Survey-based analysis of cybersecurity awareness of Turkish seafarers

تحليل قائم على المسح للوعي بالأمن السيبراني للبحارة الأتراك

👤 Ivar Moen, Aybars Oruc, Ahmed Amro, Vasileios Gkioulos, Georgios Kavallieratos 📄 Int. J. Inf. Secur. 23, 3153–3178 (2024) 🔗 10.1007/s10207-024-00884-2 ✓ CC BY 4.0

الملخص

في السنوات الأخيرة، أصبحت السفن رقمية بشكل متزايد، مما يعكس الاتجاهات المجتمعية الأوسع. ونتيجة لذلك، أصبحت العمليات البحرية هدفاً جذاباً لمهاجمي التهديدات السيبرانية. على الرغم من التدريب المحدود في الأمن السيبراني الذي يتلقاه البحارة، إلا أنه يُتوقع منهم العمل في بيئات متقدمة تقنياً. تتجلى أهمية الوعي بالأمن السيبراني، لكن مدى معرفة البحارة في هذا المجال لا يزال غير مؤكد. تبحث هذه المقالة في ثلاثة جوانب رئيسية: (1) الوضع الحالي للأمن السيبراني على متن سفن الشحن، (2) وعي البحارة بالأمن السيبراني، و(3) التحسينات المحتملة في وعي البحارة بالأمن السيبراني. لتحقيق ذلك، تم إجراء مراجعة للأدبيات لجمع وتحليل الأبحاث الحالية، مدعومة باستبيان استقصائي استهدف البحارة الأتراك. تدعم نتائجنا زيادة الاستثمار في برامج التوعية والتدريب، بما في ذلك جهود التوعية بالأمن السيبراني على مستوى المؤسسة، وتدريب أكثر تواتراً، وتدريب إلزامي لجميع البحارة من خلال اتفاقية معايير التدريب والشهادة والخفارة (STCW)، وتعيين ضابط الأمن السيبراني (CySO) لضمان مستويات مرضية من الأمن السيبراني على متن السفن. نظراً لأن هذه المقالة تركز على الموضوعات عالية المستوى من خلال تقييم الحالة العامة للأمن السيبراني البحري ووعي البحارة بالأمن السيبراني، فهي لا تتعمق في الاعتبارات التفصيلية لبرامج التوعية والتدريب. ومع ذلك، فهي تضع الأساس للبحث المستقبلي في هذا المجال.

1. المقدمة

في الاقتصاد العالمي المعاصر، يعتبر النقل البحري العمود الفقري للتجارة الدولية، حيث يتعامل مع ما يقرب من جميع حركة نقل البضائع العالمية [3، 4]. يعمل هذا القطاع المحوري كبنية تحتية حيوية، تدعم الازدهار الاقتصادي وتسهل توزيع السلع الأساسية [40]. بينما نتقدم في عصر التحول الرقمي، تطورت السفن إلى أنظمة بيئية تكنولوجية معقدة، تتضمن أنظمة تكنولوجيا المعلومات (IT) وتكنولوجيا التشغيل (OT) المتطورة [9، 22]. ومع ذلك، مع زيادة تعقيد هذه الأنظمة، تزداد احتمالية التهديدات السيبرانية، خاصة عندما يفتقر المشغلون الأساسيون لهذه الأنظمة، وهم البحارة، غالباً إلى التدريب الرسمي في مجال تكنولوجيا المعلومات [32]. على الرغم من خبراتهم البحرية الواسعة، لا يتم تجهيز البحارة عادةً بمهارات قوية في الأمن السيبراني، وهي معضلة أبرزها نقاد برامج التعليم البحري [24، 49].

