تواصل الصناعة البحرية العالمية رقمنة أنظمتها واعتمادها على التكنولوجيا المتقدمة، في اتجاه مماثل للقطاعات الصناعية الأخرى. إحدى القضايا الرئيسية التي جلبتها هذه الرقمنة هي زيادة التعرض لعدد متزايد من التهديدات السيبرانية. بينما يتم تنفيذ العديد من الإجراءات الأمنية لمنع أو الاستجابة للهجمات السيبرانية، لا يزال العنصر البشري أحد نقاط الضعف الرئيسية. تستغل العديد من الهجمات السيبرانية اليوم افتقار الموظفين البشريين للوعي، مما يجعل أنشطة التوعية والتدريب في الأمن السيبراني ذات أهمية حاسمة. لسوء الحظ، لا يزال البحث الحالي محدوداً في تقديمه لتدريب الأمن السيبراني الخاص بالعاملين في المجال البحري. علاوة على ذلك، ينبغي تطوير برامج التدريب هذه للمهنيين بناءً على الأدوار وفقاً لتوصيات العديد من المنظمات البحرية المعتمدة. لهذا السبب، قمنا بتطوير برنامج تدريب معياري للأمن السيبراني للمجال البحري يُسمى MarCy من خلال تنفيذ نموذج الأحداث الحرجة (CEM). ثم قمنا بتقييم برنامج MarCy باستخدام تقنية دلفي بمشاركة 19 خبيراً من الأوساط الأكاديمية والصناعية. في هذه الدراسة، نقدم تدريباً في الأمن السيبراني للبحارة وموظفي المكاتب في شركات الشحن. اقترحنا إحدى عشرة وحدة اختيارية لتحسين المعرفة والمهارات والاتجاهات لدى المتعلمين تجاه المخاطر السيبرانية. يمكن تنفيذ برنامج MarCy من قبل الجامعات وشركات الشحن ومعاهد التدريب والمنظمات الحكومية لأغراض التدريب على الأمن السيبراني البحري.
الصناعة البحرية قطاع حيوي في سلاسل التوريد العالمية. حالياً، تنقل السفن أكثر من 80% من التجارة العالمية من حيث الحجم. السفن الحديثة مجهزة بالعديد من أنظمة الأتمتة لتحسين السلامة والكفاءة في العمليات. ومع ذلك، فإن التكنولوجيا المتطورة في صناعة الشحن جلبت أيضاً مخاوف بشأن المخاطر السيبرانية. كشفت العديد من الدراسات عن تهديدات ونقاط ضعف سيبرانية على متن السفن، مع إظهار الأبحاث كيف يمكن أن تلعب نقاط الضعف هذه دوراً كبيراً في مختلف الحوادث البحرية وكذلك الخسائر المالية. وفقاً لذلك، اتخذت المنظمة البحرية الدولية (IMO) إجراءات تهدف إلى حماية السفن من التهديدات السيبرانية. أصبحت إدارة المخاطر السيبرانية إلزامية لمشغلي السفن. العنصر البشري هو أيضاً جانب حاسم في إدارة المخاطر ويجب النظر فيه بعناية. اليوم، يعمل ملايين المهنيين في القطاع البحري، حيث يبلغ عدد البحارة فقط حوالي 1.9 مليون مهني. وعيهم السيبراني أمر بالغ الأهمية ويجب تعزيزه بالتدريب للوقاية الفعالة من المخاطر السيبرانية.
تقوم العديد من المنظمات (مثل الجامعات وهيئات التصنيف وشركات التدريب) بتقديم التعليم والتدريب البحري للطلاب والمهنيين في مواضيع مختلفة. أحد مجالات هذا التدريب هو الأمن السيبراني. تُقدم دورات تدريب الأمن السيبراني بسبب الحوادث السيبرانية التي وقعت في الصناعة ومتطلبات هيئات التصنيف ودول العلم وبرامج الفحص. على الرغم من أن التدريب القائم على الأدوار في الأمن السيبراني مقترح في المبادئ التوجيهية المعتمدة، فإن غالبية برامج التدريب على الأمن السيبراني تقدم محتوى عاماً، حيث يأخذ كل مشارك نفس المحتوى في الدورات. ومع ذلك، فإن كل دور في الصناعة البحرية يتطلب احتياجات تعلم محددة للأمن السيبراني.
في هذا القسم، نقدم مناقشة وتحليلاً شاملاً للتوافر الحالي لتدريب الأمن السيبراني البحري. لتحقيق ذلك، أجرينا بحثاً موسعاً تضمن فحصاً دقيقاً للدراسات الأكاديمية ذات الصلة واستخدام محركات البحث لتحديد المعاهد التي تقدم تعليماً وتدريباً في الأمن السيبراني البحري للطلاب والمهنيين. بالإضافة إلى ذلك، بحثنا عن المبادئ التوجيهية والاستبيانات التي تتضمن متطلبات وتوصيات لتدريب الأمن السيبراني البحري.
