A Hacker Gets Through the Satellite Terminal. What Ship System Can They Reach Next?

🔔 Subscribe to ShipUniverse Weekly →

Shipboard Blast-Radius Test

The Shipboard Cyber Blast Radius Test

The communications boundary has failed. That does not mean the attacker owns the bridge or engine room. The next reachable system depends on how the vessel separates internet-facing IT from operational technology.

Scenario state
Satellite Terminal
Boundary compromised
The important question is no longer how the attacker got in.
What network boundary stops them next?

Modern ships can remain continuously connected through VSAT, LEO satellite services, cellular links and shore-managed networks. That connectivity supports voyage optimization, remote diagnostics, software updates, machinery monitoring and crew communications.

It also means the satellite gateway can sit only a few network boundaries away from systems that matter to navigation, cargo and machinery. Whether those boundaries are genuinely separate, loosely connected or effectively flat determines the blast radius.

The useful question is therefore not whether an attacker can “hack the ship.” It is which security zone they can reach after the first boundary fails, and whether the next boundary forces the intrusion to stop.

IACS cyber applicability
Jul 2024
Revised E26/E27 requirements apply to relevant new ships contracted from this date.
USCG rule effective
Jul 2025
Baseline maritime cybersecurity requirements became effective.
OT testing demand
+35%
Increase reported by Coast Guard Cyber for 2025.
Next U.S. milestone
Jul 2027
Major Cybersecurity Officer, assessment and plan requirements phase in.

Compromising communications is not the same as controlling the ship

Reachability and control are different problems. An attacker can only move beyond the communications layer if another system or permitted connection gives them somewhere to go.

Boundary failure

Satellite terminal compromised

The externally connected device or communications segment can no longer be trusted. Traffic, credentials, management interfaces or connected services may require containment and investigation.

Not automatically true

Safety-critical OT compromised

Navigation, machinery, cargo and power systems should sit behind separate controls. A properly designed architecture can allow the communications boundary to fail without exposing these systems.

The ship should make an attacker cross several separate doors

The diagram below is a defensive architecture model. It shows where a satellite-originated compromise can encounter another boundary before it reaches operational technology.

Simplified shipboard trust path

External → safety critical
Zone 01
Satellite / WAN

Internet-facing communications and provider connectivity.

Assume breached
Zone 02
Ship IT

Administration, email, crew services and business applications.

Firewall boundary
Zone 03
OT Gateway

Remote monitoring, data historian or controlled ship-to-shore interfaces.

Controlled conduit
Zone 04
Operational OT

Bridge, cargo, machinery and power-control networks.

Separate zone
Zone 05
Safety / Local Control

Independent or physically segmented safety and local control functions.

Final barrier
The design objective
BIMCO's guidance treats crew and administrative internet networks as uncontrolled and says they should not connect to safety-critical systems. The practical goal is to make compromise of one zone survivable rather than assume the external boundary will never fail.

What could sit on the other side of the satellite connection?

These systems are not automatically exposed. Their risk depends on the vessel's actual interfaces, remote-monitoring arrangements and segmentation.

IT

Crew and administrative networks

Email, office systems, crew welfare internet and shared services are often the nearest internal networks to external connectivity.

First exposure if poorly separated
RM

Remote monitoring gateway

Machinery telemetry, performance monitoring and vendor diagnostics can create legitimate pathways between shore connectivity and onboard OT.

Architecture dependent
NAV

Bridge and navigation systems

ECDIS, AIS, radar, VDR, GNSS-related interfaces and integrated bridge services become relevant when bridge networks exchange data with connected systems.

Should be segregated
ENG

Machinery and propulsion monitoring

Engine-management and alarm systems can become more exposed when condition monitoring or remote diagnostics crosses the IT/OT boundary.

Remote-service risk
CARGO

Cargo management

Loading, monitoring and cargo-management systems may exchange data with ports, terminals and shore applications.

Ship-to-shore interfaces
SAFE

Safety-critical local control

Steering, essential machinery and other required safety functions should have much stronger separation and retain safe local or independent operation.

Should remain isolated

The real risk is the bridge between networks

Satellite-originated reachability test
Defensive architecture view
System zone Legitimate connection If segmented correctly If segmentation is weak
Crew / guest Internet and welfare services Contained Can become a stepping stone into shared IT resources.
Business IT Email, ship management, reporting Separate from OT behind controlled interfaces. Shared switches, credentials or routes can expand lateral reach.
Remote monitoring Telemetry and condition monitoring Data-limited A bidirectional maintenance pathway can enlarge the OT exposure.
Navigation Bridge zone Updates, sensor exchange, reporting Dedicated zone Integrated networks can expose additional navigation services.
Machinery Remote diagnostics and performance data Restricted conduit Poorly controlled remote access can increase exposure to machinery networks.
Cargo systems Terminal, stowage and monitoring data Controlled exchange Shared infrastructure can create a wider operational impact.
Safety functions Ideally minimal external dependency Physically separated Loss of separation would represent a much higher-consequence architecture.
“Reachable” means a network path or trusted interface may exist. It does not mean an attacker can automatically operate or alter the system. Authentication, application security, protocol design, device hardening and local safety controls remain additional barriers.

