2024 AI Adoption and Cybersecurity Challenges in Maritime Industry
2024 saw a lot of discussion in the maritime sector about the use and benefits of AI. As with all technology evolution every sector develops specific ways of using it to good effect.
2024 also saw a marked increase in the levels and nature of cyber incidents globally as the mix of geopolitics, conflicts and the increased growth in cybercrime tools and capabilities continued to put pressure on businesses and organisations globally.
Maritime transport accounts for around 70% of the value of international trade. The total value of international trade was estimated at nearly $33 trillion in 2024. What this amplifies is that strategic risks sit in the interdependent supply lines and supply chains. These risks present a very attractive opportunity for those intent on disruption, blackmail and fraud.
The traditional concept of third-party suppliers as entirely external entities is increasingly blurred in modern business relationships. Third-party suppliers are often deeply integrated into a company’s operations, strategy, and value chain, making the distinction less clear-cut.
While the term “third party” persists for legal and contractual clarity, many suppliers function as extensions of the business itself. The relationship is less transactional and more akin to a partnership or collaboration, characterised by mutual dependence, shared goals, and integrated operations.
Most businesses are aware of the risks posed by third-party suppliers but still struggle to implement comprehensive, proactive strategies to manage these risks effectively. As supply chain cyberattacks become more frequent and sophisticated, improving the cybersecurity posture of suppliers is critical for minimising exposure and ensuring business resilience.
The IMCSO exists to improve assurance, trust and confidence in products, processes and services by establishing assurance methodologies that present clear outputs. So, we are very interested in AI and what others think about trust in that technology. We looked at the NIST standards approach to assurance and testing of AI.
The NIST AI RMF TEVV refers to the Testing, Evaluation, Verification, and Validation (TEVV) framework as part of the NIST AI Risk Management Framework (AI RMF). This framework, developed by the National Institute of Standards and Technology (NIST), aims to provide guidance for managing risks associated with artificial intelligence systems.
The TEVV component is critical for ensuring that AI systems are safe, reliable, trustworthy, and aligned with intended goals. It is an essential part of the AI lifecycle, emphasising rigorous assessment and continuous improvement. The NIST AI RMF TEVV framework serves as a foundational guideline for organizations aiming to deploy responsible and trustworthy AI systems while minimising risks and maximising benefits.
That’s all well and good but what we thought we’d do is look at what the world of AI could tell us about itself by asking a few questions, so we asked ChatGPT? (Other AI tools exist ;-). Oh, and please note that ChatGPT does have a disclaimer on its results – ChatGPT can make mistakes. Check important info. So please take what is presented below in that context.
ChatGPT 4o mini (free version) was asked the following questions and the conclusions it came to (the full response is also provided for those that want a longer read):
Q. What use can AI be put to in the Maritime Sector?
AI has the potential to revolutionise the maritime sector by improving operational efficiency, safety, and environmental sustainability. From autonomous vessels and predictive maintenance to enhanced port operations and smart shipping, AI applications are helping companies optimise their operations, reduce costs, and improve overall service quality. As AI technology continues to evolve, its role in the maritime industry will likely expand further, leading to even greater innovations and efficiencies in the sector.
Q. How does AI integrate with Zero Trust Frameworks?
AI enhances Zero Trust frameworks by providing intelligent, real-time monitoring, automated decision-making, and adaptive security controls. By continuously validating user identity, device health, and access behaviour, AI helps enforce the Zero Trust principle of “never trust, always verify.” This integration enables organizations to detect threats, respond to incidents, and maintain secure environments more efficiently, ultimately strengthening the organization’s overall cybersecurity posture.
As cyber threats become more sophisticated, AI’s role in Zero Trust frameworks is expected to grow, enabling more dynamic, proactive, and adaptive security measures.
Q. What cyber security risks does AI present?
While AI can greatly enhance cybersecurity capabilities, it also introduces new risks. To mitigate these risks, organizations should:
- Continuously monitor and test AI models for vulnerabilities and biases.
- Implement robust security controls around AI systems, including data protection and adversarial attack mitigation techniques.