كشفت اتجاهات الرقمنة التاريخية أن الأخطاء البشرية تشكل باستمرار تهديداً سيبرانياً كبيراً، غالباً بسبب عدم كفاية وعي المستخدم [76]. مع ازدياد تعقيد البيئات الرقمية، تزداد احتمالية حدوث مثل هذه الأخطاء البشرية وتأثيرها اللاحق على أمن النظام [23]. لذلك، فإن فهم حالة الوعي بالأمن السيبراني بين البحارة هو خطوة أولى حاسمة نحو تحديد نقاط الضعف المحتملة ووضع تدابير وقائية فعالة. تعالج أبحاثنا ثلاثة أسئلة بحثية رئيسية: (1) ما هو الوضع الحالي للأمن السيبراني على متن السفن؟ (2) ما هو مستوى الوعي بالأمن السيبراني بين البحارة؟ (3) كيف يمكننا تعزيز الوعي بالأمن السيبراني بين البحارة؟ تركز هذه الأسئلة على فهم المشهد الحالي للأمن السيبراني على متن سفن الشحن وتقييم وعي البحارة به. يتم تنظيم بقية هذه المقالة على النحو التالي: القسم 2 يؤسس الخلفية النظرية اللازمة لفهم مجال الأمن السيبراني البحري. القسم 3 يعرض الأبحاث ذات الصلة. القسم 4 يصف المنهجية المستخدمة. القسم 5 يعرض النتائج ويحللها. القسم 6 يناقش النتائج ويقترح تحسينات. القسم 7 يختتم المقالة ويناقش حدودها.

2. الخلفية

2.1 الأمن السيبراني البحري

لفهم كيف يمكن تحسين الأمن السيبراني البحري، من المهم أولاً أن نكون على دراية بحالته الحالية، بما في ذلك الجوانب الفنية والتنظيمية والتشغيلية. الهيكل الهرمي للسفينة يتكون من مستويات الإدارة والتشغيل والدعم [32]. يشمل مستوى الإدارة الربان (القبطان) والضباط الكبار مثل الضابط الأول وكبير المهندسين. الضباط المبتدئون يشكلون مستوى التشغيل، ومستوى الدعم يتكون من الأفراد البحريين.

شهد قطاع الأمن السيبراني البحري مستويات متفاوتة من التطور. يرى بعض الباحثين أن الأمن السيبراني البحري غير كافٍ بسبب غياب سياسات أمن سيبراني شاملة في إجراءات السفن [69، 72، 73]. بينما يؤكد آخرون على ضرورة اتباع نهج شامل يوازن بين التدخلات التقنية والاعتبارات البشرية [41]. أظهرت الدراسات أن السفن الحديثة مجهزة بأنظمة معقدة مثل النظام العالمي للملاحة عبر الأقمار الصناعية (GNSS)، ونظام عرض الخرائط الإلكترونية ومعلوماتها (ECDIS)، وأنظمة الاتصالات الخارجية، لكن هذه الأنظمة تعاني من ثغرات أمنية محتملة [38]. الاعتماد المتزايد على الإنترنت وأجهزة الكمبيوتر غير المحمية ونقص التدريب الأمني المناسب للطاقم يزيد بشكل كبير من خطر نجاح الهجمات السيبرانية [21].

2.2 الوعي بالأمن السيبراني وتدريب البحارة

يلعب البحارة دوراً أساسياً في ضمان العمليات الآمنة والفعالة للسفن. يقترح McGillivary [46] أن طاقم السفينة والإدارة غالباً ما يجدون أنفسهم في حيرة في حالة حدوث خرق أمني سيبراني. أظهرت دراسات باحثين مثل Bolat و Kayişoğlu [10]، و Alcaide و Llave [1]، و Mraković و Vojinović [49]، و Senarak [64، 65] مستويات غير كافية من الوعي بالأمن السيبراني بين البحارة. اتفاقية STCW، التي تشكل الأساس لمعظم التدريب البحري، لا تذكر الأمن السيبراني صراحة. ومع ذلك، فإن الاعتراف المتزايد بأهمية التدريب على الأمن السيبراني ينعكس في المنظمات التي تقدم مثل هذا التدريب.

