Times are displayed in (UTC-04:00) Eastern Time (US & Canada) Change
Autonomous Vessel Cybersecurity: Securing the Underlying Foundation
As the technologies that empower autonomous vessels mature and grow, so too do the vulnerabilities associated with their use. Improper design planning, as well as continual cyber hygiene and scrutiny, could have disastrous implications.
There are numerous technologies, platforms, devices, software applications, firmware versions, data flows, and human processes involved in a single autonomous vessel solution, and the skillsets and disciplines required to properly secure each vary dramatically. It is often beyond the skillsets of a single person to properly assess and secure the compete environment. To properly secure the complete lifecycle, a top-down, wholistic approach is required.
This session will start with an illustration of the technologies involved, including:
• An organizations internal network
• The public cloud
• Private clouds
• A variety of vessel connectivity solutions
• Third-party actors
• Onboard devices and equipment
• Data in motion and at rest
• Sensor and device firmware
• IoT Software and communication protocols
• Identification of passwords, connection strings, and keys
• Network and encryption protocols
It will then condense all these areas into a complete and detailed Attack Surface Map. For each element on the Attack Surface Map, a comprehensive approach to securing that element will be presented, including the various techniques, pit falls, and approaches to doing so.
Along the way, the presentation will provide valuable insight and guidance into:
• Vetting the cybersecurity hygiene of vendors and subcontractors
• Mapping the elements of the Attack Surface Map to specific regulatory cyber frameworks items (i.e. ID-AM-1, ID-AM-2, etc.), including NIST 800-153. NIST CSF, SOC and others
• Creating a continual cyber hygiene and maintenance process to maintain the autonomous vessel after go-live
• Proper reporting to stakeholders and regulatory authorities as to the cyber state of the solution on an ongoing basis
The presentation will be explained in simple terms and not assume the audience has steep technical or cybersecurity expertise.
There are numerous technologies, platforms, devices, software applications, firmware versions, data flows, and human processes involved in a single autonomous vessel solution, and the skillsets and disciplines required to properly secure each vary dramatically. It is often beyond the skillsets of a single person to properly assess and secure the compete environment. To properly secure the complete lifecycle, a top-down, wholistic approach is required.
This session will start with an illustration of the technologies involved, including:
• An organizations internal network
• The public cloud
• Private clouds
• A variety of vessel connectivity solutions
• Third-party actors
• Onboard devices and equipment
• Data in motion and at rest
• Sensor and device firmware
• IoT Software and communication protocols
• Identification of passwords, connection strings, and keys
• Network and encryption protocols
It will then condense all these areas into a complete and detailed Attack Surface Map. For each element on the Attack Surface Map, a comprehensive approach to securing that element will be presented, including the various techniques, pit falls, and approaches to doing so.
Along the way, the presentation will provide valuable insight and guidance into:
• Vetting the cybersecurity hygiene of vendors and subcontractors
• Mapping the elements of the Attack Surface Map to specific regulatory cyber frameworks items (i.e. ID-AM-1, ID-AM-2, etc.), including NIST 800-153. NIST CSF, SOC and others
• Creating a continual cyber hygiene and maintenance process to maintain the autonomous vessel after go-live
• Proper reporting to stakeholders and regulatory authorities as to the cyber state of the solution on an ongoing basis
The presentation will be explained in simple terms and not assume the audience has steep technical or cybersecurity expertise.
About the Presenter

Dean Shoultz
CTO
MarineCFO
Dean has been in the software and technology industry since 1985. Over that time, he has successfully envisioned and architected extremely mission-critical business applications, and the teams involved in supporting and servicing them. Today, thousands of companies use and distribute the technology Dean has built, or that has been built under his direct leadership and vision.
Most recently, Dean is a co-founder and the CTO/CSA of CompliCyber and MarineCFO
CompliCyber (www.complicyber.com) is a cybersecurity management and regulatory reporting platform. Organizations use it to methodically manage their cybersecurity strategy, monitor the cyber readiness of contractors, report and respond to incidents, and engender a culture of cyber hygiene.
MarineCFO (www.MarineCFO.com) is a cloud and mobile marine transportation ERP system. Maritime operators use the platform to manage fleets, operations, maintenance, and financial accounting. Vessel 365 is a resilient onboard application that collects operational data, as well as sensor data for AI and machine learning purposes.
In his spare time, Dean enjoys spending time with his family, playing the guitar, and fishing along the bays and bayous of his home town of Houma, deep in southern Louisiana.
Most recently, Dean is a co-founder and the CTO/CSA of CompliCyber and MarineCFO
CompliCyber (www.complicyber.com) is a cybersecurity management and regulatory reporting platform. Organizations use it to methodically manage their cybersecurity strategy, monitor the cyber readiness of contractors, report and respond to incidents, and engender a culture of cyber hygiene.
MarineCFO (www.MarineCFO.com) is a cloud and mobile marine transportation ERP system. Maritime operators use the platform to manage fleets, operations, maintenance, and financial accounting. Vessel 365 is a resilient onboard application that collects operational data, as well as sensor data for AI and machine learning purposes.
In his spare time, Dean enjoys spending time with his family, playing the guitar, and fishing along the bays and bayous of his home town of Houma, deep in southern Louisiana.
Presentation
Autonomous Vessel Cybersecurity: Securing the Underlying Foundation
Description