تشهد الصناعة البحرية تحولًا رقميًا سريعًا، حيث تدمج التقنيات المتقدمة لتعزيز الكفاءة التشغيلية والاتصال. ومع ذلك، يُحدث هذا التحول ثغرات أمنية سيبرانية كبيرة، حيث أن الاعتماد المتزايد على الأنظمة الرقمية للملاحة والاتصال والتحكم يعرض السفن للتهديدات السيبرانية. على الرغم من الوعي المتزايد، تفتقر الصناعة إلى أطر أمنية سيبرانية موحدة، مما يؤدي إلى دفاعات مجزأة يمكن للمهاجمين استغلالها لاختراق الأنظمة الحيوية مثل وظائف الملاحة والتحكم. يهدف إطار مراكز العمليات الأمنية البحرية (M-SOC) إلى توفير نهج موحد لمراقبة التهديدات واكتشافها والاستجابة لها. ومع ذلك، لا يزال البحث حول تكييف مراكز العمليات الأمنية التقليدية (SOC) مع البيئة البحرية الفريدة محدودًا. تعالج هذه الورقة هذه الفجوة من خلال إجراء مراجعة منهجية للأدبيات (SLR) باستخدام إطار SALSA لفحص الوضع الحالي لمراكز M-SOC. من خلال تحليل الأبحاث الحالية، نحدد الاتجاهات الرئيسية والتحديات والفرص في العمليات الأمنية السيبرانية البحرية. تسلط نتائجنا الضوء على الحاجة إلى نماذج SOC مخصصة تراعي القيود التشغيلية والتكنولوجية والبشرية المميزة للقطاع البحري.
مع دمج التقنيات المتطورة بسرعة في عمليات السفن، تشهد الصناعة البحرية تحولًا رقميًا سريعًا. تزيد هذه التطورات من الاتصال والكفاءة، ولكنها تقدم أيضًا تهديدات سيبرانية جديدة. تصبح السفن أكثر عرضة للهجمات السيبرانية كلما زاد اعتمادها على الأنظمة الرقمية للتحكم والاتصال والملاحة. يفتقر القطاع حاليًا إلى حلول متكاملة توفر صورة شاملة للحالة الأمنية السيبرانية للسفينة، على الرغم من الوعي المتزايد. الدفاعات الحالية غالبًا ما تكون مجزأة وتركز على أنظمة محددة بشكل منفصل. يمكن للمهاجمين استغلال الثغرات الأمنية الناتجة عن هذه الاستراتيجية غير المترابطة للوصول إلى الأنظمة الحيوية أو عرقلة الملاحة.
تبذل جهود لتعزيز المرونة السيبرانية في القطاع البحري، ويبحث القطاع عن حلول متكاملة تراعي تعقيد العمليات البحرية المعاصرة. مركز العمليات الأمنية البحرية (M-SOC) هو أحد النهج الجديدة التي تهدف إلى توفير مراقبة موحدة واكتشاف التهديدات والاستجابة عبر جميع الأنظمة على متن السفينة. هناك بحث محدود حول كيفية تكييف مراكز العمليات الأمنية التقليدية (SOC) للبيئة البحرية.
مع زيادة التكامل السيبراني في الأنظمة البحرية، من الضروري الاهتمام بجانب الأمن السيبراني لجميع المخاطر المستجدة وسطح الهجوم المتزايد. ومع ذلك، عند التخطيط لتدابير الأمن السيبراني، يجب أن نضع في الاعتبار الطبيعة الفريدة للصناعة البحرية ومدى تعقيدها واتساعها. مع اعتماد غالبية التجارة العالمية على النقل البحري، من الضروري تأمين العمليات ومستوى مماثل من الحماية السيبرانية كغيرها من البنى التحتية الحساسة [1]، [2].
