يتزايد انتشار التقنيات الرقمية في الصناعة البحرية، كما هو الحال في القطاعات الأخرى. وبالتالي، تتزايد المخاوف بشأن المخاطر السيبرانية. فقد وقعت حوادث في الصناعة، وتؤكد نتائج الدراسات الأكاديمية هذه المخاوف. بينما تُتخذ إجراءات تقنية ضد التهديدات السيبرانية، يظل العنصر البشري جانبًا آخر بالغ الأهمية يتطلب التعزيز. ولمكافحة التهديدات ونقاط الضعف السيبرانية بفعالية، من الضروري تعزيز وعي الأفراد من خلال التعليم والتدريب. لمعالجة احتياجات التدريب في الأمن السيبراني للمهنيين والطلاب البحريين، قمنا بتطوير نهج يُسمى برنامج التدريب مارسي (MarCy) للأمن السيبراني البحري. في هذه الدراسة، نقوم بتقييم جميع مراحل البرنامج المقترح من خلال أربع جلسات تدريبية شملت مجموعات متعلمين مختلفة. ونتيجة لذلك، تم تحسين برنامج مارسي بناءً على النتائج التي تم الحصول عليها أثناء جلسات التدريب وملاحظات المتعلمين. تثبت هذه الدراسة أن برنامج مارسي هو نهج فعال لتلبية احتياجات التدريب في الأمن السيبراني لمجموعات مختلفة في المجال البحري.
ينقل النقل البحري أكثر من 80% من حجم التجارة العالمية للبضائع [42]، ونتيجة لذلك، أصبحت الصناعة البحرية قطاعًا حيويًا يعمل فيه ملايين المهنيين. يبلغ عدد البحارة وحدهم حوالي 1.9 مليون [2]. يفتقر مدونة معايير التدريب والإجازة والمراقبة (STCW) حاليًا إلى أي متطلبات أو توصيات لتعزيز الوعي السيبراني للبحارة. لذلك، يتلقى البحارة، علاوة على متطلبات التدريب للمنظمة البحرية الدولية (IMO)، عادةً تدريبًا في الأمن السيبراني خلال حياتهم المهنية. ومع ذلك، فمن المرجح أن يتغير هذا الوضع. قدمت جمهورية كوريا اقتراحًا في ديسمبر 2021 لمناقشة أهمية دمج التدريب على الأمن السيبراني في STCW [18]. تمت دعوة اللجنة الفرعية المعنية بالعنصر البشري والتدريب والمراقبة في المنظمة البحرية الدولية لمناقشة الأحكام ذات الصلة المتعلقة بتدريب البحارة في مجال الأمن السيبراني.
قمنا بتطوير برنامج تدريب مارسي من خلال دمج رؤى وآراء الخبراء، بهدف تطبيقه في دورات التدريب على الأمن السيبراني البحري. الغرض من هذه الدراسة هو تقييم قابلية تطبيق وفعالية برنامج تدريب مارسي. هذا العمل هو استمرار لعملنا السابق الذي اقترحه أوروك وتشودري وجكيولوس [30]. يمكن تلخيص مساهمة دراستنا على النحو التالي: تقييم برنامج تدريب مارسي، تقييم جلسات التدريب، ومشاركة الملاحظات وملاحظات المشاركين. في هذه الدراسة، تم تنفيذ برنامج مارسي لتطوير دورات التدريب على الأمن السيبراني للطلاب والمهنيين. قبل الدورات التدريبية، تم إجراء استبيان مسبق من خلال عقد اجتماع مع قادة المنظمات الشريكة. ثم أرسل الشركاء استبيانًا مسبقًا آخر للمدعوين لجمع توقعاتهم التدريبية.
بينما يتمتع برنامج مارسي بإمكانية التوسع بوحدات إضافية لتلبية احتياجات مختلف أصحاب المصلحة في الصناعة البحرية، يركز البحث الأصلي على تطبيق التدريب على الأمن السيبراني للبحارة والموظفين المكتبيين في شركات الشحن. توضح هذه الدراسة تطبيق برنامج مارسي في تدريب الطلاب من أقسام مختلفة (بحريه وغير بحريه)، وموظفي المكاتب في شركات الشحن، والموظفين الفنيين من هيئات التصنيف. على الرغم من أن هذه الدراسة لا تغطي تدريب جميع المجموعات المهنية، فمن الممكن تنفيذ برنامج مارسي لتوفير التدريب على الأمن السيبراني لهذه المجموعات.
