Ship Captain's Readiness to Face the Threat of Cyber Attack on the Ship's Navigation System
DOI:
https://doi.org/10.59261/jequi.v8i3.380Keywords:
Maritime Cybersecurity, Cyber Threats, Attack Trees, Ship Navigation System, Risk AssessmentAbstract
Background: The maritime sector is highly dependent on technological infrastructure, including port management systems, ship monitoring systems, and satellite-based communication systems. This infrastructure is crucial for ensuring the smooth flow of goods between countries and maintaining port operations and safe ship navigation.
Objective: This study identifies cyberattack pathways targeting shipboard navigation and operational technology (OT) systems in Indonesian waters, develops attack-tree scenarios for those pathways, and evaluates ship captains' readiness to detect and respond to them.
Methods: Attack-tree modeling was used to describe, analyze, and represent potential attack scenarios. The model draws on a literature review and interviews with twelve maritime experts: four captains and deck officers, four cybersecurity specialists, and four technical consultants. Validation was conducted through two Delphi rounds until an agreement level of 80% was reached.
Results: Four attack trees produced eighteen validated attack paths across three primary attack goals: crashing the ship (five paths), sinking the ship (three paths), and disabling the ship (six paths), along with four shared enabling paths. Experts rated the attack scenarios for crashing and disabling the ship as highly feasible, whereas sinking the ship was considered unlikely. Overall, nine attack paths were classified as high risk.
Conclusion: The attack tree serves not only as a vulnerability assessment tool but also as a structured, prioritized risk assessment instrument for maritime cybersecurity. Mapping each validated attack path to International Maritime Organization (IMO) and National Institute of Standards and Technology (NIST) cybersecurity controls enables shipping companies
Downloads
References
Androjna, A., Satler, T. B., Pavic, I., & Greidanus, H. (2020). Assessing Cyber Challenges Of Maritime Navigation. Journal Of Marine Science And Engineering, 8(10), 776. https://doi.org/10.3390/Jmse8100776
Anwar, A., Suharso, A. R., Hendartono, A., Wantoro, W. B., Sirait, E., & Purwanto, P. (2023). Pengembangan Media Pembelajaran Electronic Chart Display And Information System Menggunakan Software Visual Basic 6. Konstruktivisme: Jurnal Pendidikan Dan Pembelajaran, 15(1), 15–26.
Ashfaq Uz Zaman, S. M., Qamar, F., Mohd, M., Sabrina Suhaimi, N. H., & Khandakar, A. (2026). A Review Of Automatic Identification System Approaches For Maritime Cyber Security. Security And Communication Networks, 2026(1), 5898106.
Balduzzi, M., Pasta, A., & Wilhoit, K. (2014). A Security Evaluation Of Ais Automated Identification System. In Proceedings Of The 30th Annual Computer Security Applications Conference (Acsac 2014) (Pp. 436–445). Association For Computing Machinery. https://doi.org/10.1145/2664243.2664257
Bueger, C. (2015). What Is Maritime Security? Marine Policy, 53, 159–164. https://doi.org/10.1016/J.Marpol.2014.12.005
Cao, Q., Chi, C., & Shan, J. (2025). Can Artificial Intelligence Technology Reduce Carbon Emissions? A Global Perspective. Energy Economics, 143, 108285.
Cybersecurity, E. U. A. For. (2025). Enisa Threat Landscape 2025. European Union Agency For Cybersecurity. https://www.Enisa.Europa.Eu/Publications/Enisa-Threat-Landscape-2025
Erbas, M., Khalil, S. M., & Tsiopoulos, L. (2024). Systematic Literature Review Of Threat Modeling And Risk Assessment In Ship Cybersecurity. Ocean Engineering, 306, 118059. https://doi.org/10.1016/J.Oceaneng.2024.118059
Erdoğan, A., & Erdoğan, N. S. (2025). Cybersecurity And Privacy In Maritime Security: Theories, Challenges, Case Studies And Future Prospects. Güvenlik Bilimleri Dergisi, Kolluk Uygulamaları Ve Güvenlik Teknolojileri Özel Sayısı, 258–287.