على عكس الصناعات البرية، تواجه العمليات البحرية عقبات خاصة جدًا. الاتصال في البحر متقطع ومحدود النطاق الترددي، مما يجعل الدفاع في الوقت الفعلي والدعم عن بعد تحديًا لوجستيًا. تعتمد العديد من السفن أيضًا على أنظمة قديمة لم تكن مصممة مع وضع الأمن السيبراني في الاعتبار، وهناك تفاوت كبير في النضج الرقمي عبر أنواع السفن والأساطيل المختلفة. أضف إلى ذلك حقيقة أن العديد من أطقم السفن لديها تدريب محدود على تكنولوجيا المعلومات، مما يترك القطاع عرضة بشكل فريد للاضطراب السيبراني [3]، [4].
تعد حماية المجال البحري من الهجمات السيبرانية مهمة حاسمة من شأنها التخفيف الاستباقي من الحوادث المدمرة، حيث تتعامل الصناعة البحرية مع ما يقرب من 90% من التجارة العالمية. تعتمد بشكل متزايد على بنى سيبرانية عالمية معقدة ومترابطة، وتدمج أنظمة تكنولوجيا المعلومات (IT) وتكنولوجيا التشغيل (OT) لدعم عملياتها المتنوعة والمعقدة [5]، [6].
المراجعة المنهجية للأدبيات (SLR) هي نهج منظم ومنهجي لجمع وتقييم نقدي وتوليف وعرض النتائج من الدراسات البحثية التي تركز على سؤال أو موضوع بحثي محدد. تطبق هذه الدراسة إطار PSALSAR، وهو نسخة موسعة من إطار SALSA (البحث، التقييم، التوليف، والتحليل)، مع دمج مرحلة البروتوكول المستمدة من إرشادات PRISMA ومرحلة تقرير مخصصة. يتكون إطار PSALSAR من ست مراحل: البروتوكول (تحديد نطاق الدراسة وأسئلة البحث باستخدام إطار PICOC)، البحث (تحديد قواعد البيانات المناسبة وصياغة سلاسل البحث)، التقييم (تحديد معايير الاشتمال والاستبعاد وتقييم الجودة)، التوليف (استخراج البيانات وتصنيفها)، التحليل (التحليل الكمي والروائي)، والتقرير (إنتاج المقالة العلمية).
باستخدام إطار PICOC، تمت صياغة خمسة أسئلة بحثية: (1) ما هو الوضع الحالي لأبحاث M-SOC؟ (2) ما هي المناهج المنهجية المستخدمة لدراسة M-SOC؟ (3) ما هي جوانب M-SOC التي حصلت على أكبر وأقل اهتمام بحثي؟ (4) ما هي التحديات والفجوات الرئيسية في تنفيذ وأبحاث M-SOC؟ (5) ما هي الاتجاهات الناشئة والتوجهات المستقبلية لتطوير M-SOC؟ [19]–[25]
حددت المراجعة 9 منشورات تغطي الفترة من 2016 إلى 2024، أجريت جميعها في أوروبا، مما يعكس تحيزًا إقليميًا قويًا. معظم المنشورات متاحة كمصادر مفتوحة، مع تباين واسع في الاستشهادات. جمعت الأعمال التأسيسية من السنوات السابقة اهتمامًا كبيرًا، بينما تعكس المنشورات الحديثة مجالات تركيز ناشئة مثل التدريب والعوامل البشرية والمرونة السيبرانية.
يمكن تصنيف دراسات M-SOC إلى أربعة محاور: (1) التدريب والتعليم، (2) البنية التقنية والتنفيذ، (3) العوامل البشرية والتحديات التشغيلية، و(4) تحليل التهديدات والسياق التاريخي. يكشف الوضع الحالي للمعرفة أنه بينما تشكل مبادئ SOC أساس عمليات M-SOC، فإن السياق البحري يقدم متغيرات فريدة تشمل الاتصال المتقطع والأنظمة القديمة ومحدودية التدريب على تكنولوجيا المعلومات بين أطقم السفن.
