Digital resilience
Cyber Security for Ports and Port Systems
Flagship programme
Port cyber risk as an operational problem rather than an IT one: assessing exposure across the terminal, designing controls that survive contact with operations, and rehearsing the response.
- Duration
- 5 days
- Modules
- 10
- Delivery
- Face-to-face
- Training pillar
- Digital resilience
Purpose
Equip port personnel with the knowledge and practical tools required to identify, assess and manage cyber risks while sustaining safe, secure and resilient port operations.
Who it is for
Port and terminal managers; business-process owners; ICT, OT, engineering and maintenance teams; security officers and incident responders; risk, legal, compliance, procurement and continuity personnel; contractors and technology providers.
Duration and delivery
5 days; 10 modules delivered through presentations, guided discussion, port case studies, video, simulations and group exercises.
Module matrix
10 modules. Learning outcomes and content as approved.
01Day 1Cyber-Security Awareness
Learning outcomes
Recognise current threat actors, attack methods, vulnerabilities and human factors affecting port operations. Apply critical thinking to port cyber-risk scenarios.
Module content
Port cyber-threat landscape. Threat actors, motivations and attack paths. Common vulnerabilities and human factors. Awareness responsibilities and scenario analysis.
02Day 1Protecting Information and Incident Response
Learning outcomes
Apply data-protection, access-control and information-security principles. Practise detecting, reporting, responding to and recovering from incidents.
Module content
Information classification and protection. Identity and access control. Reporting indicators and escalation. Initial containment, response, recovery and lessons learned.
03Day 2Cyber Security in the Port Context
Learning outcomes
Explain the port operating environment and processes from entry to exit. Relate digital systems to operational activities.
Module content
Port and terminal processes. Vessel, cargo, access-control and business systems. ICT, OT, automation and third-party interdependencies. Digital dependence and operational consequences.
04Day 2Critical Assets, Threats and Consequences
Learning outcomes
Identify targetable ICT and OT assets. Assess common vulnerabilities. Evaluate operational, safety, financial, legal and reputational impacts.
Module content
Critical asset identification. Threat and vulnerability assessment. Consequence analysis. Existing controls and risk prioritisation.
05Day 3IMO Guidelines on Maritime Cyber Risk Management
Learning outcomes
Interpret IMO Guidelines on Maritime Cyber Risk Management. Apply the functional elements in a port setting.
Module content
MSC-FAL.1/Circ.3 and related maritime cyber-risk guidance. Governance and integration with port security arrangements. Identify, protect, detect, respond and recover functions. Application to port and port-facility operations.
06Day 3Developing a Cyber Security Assessment
Learning outcomes
Identify assets, threats, vulnerabilities, controls and residual risks. Develop findings that inform security planning.
Module content
Assessment scope and methodology. Asset, threat and vulnerability identification. Control effectiveness and residual risk. Risk evaluation, prioritisation and documented findings.
07Day 4Developing a Cyber Security Plan
Learning outcomes
Translate assessment findings into proportionate measures. Align the Cyber Security Plan with the Port or Port Facility Security Plan.
Module content
Preventive and protective measures. Detection, response and recovery measures. Prioritised action plan, responsibilities and timelines. Integration with existing security plans and procedures.
08Day 4Managing Cyber Security for Ports and Port Systems
Learning outcomes
Define governance structures, responsibilities, reporting lines and coordination arrangements.
Module content
Cyber-risk ownership and accountability. Coordination among operations, ICT/OT, security, legal, procurement and leadership. Third-party and supply-chain governance. Reporting, documentation and performance oversight.
09Day 5Cyber-Security Leadership and Strategy
Learning outcomes
Set leadership priorities, risk ownership and resource allocation. Establish monitoring and a culture of awareness and accountability.
Module content
Leadership direction and strategy. Risk appetite, ownership and resource prioritisation. Performance measures and management reporting. Awareness, behaviour, competence and security culture.
10Day 5Operational Resilience
Learning outcomes
Apply continuity, contingency, crisis-management and recovery principles. Sustain or restore critical port services during and after an incident.
Module content
Critical-service continuity. Contingency and manual workarounds. Crisis coordination and communications. Recovery priorities, restoration and post-incident improvement.
Assessment
Pre- and post-training assessments, evaluated participation in practical exercises and review of draft Cyber Security Assessment and Cyber Security Plan components.
Certification
Certificate of completion for participants who complete the programme.
01 / The rest of the portfolio
Four more programmes.
Maritime law
Maritime Law and Shipping Contracts
Commercial shipping
Laytime and Demurrage
Sustainability
ESG in Shipping
Finance and risk
Ship Finance, Maritime Credit and Risk Management