
The case
The systems digitised faster than the people were trained.
More than eighty per cent of world merchandise trade by volume moves by sea. Capability, not awareness, is the binding constraint: institutions across the region know they are exposed, and what they lack is trained people.
01 / The exposure is real
Two incidents, both operational, both recent.
These are not hypotheticals used to sell a course. They are documented events with published consequences.
In June 2017 the NotPetya malware reached Maersk through accounting software in Ukraine and took the company's applications and data offline worldwide, with losses reported in the region of USD 200 to 300 million.
In July 2021 a ransomware attack on Transnet forced the declaration of force majeure at Durban, Cape Town, Ngqura and Port Elizabeth, and operations fell back to paper. Durban handles around sixty per cent of South Africa's container traffic.
02 / The standards moved
The requirement is no longer advisory.
The IMO adopted Guidelines on Maritime Cyber Risk Management (MSC-FAL.1/Circ.3) in 2017 and issued Revision 3 in April 2025. The United States Coast Guard maritime cyber rule took effect in July 2025 and reaches foreign vessels through Port State Control, so trade lanes feel it well beyond US waters.
Cyber risk now sits inside ISPS expectations rather than alongside them. The same pattern holds across the rest of the portfolio: environmental and social reporting, charterparty exposure, and ship-finance risk are all governed by instruments that have moved faster than the training available in the region.
03 / The pipeline is thin
The sector competes for talent it has never introduced itself to.
Maritime careers remain invisible to most young people in the region, including in coastal communities that live beside the industry. Employers report that they cannot find people, while a large youth population looks for work it does not know exists. Both are true at once.
Capability, not awareness, is the binding constraint. That is a training problem, and it is solvable.
Institutions across the region know they are exposed. What they lack is trained people who can carry out an assessment, write a plan, run an exercise and hold the line when an incident starts. That is the gap MarineLearn was built to address, and it is why the portfolio is five programmes in one specialisation rather than a catalogue of unrelated short courses.
Sources
- Trade volumes
- UNCTAD Review of Maritime Transport.
- IMO guidelines
- IMO MSC-FAL.1/Circ.3, adopted 2017; Revision 3 issued April 2025.
- US requirements
- United States Coast Guard maritime cyber rule, effective July 2025.
- Incidents
- Public reporting on the 2017 NotPetya attack on Maersk and the 2021 ransomware attack on Transnet.
Recognise your institution in any of this?
The gap is usually narrower and more specific than it looks from the outside. Tell us what your people currently cannot do, and we will be straight with you about whether we can close it.