على مر السنين، تم طرح عدة نماذج لتوجيه تصميم وتطوير برامج التدريب. أحد هذه النماذج هو نموذج الأحداث الحرجة (CEM) الذي قدمه ليونارد نادلر في عام 1982، والذي حصل على اعتراف كنهج راسخ وموصوف على نطاق واسع لتصميم التدريب. يوفر CEM إطارًا شاملاً لتصميم الدورات التدريبية. وهو ليس مقتصرًا على إعدادات التعليم الرسمي، بل يمكنه أيضًا معالجة متطلبات التدريب لمختلف المنظمات. يُعد CEM مناسبًا بشكل خاص للصناعات التي تتميز بتغيرات سريعة، حيث يقدم نهجًا مرنًا وقابلاً للتكيف [25]. قمنا بإجراء ثلاثة تعديلات على CEM في برنامج مارسي: إضافة نهج معياري، وتخصيصه خصيصًا للأمن السيبراني البحري، واستبدال مرحلة التقييم الأصلية بنهج التقييم الخاص بنا الذي يعتمد على ملاحظات أصحاب المصلحة الداخليين.
يتضمن نهج التدريب المعياري تقديم مكونات ذات صلة من برنامج تدريبي للمتعلمين مصممة خصيصًا لاحتياجاتهم التدريبية الفردية. تم تطبيق هذا النهج لمتطلبات تدريبية مختلفة وأثبت فعاليته بشكل خاص في التدريب المهني [16، 11]. من خلال تزويد الحاضرين بالمعرفة الضرورية فقط المتوافقة مع احتياجاتهم التعليمية، يقلل هذا النهج من الاضطرابات في حياتهم المهنية. وبالتالي، فإن التدريب المعياري هو طريقة فعالة من حيث التكلفة يمكن تقديمها عبر الإنترنت، مما يوفر المرونة لكل من مصمم التدريب والمتعلم [39].
استخدمنا طريقة دلفي لتقييم برنامج تدريب مارسي. طريقة دلفي معترف بها على نطاق واسع في الأدبيات كأداة بحث مناسبة لجمع الأحكام والآراء حول الموضوعات التي قد تكون المعرفة فيها غير مكتملة [40]. تتضمن هذه الطريقة عملية تكرارية تهدف إلى جمع الملاحظات من مجموعة مختارة من الخبراء الذين يقدمون رؤاهم بشكل مجهول. اخترنا طريقة دلفي كتقنية تحقق لبرنامجنا لأنها تمكننا من جمع ملاحظات مرجحة من لجنة الخبراء وتسهل النقاش المفتوح دون الحاجة إلى طرق تقييم عملية مثل التجريب.
يستكشف إرستاد وآخرون [14] تطبيق نهج التصميم المتمحور حول الإنسان (HCD) للتدريب على المرونة السيبرانية البحرية. يقترح المؤلفون استخدام HCD لتطوير تدريب مخصص للمرونة السيبرانية البحرية، بما في ذلك التدريب الجماعي القائم على المحاكاة. من خلال التفاعل مع المستخدمين النهائيين ودمج نظريات التعلم، يصبح التدريب واقعيًا وملائمًا لاحتياجات المتعلمين.
يدرس كانيبا وآخرون [7] تحديات التدريب على الأمن السيبراني البحري واستخدام النطاق السيبراني كحل. يقدم البحث مشروع Cyber-MAR [10]، الذي ينفذ حلاً للنطاق السيبراني الموحد كجزء من منصة تدريب على الأمن السيبراني مصممة خصيصًا للقطاع البحري. تشمل المنهجية التحليل النوعي من خلال مراجعة الأدبيات وتحليل المجموعات المستهدفة، بالإضافة إلى التحليل الكمي لنتائج التدريب الأولي لنظام إدارة التعلم (LMS).
