Maritime operations are undergoing a massive increase in cyber threats. This research focuses on how cyber resilience is enacted across eight major cyber incidents affecting both shipping and non-shipping organizations. Thus, it extends from port-centric perspectives, incorporating the heterogeneity of actors within the maritime logistics ecosystem. Adopting the cyber-resilience framework of Dupont et al. (2023), the study draws on secondary sources, such as annual reports and trade publications, to examine response patterns across the pre-, during-, and post-disruption phases. Documents were analyzed using an iterative approach that combined open and axial coding. The findings reveal that cyber resilience is unevenly disclosed across the framework's conceptual dimensions and time phases, with non-shipping organizations exhibiting more limited transparency. The study contributes to the literature by providing a comparative analysis of publicly disclosed cyber incident responses across different maritime organizations and cyber resilience phases. Furthermore, it identifies patterns and asymmetries in observable organizational responses using a structured holistic analytical framework that extends beyond technical protection measures to encompass governance, resource mobilization, organizational learning, and adaptive capacity.
A sea of threats: mapping cyber-incident responses and resilience signals across maritime organizations
Martina Neri
;Gianluca Dini;Federico Niccolini
2026-01-01
Abstract
Maritime operations are undergoing a massive increase in cyber threats. This research focuses on how cyber resilience is enacted across eight major cyber incidents affecting both shipping and non-shipping organizations. Thus, it extends from port-centric perspectives, incorporating the heterogeneity of actors within the maritime logistics ecosystem. Adopting the cyber-resilience framework of Dupont et al. (2023), the study draws on secondary sources, such as annual reports and trade publications, to examine response patterns across the pre-, during-, and post-disruption phases. Documents were analyzed using an iterative approach that combined open and axial coding. The findings reveal that cyber resilience is unevenly disclosed across the framework's conceptual dimensions and time phases, with non-shipping organizations exhibiting more limited transparency. The study contributes to the literature by providing a comparative analysis of publicly disclosed cyber incident responses across different maritime organizations and cyber resilience phases. Furthermore, it identifies patterns and asymmetries in observable organizational responses using a structured holistic analytical framework that extends beyond technical protection measures to encompass governance, resource mobilization, organizational learning, and adaptive capacity.I documenti in IRIS sono protetti da copyright e tutti i diritti sono riservati, salvo diversa indicazione.


