Marlink and NORMA Cyber Launch Fleet-Wide Maritime Cyber Response Service

🔔 Subscribe to ShipUniverse Weekly →
Marlink and the Nordic Maritime Cyber Resilience Centre, NORMA Cyber, have launched a combined cybersecurity service that links independent fleet-wide monitoring directly to maritime incident response, with Höegh Autoliners among the first operators to deploy the model across its entire fleet. Under the arrangement, real-time security data from Marlink Unified Threat Management and Endpoint Detection and Response systems is forwarded to NORMA Cyber's Security Operations Centre, where potential threats are independently analysed and triaged. Incidents requiring intervention are then escalated to Marlink's maritime cyber specialists for investigation, containment and remediation. The September 29 launch turns a partnership established between Marlink and NORMA Cyber in 2023 into a more structured operational response chain spanning shipboard IT, operational technology and shore systems.
One Team Watches. Another Team Responds.
The new model separates continuous cyber monitoring and initial threat analysis from the team responsible for investigating and containing an incident onboard. Security data moves continuously from vessels to NORMA Cyber, while Marlink remains positioned to intervene in the networks and systems it manages.
Maritime IT and OT environments can be monitored continuously while vessels operate across time zones.
NORMA Cyber's current membership represents more than 3,000 vessels and offshore units.
Marlink operates security centres in Uruguay, Palma, Zagreb, Rotterdam and Bangkok.
Höegh Autoliners is using the combined monitoring and response structure across its full fleet.
How an onboard cyber event moves through the new response chain
Unified Threat Management and Endpoint Detection and Response systems produce security logs from the onboard environment.
Security data is streamed to NORMA Cyber's SOC for independent monitoring, analysis and initial assessment.
Analysts determine whether an event is routine noise, suspicious activity or an incident requiring operational intervention.
Escalated incidents move to Marlink specialists for investigation, containment, remediation and restoration support.
Threat monitoring, analysis, triage, maritime intelligence and escalation are separated from the provider operating much of the onboard cyber and connectivity environment.
Marlink can investigate security events within the managed vessel environment, isolate affected systems, coordinate remediation and help restore normal operation.
The car-carrier operator is combining NORMA Cyber monitoring with Marlink connectivity, IT and cybersecurity services already deployed across the fleet, making the new response structure an operating deployment rather than only a partnership announcement.
From Security Alert to Vessel Recovery
The architecture is designed around a practical division of responsibilities. NORMA watches and validates. Marlink acts inside the managed environment when the incident becomes operational.
| Incident Stage | Primary Actor | Data / Capability | Action | Operational Objective | Typical Trigger |
|---|---|---|---|---|---|
| Continuous Monitoring | NORMA Cyber | Real-time security logs forwarded from vessel UTM and EDR systems. | Monitor activity across connected onboard environments and identify anomalies requiring analyst review. | Detect suspicious activity before it becomes a wider vessel or fleet incident. | New malware behaviour, suspicious credentials, abnormal endpoints or unusual network activity. |
| Threat Analysis | NORMA Cyber | Maritime threat intelligence, event correlation and security context. | Determine whether the activity represents routine noise, a false positive, an exposure or an active incident. | Avoid unnecessary onboard intervention while escalating genuine threats quickly. | Multiple indicators point toward malicious or unauthorised activity. |
| Escalation | Shared | Validated event data, indicators of compromise and operational context. | NORMA escalates events that require direct technical action to Marlink's specialists. | Move from monitoring into active containment without losing incident context. | Threat has credible potential to affect vessel systems, users or operations. |
| Containment | Marlink | Access to managed vessel network and cybersecurity infrastructure. | Isolate affected endpoints, restrict communications or apply other controls appropriate to the incident. | Prevent lateral movement and reduce operational disruption. | Confirmed malware, compromised endpoint, suspicious remote access or active intrusion. |
| Investigation | Marlink | EDR, NDR, firewall telemetry, forensic data and threat intelligence. | Determine root cause, affected systems, compromise path and required remediation. | Establish what happened and whether additional vessels or shore systems may be exposed. | Incident confirmed and scope still being determined. |
| Remediation | Marlink | Security configuration, endpoint controls, network management and remote support. | Remove malicious elements, restore systems and apply corrective measures. | Return the vessel to a known and secure operating state. | Containment complete and recovery can safely begin. |
| Reporting & Lessons | Operator + Providers | Incident timeline, evidence, root cause and remediation record. | Document the incident, strengthen controls and support regulatory or internal reporting. | Reduce recurrence and preserve evidence of cyber-risk management. | Incident stabilised or closed. |
Marlink says 82% of maritime alerts observed in its 2025 data were concentrated in crew network zones.
Compromised or exposed credentials accounted for 69% of identified risks in Marlink's broader remote-operations assessment.
Sixty percent of assessed environments relied on shared IT and OT infrastructure.
One in five recipients clicked malicious links during Marlink's simulated phishing campaigns.
Marlink says detected ransomware activity across its monitored environments rose from 5,740 in 2024 to 7,793 in 2025.
IMO Resolution MSC.428(98) requires cyber risk to be addressed through the objectives and functional requirements of the International Safety Management Code, embedding cyber resilience into the ship-management framework rather than treating it as a separate IT exercise.
Where NIS2 applies, a significant incident can trigger an early-warning requirement within 24 hours, a fuller notification within 72 hours and a final report generally within one month. Fast triage and reliable incident evidence therefore have regulatory as well as operational value.
Fleet Cyber Incident Escalation Planner
Build a first-pass response picture for a suspected vessel cyber incident. The tool prioritises escalation based on operational impact, number of vessels affected and whether operational technology is involved.
Initial monitoring response
Validate the event, preserve logs and confirm whether the activity represents an actual compromise before making disruptive changes to vessel systems.
We welcome your feedback, suggestions, corrections, and ideas for enhancements.
Please click here to get in touch