يقدم بوتاموس وآخرون [37] منهجًا تدريبيًا جديدًا وإرشادات تصميمية لإنشاء أنشطة على نطاق سيبراني بحري، بهدف تعزيز الدفاعات ضد هجمات برامج الفدية. يركز المنهج على ممارسة المشي المنظم التي تشجع التعلم النشط وتعزز التطبيق العملي للتجربة التعليمية.
يناقش لا فالي وآخرون [21] التدريب الخاص بالمجال البحري الذي تم من خلال اتحاد من النطاقات السيبرانية. يغطي التدريب جوانب مختلفة من الإجراءات الدفاعية، مع التركيز على تأثير إصابة وحدة عرض الخرائط الإلكترونية ونظام المعلومات (ECDIS) على نظام الملاحة.
يهدف مشروع معالجة الأمن السيبراني في التعليم والتدريب البحري (CYMET) من قبل الرابطة الدولية للجامعات البحرية (IAMU) إلى تعزيز الوعي السيبراني في الصناعة البحرية من خلال التعليم والتدريب [1]. قام المشروع بتقييم احتياجات تدريب البحارة وقدم توصيات للتعليم والتدريب البحري. تم اقتراح حل تدريبي قائم على الويب باستخدام منصتي Moodle [24] وitsLearning [38].
أجرى تشودري وجكيولوس [8] دراسة لتطوير وتقييم تمرينين تدريبيين في الأمن السيبراني يركزان على المشارك باستخدام إطار التدريب القائم على نظرية التعلم الشخصي (PLT). أظهر تقييم كلا التمرينين أن مشاركة المتعلمين وتحفيزهم زادا عندما شاركوا في تطوير التمرين، مما دفعهم إلى استخدام أدوات التدريب بشكل مستقل.
في هذه الدراسة، تم تنفيذ وتقييم برنامج مارسي، مع التركيز بشكل خاص على تقييم مشاركة القادة والمتعلمين والمدعوين وتعليقاتهم. لتحقيق هذه الغاية، تم اتباع العملية التالية لإجراء تحليلات كمية ونوعية: تحديد الشركاء، وإجراء استبيانات مسبقة للقادة والمدعوين، وتحليل توقعات التدريب، وتطوير المواد مثل العروض التقديمية واستبيانات التقييم البعدي، وإجراء التدريب واستبيانات التقييم البعدي، وتحليل الامتحانات والتقييمات والملاحظات، وتحسين برنامج تدريب مارسي.
لغرض تقييم فعالية برنامج تدريب مارسي، قررنا إجراء جلسات تدريبية. لتسهيل هذه العملية، بحثنا بنشاط عن شركاء يتعاونون معنا في تنظيم التدريب. في اختيار شركائنا، أولينا أهمية لضمان مجموعة متنوعة من ملفات المتعلمين المحتملين. في النهاية، أقمنا شراكات ناجحة مع أربع منظمات: هيئة تصنيف، ونادي طلابي تابع لجامعة، وكلية بحرية، وشركة تدريب بحري.
بعد تحديد شركائنا، أعددنا استبيانين مسبقين مختلفين لفهم احتياجات وتوقعات التدريب. تم تصميم أحد هذه الاستبيانات لقادة شركائنا، بينما كان الآخر موجهًا للمدعوين. أولاً، أجرينا اجتماعات منفصلة مع قادة شركائنا لإجراء الاستبيانات المسبقة، استمر كل منها 2.5 ساعة. بعد تحليل توقعات التدريب، تم تخطيط الجلسات التدريبية وتم تطوير استبيانات التقييم البعدي بناءً على ملفات المتعلمين المحتملين والوحدات التدريبية المقدمة.
من خلال استبيان التقييم البعدي، تم جمع معلومات حول خلفية المتعلمين وتمت الإجابة على أسئلة الاختبار القبلي من قبل المتعلمين قبل التدريب. ثم تم تقديم الوحدات التدريبية من قبل المدربين. بعد كل وحدة، طُلب من المتعلمين تقييم الوحدة. بعد تغطية جميع الوحدات، أجاب المتعلمون على أسئلة الاختبار البعدي. أخيرًا، تم تقييم التدريب العام من قبل المتعلمين. تم تحليل جلسات التدريب التي أجريت، مع مراعاة ملاحظات المدربين والتقييمات والملاحظات ونتائج الامتحانات، وتم تحسين برنامج مارسي بناءً على النتائج التي تم الحصول عليها.
