Plain-language briefings on how commercial ships get found, exposed, and attacked online, grounded in our own scans and peer-reviewed methodology, not vendor marketing.
We analyze the realities of shipboard connectivity, satellite terminal hygiene, and bridge OT resilience.
How threat actors use Shodan, Censys, and public ASN databases to discover commercial vessels, port calls, and terminal IPs.
Passive OSINT · ScanningTerminal firmware flaws, default credentials, exposed web interfaces, and uplink traffic analysis across major satellite operators.
VSAT · Inmarsat · IridiumNavigation system hardening, NMEA sentence spoofing, USB malware propagation, and Port State Control compliance evidence.
ECDIS · NMEA · IACS E26Actionable research articles written for technical superintendents, DPA officers, and maritime security teams.
An empirical breakdown of the queries, filters, and satellite ASN ranges that surface exposed vessels, and what the findings actually mean.
6 min readRead brief →What a VSAT terminal is, why it keeps showing up in scans, and the checklist every fleet manager should run before the next port call.
5 min readRead brief →Electronic chart display risks explained without the jargon: what can go wrong, how often, and what the bridge team should know.
5 min readRead brief →What Port State Control inspections will actually check, what evidence counts, and how to build it without a year-long compliance project.
6 min readRead brief →A real three-vessel exposure scan, what it surfaced, and the remediation path, anonymized with the numbers intact.
5 min readRead brief →Our detection methodology is published in IEEE Access 2026. The free scan is how you verify it on your fleet.