2.3 تحسين حالة الوعي بالأمن السيبراني البحري

يقترح العديد من الباحثين تدابير مختلفة تهدف إلى تحسين حالة الأمن السيبراني في القطاع البحري. من المهم دمج الوعي بالأمن السيبراني في جميع مستويات المنظمة، ويجب أن يبدأ الجهد من القمة [2، 37، 48، 59]. هناك حاجة إلى معايير تنظيمية أو إرشادات معززة [36]. يمكن أن يساعد دمج التدريب على الأمن السيبراني في العناصر الإلزامية لاتفاقية STCW في تحسين الكفاءات الرقمية [25]. كما أن إعادة تصميم الأدوار التنظيمية قد تكون مفيدة، مثل تقديم ضابط الأمن السيبراني (CySO) المسؤول عن حماية حالة الأمن السيبراني الشاملة للسفينة والمؤسسة بأكملها [11].

3. الأعمال ذات الصلة

تم إجراء مراجعة الأدبيات بطريقة منهجية، مكيفة من خطوات Okoli [52] لإجراء مراجعات الأدبيات. تضمنت هذه المراجعة خمس خطوات: تحديد الغرض، البحث عن الأدبيات واختيارها، استخراج البيانات وتقييم الجودة، تجميع البيانات، وكتابة المراجعة. تم استخدام محركات البحث Oria و Web of Science و Engineering Village، مع سلاسل بحث مثل "maritime cybersecurity" و "maritime cybersecurity awareness" و "maritime cybersecurity training". أسفر البحث عن 559 نتيجة، تم اختيار 35 ورقة منها للفحص الأولي.

أجرى Alcaide و Llave [1] بحثاً حول معرفة الأمن السيبراني للمهنيين البحريين باستبيان عبر الإنترنت تلقى 124 رداً. أشار الباحثون إلى أن 33٪ من المشاركين تعرضوا لحادث سيبراني خلال العام الماضي، و 40٪ يشاركون كلمات المرور مع زملائهم. أجرى Mraković و Vojinović [49] دراسة لتقييم مستوى الوعي بالأمن السيبراني للبحارة في الجبل الأسود باستبيان وزع على 429 مشاركاً. أشارت النتائج إلى مستوى خطر متوسط، مما يشير إلى مستوى ضعيف من الوعي. أجرى Bolat و Kayişoğlu [10] بحثاً لتقييم تأثير التدابير المختلفة على الوعي بالأمن السيبراني للبحارة الأتراك، وجدوا أن التعليم عامل مهم في تحسين الوعي، وأن معرفة الحوادث السيبرانية تؤثر على الوعي.

4. المنهجية

4.1 منهجية الاستبيان

تم تطوير الاستبيان باستخدام إطار منهجي وصفه العديد من الباحثين البارزين، بما في ذلك Lee [42] و Saris و Gallhofer [63] و Burgess [12]. تم اتباع المراحل السبع التي أوضحها Burgess بدقة: تحديد أهداف البحث، تحديد المجتمع والعينة، تحديد طريقة جمع الردود، تصميم الاستبيان، إجراء المسح التجريبي، تنفيذ المسح الرئيسي، وتحليل البيانات. استهدف الاستبيان المهنيين البحريين الأتراك، سواء البحارة النشطين أو موظفي المكاتب من ذوي الخلفية البحرية. كان عدد البحارة الأتراك حوالي 28,000 في عام 2021 [29]. تم إدارة الاستبيان من خلال أداة Nettskjema بجامعة أوسلو. تألف الاستبيان من 27 سؤالاً بأنماط مختلفة. تمت ترجمة الاستبيان إلى اللغة التركية قبل التوزيع. تم توزيع الاستبيان على مدى خمسة أسابيع في سبتمبر وأكتوبر 2022.

4.2 الاعتبارات الأخلاقية

بدأت عملية جمع البيانات بعد الحصول على الموافقة من الوكالة النرويجية للخدمات المشتركة في التعليم والبحث (Sikt). كانت المشاركة في الاستبيان طوعية بالكامل، وتم الحصول على الموافقة المستنيرة للمشاركين. لم يحتوي الاستبيان على أسئلة تجمع معلومات شخصية أو قابلة للتحديد. تم جمع عناوين البريد الإلكتروني للحفاظ على تفرد الردود، ثم تم إزالتها بعد ذلك.