تم تحديد العديد من المعاهد التي تقدم تدريباً في الأمن السيبراني البحري. تقدم جامعة سولنت ثلاث دورات في هذا المجال. تنظم الأكاديمية البحرية الإستونية مدرسة صيفية للأمن السيبراني البحري. تقدم الجامعة النرويجية للعلوم والتكنولوجيا (NTNU) مقرراً بعنوان "الأمن الرقمي البحري" لطلاب الماجستير. كما تقدم جامعات أخرى مثل بليموث وكلية BSA في اليونان والمدرسة الوطنية العليا للعلوم البحرية (ENSM) في فرنسا برامج تعليمية في هذا المجال. تقدم هيئات التصنيف مثل RINA و IRClass دورات تدريبية للعاملين في الصناعة البحرية. وجدت الدراسة أن الدورات التدريبية تفتقر عموماً إلى طرق التدريس المتنوعة مثل المناقشات الجماعية ودراسات الحالة والعروض التوضيحية، وأن المعلومات المحدودة عن المناهج متاحة للعديد من الدورات.
توصي المنظمة البحرية الدولية (IMO) باتباع المبادئ التوجيهية بشأن إدارة المخاطر السيبرانية البحرية لمنع المخاطر السيبرانية على متن السفن. وفقاً لهذه المبادئ، فإن التدريب والتوعية هما عنصران رئيسيان لتجنب التهديدات ونقاط الضعف السيبرانية. ينبغي أن يغطي برنامج التوعية إجراءات الصيانة (مثل مكافحة الفيروسات والتصحيح والنسخ الاحتياطي)، ومخاطر البريد الإلكتروني (مثل هجمات التصيد)، ومخاطر استخدام الإنترنت، ومخاطر استخدام الأجهزة الشخصية، وإجراءات الإبلاغ عن الحوادث السيبرانية. كما توصي أدلة أخرى، مثل "دفتر العمل للأمن السيبراني على متن السفن" ومبادئ DCSA و ABS، بالتدريب القائم على الأدوار وتقدم متطلبات محددة لتدريب الأمن السيبراني للبحارة وموظفي المكاتب.
في هذا القسم، استعرضنا الأوراق العلمية والمشاريع البحثية المتعلقة بتدريب وتعليم الأمن السيبراني البحري. تم إجراء مراجعة الأدبيات باستخدام المكتبات العلمية الرقمية الموثوقة. تم استخراج الأهداف ونتائج التعلم وطرائق التعليم والمناهج والمجموعات المستهدفة والمزايا والعيوب من مقترحات التدريب. استُخدمت النتائج التي تم جمعها في مراجعة الأدبيات لاحقاً لتصميم برنامج تدريب MarCy.
من بين المشاريع البارزة، مشروع CYMET التابع للاتحاد الدولي للجامعات البحرية (IAMU) الذي يهدف إلى تعزيز الوعي السيبراني. قدم Lee et al. [75] دورة تدريبية لضابط الأمن السيبراني للسفن (SCySO)، بينما اقترح Lee et al. [76] تدريباً توعوياً إلزامياً لجميع البحارة ضمن مدونة STCW. تناولت دراسات أخرى التدريب القائم على المحاكاة والنطاقات السيبرانية. استكشف Lovell and Heering [79] تمرين Neptune الذي نظمته جامعة تالين للتكنولوجيا (TalTech) في 2018. طور Potamos et al. [111] بيئة تدريب للنطاق السيبراني البحري تحاكي الإجراءات الهجومية والدفاعية. وجدت مراجعة الأدبيات أن تطوير منهجية لتصميم برنامج تدريبي جذب انتباه العديد من الباحثين.
تم اقتراح عدة نماذج لتصميم وتطوير التدريب على مر السنين. يبرز نموذج الأحداث الحرجة (CEM) [93]، الذي طوره ليونارد نادلر في عام 1982، كواحد من أكثر الطرق رسوخاً ووصفاً شاملاً في تصميم التدريب. يوفر CEM نهجاً شاملاً لتصميم أي نوع من الدورات التدريبية، وهو قابل للتطبيق ليس فقط على التعليم الرسمي ولكن أيضاً على احتياجات التدريب المتنوعة للمنظمات المختلفة. في دراستنا، قمنا بدمج CEM مع عدة تعديلات، بما في ذلك إضافة نهج معياري وتغييرات في خطوة التقييم.