في البداية، تم إجراء استبيانات مسبقة مع قادة جميع الشركاء. لوحظ خلال هذه الاجتماعات أن القادة يفتقرون إلى المعرفة الكافية في مجال الأمن السيبراني البحري. لذلك، كان من الضروري تزويدهم بشروحات مفصلة بخصوص الأسئلة المدرجة في الاستبيان المسبق. تراوحت متوسط درجات الاختبارات القبلية في جلسات التدريب المنفذة من 43 إلى 51، بينما تراوحت درجات الاختبارات البعدية من 61 إلى 78. حققت جلسات التدريب زيادة متوسط قدرها 52% في الدرجات. وقد لوحظ أن جميع درجات الاختبارات البعدية كانت أعلى من درجات الاختبارات القبلية، مما يشير إلى أن الوحدات المنفذة توفر فوائد للمتعلمين.
في مرحلة تحديد احتياجات المنظمة، وجدنا أن الاحتياجات المذكورة كانت مغطاة بالفعل بالمحتوى الذي أوصينا به في برنامج مارسي. لاحظنا أيضًا أن القادة واجهوا تحديات في تحديد احتياجاتهم التدريبية بسبب معرفتهم المحدودة بالأمن السيبراني البحري. تم تأكيد الوحدات المحددة في برنامج مارسي لتلبية احتياجات شركائنا، باستثناء النادي الطلابي، مما أدى إلى تطوير وحدة M12 للسفن المستقلة.
في مرحلة تحديد أداء الوظيفة، تم فحص أدوار ومسؤوليات المتعلمين المحتملين. أظهرت الدراسة أن الموظفين قد يكون لديهم أدوار مركبة مثل "DPA & CSO"، وأن مسؤوليات المهنيين قد تكون أيضًا مجموعة بناءً على الأدوار. تم تحسين توصيات البرنامج بناءً على هذه النتائج، بما في ذلك إضافة مسؤولية "التشغيل الآمن للسفن".
في مرحلة تحديد احتياجات المتعلم، تم تقييم الوحدات من قبل المتعلمين حسب مسؤولياتهم. أكدت التقييمات التي قدمها المتعلمون بعد التدريب صحة توصية برنامج مارسي بتصميم التدريب وفقًا لأدوار ومسؤوليات الأفراد. تم تفضيل طريقة دراسة الحالة بشكل خاص من قبل المتعلمين من جميع الشركاء.
في مرحلة بناء المنهج واختيار الاستراتيجيات التعليمية، تم استشارة قادة الشركاء. قمنا بتطوير منهج لوحدة M12 للسفن المستقلة. تم تنفيذ المحاضرات ودراسات الحالة والمناقشات كطرق تدريسية. فضل جميع المتعلمين طرق المحاضرة والمناقشة ودراسة الحالة. تمت ملاحظة مشكلات تتعلق بتسليم المواد التدريبية والموارد البشرية والمادية، وتم تقديم توصيات لمعالجتها.
تم تنظيم جلسات التدريب بتنسيقات عبر الإنترنت (مباشر) وحضوري وهجين، مما سمح بالتحقق من برنامج مارسي للتطبيقات الثلاثة. تراوحت مدة التدريب من 1.5 إلى 3 ساعات، مع تخصيص حوالي 20-25 دقيقة لكل وحدة. أعرب نصف متعلمي هيئة التصنيف تقريبًا عن أن مدة التدريب غير كافية. أوصى برنامج مارسي بتخصيص ساعتين على الأقل لكل وحدة تدريبية.
أثبتت هذه الدراسة أن برنامج مارسي يمكن استخدامه لتدريب الطلاب والمهنيين العاملين في مشغلي السفن والموظفين الفنيين في هيئات التصنيف. تم تأكيد أن وحدة تدريبية جديدة يمكن إنشاؤها باستخدام البرنامج، وأنه يمكن استخدامه للبرامج التدريبية الهجينة وعبر الإنترنت والحضورية. في الدراسات المستقبلية، يمكن تطوير وتقييم برامج تدريبية لأبعاد أخرى من المجال البحري مثل القوات البحرية والسلطات البحرية باستخدام برنامج مارسي.
