Politics

As long as the boat goes…

Do you know an oil tanker 333 meters long, more than three football fields, capable of transporting approximately 2.3 million barrels of crude oil? I suppose so: a mass of steel that crosses seas, straits and ports with the inertia of a small floating neighborhood. Now imagine that, to understand if it is still “safe”, cyber specialists from the FBI and the US Coast Guard are needed to physically come on board to look for malware. It happened in August in the Gulf of Mexico, and this alone explains why cybersecurity is no longer a problem confined to a computer.

US authorities boarded two commercial ships bound for the United States on August 21 and 24 after indications that their respective networks had been compromised. We still know little about the second. We know the name and dimensions of the first: VL Prosperity, a VLCC tanker flying the Liberian flag, which left Egypt and headed to Galveston, Texas. Its handler then announced that the Coast Guard had authorized the resumption of normal operations.

Here it is worth focusing for a moment on the facts. The cyber compromise was confirmed and the commander of the Coast Guard Cyber ​​Command, Rear Adm Amy Grablesaid investigators found malicious cyber activity on board and scanned systems to identify and remove the attacker’s presence. The Coast Guard spoke of «foreign cyber actors», therefore of foreign actors, without identifying them. There is no public technical attribution to a country or group.

However, there is a second version of the story, much more spectacular. Iran’s Mehr News Agency reported that on August 7, during the passage through the Strait of Gibraltar, the VL Prosperity lost communications for about thirty hours and that the attackers intervened in the engine room systems. These are impressive details, but not publicly confirmed by US authorities. Rob LeeCEO of Dragos, interviewed by CBS, defined them as technically plausible, which, however, does not mean that it happened. In the cyber world, between “it can be done” and “it has been done” there is the same space, notoriously “marine”, which separates saying and doing.

The interesting point is not whether an attacker remotely took over the rudder of an oil tanker. The image works very well in a television series, much less in the engine room. Ships are complex systems and there is no need to transform them into 333 meter drones to create a serious problem, because it is enough to make one of the systems necessary for them to navigate safely unreliable. It is not necessary to command everything: it may be sufficient to remove certainty from those who must command.

As I have been saying for more than ten years, the meeting between IT and OT changes the nature of risk. In the world of Information Technology, an attack can steal data, block applications, encrypt documents. In Operational Technology, however, behind a digital variable there can be a pump, a flow, a propulsion system, a navigation system. The command no longer ends on the screen, but continues into the physical world. For years we’ve been concerned about protecting digital from humans, and now we also need to prevent bad digital intent from producing tons of real consequences.

A modern ship is no longer just an engine, rudder and radar. It is an ecosystem of satellite communications, IP networks, sensors, navigation, maintenance, energy management, automation, cargo systems, administrative computers and operational equipment. The benefit is enormous, but efficiency arises from connections, and connections also distribute fragility.

Digitizing is fine, but every connection must be treated as a relationship to be governed, not as a neutral convenience. If the administrative network can become a bridge to operating systems, the problem is not just the malware, but the architecture itself.

Not surprisingly, among the measures recalled by it Grable concepts appear that are almost disappointing for those expecting exotic digital weapons: network segmentation, attention to phishing, basic cyber hygiene. It’s one of the recurring ironies of technology: the more gigantic the object becomes, the more minuscule the vulnerability can be. We can have two million barrels of oil in front of us and behind, somewhere, a badly managed credential, a wrong configuration or two networks that should have talked to each other much less.

Furthermore, the ship does not live isolated: it must communicate with land, transmit telemetry and support maintenance and operations. Satellite connections expand the operational possibilities and, inevitably, the exposed surface area. It is no coincidence that the International Maritime Organization’s guidelines on cyber risk start from this assumption.

The case of VL Prosperity thus forces us to keep two truths together. The first. We still don’t know if anyone has actually managed to manipulate engines or other OT systems. The second. The authorities considered the possibility concrete enough to send specialized teams on board to monitor both IT and OT.

Finally, there is attribution. There has been talk of Iran, but US authorities have not made such an attribution public. In cyberspace, identifying the culprit is often more difficult than establishing the fact. Malware, infrastructure, tactics, techniques and procedures must be compared and the apparent provenance may be part of the deception. When we don’t know who lit the match, we can still study why the room was filled with combustible material.

Perhaps this is the most useful lesson that this tanker leaves us. Digital transformation has built a luxurious penthouse above the physical world: efficient, functional and hyper-connected. It’s a shame that the underlying foundations are similar to those of the Holocene stilt houses.

Between us: we connected everything to better control the world. Now we must learn to better control what we have connected.