في نهج التدريب المعياري، تُقدم أجزاء ذات صلة من هيكل تدريبي للمتعلمين مع مراعاة احتياجات التدريب الشخصية. أثبت هذا النهج فعاليته خاصة للتدريب المهني. نظراً لأن المعرفة المطلوبة فقط تُقدم للحاضرين مع مراعاة احتياجاتهم التعليمية، فإنه لا يسبب وقتاً ضائعاً في الحياة المهنية. لهذا السبب، فإن التدريب المعياري هو طريقة فعالة من حيث التكلفة ويمكن تقديمه عبر الإنترنت أيضاً. يوفر المرونة لمصمم التدريب والمتعلم.
بالإضافة إلى التعديلات المذكورة، تم استخدام تقنية دلفي لتقييم فعالية وقابلية استخدام برنامج MarCy. تعتبر تقنية دلفي أداة بحث مناسبة للحصول على الحكم والرأي حول المعرفة غير المكتملة حول مشكلة أو ظاهرة. تم اختيار 19 خبيراً من الأوساط الأكاديمية والصناعية للمشاركة. تم إجراء جولتين من دلفي، مع استبيانات إضافية أجاب عليها المشاركون الذين لم يتمكنوا من المشاركة في الجولات السابقة. قضى المشاركون 7 ساعات إجمالاً خلال مناقشات جولتي دلفي.
في هذا القسم، نناقش بالتفصيل برنامج MarCy لتدريب الأمن السيبراني البحري. يتكون برنامج MarCy من تسع خطوات، مستمدة من نموذج الأحداث الحرجة (CEM) مع تعديلات لتناسب الاحتياجات الخاصة للصناعة البحرية. فيما يلي وصف موجز لكل خطوة من خطوات البرنامج.
الهدف من هذه الخطوة هو تحديد طبيعة المشكلة [93]. في الخطوة الأولى، يجب تحديد احتياجات التدريب للشركة، مثل اللوائح الدولية وتصنيفات الهيئات التصنيفية. تحدد احتياجات التدريب المحددة وحدات التدريب المطلوبة. يتم اقتراح إحدى عشرة وحدة تدريبية اختيارية في برنامج MarCy: M1 الأمن السيبراني الأساسي، M2 الأمن السيبراني المتقدم، M3 المتطلبات التنظيمية، M4 متطلبات الفحص، M5 أنظمة السطح الحيوية، M6 أنظمة المحرك الحيوية، M7 الأنظمة الحيوية الأخرى، M8 استثمارات الأمن السيبراني، M9 ممارسات الأمن السيبراني، M10 إدارة الأمن السيبراني، وM11 المهارات المتقدمة.
الهدف من هذه الخطوة هو التحقيق في أدوار ومسؤوليات الموظفين [93]. حللنا أفراد الطاقم على متن السفن والموظفين على الشاطئ في الشركات. تم تقسيم طاقم السفينة النموذجية إلى ثلاثة أقسام: سطح السفينة والمحرك والتموين. تشمل الإدارات النموذجية في الشركة المطالبات والتأمين، وتكنولوجيا المعلومات، والتشغيل، والتأجير، والمحاسبة، والمالية، والفحص، والجودة والسلامة والبيئة (HSEQ)، والتدريب، والتوظيف، والتقنية، والمشتريات، والبحرية. يُقترح دور ضابط الأمن السيبراني (CySO) كوظيفة جديدة لإدارة شؤون الأمن السيبراني.
الهدف من هذه الخطوة هو فهم الاحتياجات التعليمية المحددة للأدوار [93]. في هذه المرحلة، يتم تحديد وحدات التدريب لكل دور محدد. يتم ربط الوحدات التدريبية بالمسؤوليات كما هو موضح في الجداول. بعد تحديد وحدات التدريب المطلوبة، يمكن إجراء اختبار لتقييم معرفة المشاركين. إذا كان لدى المشارك معرفة كافية، فليس من الضروري إعطاؤه وحدة تدريبية معينة.
الهدف من هذه الخطوة هو تحديد الأهداف المحددة ونتائج التعلم لكل وحدة تدريبية [93]. تتضمن نتيجة التعلم ثلاثة مكونات للوصول إلى الأهداف المحددة: المعرفة والمهارة والاتجاه [93]. المعرفة هي حالة المعرفة بحقيقة أو موقف معين. المهارة هي القدرة على فعل شيء ما بشكل جيد. الاتجاه هو الشعور أو الرأي حول شيء ما.
الغرض من هذه الخطوة هو بناء منهج لتحقيق أهداف التعلم المذكورة [93]. تُحدد المحتويات من خلال النظر في أهداف الوحدة ونتائج التعلم المرجوة. تنقسم المحتويات إلى مجموعتين: أساسية ومساعدة. تم اقتراح قائمة محتويات لكل وحدة تدريبية كما هو موضح في الملحق 1.
