
On 27 June 2017, the disruption was not just digital. It was a logistics problem that began in software and reached the physical world quickly.
The NotPetya attack and the disruption seen in Maersk and APM Terminals showed how a cyber incident can stop planning, delay cargo movement and reduce visibility across an operation. Screens go dark. Data becomes unreliable. Teams scramble to reconstruct what is happening. In a port environment, that is not an abstract IT issue. It is a business continuity issue and an operational risk issue.
That is the bridge into the problem. A digital incident can become a physical logistics problem in a short period of time. Cargo stops moving. Planning systems become unavailable. People lose visibility. Processes slow or stop. The result is not just a security issue. It is a resilience issue.
1. The port is becoming a software system
A modern port is not just infrastructure. It is a living software environment. Cranes, terminals, warehouses, quay planning, customs data, berth coordination, cargo visibility and vessel communication increasingly depend on digital systems. These systems do not sit neatly in one place. They connect through APIs, integrations, vendor platforms, monitoring tools and shared data feeds.
That creates efficiency. It also creates a different kind of operational dependency. When a terminal operating system slows down, when a planning tool becomes unavailable, when a data exchange fails or when a vendor integration goes stale, the operational impact can extend far beyond the software itself.
In the Port of Rotterdam, the question is not whether the port is digital. It is how deeply digital workflows are intertwined with physical logistics. The more automated the operation, the more important the reliability of the underlying software and data becomes.

2. One company is rarely an island
A terminal does not operate alone. It connects to shipping lines, customs and data exchange partners, freight forwarders, trucking partners, warehouse operators, supplier systems, software vendors and cloud platforms. A cargo movement process often passes through several organisations before it becomes a physical operation on the quay or at the gate.
That means cyber risk is partly a network problem. Not every failure happens inside one company. Some incidents begin in a supplier, an external platform, a weak integration or a dependency that no one fully mapped. A maritime business can be operationally sound and still suffer because a connected system fails or a shared data stream becomes unreliable.
The digital chain is therefore as important as the internal system. In practice, resilience is a matter of understanding dependencies across the ecosystem — not just protecting the systems inside the company perimeter.
3. IT and OT are moving closer together
IT systems handle information, business processes and software workflows. OT systems handle equipment and physical operations: cranes, gates, sensors, monitoring systems, controllers and machine interfaces. For many years, these layers were kept fairly separate.
That separation is narrowing. Increasingly, operational technology is connected to planning systems, dashboards, vendor portals, remote monitoring and cloud services. An automation layer may read live data from a piece of equipment, route it through a business process and feed decisions back into operations. The boundary between a business system and an operational system becomes thinner.
That is not just a technical issue. It changes the risks. A software failure can prevent a piece of equipment from being planned correctly, a sensor feed can influence dispatch decisions, and a weak integration can create blind spots in the movement of cargo and people. Maritime entrepreneurs do not need a deep engineering lecture to understand the point: operational systems increasingly depend on software reliability.
4. Cybersecurity becomes operational resilience
For maritime companies, cybersecurity is not only an IT concern. It increasingly affects continuity, safety, cargo movement, customer service, planning, vessel operations and commercial reputation. In other words, it is part of operational resilience.
When a critical system is unavailable, the business does not just lose a digital tool. It may lose visibility over a vessel, delay cargo handling, miss documentation milestones, or struggle to provide reliable updates to clients and partners. The operational impact often arrives before the technical cause is fully understood.
This is why cybersecurity should be discussed in business language. What happens if a planning system is unavailable for 12 hours? Which cargo tasks stop if a supplier integration fails? Which operational decisions still work on paper, by phone or through a manual fallback? These questions are not theoretical. They shape resilience in real operations.

5. The smaller supplier matters too
It is tempting to imagine cyber risk as a story of mega-corporations and giant terminals. In reality, the same digital chain includes smaller maritime service providers, contractors, software vendors, ports, customs data partners and specialist suppliers. These organisations may be smaller, but they can still matter greatly.
A small supplier with poor access controls, a fragile file transfer, a weak customer portal or an outdated integration can create operational risk for a much larger party downstream. In maritime ecosystems, the weak link is often not the biggest company. It is the party with the least visibility into dependencies or the least disciplined process around system access and change management.
This matters especially for maritime SMEs. They may not operate a SOC or employ a large security function, but they do operate systems that matter to customers, partners and cargo flow. Digital discipline is not only a large-company problem. It is part of running a dependable maritime business.
6. More automation means more software dependency
Automation improves speed, visibility and consistency. It also changes failure modes. When an operation depends on APIs, live data feeds, machine-to-machine communication, cloud services and AI-assisted planning, the organisation becomes dependent on the reliability of those systems and the quality of the data behind them.
This does not mean AI is magic or that every digital process is dangerous. It means that the more an organisation automates, the more important it becomes to understand where decisions are made, who owns the data, what fails when connectivity is weak, and which manual fallback still works if a system is unavailable.
Automation is often a positive business move. The risk is not automation itself. The risk is unexamined dependency: software that is assumed to be reliable without a clear ownership model, fallback plan or operational understanding of how it fits into the broader workflow.
7. Good maritime software should reduce fragility
This is where focused maritime software matters. Software should not just digitise complexity. It should reduce avoidable fragility. A useful system can replace fragile spreadsheet workflows, reduce manual transfers, structure data more clearly, create better ownership, improve traceability, and make operational work easier to understand. For an example of how a recurring workflow can become infrastructure, see our article on maritime spreadsheets.
At its best, good software creates clearer boundaries between tasks. It reduces duplicate work. It slows the spread of uncontrolled files. It makes it easier to see who owns a process, which data is authoritative and where handoffs happen. A well-designed workflow can reduce operational risk without pretending that software alone creates security.
Security depends on architecture, access control, maintenance, deployment discipline, process design and people. A custom tool can improve clarity and reduce fragility, but it does not automatically make an organisation secure. The real value is that software can make a workflow more understandable, more controllable and less dependent on informal knowledge held in spreadsheets, inboxes or private memory.
8. Practical questions maritime companies should ask
The first step is not buying more software. It is asking better operational questions. A useful resilience review starts with the actual workflow, not with a generic security checklist.
Consider questions such as: Which operational processes stop if one system is unavailable? Which spreadsheets have silently become critical infrastructure? Which suppliers have access to operational systems or data? Which systems exchange data automatically? Who owns each integration? Which manual fallback still works? What information is required to continue operations during disruption? Which systems contain duplicated or uncontrolled data? Are software dependencies documented? What happens if cloud or internet connectivity disappears temporarily?
These are not technical theatre questions. They are practical management questions. They help a business understand where its real dependencies sit and where operational risk is hiding in plain sight.
Conclusion
When software becomes infrastructure, cybersecurity becomes operational safety.
The question is not whether maritime companies can avoid digital dependency. They cannot. The question is whether they understand which systems matter, who owns them, how operations continue when they fail, and how much fragility still sits in informal workflows and overlooked integrations.