Superyacht cyber risk grows as Starlink connectivity expands

Cheap satellite internet has connected superyachts like never before, but cyber resilience has failed to keep pace

Superyacht cyber risk grows as Starlink connectivity expands

Cyber

By

The superyacht sector is facing a widening cyber security gap as low-cost satellite connectivity brings vessels permanently online for the first time, according to Matthew Geyman, managing director at cyber security firm Intersys.

The rapid shift to always-on connectivity, he said, has outpaced many vessels' cyber security controls.

"There are practices that are born of perfectly understandable motivations within the superyacht industry that just wouldn't be acceptable in many other industries," he said.

 "The value at risk here is very tangible and quite different to many other organisations – and it's not just value, it's all of the other things as well, like personal safety that can be affected through exploitation and vulnerability."

How has Starlink changed the risk picture?

Until recently, superyachts relied on VSAT and Inmarsat satellite systems that were slow, expensive and used sparingly. That changed with the arrival of Starlink and rival low-earth-orbit satellite networks.

"With the advent of Starlink and with the advent of other competing systems such as the upcoming Amazon Leo, people are online in a way that the vessels never were before," Geyman said. "So the vessel is everything, and it is all connected, and that's what's changed."

One chief engineer told Geyman monthly satellite communications costs had fallen from tens of thousands of dollars for limited VSAT traffic to a few thousand dollars for unlimited Starlink connectivity. A high-quality connection with a 99.9% service level agreement now costs around $1,000 to $2,000 a month for one to two terabytes of data on a medium-sized yacht, he said.

That accessibility has outpaced the engineering behind it.

"All the systems that are on board previously worked on the model that they're not really connected all the time – it doesn't really matter," Geyman said. "But now all of a sudden people are plugging cables in left, right and centre, and, oh well, let's connect that to the Wi-Fi – and there's an unsecured guest network that's also linked to the onboard vessel network."

Navigation and propulsion systems running on protocols such as CAN bus and NMEA 2000 were never designed with cyber security in mind, leaving critical vessel systems visible to basic network scanning.

Is resilience more important than insurance?

Asked whether cyber resilience now matters as much as cyber insurance, Geyman was unequivocal.

"It's more important, isn't it? Resilience is clearly more important, and I think the reason is that implementation of the controls that give you security aren't catching up with the adoption of tech yet," he said.

"Insurance remedies financial risk, whereas good cyber resilience reduces the likelihood and the impact of both that financial risk and also the risk to the personal safety of crews and guests."

He pointed to the International Maritime Organization (IMO), which since 2021 has required cyber risk management as part of a vessel's safety management system before issuing a certificate of compliance.

"The regulators clearly understand how important cyber resilience is," he said. "Insurance is usually there to do what you can't do, or what is impractical to mitigate, and therefore to cover those other risks, particularly from a financial perspective."

On the insurance side, the long-standing silent cyber clause, CL380, introduced in 2003, excludes cyber exposures from hull and protection and indemnity cover, meaning owners typically need a separate endorsement or standalone policy.

"That's an old clause, so I think that's being superseded by many policy wordings, but the principle is the same," he said. "Insurers are rightly wary of it as well, because they've still got this concern about the readiness and the capability – the cyber resilience capability – of the sector."

The market has nevertheless evolved in recent years, with insurers launching dedicated marine cyber products.

Where are the biggest vulnerabilities?

Geyman identified culture, rather than technology, as the industry's central weakness, arguing that high crew turnover has prevented cyber resilience from becoming embedded.

"Cyber resilience culture is not embedded in the same way as it is elsewhere – even though many of these superyachts are phenomenally technologically complex, that discipline isn't embedded in them in the way that it is in other industries, especially other regulated industries as well."

He also highlighted poor cyber hygiene, including senior crew being handed every onboard password on a sheet of paper when they join a vessel, contrary to the cybersecurity principle of least privilege. Third-party contractors present a further weak point, with control systems for propulsion, lighting, CCTV and even hot tub sensors frequently interconnected through permanent remote-access equipment installed by suppliers.

He recounted one chief engineer questioning why a propulsion contractor always had unrestricted access to the vessel's network. Suppliers legitimately need remote access to diagnose faults, but that access should be properly segregated, controlled and reviewed.

"He said, 'well, I've got a box in your comms room in the boat, so unplug it, I'll plug it back in when I need you to connect to the engines' – and that's pretty normal."

What role will regulation and AI play?

Insurers and underwriters need to push for stronger baseline standards, Geyman said, pointing to the International Association of Classification Societies' E26 and E27 cyber resilience requirements for vessels of 500 gross tonnes and above.

He also wants cyber security built into the Standards of Training, Certification and Watchkeeping (STCW) human element courses, which currently do not address it.

Geyman warned artificial intelligence is accelerating both the discovery and exploitation of vulnerabilities, potentially at fleet scale.

"You've got this humongous amount of processing power within AI that can discover a vulnerability and then exploit it – not just at one vessel, you can do it at scale with AI as well," he said.

Social engineering, whether AI-assisted or traditional, remains a parallel threat across every sector, he added.

The discreet nature of the superyacht industry makes the scale of the problem difficult to quantify because owners and managers rarely disclose cyber breaches. That reluctance can make yacht management agencies hesitant to push for additional cyber security investment without clear examples to justify the cost. Even so, he said skippers and chief engineers are becoming noticeably more aware of the threat.

"They've heard of losses or compromises, and they're beginning to be worried in a way that they weren't just a couple of years ago."

As permanently connected vessels become the norm, cyber security is shifting from a technical consideration to a core operational risk. The shift mirrors broader changes across the marine insurance market, with underwriters increasingly highlighting cyber connectivity as an emerging exposure and brokers reporting greater scrutiny of vessel cyber resilience.

Related Stories

Keep up with the latest news and events

Join our mailing list, it’s free!