestures at everything and pays nothing serves no one, . . . least of all with the Coast Guard on the gangway.
The vessels being tracked today will clear, and the headlines will move on. The exposure will not. Every ship at sea is now a networked industrial site with a rotating workforce and equipment that predates the threat, and the losses that follow will divide, cleanly, into the ones a disciplined owner can insure and the ones no one can. Knowing which is which before an incident, not after, is the whole of the exercise.
~ C. Constantin Poindexter, MA, JD, CPCU, AFSB, ASLI, ARe, AINS, AIS, CPLP


















