5. النتائج والتحليل

5.1 عينة السكان ومستوى الثقة

تم استلام 117 رداً في البداية. بعد عملية التحقق، تم تحديد 115 رداً فريداً. استبعد التحليل خمسة مشاركين لعدم وجود خبرة بحرية لديهم، مما أدى إلى 110 ردود نهائية. كانت فترة الثقة ±9.52٪ عند مستوى ثقة 95٪، وهو ما يعتبر تمثيلاً مقبولاً لإجمالي عدد 28,000 بحار.

5.2 البيانات الديموغرافية

أظهرت البيانات الديموغرافية أن معظم المشاركين لديهم خبرة كبيرة في القطاع البحري، ومعظمهم من كبار الضباط. الغالبية العظمى عملت على سفن الشحن الجاف والناقلات. كان لدى 65.5٪ من المشاركين شكل من أشكال التعليم أو التدريب في الأمن السيبراني أو تكنولوجيا المعلومات، بينما لم يكن لدى 34.5٪ أي تعليم في هذا المجال.

5.3 التصور الشخصي للأمن السيبراني

أظهرت النتائج أن 48.2٪ من المشاركين لا يتلقون تدريباً على الأمن السيبراني أبداً. يفضل معظم المشاركين (42.7٪) مزيجاً من الدراسة الذاتية والتدريب الشخصي وعبر الإنترنت. يعتقد 77.3٪ من المشاركين أن هناك حاجة لتدريب إضافي على الأمن السيبراني. يعتقد 60.0٪ أن التدريب على الأمن السيبراني يجب أن يكون إلزامياً كجزء من اتفاقية STCW. يعتقد 51.8٪ أن الأمن السيبراني مهم للطاقم الأعلى رتبة. كان 90٪ على دراية بالتهديدات السيبرانية. أشار 60.0٪ إلى وجود إرشادات لتحديث أنظمة الملاحة.

5.4 السلوك في سيناريوهات الأمن السيبراني

في السيناريوهات الستة المقدمة للمشاركين، أظهر معظمهم سلوكاً مناسباً في مجال الأمن السيبراني: 88.2٪ لن يشاركوا كلمة مرور Wi-Fi مع شخص غريب في الميناء، لم يتبع أي مشارك تعليمات بريد إلكتروني مشبوه، 80٪ سيختارون كلمة مرور مختلفة تماماً عند الطلب، 88.2٪ سيتجاهلون أو يبلغون عن بريد إلكتروني يسأل عن الإجراءات الأمنية للسفينة، 88.2٪ سيبلغون عن وجود USB عُثر عليه مشرفهم، و 70.9٪ سيخزنون كلمة المرور في قائمة مخصصة على متن السفينة. ومع ذلك، اختار ما بين 5.5٪ و 14.5٪ من المشاركين إجابات أقل استحساناً في كل سيناريو، مما يشير إلى وجود مجال للتحسين.

6. المناقشة

6.1 تصور الأمن السيبراني

تشير البيانات المتعلقة بموضوعات محددة تتعلق بالأمن السيبراني إلى أن الحالة العامة للوعي أفضل قليلاً مما كانت عليه في الدراسات الموصوفة في قسم الخلفية. كان لدى معظم المشاركين وعي بالأمن السيبراني متعلق بالعمل، حيث تعرف 90٪ على التهديدات السيبرانية. كان 48.2٪ من المشاركين لا يتلقون تدريباً على الأمن السيبراني، وهو رقم مقلق. يختلف تواتر التدريب حسب نوع السفينة، حيث كانت الناقلات لديها نظام تدريب أكثر تواتراً. حوالي 50٪ من المشاركين يعتقدون أن التدريب على الأمن السيبراني مطلوب للطاقم الأعلى رتبة. فيما يتعلق بالمسؤولية عن الأمن السيبراني على متن السفينة، يعتقد 40.9٪ أن الجميع مسؤول، و 9.1٪ قالوا إن الربان مسؤول، و 30٪ قالوا إن ضابطاً كبيراً مسؤول، و 20٪ يعتقدون أن موظفين معينين في المكتب يجب أن يكونوا مسؤولين.