Three ships can have the same satellite terminal and completely different blast radii

Architecture A

Segmented vessel

External communications, crew IT, business IT and operational systems occupy separate zones. OT interfaces allow only necessary traffic and remote maintenance is tightly controlled.

Satellite breach stops near the communications boundary.
Architecture B

Connected monitoring vessel

IT and OT are segmented, but remote machinery monitoring, voyage services or vendor support create controlled cross-zone pathways.

Remote-service gateways become the critical choke point.
Architecture C

Flat or poorly segmented vessel

Crew, administration and operational networks share routing, infrastructure or overly permissive firewall rules.

One communications compromise can create a much larger investigation.

The Coast Guard keeps finding the same weak point

Coast Guard Cyber's 2024 field work identified improper network segmentation as one of the most common vulnerabilities it encountered, particularly in OT environments. Its description of the modern vessel is striking: continuous connectivity means a ship can appear to the enterprise network much like another remote facility.

The 2025 CTIME report showed growing concern around OT rather than a retreat from it. Demand for Coast Guard OT testing increased 35%. Across broader maritime missions, teams continued finding weak credentials, exposed services and poor segmentation even as organizations adopted more sophisticated defensive technology.

The uncomfortable implication
Buying a better satellite service or a more advanced firewall cannot compensate for an architecture in which the communications, business and operational networks are allowed to trust each other too broadly.

The rulebook is moving toward blast-radius control

January 2021
IMO cyber risk enters Safety Management Systems

IMO Resolution MSC.428(98) establishes the expectation that maritime cyber risk is addressed through company safety management.

July 2024
Revised IACS E26/E27 requirements apply

Relevant new ships contracted from this date fall under the revised cyber-resilience requirements for ship integration and onboard systems.

July 2025
U.S. Coast Guard cybersecurity rule takes effect

Baseline cybersecurity requirements enter force for covered U.S.-flagged vessels and other regulated MTS entities.

January 2026
Cyber training deadline

Covered personnel become subject to specified cybersecurity training requirements, including OT-specific training where applicable.

July 2027
Major U.S. planning deadline

Covered owners and operators must meet the scheduled requirements for a Cybersecurity Officer, assessment and Cybersecurity Plan.

If the satellite boundary fails, the response priority is containment

The first objective is not to prove exactly who the attacker is. It is to prevent an external communications incident from becoming a navigation, machinery or cargo incident.

01

Isolate external access

Separate the affected communications path from internal networks while preserving safe vessel operations.

02

Protect OT boundaries

Confirm that bridge, cargo, machinery and safety zones are still isolated and operating as designed.

03

Preserve evidence

Retain logs, alerts and network records needed to reconstruct what systems communicated during the incident.

04

Maintain local control

Use safe local or independent operating modes where required while external connectivity is being investigated.

Satellite Breach Blast-Radius Simulator

Assume the external communications terminal is already compromised. Change the ship's internal architecture and see how far that compromise can plausibly propagate before another security boundary stops it.

ShipUniverse Defensive Reachability Model

Where does the intrusion stop?

This tool models defensive network reachability only. It does not simulate exploitation of ship systems.

Boundary failed
IT separation
Crew / guest network Separate uncontrolled internet traffic from business systems.
Ship business IT Administrative systems relative to the satellite gateway.
IT / OT boundary
OT firewall / gateway Controls traffic between business IT and operational systems.
Remote monitoring Machinery or performance data sent to shore.
Remote maintenance access How external support sessions reach onboard systems.
Safety architecture
Navigation zone Bridge systems relative to other operational networks.
Machinery / cargo zone Separation between operational control and general networks.
Safety / local fallback Independent or physically separated operating capability.
Modeled blast radius
5 / 100

The satellite compromise is likely to remain close to the communications boundary.

Furthest zone Ship IT
OT exposure Low
Safety-system exposure Minimal
Critical choke point IT firewall
Network propagation potential Low
Relative zone exposure
Communications
Breached
Business IT
Low
OT gateway
Low
Navigation
Low
Machinery / cargo
Low
Safety / local
Minimal
First containment priority Isolate the compromised communications segment from ship IT.

The objective is to preserve navigation, machinery and safety functions while investigators determine what traffic crossed the failed boundary.

Defensive screening model only. The score estimates network propagation potential from architectural choices and does not predict whether a real attacker could exploit, operate or alter any specific onboard system. Actual exposure depends on system configuration, credentials, software state, firewall policy, equipment design, network topology, remote-access arrangements and local safety controls.
Research basis: IMO Guidelines on Maritime Cyber Risk Management MSC-FAL.1/Circ.3/Rev.3 and Resolution MSC.428(98); Guidelines on Cyber Security Onboard Ships Version 5 from BIMCO and partner maritime organizations; IACS Unified Requirements E26 and E27 for ship and onboard-system cyber resilience; U.S. Coast Guard 2024 and 2025 Cyber Trends and Insights in the Marine Environment reports; U.S. Coast Guard Cybersecurity in the Marine Transportation System regulations and 2026 implementation guidance; and CISA guidance for satellite communications network security. The satellite-terminal breach and resulting reachability scenarios in this report are ShipUniverse defensive modeling examples rather than descriptions of a specific real-world compromise.
Feedback Welcome

We welcome your feedback, suggestions, corrections, and ideas for enhancements.

Please click here to get in touch
By the ShipUniverse Editorial Team — About Us | Contact