أظهرت الدراسة أن الخلفية المعرفية ضرورية لفهم المخاطر السيبرانية لأنظمة السفن الحيوية. لذلك، عند تشكيل مجموعات التعلم، من المفيد تجميع الأفراد ذوي المستويات المعرفية المتقاربة. أظهرت دراستنا أنه بغض النظر عن الاختلافات الأولية في مستويات معرفة المتعلمين بالأمن السيبراني، فقد تقاربت مستوياتهم بعد التدريب. وجد أن 31% على الأقل من الشركات البحرية قد تعرضت سابقًا لهجمات سيبرانية، بينما تلقى 25% فقط من موظفي المكاتب تدريبًا في الأمن السيبراني البحري.
بناءً على نتائج الامتحانات قبل وبعد التدريب، تثبت هذه الدراسة أن برنامج مارسي زاد من درجات المتعلمين بنسبة تتراوح بين 27% و81%. وفقًا لآراء المتعلمين، تم التأكيد على ضرورة تطوير مقرر إلزامي باتباع برنامج مارسي لمعالجة احتياجات التدريب على الأمن السيبراني للطلاب البحريين. يساهم هذا البحث في سد الفجوة بين الأوساط الأكاديمية والصناعة في مجال الأمن السيبراني البحري.
تم تمويل هذا البحث من مجلس البحوث النرويجي من خلال مشروع المرونة السيبرانية البحرية (MarCy، رقم المشروع 295077) ومركز NORCICS (رقم المشروع 310105). المحتوى يعكس فقط آراء المؤلفين.
قائمة المراجع الكاملة (46 مصدرًا) متاحة في الملف الأصلي للPDF.
The prevalence of digital technologies is growing in the maritime industry, as in other sectors. Consequently, concerns regarding cyber risks are also escalating. Incidents have occurred in the industry, and findings from academic studies further validate these concerns. While technical measures are being taken against cyber threats, the human element remains another crucial aspect that requires strengthening. To effectively combat cyber threats and vulnerabilities, it is imperative to enhance individuals' awareness through education and training. In order to address the cyber security training needs of maritime professionals and students, we have developed an approach called the Maritime Cyber Security (MarCy) training programme. In this study, we evaluate all stages of the proposed programme through four conducted training sessions involving different learner groups. As a result, the MarCy programme was improved based on the findings obtained during the training sessions and the feedback from the learners. This study validates that the MarCy programme is an effective approach to meet the cyber security training needs of various groups in the maritime domain.
Sea transport handles over 80% of the global merchandise trade volume [42], and as a result, the maritime industry has become a vital sector with millions of professionals working in it. The number of seafarers alone is approximately 1.9 million [2]. The Standards of Training Certification and Watchkeeping (STCW) Code currently lacks any requirements or recommendations for enhancing the cyber awareness of seafarers. Therefore, seafarers, beyond the training requirements of the International Maritime Organization (IMO), typically receive cyber security training during their professional careers. However, the possibility of this situation changing is likely. The Republic of Korea submitted a proposal in December 2021 to discuss the importance of integrating cyber security training into the STCW [18]. The Sub-committee on Human Element Training and Watchkeeping at the IMO was invited to deliberate on relevant provisions concerning training for seafarers in the field of cyber security.
We developed the MarCy training programme by incorporating the insights and opinions of experts, with the aim of its application in maritime cyber security training courses. The purpose of this study is to evaluate the applicability and effectiveness of the MarCy training programme. This work is a continuation of our previous work proposed by Oruc, Chowdhury, and Gkioulos [30]. The contribution of our study can be summarized as: evaluation of the MarCy training programme, evaluation of training sessions, and sharing observations and participants' feedback. In this study, the MarCy programme was implemented to develop cyber security training courses for students and professionals. Before the training courses, a pre-requisite survey was conducted by holding a meeting with the leaders of partner organizations. Subsequently, partners sent another pre-requisite survey to invitees to gather their training expectations.