- Ensure that AI systems are explainable and auditable so that their decisions can be understood and validated.
- Use a combination of AI and human expertise to ensure comprehensive threat detection, investigation, and response.
As AI continues to play a larger role in cybersecurity, organisations must balance its benefits with the risks, ensuring that proper safeguards and oversight are in place to prevent exploitation or manipulation.
Q. Is offensive AI more prevalent than defensive AI?
While defensive AI is currently more prevalent and widely adopted, offensive AI is a growing threat that organizations must take seriously. Defensive AI tools are essential for protecting networks, systems, and data, and they are increasingly becoming an integral part of modern cybersecurity practices. However, the rise of AI-powered cyberattacks has introduced new challenges and risks, which may increase in the coming years as AI technology becomes more advanced and accessible to malicious actors.
To address these emerging risks, cybersecurity professionals must invest in advanced defensive AI solutions, while also developing strategies to detect and mitigate AI-driven threats before they can cause significant harm.
Q. Is Artificial intelligence well-regulated currently?
While there are significant efforts underway to regulate AI, especially in the EU and China, AI regulation is still fragmented and evolving. Comprehensive, globally accepted regulations are not yet in place, but the growing recognition of the need for robust oversight means we are likely to see more structured and harmonized frameworks in the future.
Q. Can I trust AI output (interestingly it gave us two response options for this so a case of which one best suited your need)
You can trust AI output in certain contexts, particularly when:
- The data used to train the AI is high-quality, diverse, and up to date.
- The AI tool is transparent about how it works and provides reasoning for its outputs.
- The output is used for low-risk tasks or as a supplement to human judgment.
However, you should be cautious and often verify AI output in high-stakes applications or when the tool’s reliability is uncertain. Human oversight is crucial, and AI should be viewed as a tool to augment decision-making, not as a final arbiter of truth.
On the other hand , while AI tools are increasingly powerful and can be trusted for many tasks, they are not infallible. You should not fully rely on them without critical thinking and validation, particularly in areas where accuracy, ethics, or legal implications are involved. Trust in AI output should be earned, and human oversight is key to ensuring its reliability.
Q. Are companies that produce AI tools responsible for any legal consequences of false or misleading outputs?
Who Is Responsible? In short, AI companies can be held legally responsible for the outputs of their tools, particularly if those outputs are false, misleading, or harmful. However, the extent of their responsibility depends on the legal framework in place, the nature of the harm caused, and whether the company met standards of care in developing, deploying, and maintaining its AI system. In the absence of clear regulations, many companies are working proactively to create guidelines, ethical standards, and accountability mechanisms to mitigate potential legal risks and build trust in their AI products. As AI regulation continues to evolve, it is likely that companies will face more defined legal responsibilities in the future.
Q. How many AI products Fail?
The failure rate of AI products is high, with estimates suggesting that 70-80% of AI projects fail to meet their business objectives. This is primarily due to challenges in data quality, lack of skilled personnel, poor integration, and unrealistic expectations. However, as organisations become more experienced with AI, the rate of failure should decrease, particularly with the application of best practices in data management, model development, and project planning. Ultimately, while AI holds great potential, its successful implementation requires careful planning, resources, and continuous monitoring to avoid common pitfalls.
Q. What should I put in a supply contract for an AI tool to protect my business from the risks?
A well-structured supply contract for an AI tool should address data privacy, ethical considerations, performance standards, liability, and intellectual property, among other concerns. This comprehensive approach will help mitigate the risks associated with AI tools and ensure that both parties understand their obligations and responsibilities. By clearly defining these terms upfront, you can protect your business from potential pitfalls and set expectations for both the vendor and your organization.
What we learned in IMCSO about AI?
The IMCSO mission is to be the standard in the maritime cyber security industry, a collective voice, working towards alignment and standardisation. By setting frameworks for effective, universally adoptable methodology and innovating for future developments. Be transparent, reliable, deliver cyber security by design towards digitalization, green technology and Autonomous shipping.
Read more stories like this on our LinkedIn page.