6.2 سيناريوهات الأمن السيبراني

تتوافق إجابات السيناريوهات مع نتائج أسئلة التصور الشخصي. أظهر معظم المشاركين فهماً للتهديدات السيبرانية والأمن السيبراني البحري، لكن بعضهم أجاب بعكس ذلك مما يشير إلى الحاجة للتحسين. تُظهر تحليلات السيناريوهات الحاجة إلى تضمين التهديدات الواقعية مثل الهندسة الاجتماعية والتصيد والهجمات عبر USB في برامج التوعية.

6.3 تحسين حالة الوعي بالأمن السيبراني

بناءً على الخلفية ومقترحات الباحثين الآخرين، يدعم بحثنا تطبيق بعض التحسينات: شرط الخضوع لتدريب الأمن السيبراني كجزء من STCW، تدريب أكثر تواتراً، خيارات ترتيبات التدريب، التوعية في جميع مستويات المنظمة، تعيين CySO، وضمان فهم البحارة لكيفية وسبب تطبيق ممارسات الأمن السيبراني. تشمل العناصر المهمة للبرامج: التركيز الواقعي على التهديدات السيبرانية، إرشادات تحديث البرامج، المصادقة متعددة العوامل، سياسات كلمات المرور القوية، مخاطر الهندسة الاجتماعية، وكيفية إساءة استخدام رسائل البريد الإلكتروني وأجهزة USB.

6.4 القيود

تشمل القيود الرئيسية: حجم العينة المحدود (110 مشاركاً فقط من أصل 28,000)، التركيز على البحارة الأتراك فقط (قد لا يكون قابلاً للتعميم على جنسيات أخرى)، غالبية المشاركين من كبار الضباط، قلة العناصر التربوية في الاستبيان، صعوبة التحقق من الرغبة في الإجابة بصدق، والنطاق الواسع نسبياً للبحث.

6.5 البحوث المستقبلية

يمكن أن يستفيد المجتمع العلمي من إجراء بحث مماثل بحجم عينة أكبر. يمكن أيضاً تغيير السكان المستهدفين بالتركيز على جنسيات أخرى، أو تضييق النطاق ليشمل أنواع سفن محددة. يمكن للبحوث المستقبلية أيضاً استكشاف كيفية تأثير العوامل التربوية على الوعي بالأمن السيبراني.

7. الاستنتاج

هدف هذا البحث إلى تقييم الوضع الحالي للأمن السيبراني على متن السفن، والوضع الحالي لوعي البحارة بالأمن السيبراني، وكيف يمكن تحسين هذا الوعي. تم ذلك من خلال مراجعة الأدبيات واستبيان استقصائي استهدف البحارة الأتراك. بناءً على مراجعة الأدبيات، تبين أن الحالة العامة للوعي بالأمن السيبراني في القطاع البحري غير مرضية. يبدو أن الوعي والتدريب يحصلان على أولوية غير كافية بين الإدارة العليا للمنظمات البحرية. من خلال تقييم وتحليل معرفة المشاركين بمبادئ الأمن السيبراني وكيف سيتصرفون في سيناريوهات متعلقة بالأمن السيبراني، تم الحصول على فهم عام لمستوى وعيهم. كشف هذا أن مستوى الوعي العام أفضل قليلاً مما كان متوقعاً من خلال مراجعة الأدبيات. كان هناك أيضاً فرق كبير لأولئك الذين لديهم تعليم في الأمن السيبراني أو تكنولوجيا المعلومات. تقدم النتائج رؤى حول كيف يمكن تحسين الوعي والتدريب، بما في ذلك اقتراح أن يخضع جميع البحارة لتدريب الأمن السيبراني وأن يتم ذلك بشكل متكرر.

