Ports sit at the heart of global trade, handling around 80% of traded goods by volume. Yet they are no longer simply physical gateways for vessels and goods. Today, ports operate as digital, interconnected ecosystems where port authorities, terminal operators, customs, shipping lines, logistics providers, and public agencies rely on shared computer-based systems and real-time data exchange.
This digital transformation creates major opportunities for efficiency and transparency. Yet, it also exposes ports to new cyber risks that can disrupt trade, delay cargo, endanger operations, and create economy-wide impacts—even beyond port or national boundaries.
The World Bank’s new report Cybersecurity in Ports: Shifting from Risk to Resilience provides a comprehensive overview of current cybersecurity policies, practices, and barriers across port ecosystems worldwide. Drawing on a global survey with more than 100 port stakeholders, expert interviews, and literature review, the report identifies key policy, operational, and capacity gaps—with a particular focus on low- and middle-income countries.
A global port cyber resilience gap. Survey findings show significant disparities between high-income and low- and middle-income settings. Respondents from port sectors in high-income countries report higher levels of incident reporting, recent risk assessments, and regular cybersecurity training, while respondents in low- and middle-income contexts face more pronounced capacity shortcomings.
Nearly 85% of surveyed port stakeholders in high-income countries have reporting mechanisms for cyber incidents in place. It’s just over 55% in low- and middle-income settings.
Cybersecurity risk assessments are not routine yet for ports worldwide. Just over 55% conduct them in low- and middle-income economies, while nearly 80% do so in high-income countries.
Training remains a major capacity gap — more than 80% of surveyed port stakeholders in high-income countries benefit from regular training, as opposed to just under 50% in low- and middle-income settings.
As consequence, the report makes specific recommendations to enhance cybersecurity in ports worldwide. Amongst others, the following ones:
- Policy – Set clear cybersecurity rules for critical ports, including defined responsibilities, minimum requirements, compliance mechanisms, and mandatory incident reporting.
- Practice – Manage cyber risk continuously through up-to-date inventories of information technology (e.g., digital systems) and operational technology assets (e.g., cranes), regular risk assessments, vulnerability scans, and tested incident response and business continuity plans.
- Barriers – Close capacity and coordination gaps through role-based training, trusted information sharing, no-blame reporting, and targeted investment in cyber-resilient supply chains. Strive to align private incentives with collective resilience interests in contractual relations.
read more:https://www.worldbank.org/en/topic/transport/publication/cybersecurity-in-ports