A Hacker Gets Through the Satellite Terminal. What Ship System Can They Reach Next?

🔔 Subscribe to ShipUniverse Weekly →
The Shipboard Cyber Blast Radius Test
The communications boundary has failed. That does not mean the attacker owns the bridge or engine room. The next reachable system depends on how the vessel separates internet-facing IT from operational technology.
Modern ships can remain continuously connected through VSAT, LEO satellite services, cellular links and shore-managed networks. That connectivity supports voyage optimization, remote diagnostics, software updates, machinery monitoring and crew communications.
It also means the satellite gateway can sit only a few network boundaries away from systems that matter to navigation, cargo and machinery. Whether those boundaries are genuinely separate, loosely connected or effectively flat determines the blast radius.
The useful question is therefore not whether an attacker can “hack the ship.” It is which security zone they can reach after the first boundary fails, and whether the next boundary forces the intrusion to stop.
Compromising communications is not the same as controlling the ship
Reachability and control are different problems. An attacker can only move beyond the communications layer if another system or permitted connection gives them somewhere to go.
Satellite terminal compromised
The externally connected device or communications segment can no longer be trusted. Traffic, credentials, management interfaces or connected services may require containment and investigation.
Safety-critical OT compromised
Navigation, machinery, cargo and power systems should sit behind separate controls. A properly designed architecture can allow the communications boundary to fail without exposing these systems.
The ship should make an attacker cross several separate doors
The diagram below is a defensive architecture model. It shows where a satellite-originated compromise can encounter another boundary before it reaches operational technology.
Simplified shipboard trust path
External → safety criticalInternet-facing communications and provider connectivity.
Administration, email, crew services and business applications.
Remote monitoring, data historian or controlled ship-to-shore interfaces.
Bridge, cargo, machinery and power-control networks.
Independent or physically segmented safety and local control functions.
What could sit on the other side of the satellite connection?
These systems are not automatically exposed. Their risk depends on the vessel's actual interfaces, remote-monitoring arrangements and segmentation.
Crew and administrative networks
Email, office systems, crew welfare internet and shared services are often the nearest internal networks to external connectivity.
Remote monitoring gateway
Machinery telemetry, performance monitoring and vendor diagnostics can create legitimate pathways between shore connectivity and onboard OT.
Bridge and navigation systems
ECDIS, AIS, radar, VDR, GNSS-related interfaces and integrated bridge services become relevant when bridge networks exchange data with connected systems.
Machinery and propulsion monitoring
Engine-management and alarm systems can become more exposed when condition monitoring or remote diagnostics crosses the IT/OT boundary.
Cargo management
Loading, monitoring and cargo-management systems may exchange data with ports, terminals and shore applications.
Safety-critical local control
Steering, essential machinery and other required safety functions should have much stronger separation and retain safe local or independent operation.
The real risk is the bridge between networks
| System zone | Legitimate connection | If segmented correctly | If segmentation is weak |
|---|---|---|---|
| Crew / guest | Internet and welfare services | Contained | Can become a stepping stone into shared IT resources. |
| Business IT | Email, ship management, reporting | Separate from OT behind controlled interfaces. | Shared switches, credentials or routes can expand lateral reach. |
| Remote monitoring | Telemetry and condition monitoring | Data-limited | A bidirectional maintenance pathway can enlarge the OT exposure. |
| Navigation Bridge zone | Updates, sensor exchange, reporting | Dedicated zone | Integrated networks can expose additional navigation services. |
| Machinery | Remote diagnostics and performance data | Restricted conduit | Poorly controlled remote access can increase exposure to machinery networks. |
| Cargo systems | Terminal, stowage and monitoring data | Controlled exchange | Shared infrastructure can create a wider operational impact. |
| Safety functions | Ideally minimal external dependency | Physically separated | Loss of separation would represent a much higher-consequence architecture. |
Three ships can have the same satellite terminal and completely different blast radii
Segmented vessel
External communications, crew IT, business IT and operational systems occupy separate zones. OT interfaces allow only necessary traffic and remote maintenance is tightly controlled.
Connected monitoring vessel
IT and OT are segmented, but remote machinery monitoring, voyage services or vendor support create controlled cross-zone pathways.
Flat or poorly segmented vessel
Crew, administration and operational networks share routing, infrastructure or overly permissive firewall rules.
The Coast Guard keeps finding the same weak point
Coast Guard Cyber's 2024 field work identified improper network segmentation as one of the most common vulnerabilities it encountered, particularly in OT environments. Its description of the modern vessel is striking: continuous connectivity means a ship can appear to the enterprise network much like another remote facility.
The 2025 CTIME report showed growing concern around OT rather than a retreat from it. Demand for Coast Guard OT testing increased 35%. Across broader maritime missions, teams continued finding weak credentials, exposed services and poor segmentation even as organizations adopted more sophisticated defensive technology.
The rulebook is moving toward blast-radius control
IMO Resolution MSC.428(98) establishes the expectation that maritime cyber risk is addressed through company safety management.
Relevant new ships contracted from this date fall under the revised cyber-resilience requirements for ship integration and onboard systems.
Baseline cybersecurity requirements enter force for covered U.S.-flagged vessels and other regulated MTS entities.
Covered personnel become subject to specified cybersecurity training requirements, including OT-specific training where applicable.
Covered owners and operators must meet the scheduled requirements for a Cybersecurity Officer, assessment and Cybersecurity Plan.
If the satellite boundary fails, the response priority is containment
The first objective is not to prove exactly who the attacker is. It is to prevent an external communications incident from becoming a navigation, machinery or cargo incident.
Isolate external access
Separate the affected communications path from internal networks while preserving safe vessel operations.
Protect OT boundaries
Confirm that bridge, cargo, machinery and safety zones are still isolated and operating as designed.
Preserve evidence
Retain logs, alerts and network records needed to reconstruct what systems communicated during the incident.
Maintain local control
Use safe local or independent operating modes where required while external connectivity is being investigated.
Satellite Breach Blast-Radius Simulator
Assume the external communications terminal is already compromised. Change the ship's internal architecture and see how far that compromise can plausibly propagate before another security boundary stops it.
Where does the intrusion stop?
This tool models defensive network reachability only. It does not simulate exploitation of ship systems.
The satellite compromise is likely to remain close to the communications boundary.
The objective is to preserve navigation, machinery and safety functions while investigators determine what traffic crossed the failed boundary.
We welcome your feedback, suggestions, corrections, and ideas for enhancements.
Please click here to get in touch