المراجع

قائمة المراجع الكاملة (77 مصدراً) متاحة في الملف الأصلي للPDF.

Abstract

In recent years, vessels have become increasingly digitized, reflecting broader societal trends. As a result, maritime operations have become an attractive target for cyber threat actors. Despite the limited cybersecurity training seafarers receive, they are expected to operate within technologically advanced environments. The importance of cybersecurity awareness is evident, but the extent of seafarers' knowledge in this area remains uncertain. This article investigates three primary aspects: (1) the current state of cybersecurity onboard cargo vessels, (2) seafarers' cybersecurity awareness, and (3) potential improvements in seafarers' cybersecurity awareness. To accomplish this, a literature review is conducted to collect and analyze current research, supplemented by a questionnaire survey targeting Turkish seafarers. Our findings support increased investment in awareness and training programs, including organizational-wide cybersecurity awareness efforts, more frequent training, mandatory training for all seafarers through the Standards of Training Certification and Watchkeeping (STCW), and the appointment of a cybersecurity Officer (CySO) to ensure satisfactory cybersecurity levels onboard. Since this article focuses on high-level topics by assessing the general state of maritime cybersecurity and seafarers' cybersecurity awareness, it does not delve into detailed considerations of awareness and training programs. Nevertheless, it lays the foundation for future research in this area.

1. Introduction

In the contemporary global economy, maritime transport serves as the backbone of international trade, handling nearly all global transportation of goods [3, 4]. This pivotal sector serves as critical infrastructure, underpinning economic prosperity and facilitating the distribution of indispensable commodities [40]. As we advance into an era of digital transformation, vessels have evolved into complex technological ecosystems, incorporating state-of-the-art information technology (IT) and operational technology (OT) systems [9, 22]. Yet, as these systems become more intricate, the potential for cybersecurity threats increases, particularly when the primary operators of these systems, the seafarers, often lack formal IT training [32]. Despite their extensive maritime expertise, seafarers are typically not equipped with robust cybersecurity skills, a predicament highlighted by critics of maritime education programs [24, 49].

Historical digitization trends have revealed that human errors consistently pose a significant cybersecurity threat, often due to inadequate user awareness [76]. As digital environments become more complex, the likelihood of such human-induced errors and their subsequent impact on system security increases [23]. Therefore, understanding the state of cybersecurity awareness among seafarers is a critical first step toward identifying potential vulnerabilities and instituting effective preventive measures. Our research addresses three primary research questions: (1) What is the current state of cybersecurity onboard vessels? (2) What is the level of cybersecurity awareness among seafarers? (3) How can we enhance cybersecurity awareness among seafarers? These questions guide our research focus toward understanding the present cybersecurity landscape onboard cargo vessels and assessing the cybersecurity awareness of seafarers. The remainder of this article is organized as follows: Section 2 establishes the theoretical background. Section 3 presents related research. Section 4 describes the methodology. Section 5 presents results and analysis. Section 6 discusses results and proposes improvements. Section 7 concludes the article and discusses limitations.

2. Background

2.1 Maritime cybersecurity

To understand how maritime cybersecurity can be improved, it is important to first be aware of its current state, including technical, organizational, and operational aspects. The hierarchical structure of a vessel consists of the management, operational, and support levels [32]. The management level includes the Master and senior officers such as the Chief Officer and Chief Engineer. Junior officers constitute the operational level, and the support level consists of ratings.

The maritime cybersecurity sector displays varying degrees of sophistication. Some researchers argue that maritime cybersecurity is deficient, primarily due to the absence of comprehensive cybersecurity policies embedded in vessel procedures [69, 72, 73]. Others emphasize the necessity of a holistic approach balancing technical interventions with human-centric considerations [41]. Studies show that modern vessels are equipped with complex systems such as GNSS, ECDIS, and external communication systems, but these systems suffer from potential vulnerabilities [38]. The rising dependence on the internet, unprotected computers, and a lack of appropriate security training for crews greatly heighten the risk of successful cyber attacks [21].