Fitton, O., Prince, D., Germond, B., & Lacy, M. (2015). The Future Of Maritime Cyber Security. Lancaster University. https://Eprints.Lancs.Ac.Uk/Id/Eprint/72696/
Ghosh, A., & Sourav, S. (2026). Shock Propagation And Port-Congestion Hysteresis In Maritime Disruptions: Evidence From Covid-19, The Suez Blockage, And The Red Sea Crisis. Maritime Economics & Logistics, 1–36.
Huso, D., Munim, Z. H., Chai, Y., Kim, T. E., & Bhuiyan, Z. (2025). Factors Influencing Cybersecurity Risk And Autonomous Shipping Awareness. 2025 Ieee International Conference On Industrial Engineering And Engineering Management (IEEM), 960–964.
Jin, Y., Feng, Y., Liu, C., & Li, S. (2025). Navigating The Digital Seas: Legal Challenges And Global Governance Of Maritime Cyber Operations. Frontiers In Marine Science, 12, 1616906.
Jo, Y., Choi, O., You, J., Cha, Y., & Lee, D. H. (2022). Cyberattack Models For Ship Equipment Based On The Mitre Att&Ck Framework. Sensors, 22(5), 1860. https://doi.org/10.3390/S22051860
Kapalidis, C. (2025). Cyber Risk Assessment In The Maritime Transport Sector: Ships, Ports And Port Systems. Loughborough University.
Keskin, O. F., Lubja, K., Bahsi, H., & Tatar, U. (2025). Systematic Cyber Threat Modeling For Maritime Operations: Attack Trees For Shipboard Systems. Journal Of Marine Science And Engineering, 13(4), 645. https://doi.org/10.3390/Jmse13040645
Kiss, L., Savaliya, S. K., Schunck, C. H., Sellung, R., & Winterstetter, M. (2026). Critical Infrastructure Risk Assessment: Current Practices And Emerging Challenges. Open Identity Summit 2026, 63–77.
Kurt, Y. B., Uflaz, E., Akyuz, E., Kurt, R. E., & Turan, O. (2025). Analysis Of Human Reliability In Detecting Gps Spoofing On Ecdis In Congested Waterways Under Evidential Reasoning And Heart Approach. Computers & Security, 151, 104316. https://doi.org/10.1016/J.Cose.2025.104316
Malik, D., & Widodo, W. (2025). Analisis Pengaruh Human Faktor Terhadap Keselamatan Pelayaran Di Kapal Penumpang Perusahaan Surabaya. Jurnal Sains Dan Teknologi Maritim, 25(2), 215–228.
Mudiyanto. (2020). Analisis Kelaiklautan Kapal Terhadap Keselamatan Pelayaran Dikapal Niaga (Study Kasus Pada Perusahaan Pelayaran Kapal Penumpang Di Surabaya). Jurnal Sains Dan Teknologi Maritim, 20(1), 13–27. https://doi.org/10.33556/Jstm.V20i1.213
Negara, B. S. Dan S. (2024). Lanskap Keamanan Siber Indonesia 2023. Badan Siber Dan Sandi Negara Republik Indonesia. Https://Csirt.Kemenkeu.Go.Id/In/Post/Lanskap-Keamanan-Siber-Indonesia-2023
Nist. (2024). The Nist Cybersecurity Framework (CSF) 2.0. Https://Doi.Org/10.6028/Nist.Cswp.29
Nur, F. (2025). Analisis Peranan Alat Navigasi Ais Sebagai Pemantau Untuk Meningkatkan Keselamatan Pelayaran Di PSV S Panglima. Politeknik Ilmu Pelayaran Makassar.