الهدف من هذه الخطوة هو تحديد الاستراتيجيات التعليمية المناسبة للمنهج المحدد [93]. تم اقتراح خمس استراتيجيات تعليمية للوحدات المحددة: المحاضرة، والمناقشة، ودراسة الحالة، والتدريب العملي، والعرض التوضيحي. يمكن تقديم الوحدة باستراتيجية واحدة أو مزيج من استراتيجيات متعددة.
الهدف من هذه الخطوة هو ضمان توفر جميع الموارد المطلوبة للتدريب. نركز على الموارد المادية والبشرية والمواد التدريبية. الموارد المادية تشمل المنشأة والأدوات والمعدات. يجب اختيار المحاضرين بدقة. المواد التدريبية تشمل الكتب والأوراق العلمية والمبادئ التوجيهية والرسوم المتحركة ومقاطع الفيديو والعروض التقديمية والصور.
الهدف من هذه الخطوة هو تنفيذ التدريب المصمم. قبل التدريب، يمكن تحديد جدول زمني. يمكن تعديل الوحدات قليلاً من خلال النظر في احتياجات الحضور. يمكن تحديد مدة الوحدات من خلال النظر في احتياجات التعلم للمشاركين وقرارات المديرين المسؤولين. يُوصى بساعتين لكل وحدة من M1 إلى M8، و8 ساعات لـ M9، و40 ساعة لـ M10، بينما تعتمد مدة M11 على خلفية المشارك.
مرحلة التقييم هي لفحص نتائج وأهداف التدريب المصمم. وفقاً لتوصيات CEM، يجب أن يكون تقييم التدريب على نحوين: (1) تقييم تكويني مستمر لمكونات التدريب المطورة أثناء تصميم الدورة، و(2) تقييم ختامي في ختام التدريب. البيانات التي تم جمعها من التقييمات التكوينية والختامية حاسمة لتحسين ومراجعة عروض التدريب المطورة باستخدام برنامج MarCy في التكرارات المتعاقبة.
كما نوقش سابقاً في القسم 4، تم تقييم برنامج MarCy باستخدام طريقة دلفي عبر جولتين. في كلتا الجولتين، شارك الخبراء في مناقشات حول جوانب مختلفة من تدريب الأمن السيبراني البحري وقدموا ملاحظات حول برنامج MarCy.
في سياق تدريب الأمن السيبراني البحري، تقدم البيئة التشغيلية الفريدة للصناعة البحرية تحديات مميزة مقارنة بالقطاعات الأخرى. تواجه السفن مجموعة من التعقيدات التي تتطلب مناهج تدريب متخصصة. أحد الاعتبارات البارزة هو الصعوبة المحتملة في الاستجابة لهجوم سيبراني فوراً. قد يكون الوصول إلى السفينة للاستجابة الفورية من قبل خبير الأمن السيبراني صعباً بسبب موقعها البعيد واتصالها المحدود بالإنترنت.
قدم المشاركون توصيات متنوعة، تتراوح من مناهج قائمة على المحاكاة إلى التدريب في الفصول الدراسية. الميزة الرئيسية للتدريب القائم على المحاكاة هي السماح بالتدريب العملي القائم على سيناريوهات واقعية دون التسبب في مخاطر أمنية للسفن. أوصى المشاركون بالجمع بين التدريب القائم على المحاكاة والتدريب في الفصول الدراسية عند الإمكان، مع التركيز على سيناريوهات الحياة الواقعية.
سلط المشاركون الضوء على عدة قيود فيما يتعلق بتدريب الأمن السيبراني البحري الحالي. تضمنت هذه القيود: الافتقار إلى الخلفية في تكنولوجيا المعلومات لدى البحارة، والمواد المحدودة المتاحة للتدريب، ونقص الموارد (مثل الوقت والإرهاق والإنترنت عريض النطاق على متن السفن)، ونقص متطلبات المنظمة البحرية الدولية، ونقص المدربين المؤهلين، وقيود الميزانية، والأنظمة غير المتجانسة بين السفن المختلفة.
لحل القيود المذكورة سابقاً، اقترح المشاركون عدة تدابير بما في ذلك: التركيز على دراسات الحالة والسيناريوهات الواقعية لإشراك المشاركين، وتحديث التدريب بانتظام، وإلزام الموظفين الجدد بالتدريب وضمان تكراره أو استمراره للموظفين الحاليين، وتكييف التدريب مع لغات مختلفة، وإضافة تدريب الأمن السيبراني البحري إلى التعليم الرسمي للطلاب.
لوحظ أن تقييم التدريب غالباً ما يكون أقل أولوية. اعتبر هذا تحدياً رئيسياً في تدريب الأمن السيبراني البحري. أوصى المشاركون باستخدام مؤشرات ومقاييس الأداء، تتراوح من الامتحانات متعددة الاختيارات إلى تحليل السجلات والأنظمة. للتقييم النوعي، شملت التوصيات جمع الملاحظات القائمة على المناقشة أو الاستبيان.