2.2 Cybersecurity awareness and training of seafarers

Seafarers play a fundamental role in ensuring secure and efficient vessel operations. McGillivary [46] posits that ship crew and management often find themselves at a loss in case of a cybersecurity breach. Studies by Bolat and Kayişoğlu [10], Alcaide and Llave [1], Mraković and Vojinović [49], and Senarak [64, 65] have shown inadequate levels of cybersecurity awareness among seafarers. The STCW convention, which lays the foundation for most maritime training, does not explicitly mention cybersecurity. However, the increasing recognition of the importance of cybersecurity training is reflected in organizations providing such training.

2.3 Improving the state of maritime cybersecurity awareness

Many researchers have proposed various measures intended to improve the state of cybersecurity in the maritime sector. It is important to incorporate cybersecurity awareness in all levels of the organization, and effort should begin from the top [2, 37, 48, 59]. Enhanced regulatory standards or guidelines are needed [36]. Integrating cybersecurity training into the mandatory elements of the STCW could contribute to improving digital competencies [25]. Redesigning organizational roles may prove beneficial, such as introducing a CySO responsible for safeguarding the overall cybersecurity state of the vessel [11].

3. Related work

A literature review was conducted in a systematic manner, adapted from Okoli's [52] steps for conducting literature reviews. This involved five steps: identification of purpose, literature search and selection, data extraction and quality appraisal, data synthesis, and writing the review. Oria, Web of Science, and Engineering Village were the chosen search engines, with search strings such as "maritime cybersecurity", "maritime cybersecurity awareness", and "maritime cybersecurity training". The search generated 559 hits, from which 35 papers were selected for initial screening.

Alcaide and Llave [1] conducted research on the cybersecurity knowledge of maritime professionals via an online questionnaire receiving 124 responses. They highlighted that 33% of participants experienced a cyber incident within the last year, 40% share passwords with colleagues. Mraković and Vojinović [49] assessed cybersecurity awareness of Montenegrin seafarers via a questionnaire distributed to 429 participants, indicating a medium risk level pointing to poor awareness. Bolat and Kayişoğlu [10] assessed the effect of various measures on Turkish seafarers' cybersecurity awareness, finding that education is an important factor in improving awareness, and that knowledge of cybersecurity incidents affects awareness.

4. Methodology

4.1 Questionnaire methodology

The questionnaire was developed using a methodology framework described by multiple renowned scholars, including Lee [42], Saris and Gallhofer [63], and Burgess [12]. The seven key stages outlined by Burgess were meticulously followed: defining research aims, identifying the population and sample, deciding on the method of response collection, designing the questionnaire, conducting a pilot survey, implementing the main survey, and analyzing the data. The questionnaire targeted Turkish maritime professionals, both active seafarers and office personnel with seafarer backgrounds. The total count of Turkish seafarers was approximately 28,000 in 2021 [29]. The survey was administered through the University of Oslo's Nettskjema tool. The survey consisted of 27 questions in different styles. The questionnaire was translated into Turkish before distribution. The survey was distributed over five weeks in September and October 2022.

4.2 Ethical considerations

The data collection process began after receiving approval from the Norwegian Agency for Shared Services in Education and Research (Sikt). Participation was entirely voluntary, and informed consent was obtained. The questionnaire did not contain questions gathering personal or identifiable information. Email addresses were collected to preserve response uniqueness, but were later removed.

5. Results and analysis

5.1 Population sample and confidence level

A total of 117 answers were initially received. After a control process, 115 unique answers were identified. Five participants were excluded for lacking maritime experience, resulting in 110 final responses. The confidence interval of ±9.52% at a 95% confidence level was deemed a fair representation of the total population of 28,000 seafarers.

5.2 Demographic data

Demographic data showed that most participants had significant experience in the maritime sector, with the majority being senior officers. The vast majority worked on dry cargo vessels and tankers. 65.5% of participants had some form of education or training in cybersecurity or IT, while 34.5% had none.