تظهر النتائج تركيزًا كبيرًا على برامج التدريب والهياكل التقنية للأنظمة، مع بقاء الفئات الحاسمة مثل مقاييس التنفيذ واعتبارات السفن الصغيرة غير مستكشفة بشكل كاف. تناولت الدراسات موضوعات تشمل بيئات المحاكاة السيبرانية، وتكييف إطار SOC للبيئة البحرية، والتفاعل البشري-الآلي، وتحليل الحوادث السيبرانية التاريخية في القطاع البحري [6]، [10]، [13]–[18].
تم تحديد العديد من التحديات والفجوات البحثية الحرجة. أولاً، النطاق الجغرافي الضيق — أجريت جميع الدراسات الـ 9 في أوروبا، تاركة مناطق بحرية شاسعة مثل آسيا والمحيط الهادئ وأفريقيا وأمريكا الشمالية والجنوبية غير مستكشفة إلى حد كبير. ثانيًا، التركيز المواضيعي يميل بشكل كبير نحو مؤشرات التدريب وهياكل الأنظمة، بينما تظل مقاييس التنفيذ والتحديات المحددة للسفن الصغيرة غير مستكشفة.
هناك تركيز غير متناسب على البنية التقنية وبرامج التدريب على حساب التقييمات التشغيلية والعوامل البشرية ومقاييس التنفيذ في العالم الحقيقي. معظم دراسات M-SOC تعامل النظام كأداة تقنية، بينما يتم تجاهل المشغلين البشريين — إرهاقهم، جودة تدريبهم، اتخاذ القرار تحت الضغط، وديناميكيات الفريق — إلى حد كبير.
يجب على الأبحاث المستقبلية توسيع نطاقها الجغرافي ليعكس الطبيعة العالمية الحقيقية للعمليات الأمنية البحرية، ليشمل مصادر متعددة اللغات ودراسات من مناطق متنوعة. هناك حاجة ماسة للتقييمات التجريبية القائمة على عمليات العالم الحقيقي بدلاً من العمل المفاهيمي أو التجريبي البحت. هناك حاجة لدراسات حول الأنظمة الفرعية المتكاملة لـ M-SOC والأطر الشاملة لدعم فهم أكثر شمولاً.
يجب أن يتناول العمل المستقبلي أيضًا الجانب البشري للعمليات الأمنية البحرية — كيفية تفاعل الأفراد مع الأنظمة الآلية، وكيفية تدفق الاتصالات عبر الوحدات والوكالات المختلفة، وماذا يحدث عندما يتعارض الحكم البشري مع التوصيات الخوارزمية. فهم هذه الديناميكيات ضروري لبناء أنظمة تعمل بفعالية في البيئات التشغيلية الحقيقية.
على الرغم من تزايد الأعمال حول مراكز العمليات الأمنية البحرية (M-SOC)، فإن الأبحاث الحالية لا تخدش إلا سطح ما هو مطلوب حقًا لفهم شامل. بقيت العديد من الدراسات ضمن نطاق ضيق، مركزة بشكل كبير على الأطر المفاهيمية أو التحقق التجريبي دون التطور إلى رؤى تشغيلية كاملة النطاق. معرفتنا الجماعية بـ M-SOC تظل مجزأة ومركزة بشكل غير متناسب على عناصر محددة مثل التدريب أو التصميم التقني أو التعليم.
من أبرز القيود هو النطاق الجغرافي الضيق، حيث أن معظم الدراسات تنحصر في السياقات الأوروبية. هذا التحيز الإقليمي يخاطر بتوليد فهم جزئي للعمليات الأمنية البحرية، حيث تظل التحديات المحلية مثل بؤر القرصنة والبنية التحتية المحدودة والبيئات التنظيمية المختلفة غير مرئية في الخطاب السائد. التركيز المواضيعي يميل بشكل كبير نحو التدريب وهياكل الأنظمة، بينما تظل الفئات الحاسمة مثل مقاييس التنفيذ واعتبارات السفن الصغيرة غير مستكشفة إلى حد كبير.