اقترح المشاركون تقديم دور جديد وهو ضابط الأمن السيبراني المخصص (CySO) إما للخدمة على متن السفينة (SCySO) أو على الشاطئ (CCySO). نوقشت أيضاً الفعالية الواقعية للتدريب، حيث أن الشهادات التي يتم الحصول عليها بعد التدريب غالباً لا تضمن أمنًا سيبرانياً مناسباً.
فيما يتعلق بتقييم برنامج MarCy، وجدت غالبية المشاركين أنه منظم جيداً وشامل. ومع ذلك، تم عكس عدد من التوصيات للتحسينات في البرنامج. يلخص الجدول 13 جميع التوصيات التي تم تقديمها خلال جولات دلفي المتعددة.
برنامج MarCy هو أداة فعالة لمصممي التعليم في تصميم برامج تدريب الأمن السيبراني البحري. تم تطوير التوصيات ليس فقط بناءً على آراء المؤلفين ولكن أيضاً بمساهمات من خبراء في هذا المجال. بعبارة أخرى، MarCy هو برنامج متفق عليه من قبل عدة خبراء. على حد علمنا، هذا الجانب فريد في الأدبيات.
على الرغم من أن برنامج MarCy لم يتم تنفيذه بعد في جلسة تدريبية حقيقية، إلا أن هناك تطبيقات واقعية في الأدبيات. نعتزم أيضاً تنظيم جلسات تدريبية مع مجموعات متعلمين مختلفة في القطاع البحري لتقييم جميع مراحل برنامج MarCy وتقديم نتائجنا في دراسة إضافية. بينما تم تخصيص برنامج MarCy للأغراض البحرية، يمكن استخدام نهجه المعياري لتطوير مجموعة واسعة من برامج التدريب. إنه ليس مقصوراً على السياقات البحرية أو تدريب الأمن السيبراني وحده. يمكن أيضاً تطبيقه على تصميم التعليم الرسمي إلى جانب التدريب الخاص بالصناعة.
من خلال هذا العمل، نقوم بتوسيع نموذج CEM ونساهم علمياً في الأدبيات مع تسهيل تصميم تدريب الأمن السيبراني البحري لخبراء الصناعة. بعبارة أخرى، نعتقد أن دراستنا لا تحمل قيمة علمية فحسب، بل تعالج أيضاً الاحتياجات العملية للقطاع البحري.
في الختام، استدعت المخاوف المتزايدة المحيطة بالمخاطر السيبرانية داخل الصناعة البحرية دعوة لاتخاذ تدابير سريعة واستباقية. العواقب المحتملة لهجوم سيبراني ناجح - بما في ذلك الخسائر الاقتصادية وخرق البيانات وتعريض السلامة التشغيلية للخطر - تؤكد الأهمية القصوى للوعي السيبراني. يبرز التدريب كأداة لا غنى عنها لرفع الوعي السيبراني وبالتالي الحماية من هذه التهديدات. وقد حظيت هذه الحاجة بالدعم، ووجدت مكانها ضمن برامج الفحص والتصنيفات السيبرانية لهيئات التصنيف ودول العلم، وحتى الاندماج المقترح ضمن STCW للبحارة.
تستدعي المسؤوليات والأدوار المتميزة التي يشغلها الموظفون منهجيات تدريب مخصصة. استجابة لذلك، اقترحنا برنامج تدريب MarCy من خلال تنفيذ CEM لتلبية المتطلبات الفريدة للمهنيين في تدريب الأمن السيبراني البحري. يشمل برنامج MarCy عملية من تسع خطوات: (1) تحديد احتياجات المنظمة، (2) تحديد أداء الوظيفة، (3) تحديد احتياجات المتعلم، (4) تحديد الأهداف، (5) بناء المنهج، (6) اختيار الاستراتيجيات التعليمية، (7) الحصول على الموارد التعليمية، (8) إجراء التدريب، (9) التقييم والتغذية الراجعة. تم تحديد إحدى عشرة وحدة تدريبية اختيارية مصممة خصيصاً لتعزيز المعرفة والمهارات والاتجاهات للبحارة وموظفي المكاتب في الحماية من المخاطر السيبرانية البحرية. تم تأكيد متانة برنامج MarCy من خلال تقنية دلفي بمشاركة 19 خبيراً.
نود أن نعرب عن خالص امتناننا للخبراء، وخاصة أحمد عمرو، لتعليقاتهم التي ساهمت في تحسين دراستنا. تم تمويل هذا البحث من مجلس البحوث النرويجي من خلال مشروع المرونة السيبرانية البحرية (MarCy، رقم المشروع 295077). المحتوى يعكس فقط آراء المؤلفين.