5.3 Personal perception of cybersecurity

Results showed that 48.2% of participants never receive cybersecurity training. The majority of participants (42.7%) preferred a combination of self-study, in-person, and online training. 77.3% of participants identified a need for additional cybersecurity training. 60.0% believed cybersecurity training should be mandatory as part of STCW. 51.8% believed cybersecurity is important for senior crew. 90% were aware of cyber threats. 60.0% indicated guidelines exist for updating navigation systems.

5.4 Behavior in cybersecurity scenarios

Across the six scenarios presented to participants, most demonstrated appropriate cybersecurity behavior: 88.2% would not share a Wi-Fi password with a stranger at port, no participants followed instructions from a suspicious email, 80% would create a significantly different password when required, 88.2% would ignore or report an email asking about vessel security routines, 88.2% would report a found USB stick to their supervisor, and 70.9% would store a password in a dedicated list on the vessel. However, between 5.5% and 14.5% of participants chose less desirable answers in each scenario, indicating room for improvement.

6. Discussion

6.1 Cybersecurity perception

The data regarding specific cybersecurity-related topics suggest that the overall state of cybersecurity awareness is slightly better than for the studies described in the background section. Most participants had work-related cybersecurity awareness, with 90% recognizing cyber threats. Almost half of the participants never receive cybersecurity training, which is alarming. Cybersecurity training frequency varies based on vessel type, with tanker vessels having a more frequent training regime. Approximately 50% of participants think cybersecurity training is needed for senior crew. Regarding responsibility for cybersecurity on a vessel, 40.9% said everyone is responsible, 9.1% said the master is responsible, 30% said a senior officer is responsible, and 20% believed nominated staff at the office should be responsible.

6.2 Cybersecurity scenarios

The scenario answers align with personal perception question findings. Most participants showed an understanding of cyber threats and maritime cybersecurity, but some answered oppositely indicating a need for improvement. The scenario analyses highlight the need to include real-life threats such as social engineering, phishing, and USB-based attacks in awareness programs.

6.3 Improving the state of cybersecurity awareness

Based on the background and proposals of other researchers, our research supports the application of several improvements: a requirement to undergo cybersecurity training as part of STCW, more frequent training, choice of training arrangements, awareness training at all organizational levels, appointment of a CySO, and ensuring that all seafarers understand how and why common cybersecurity practices should be applied. Important elements for programs include: a real-life focus on cyber threats, guidelines for updating vessel software, multi-factor authentication, stronger password policies, dangers of social engineering, and information on how emails and USB devices can be misused.

6.4 Limitations

Key limitations include: limited sample size (only 110 participants out of 28,000), nationality focus on Turkish seafarers only (not necessarily transferable), ship type variation, statistical analysis limited to two-variable tests, demographic skew toward senior officers, few pedagogical elements in the questionnaire, difficulty verifying truthful responses, and a relatively wide research scope.

6.5 Future research

The community can benefit from conducting a similar research project with a larger sample size. The population could also be altered by focusing on other nationalities, or narrowed to only include specific vessel types. Future research could also explore how pedagogical factors affect cybersecurity awareness.

7. Conclusion

This research aimed to assess the current state of cybersecurity onboard vessels, the current state of cybersecurity awareness of seafarers, and how this awareness can be improved. This was done through a literature review and a questionnaire survey targeting Turkish seafarers. Based on the literature review, the overall state of cybersecurity awareness in the maritime sector was found to be unsatisfactory. Awareness and training seem to be insufficiently prioritized amongst the senior management of maritime organizations. By assessing and analyzing the participants' knowledge of cybersecurity principles and how they would act in given cybersecurity-related scenarios, a general understanding of their awareness level was acquired. This revealed that the overall awareness level is slightly better than anticipated through the literature review. There was also a significant difference for those having education in cybersecurity or IT. The findings from the research give an insight into how cybersecurity awareness and training could be improved, including proposing a requirement that all seafarers undergo cybersecurity training and that it is undergone frequently.

References

Full reference list (77 sources) available in the original PDF.