While the MarCy programme has the potential for expansion with additional modules to cater to various stakeholders in the maritime industry, the focus of the original paper is specifically on the implementation of cyber security training for seafarers and office staff in shipping companies. This study demonstrates the application of the MarCy programme in the training of students from different departments (both maritime and non-maritime), office employees in shipping companies, and technical staff from class societies. Even though this study does not cover the training of all professional groups, it is possible to implement the MarCy programme to provide cyber security training for these groups.
Over the years, several models have been put forth to guide the design and development of training programs. One such model is the Critical Events Model (CEM) introduced by Leonard Nadler in 1982, which has acquired recognition as a well-established and extensively described approach to training design. The CEM provides a comprehensive framework for designing training courses. It is not limited to formal education settings, but can also address the training requirements of various organizations. Notably, the CEM is well-suited for industries characterized by rapid changes, offering a flexible and adaptable approach [25]. We made three modifications to CEM with the MarCy programme: adding a modular approach, tailoring it specifically for maritime cyber security, and replacing the original evaluation phase with our own evaluation approach relying on internal stakeholder feedback.
The modular training approach involves offering learners relevant components of a training program tailored to their individual training needs. This approach has been implemented for various training requirements and has proven particularly effective in vocational training [16, 11]. By providing attendees with only the necessary knowledge aligned with their learning needs, this approach minimizes disruptions to their professional lives. Consequently, modular training is a cost-effective method that can be delivered online, offering flexibility to both the training designer and the learner [39].
We employed the Delphi method to evaluate the MarCy training programme. The Delphi method is widely recognized in the literature as a suitable research instrument for gathering judgments and opinions on topics where knowledge may be incomplete [40]. This method involves an iterative process that aims to collect feedback from a selected panel of experts who provide their insights anonymously. We chose the Delphi method as the validation technique for our programme because it enables us to gather weighted feedback from the panel of experts and facilitates open debate without the need for practical evaluation methods such as experimentation.
Erstad et al. [14] explore the application of a Human-Centered Design (HCD) approach for maritime cyber resilience training. The authors propose using HCD for the development of tailored maritime cyber resilience training, including simulator-based team training. By engaging with end-users and incorporating learning theories, the training becomes realistic and relevant to the learners' needs.
Canepa et al. [7] examine the challenges of maritime cyber security training and the use of a cyber range as a solution. The paper presents the Cyber-MAR project [10], which implements a federated cyber range solution as part of a cyber security training platform tailored to the maritime sector. The methodology includes qualitative analysis through literature review and analysis of target groups, as well as quantitative analysis of the results from the initial LMS training.
Potamos et al. [37] present a novel training curriculum and offer design guidelines for creating activities on a maritime cyber range, with the aim of strengthening defenses against ransomware attacks. The curriculum emphasizes structured walkthrough practice, which encourages active learning and enhances the practicality and memorability of the educational experience.
La Vallée et al. [21] discuss maritime-specific training conducted through a federation of cyber ranges. The training covers various aspects of defensive actions, focusing on the impact of ECDIS console infection on the navigation system.
The CYMET research project by the IAMU aims to enhance cyber awareness in the maritime industry through education and training [1]. The project evaluated the training needs of seafarers and provided recommendations for maritime education and training. A web-based training solution was proposed using Moodle [24] and itsLearning [38] platforms.
Chowdhury and Gkioulos [8] performed a study to develop and evaluate two participant-centered cyber security training exercises using the Personalized Learning Theory (PLT)-based training framework. Evaluation of both exercises showed that participants' engagement and motivation increased as they were involved in exercise development, leading them to use the training tools independently.
In this study, the MarCy programme is implemented and evaluated, with a particular focus on evaluating leaders', learners', and invitees' engagement and feedback. To this end, the following process was pursued to make quantitative and qualitative analyses: identification of partners, performing pre-requisite surveys for leaders and invitees, analysis of training expectations, development of materials such as presentations and post-assessment surveys, performing training and post-assessment surveys, analysis of exams, evaluations, and feedback, and improvement of the MarCy training programme.
For the purpose of evaluating the effectiveness of the MarCy training programme, we decided to conduct training sessions. To facilitate this process, we actively sought out partners who would collaborate with us in organizing the training. In selecting our partners, we placed importance on ensuring a diverse range of potential learner profiles. Ultimately, we successfully established partnerships with four organizations: a class society, a student club affiliated with a university, a maritime faculty, and a maritime training company.