التركيز على الأبحاث المفاهيمية والتجريبية — حوالي 70% من الأدبيات التي تمت مراجعتها — يشير إلى مجال لا يزال في مراحله التطويرية. بدون أبحاث تجريبية قائمة على عمليات العالم الحقيقي، يكاد يكون من المستحيل تصميم حلول تعمل تحت الضغط. يجب على الدراسات المستقبلية التوسع جغرافيًا، وتنويع مواضيعيًا، ووضع المشغلين البشريين في مركز أبحاث M-SOC لبناء أنظمة فعالة من الناحية التقنية والتشغيلية [19]–[51].
The maritime industry is undergoing rapid digital transformation, integrating advanced technologies to enhance operational efficiency and connectivity. However, this shift introduces significant cybersecurity vulnerabilities, as increasing reliance on digital systems for navigation, communication, and control exposes vessels to cyber threats. Despite growing awareness, the industry lacks unified cybersecurity frameworks, leading to fragmented defenses that attackers can exploit to compromise critical systems such as navigation and control functions. The Maritime Security Operations Centers (M-SOCs) Framework aims to provide a consolidated approach to threat monitoring, detection, and response. However, research on adapting traditional Security Operations Centers (SOCs) to the unique maritime environment remains limited. This paper addresses this gap by conducting a systematic literature review (SLR) using the SALSA (Search, Appraisal, Synthesis, and Analysis) framework to examine the current state of M-SOCs. By analyzing existing research, we identify key trends, challenges, and opportunities in maritime cybersecurity operations. Our findings highlight the need for tailored SOC models that account for the maritime sector's distinct operational, technological, and personnel constraints.
With cutting-edge technologies quickly incorporated into vessel operations, the maritime industry is seeing a rapid digital transformation. These developments increase connectedness and efficiency, but they also present new cybersecurity threats. Ships are more susceptible to cyberattacks as they depend more and more on digital systems for control, communication, and navigation. The sector currently lacks integrated solutions that provide a comprehensive picture of a vessel's cybersecurity state, despite growing awareness. The defenses in place now are frequently fragmented and focus on specific systems separately. Attackers can use the security flaws created by this disjointed strategy to get access to vital systems or obstruct navigation.
Efforts to enhance cyber resilience in the maritime sector are underway, and the industry is investigating integrated solutions that consider the complexity of contemporary maritime operations to increase cyber resilience. The Maritime Security Operations Center (M-SOC), which aims to offer unified monitoring, threat detection, and response across all onboard systems, is one new approach. There is little research on how to tailor conventional Security Operations Centers (SOCs) for the maritime environment.
With the increased cyber integration into the maritime systems, it is needed to tend to the cybersecurity aspect of all the newly introduced concerns and increasing attack surface. However, when planning cybersecurity measures, we need to keep in mind the unique nature of the maritime industry and how complex and vast it is. With majority of the world trade relying on maritime transportation, it is crucial to have secure operations and a similar level of cyber protection as other sensitive infrastructures [1], [2].
Unlike land-based industries, maritime operations face some very particular hurdles. For starters, connectivity at sea is intermittent and bandwidth-limited, making real-time defense and remote support a logistical nightmare. Many vessels also rely on legacy systems that weren't designed with cybersecurity in mind, and there's a wide disparity in digital maturity across different types of ships and fleets. Add to that the fact that many crews have limited IT training, and you're left with a sector uniquely vulnerable to cyber disruption [3], [4].
Safeguarding the maritime domain from cyberattacks is a crucial task that will proactively mitigate devastating incidents, with the maritime industry handling nearly 90% of world trade. It increasingly depends on complicated, interconnected global cyber architectures, integrating Information Technology (IT) and Operational Technology (OT) systems to support its various and complex operations and processes [5], [6].
A Systematic Literature Review (SLR) is a structured and methodical approach to gathering, critically assessing, synthesizing, and presenting findings from research studies focused on a specific research question or topic. This study applies the PSALSAR framework, an extended version of the SALSA (Search, Appraisal, Synthesis, and Analysis) framework, incorporating a Protocol phase derived from PRISMA guidelines and a dedicated Report phase. The PSALSAR framework consists of six phases: Protocol (defining study scope and research questions using the PICOC framework), Search (identifying relevant databases and formulating search strings), Appraisal (defining inclusion/exclusion criteria and quality assessment), Synthesis (data extraction and categorization), Analysis (quantitative and narrative analysis), and Report (journal article production).