قائمة المراجع الكاملة (140+ مصدراً) متاحة في المقال الأصلي على SpringerLink.
هذا العمل مرخص بموجب رخصة المشاع الإبداعي نسب المصنف 4.0 الدولية (CC BY 4.0).
The global maritime industry is continuing the rapid digitization of systems and dependency on advancing technology, in a trend akin to other industrial domains. One of the main issues that this integration has brought is an increased vulnerability to a growing number of cyber threats. While several security measures are being implemented to prevent or respond to cyber attacks, the human element is still one of the main weaknesses. Many of today's cyber attacks take advantage of human personnel's lack of awareness, which makes cyber security awareness and training activities of critical importance. Unfortunately, current research is still limited in its offerings for cyber security training specific to maritime personnel. Moreover, such training programmes for the professionals should be developed role-based in accordance with the suggestions of many credited maritime organizations. For this reason, we developed a modular cyber security training programme for the maritime domain called Maritime Cyber Security (MarCy) by implementing Critical Events Model (CEM). Then, we evaluated the MarCy programme by utilizing the Delphi technique with the participation of 19 experts from academia and industry. In this study, we offer cyber security training for seafarers and office employees in shipping companies. We proposed eleven elective modules to improve the knowledge, skills, and attitude of learners against cyber risks. The MarCy programme can be implemented by universities, shipping companies, training institutes, and governmental organizations for maritime cyber security training purposes.
The maritime industry is a vital sector in global supply chains [134]. Currently, ships perform over 80% of the world trade by volume [134]. Modern vessels are equipped with many automation systems to improve safety and efficiency in operations. However, developing technology in the shipping industry also brought along concerns about cyber risks. Several studies revealed cyber threats and vulnerabilities onboard ships [5], with research highlighting how these vulnerabilities may play a significant role in various maritime incidents as well as financial losses [7, 83, 104]. Accordingly, the International Maritime Organization (IMO) took action, aiming to protect ships from cyber threats. Cyber risk management became mandatory for ship operators [59]. The human element is also a crucial aspect of risk management and should be carefully considered. Today, millions of professionals work in the maritime sector, with only seafarers numbering nearly 1.9 million professionals [13]. Their cyber awareness is crucial and should be reinforced with training for the effective prevention of cyber risks.
Several organizations (e.g. universities, class societies, and training companies) offer maritime education and training for cadets and professionals in different subjects. One of the domains of this training is cyber security. Cyber security training courses are offered because of occurred cyber incidents in the industry and the requirements of class societies, flag states, and vetting programmes. Even though role-based cyber security training is suggested in credited guidelines [14, 32, 100, 139], a majority of cyber security training programmes offer generic content, with each participant taking the same content in courses. However, each role in the maritime industry requires specific learning needs for cyber security.
In this section, we present a comprehensive discussion and analysis of the current availability of maritime cyber security training. To achieve this, we conducted extensive research, which involved careful examination of relevant academic studies and utilization of search engines to identify institutes offering maritime cyber security education and training to cadets and professionals. Additionally, we sought out guidelines and questionnaires that include requirements and recommendations for maritime cyber security training.
Several institutes providing maritime cyber security training were identified. Solent University offers three courses regarding maritime cyber security. The Estonian Maritime Academy organized a summer school for maritime cyber security in 2018. The Norwegian University of Science and Technology (NTNU) provides a course titled Maritime Digital Security for master students. Other universities like Plymouth, BSA College in Greece, and ENSM in France also offer programmes. Class societies such as RINA and IRClass provide courses for professionals. The study found that training courses generally lack diverse teaching methods such as group discussions, case studies, and demonstrations, and limited curriculum information is available for many courses.
The IMO recommends following the Guidelines on Maritime Cyber Risk Management to prevent cyber risks onboard ships. Per the guideline, training and awareness are the key elements to avoid cyber threats and vulnerabilities. The awareness programme should cover maintenance routines (e.g. antivirus, patching, and backup), e-mail risks (e.g. phishing attacks), risks related to the use of the internet, risks of the use of own devices, and reporting procedure of cyber incidents. Other guides, such as the Cyber Security Workbook for on Board Ship Use [139], DCSA guidelines [32], and ABS guides [2], recommend role-based training and provide specific requirements for cyber security training for seafarers and office staff.
In this section, we reviewed scientific papers and research projects related to maritime cyber security training and education. The literature review was conducted using reputable digital scientific libraries. Objectives, learning outcomes, modalities, curriculums, target groups, advantages and drawbacks of training proposals were extracted. Findings collected in the literature review were later used to design the MarCy training programme.
