Marlink and NORMA Cyber Launch Fleet-Wide Maritime Cyber Response Service

🔔 Subscribe to ShipUniverse Weekly →

Marlink and the Nordic Maritime Cyber Resilience Centre, NORMA Cyber, have launched a combined cybersecurity service that links independent fleet-wide monitoring directly to maritime incident response, with Höegh Autoliners among the first operators to deploy the model across its entire fleet. Under the arrangement, real-time security data from Marlink Unified Threat Management and Endpoint Detection and Response systems is forwarded to NORMA Cyber's Security Operations Centre, where potential threats are independently analysed and triaged. Incidents requiring intervention are then escalated to Marlink's maritime cyber specialists for investigation, containment and remediation. The September 29 launch turns a partnership established between Marlink and NORMA Cyber in 2023 into a more structured operational response chain spanning shipboard IT, operational technology and shore systems.

Maritime Cybersecurity | September 29, 2026

One Team Watches. Another Team Responds.

The new model separates continuous cyber monitoring and initial threat analysis from the team responsible for investigating and containing an incident onboard. Security data moves continuously from vessels to NORMA Cyber, while Marlink remains positioned to intervene in the networks and systems it manages.

24/7 Monitoring & Response

Maritime IT and OT environments can be monitored continuously while vessels operate across time zones.

180+ NORMA Members

NORMA Cyber's current membership represents more than 3,000 vessels and offshore units.

5 Marlink SOC Locations

Marlink operates security centres in Uruguay, Palma, Zagreb, Rotterdam and Bangkok.

Fleet-Wide First Deployment

Höegh Autoliners is using the combined monitoring and response structure across its full fleet.

How an onboard cyber event moves through the new response chain

1. Vessel Generates Security Data

Unified Threat Management and Endpoint Detection and Response systems produce security logs from the onboard environment.

→
2. NORMA Cyber Monitors

Security data is streamed to NORMA Cyber's SOC for independent monitoring, analysis and initial assessment.

→
3. Threat Is Triaged

Analysts determine whether an event is routine noise, suspicious activity or an incident requiring operational intervention.

→
4. Marlink Responds

Escalated incidents move to Marlink specialists for investigation, containment, remediation and restoration support.

NORMA Cyber: Independent Watch Layer

Threat monitoring, analysis, triage, maritime intelligence and escalation are separated from the provider operating much of the onboard cyber and connectivity environment.

Höegh Autoliners

The car-carrier operator is combining NORMA Cyber monitoring with Marlink connectivity, IT and cybersecurity services already deployed across the fleet, making the new response structure an operating deployment rather than only a partnership announcement.

From Security Alert to Vessel Recovery

The architecture is designed around a practical division of responsibilities. NORMA watches and validates. Marlink acts inside the managed environment when the incident becomes operational.

Incident Stage Primary Actor Data / Capability Action Operational Objective Typical Trigger
Continuous Monitoring NORMA Cyber Real-time security logs forwarded from vessel UTM and EDR systems. Monitor activity across connected onboard environments and identify anomalies requiring analyst review. Detect suspicious activity before it becomes a wider vessel or fleet incident. New malware behaviour, suspicious credentials, abnormal endpoints or unusual network activity.
Threat Analysis NORMA Cyber Maritime threat intelligence, event correlation and security context. Determine whether the activity represents routine noise, a false positive, an exposure or an active incident. Avoid unnecessary onboard intervention while escalating genuine threats quickly. Multiple indicators point toward malicious or unauthorised activity.
Escalation Shared Validated event data, indicators of compromise and operational context. NORMA escalates events that require direct technical action to Marlink's specialists. Move from monitoring into active containment without losing incident context. Threat has credible potential to affect vessel systems, users or operations.
Containment Marlink Access to managed vessel network and cybersecurity infrastructure. Isolate affected endpoints, restrict communications or apply other controls appropriate to the incident. Prevent lateral movement and reduce operational disruption. Confirmed malware, compromised endpoint, suspicious remote access or active intrusion.
Investigation Marlink EDR, NDR, firewall telemetry, forensic data and threat intelligence. Determine root cause, affected systems, compromise path and required remediation. Establish what happened and whether additional vessels or shore systems may be exposed. Incident confirmed and scope still being determined.
Remediation Marlink Security configuration, endpoint controls, network management and remote support. Remove malicious elements, restore systems and apply corrective measures. Return the vessel to a known and secure operating state. Containment complete and recovery can safely begin.
Reporting & Lessons Operator + Providers Incident timeline, evidence, root cause and remediation record. Document the incident, strengthen controls and support regulatory or internal reporting. Reduce recurrence and preserve evidence of cyber-risk management. Incident stabilised or closed.
Why fleet operators are adding another response layer
82% Crew-Network Alerts

Marlink says 82% of maritime alerts observed in its 2025 data were concentrated in crew network zones.

69% Credential Exposure

Compromised or exposed credentials accounted for 69% of identified risks in Marlink's broader remote-operations assessment.

60% Shared IT / OT

Sixty percent of assessed environments relied on shared IT and OT infrastructure.

20% Phishing Click Rate

One in five recipients clicked malicious links during Marlink's simulated phishing campaigns.

7,793 Ransomware Activity

Marlink says detected ransomware activity across its monitored environments rose from 5,740 in 2024 to 7,793 in 2025.

IMO: Cyber Risk Is Already an SMS Issue

IMO Resolution MSC.428(98) requires cyber risk to be addressed through the objectives and functional requirements of the International Safety Management Code, embedding cyber resilience into the ship-management framework rather than treating it as a separate IT exercise.

NIS2: The Reporting Clock Can Move Fast

Where NIS2 applies, a significant incident can trigger an early-warning requirement within 24 hours, a fuller notification within 72 hours and a final report generally within one month. Fast triage and reliable incident evidence therefore have regulatory as well as operational value.

Fleet Cyber Incident Escalation Planner

Build a first-pass response picture for a suspected vessel cyber incident. The tool prioritises escalation based on operational impact, number of vessels affected and whether operational technology is involved.

Indicative Priority LOW Score 0

Initial monitoring response

Validate the event, preserve logs and confirm whether the activity represents an actual compromise before making disruptive changes to vessel systems.

1. Preserve Evidence Retain relevant UTM, EDR, authentication and network records before systems are changed.
2. Confirm Scope Determine whether the event is limited to one endpoint, one vessel or multiple fleet assets.
3. Protect Operations Prioritise navigational, propulsion, cargo and safety continuity when considering containment actions.
4. Escalate & Recover Move confirmed incidents into specialist investigation, containment, remediation and controlled restoration.
This tool is an operational discussion aid, not a substitute for a company's incident-response plan, flag-state requirements, class rules, legal advice or regulatory assessment. Do not disconnect, reboot or isolate safety-critical OT solely on the basis of this tool.
Feedback Welcome

We welcome your feedback, suggestions, corrections, and ideas for enhancements.

Please click here to get in touch
By the ShipUniverse Editorial Team — About Us | Contact