Organization, I. M. (2022). Guidelines On Maritime Cyber Risk Management (Msc-Fal.1/Circ.3/Rev.2). International Maritime Organization. https://www.Uscg.Mil/Portals/0/Msc-Fal_1-Circ_3-Rev_2 - Guidelines On Maritime Cyber Risk Management %28secretariat%29.Pdf
Putra, I. N., Octavian, A., Susilo, A. K., & Prabowo, A. R. (2023). A Hybrid Ahp-Topsis For Risk Analysis In Maritime Cybersecurity Based On 3d Models. Decision Science Letters, 12(4), 759–772. https://doi.org/10.5267/J.Dsl.2023.6.005
Ramos, K. G., Rocha, I. C. N., Cedeño, T. D. D., Costa, A. C. Dos S., Ahmad, S., Essar, M. Y., & Tsagkaris, C. (2021). Suez Canal Blockage And Its Global Impact On Healthcare Amidst The Covid-19 Pandemic. International Maritime Health, 72(2), 145–146. https://doi.org/10.5603/Imh.2021.0026
Santoso, H. B., & Noviarianto. (2021). Meningkatkan Kompetensi Navigasi Mahasiswa Politeknik Maritim Negeri Indonesia Melalui Pengembangan Media Pembelajaran Electronic Chart And Display Information System (ECDIS) Simulator. Jurnal Sains Dan Teknologi Maritim, 21(2), 172–178. https://doi.org/10.33556/Jstm.V21i2.279
Suruwaky, A. M., Ndahawali, D. H., Kasim, M., Bachri, S., Komboe, A. A., Abdullah, A., Maysaroh, S., & Leatemia, B. M. (2025). Pengenalan Dan Praktik Alat Navigasi Kapal Bagi Generasi Muda Biak Pada Km Airaha 02. Buletin Swimp, 5(2), 29–38.
Sutini, & Mahendro, I. (2018). Pengenalan Teknologi Navigasi Melalui Pembelajaran Sistem Navigasi Elektronik Untuk Pemahaman Taruna Tentang Navigasi. Jurnal Sains Dan Teknologi Maritim, 18(1), 41–49. https://doi.org/10.33556/Jstm.V0i1.185
Syibli, Y. M., & Nuryaman, D. (2021). Peranan Alat Navigasi Di Kapal Untuk Meningkatkan Keselamatan Pelayaran Di Atas Kapal. Dinamika Bahari, 2(1), 39–48. https://doi.org/10.46484/Db.V2i1.250
Tam, K., & Jones, K. D. (2018). Cyber-Risk Assessment For Autonomous Ships. In 2018 International Conference On Cyber Security And Protection Of Digital Services (Cyber Security) (Pp. 1–8). IEEE. https://doi.org/10.1109/Cybersecpods.2018.8560690
Tam, K., Moara-Nkwe, K., & Jones, K. D. (2021). The Use Of Cyber Ranges In The Maritime Context: Assessing Maritime-Cyber Risks, Raising Awareness, And Providing Training. Maritime Technology And Research, 3(1), 16–30. https://doi.org/10.33175/Mtr.2021.241410
Topping, C., Dwyer, A., Michalec, O., Craggs, B., & Rashid, A. (2021). Beware Suppliers Bearing Gifts!: Analysing Coverage Of Supply Chain Cyber Security In Critical National Infrastructure Sectorial And Cross-Sectorial Frameworks. Computers & Security, 108, 102324. https://doi.org/10.1016/J.Cose.2021.102324
Uğurlu, Ö., Aydın, B., Kaya, A. Y., & Tonoğlu, F. (2026). Analysis Of Cybersecurity Threats To Ships In Maritime Transportation And Optimal System Design On Ships. Proceedings Of The Institution Of Mechanical Engineers, Part M: Journal Of Engineering For The Maritime Environment. https://doi.org/10.1177/14750902251408643
Wolff, J. (2021). How Is Technology Changing The World, And How Should The World Change Technology? Global Perspectives, 2(1), 27353. https://doi.org/10.1525/Gp.2021.27353
Downloads
Published
Issue
Section
License
Copyright (c) 2026 Agus Widodo, Siwi Woro Herningsih, Roma Dormawaty, Riza Nur Amala

This work is licensed under a Creative Commons Attribution-ShareAlike 4.0 International License.
Authors who publish with this journal agree to the following terms:
- Authors retain copyright and grant the journal right of first publication with the work simultaneously licensed under a Creative Commons Attribution-ShareAlike 4.0 International (CC-BY-SA). that allows others to share the work with an acknowledgement of the work's authorship and initial publication in this journal.
- Authors are able to enter into separate, additional contractual arrangements for the non-exclusive distribution of the journal's published version of the work (e.g., post it to an institutional repository or publish it in a book), with an acknowledgement of its initial publication in this journal.
- Authors are permitted and encouraged to post their work online (e.g., in institutional repositories or on their website) prior to and during the submission process, as it can lead to productive exchanges, as well as earlier and greater citation of published work.