Notable projects include the IAMU's CYMET project aimed at enhancing cyber awareness. Lee et al. [75] offered a training course for the Ship Cyber Security Officer (SCySO), while Lee et al. [76] proposed mandatory familiarization training for all seafarers within the STCW Code. Other studies explored simulation-based training and cyber ranges. Lovell and Heering [79] summarized findings in the Exercise Neptune organized by TalTech in 2018. Potamos et al. [111] introduced a maritime cyber range training environment simulating offensive and defensive actions. The literature review revealed that developing a methodology for designing a training programme attracted the attention of many researchers.
Several models for designing and developing training have been proposed over the years. The Critical Events Model (CEM) [93], initially developed by Leonard Nadler in 1982, stands out as one of the most well-established and thoroughly described methods in training design. The CEM provides a comprehensive approach to designing any types of training courses, applicable not only to formal education but also to the diverse training needs of various organizations. In our study, we incorporated the CEM with several modifications, including the addition of a modular approach and changes to the evaluation step.
In the modular training approach, relevant parts of a training structure are offered to learners by considering personalized training needs. This approach is especially effective for vocational training [38]. Given that only required knowledge is provided to attendees by considering their learning needs, it does not cause lost time in business life. That is why modular training is a cost-effective method and can be given online, as well [123]. It provides flexibility to the training designer and learner.
In addition to the modifications mentioned, the Delphi technique was performed to evaluate the effectiveness and usability of the MarCy programme. The Delphi technique is considered a well-suited research instrument to obtain judgement and opinion on incomplete knowledge about a problem or phenomenon. A panel of 19 experts from academia and industry was selected. Two rounds of Delphi were conducted, with additional questionnaires answered by participants who could not participate in the previous rounds. A total of 7 hours were spent during the discussions of the two Delphi rounds.
In this section, we discuss in detail the MarCy programme for maritime cyber security training. The MarCy programme comprises a total of nine steps, derived from the CEM with modifications to suit the specific needs of the maritime industry. Below is a brief description of each step of the programme.
The objectives of this step are to identify the nature of the problem [93]. In the first step, the training needs of the company should be identified, such as international regulations and class notations. Determined training needs identify the required training modules. Eleven elective training modules are proposed in the MarCy programme: M1 Basic Cyber Security, M2 Advanced Cyber Security, M3 Regulatory Requirements, M4 Vetting Requirements, M5 Critical Deck Systems, M6 Critical Engine Systems, M7 Other Critical Systems, M8 Cyber Security Investments, M9 Cyber Security Practices, M10 Cyber Security Management, and M11 Advanced Skills.
The objective of this step is to investigate employees' roles and responsibilities [93]. We analysed seafarers onboard and employees on the shoreside of companies. A typical ship crew was divided into three departments: deck, engine, and catering. Typical departments in a company include claims & insurance, IT, operations, chartering, accounting, finance, vetting, HSEQ, training, crewing, technical, purchasing, and marine. The Cyber Security Officer (CySO) role is proposed as a new position to manage cyber security matters.
The objective of this step is to understand the specific learning needs of roles [93]. The training modules for each specific role are determined in this phase. Training modules are mapped with responsibilities as represented in the tables. After the required training modules are determined, an exam can be given to assess the knowledge of participants. If a participant has sufficient knowledge, it is unnecessary to give him/her such a training module.
The purpose of this step is to identify the specific objectives and learning outcomes for each training module [93]. The learning outcome comprises three components to reach the objectives identified: knowledge, skill, and attitude [93]. Knowledge is defined as the state of knowing about a particular fact or situation. Skill is defined as the ability to do something well. Attitude is defined as a feeling or opinion about something.
The purpose of this step is to build a syllabus to meet the learning objectives stated [93]. The contents are specified by considering module objectives and desired learning outcomes. The contents are divided into two groups: essential and helpful. A content list for each training module was offered as represented in Appendix 1.
The objective of this step is to determine the appropriate instructional strategies for the curriculum identified [93]. Five instructional strategies are proposed for the modules identified: lecture, discussion, case study, drill, and demonstration. A module can be given with a strategy or a combination of multiple strategies.
The objective of this step is to ensure that all required resources for the training are in place. We focus on physical and human resources, and training materials. Physical resources are regarding the facility, tools, and equipment. Lecturers should be selected studiously. The training materials are books, scientific papers, guidelines, animations, videos, presentations, and photos.
The objective of this step is to perform the training designed. Before the training, a schedule can be identified. The modules can be slightly modified by considering the attendees' needs. The duration of the modules can be identified by considering the learning needs of the participants. Recommended training duration is 2 hours each for M1-M8, 8 hours for M9, 40 hours for M10, while M11 depends on the participant's background.
The evaluation phase is to examine the outcomes and objectives of the training designed. According to CEM recommendations, training evaluation should occur two-fold: (1) continuous formative evaluation of training components during course design, and (2) summative assessment at the conclusion of training. The data collected by formative and summative assessments are critical for improving and revising the training offerings developed using the MarCy programme in successive iterations.