Using the PICOC framework, five research questions were formulated: (1) What is the current state-of-the-art in M-SOC research? (2) What methodological approaches are being used to study M-SOCs? (3) Which aspects of M-SOCs have received the most and least research attention? (4) What are the primary challenges and gaps in M-SOC implementation and research? (5) What are the emerging trends and future directions for M-SOC development? [19]–[25]
The review identified 9 publications covering the period from 2016 to 2024, all conducted within Europe, reflecting a strong regional bias. Most papers are openly accessible, with citations varying widely. Foundational works from earlier years gathered significant attention, while recent publications reflect emerging focus areas such as training, human factors, and cyber resilience.
M-SOC studies can be categorized into four themes: (1) Training and Education, (2) Technical Architecture and Implementation, (3) Human Factors and Operational Challenges, and (4) Threat Analysis and Historical Context. The current state of the art reveals that while SOC principles form the foundation of M-SOC operations, the maritime context introduces unique variables including intermittent connectivity, legacy systems, and limited IT training among crews.
The results show a heavy focus on training programs and technical system architectures, with critical categories such as implementation metrics and small vessel considerations remaining underexplored. Studies addressed topics including cyber ranges and simulation environments, SOC framework adaptation for maritime, human-automation interaction, and analysis of historical cyber incidents in the maritime sector [6], [10], [13]–[18].
Several critical challenges and research gaps were identified. First, the narrow geographical scope — all 9 studies were conducted in Europe, leaving vast maritime regions such as Asia-Pacific, Africa, North America, and South America largely unexplored. Second, the thematic focus leans heavily on training indicators and system architectures, while implementation metrics and the specific challenges posed by small vessels remain underexplored.
There is a disproportionate focus on technical architecture and training programs at the expense of operational assessments, human factors, and real-world implementation metrics. The lack of standardization and the misalignment between regulations and real-world needs present additional challenges. Most M-SOC studies treat the system as a technical artifact, while human operators — their fatigue, training quality, decision-making under stress, and team dynamics — are largely ignored.
Future research must broaden its geographical scope to reflect the true global nature of maritime security operations, encompassing multilingual sources and studies from diverse regions. There is a critical need for empirical evaluations grounded in real-world operations rather than purely conceptual or experimental work. Studies on integrated M-SOC subsystems and holistic frameworks are needed to support a more comprehensive understanding.
Future work should also address the human side of maritime security operations — how personnel interact with automated systems, how communication flows across different units and agencies, and what happens when human judgment clashes with algorithmic recommendations. Understanding these dynamics is essential for building systems that work effectively in real operational environments.
Despite a growing body of work on Maritime Security Operations Centers (M-SOCs), current research only scratches the surface of what is truly needed for a comprehensive understanding. Many studies have remained within a narrow scope, focused largely on conceptual frameworks or experimental validations without evolving into full-scale, operational insights. Our collective knowledge of M-SOCs remains fragmented and disproportionately focused on specific elements like training, technical design, or education.
One of the most striking limitations is the narrow geographical scope, with most studies rooted in European contexts. This regional bias risks generating a partial understanding of maritime security operations, as localized challenges such as piracy hotspots, limited infrastructure, and different regulatory environments remain invisible in the dominant discourse. The thematic focus leans heavily on training and system architectures, while critical categories such as implementation metrics and small vessel considerations remain vastly underexplored.
The emphasis on conceptual and experimental research — around 70% of the reviewed literature — points to a field still in its developmental stages. Without empirical research grounded in real-world operations, it is nearly impossible to design solutions that work under pressure. Future studies must expand geographically, diversify thematically, and place human operators at the center of M-SOC research to build systems that are both technically sound and operationally effective [19]–[51].
Full reference list (51 sources) available in the original PDF.