After determining our partners, we prepared two different pre-requisite surveys to understand the training needs and expectations. One of these surveys was designed for the leaders of our partners, while the other was aimed at invitees. Firstly, we conducted separate meetings with the leaders of our partners to perform pre-requisite surveys, each lasting 2.5 hours. After analyzing the training expectations, the training sessions were planned and post-assessment surveys were developed based on potential learner profiles and the training modules to be provided.
Through the post-assessment survey, information about the learners' background was collected and the questions in the Quiz were answered by learners prior to the training. Then, the training modules were delivered by the instructors. After each module, learners were asked to evaluate the module. After all modules were covered, learners answered the questions in the Test. Finally, the overall training was evaluated by the learners. The conducted training sessions were analyzed, considering the observations of the instructors, evaluations, feedback, and exam results, and the MarCy programme was improved based on the findings obtained.
Initially, pre-requisite surveys were conducted with the leaders of all partners. It was observed during these meetings that the leaders lacked sufficient knowledge in the field of maritime cyber security. Therefore, it was necessary to provide them with detailed explanations regarding the questions included in the pre-requisite survey. The average Quiz scores in the conducted training sessions range from 43 to 51, while the Test scores range from 61 to 78. The training sessions resulted in an average score increase of 52%. It has been observed that all Test scores are higher than the Quiz scores, indicating that the conducted modules provide benefits to the learners.
In the identify the needs of the organization step, we found that the stated needs were already covered by the content we recommended in the MarCy programme. We observed that the leaders faced challenges in identifying their training needs because of their limited knowledge of maritime cyber security. We confirmed the modules specified in the MarCy programme met the needs of our partners, except for the Student Club, leading to the development of the M12 Autonomous Ships module.
In the specify job performance step, the roles and responsibilities of potential learners were examined. The study showed that employees might have combined roles such as "DPA & CSO", and that the responsibilities of professionals might also be a combination based on roles. The programme's recommendations were refined based on these findings, including adding the "safe manning of ships" responsibility.
In the identify learner needs step, modules were evaluated by learners according to their responsibilities. The evaluations provided by the learners after the training confirmed the validity of the MarCy programme's recommendation that training should be tailored to individuals' roles and responsibilities. The case study method was particularly preferred by learners across all partners.
In the build curriculum and select instructional strategies steps, partners' leaders were consulted. We developed a curriculum for the M12 Autonomous Ships module. Lectures, case studies, and discussions were implemented as instructional methods. All learners found lecture, discussion, and case study methods effective. Issues with training material delivery, human resources, and physical resources were observed and recommendations were made.
The training sessions were organized in online (live), on-site, and hybrid formats, allowing the MarCy programme to be verified for all three implementations. Training duration ranged from 1.5 to 3 hours, with approximately 20-25 minutes allocated per module. Half of the Class Society learners found the training duration insufficient. The MarCy programme recommends allocating at least two hours per training module.
This study verified that the MarCy programme can be used for the training of students, professionals working in ship operators, and technical personnel in class societies. It was confirmed that a new training module can be created using the programme, and that it can be used for hybrid, online, and on-site training programs. In future studies, training programs for other dimensions of the maritime domain such as naval forces and maritime authorities can be developed and evaluated using the MarCy programme.
This study demonstrated that background knowledge is crucial in understanding the cyber risks of critical ship systems. Therefore, when forming learning groups, it is beneficial to group individuals with close knowledge levels. Our study showed that regardless of the initial differences in learners' knowledge levels in cyber security, they converged towards each other after the training. It was found that at least 31% of maritime companies have previously experienced cyber attacks, while only 25% of office employees have received maritime cyber security training.
Based on the exam results before and after the training, this study demonstrates that the MarCy programme increased learners' scores by 27% to 81%. According to the learners' opinions, it is emphasized that a mandatory course should be developed by following the MarCy programme to address the cyber security training needs of cadets. This research contributes to bridging the gap between academia and industry in maritime cyber security.
This paper has received funding from the Research Council of Norway through the Maritime Cyber Resilience (MarCy, project number 295077) project and the NORCICS centre (project number 310105). The content reflects only the authors' views.
Full reference list (46 sources) available in the original PDF.