As previously discussed in Sect. 4, the evaluation of the MarCy programme was conducted using the Delphi method across two rounds. In both rounds, experts engaged in discussions concerning various aspects of maritime cyber security training and provided feedback on the MarCy programme.
In the context of maritime cyber security training, the unique operating environment of the maritime industry presents distinctive challenges compared to other sectors. Vessels face a range of complexities that demand specialized training approaches. One notable consideration is the potential difficulty in responding to a cyber attack promptly. Accessing a vessel for immediate response by a cyber security expert may prove challenging due to its remote location and limited connectivity.
Participants have given various recommendations, ranging from simulation-based approaches to classroom training. The main advantage of simulation-based training is allowing hands-on training based on realistic scenarios without causing security risks to vessels. It was recommended to combine simulation-based and classroom-based training when possible, and keep a focus on real-life scenarios.
Several limitations were highlighted by participants regarding current maritime cyber security training. These included lack of IT background of seafarers, limited material available for training, lack of resources (e.g. time, fatigue, and onboard broadband internet), lack of IMO requirements, lack of qualified trainers, budget limitations, heterogeneous systems between vessels.
To resolve the limitations previously mentioned, participants suggested several measures including: focusing on real-life case studies and scenarios to engage participants; updating training regularly; mandating training to new employees and ensuring it is repeated for existing employees; adapting training to different languages; adding maritime cyber security training to formal education of cadets.
Evaluation of training was noted to be often less prioritized. This has been considered a key challenge in maritime cyber security training. Participants suggested using performance indicators and metrics, ranging from multiple-choice exams to log and system analysis. For qualitative evaluation, recommendations included discussion-based or survey-based feedback collection.
Participants proposed introducing a new role: a dedicated CySO for either onboard (SCySO) or off-board duty (CCySO). The real-life effectiveness of training was also discussed, as certifications obtained post-training often do not guarantee proper cyber security.
When it comes to the evaluation of the MarCy programme, the majority of the participants found it to be well-structured and comprehensive. That being said, a number of recommendations for improvements were reflected to the programme. Table 13 summarizes all recommendations made during the multiple rounds of Delphi.
The MarCy programme is an effective tool for instructional designers in designing maritime cyber security training programmes. The recommendations were developed not solely based on the authors' opinions but also with contributions from experts in the field. In other words, the MarCy is a programme agreed upon by multiple experts. To the best of our knowledge, this aspect is unique in the literature.
Although the MarCy programme has not been implemented in a real training session, real-world applications are in place in the literature. We also intend to organize training sessions with various learner groups in the maritime sector to evaluate all stages of the MarCy programme and present our findings in an additional study. While the MarCy programme is customized for maritime purposes, its modular approach can be used to develop a wide range of training programmes. It is not limited to maritime contexts or cyber security training alone. It can also be applied to designing formal education beyond industry-specific training.
Through this work, we extend the CEM and contribute scientifically to the literature while facilitating the design of maritime cyber security training for industry experts. In other words, we believe that our study not only holds scientific value but also addresses the practical needs of the maritime sector.
In conclusion, the mounting concern surrounding cyber risks within the maritime industry has necessitated a call for swift, proactive measures. The potential fallout from a successful cyber attack—including economic losses, data breaches, and compromised operational safety—underscores the utmost importance of cyber awareness. Training emerges as an indispensable tool to heighten cyber awareness and subsequently shield against these threats. This need has garnered support, finding its place within vetting programmes, cyber notations of class societies and flag states, and even proposed integration within the STCW for seafarers.
The distinct responsibilities and roles held by employees necessitate customized training methodologies. In response, we proposed the MarCy training programme by implementing the CEM to address the unique demands of professionals in maritime cyber security training. The MarCy training programme encompasses a meticulous nine-stage process: (1) identify the needs of the organization, (2) specify job performance, (3) identify learner needs, (4) determine objectives, (5) build curriculum, (6) select instructional strategies, (7) obtain instructional resources, (8) conduct training, (9) evaluation and feedback. Eleven elective training modules were specifically designed to enhance the knowledge, skills, and attitudes of seafarers and office personnel in safeguarding against maritime cyber risks. The robustness of the MarCy programme was subsequently confirmed through a Delphi technique involving 19 experts from both academic and industrial backgrounds.
We would like to express our sincere gratitude to experts, particularly Ahmed Amro, for their comments towards improving our study. This paper has received funding from the Research Council of Norway through the Maritime Cyber Resilience (MarCy, project number 295077) project. The content reflects only the authors' views.
The full reference list (140+ sources) is available at the original article on SpringerLink.
This article is licensed under a Creative Commons Attribution 4.0 International License (CC BY 4.0).