A ransomware attack locks your vessel’s bridge navigation systems at sea. A phishing email compromises your cargo booking platform. A GPS spoofing attack sends your vessel off course in the Strait of Malacca. Maritime cyber attacks are no longer hypothetical — they are a documented and growing threat. In Malaysia, the legal framework has caught up. Is your vessel compliant?

Maritime cyber security has moved from a niche IT concern to a mainstream legal and regulatory obligation. The IMO’s Maritime Cyber Risk Management guidelines — incorporated into the ISM Code through MSC-FAL.1/Circ.3 and Resolution MSC.428(98) — have required shipping companies to address cyber risk management in their Safety Management Systems (SMS) since 1 January 2021. Malaysian-flagged vessels operating under the ISM Code must demonstrate cyber risk management compliance as part of their Document of Compliance (DOC) and Safety Management Certificate (SMC) audit — and port state control officers in Malaysia and globally are increasingly checking for it.

The legal significance of a maritime cyber attack extends well beyond IT. A cyber attack that compromises navigation systems and causes a collision or grounding triggers potential liability claims from damaged vessels, cargo interests, and port authorities. A cyber attack that corrupts cargo documentation could invalidate bills of lading and letters of credit, triggering cargo claim disputes. A ransomware attack that grounds a vessel triggers off-hire deductions under the time charter. The question of whether the shipowner’s P&I Club and hull insurer will respond to cyber-related losses — or rely on a cyber exclusion clause — is one of the most actively litigated insurance questions in the shipping industry today.

In Malaysia, the Personal Data Protection Act 2010 (PDPA) imposes additional obligations where a cyber breach compromises personal data of seafarers, port employees, or customers. The PDPA requires reasonable security measures to protect personal data, and a cyber breach that exposes personal data may trigger a regulatory investigation by the Personal Data Protection Commissioner alongside any maritime law proceedings.

Malaysian shipowners and operators must treat cyber security not as an IT issue but as a legal and commercial risk management priority — with defined consequences for non-compliance in port state control, insurance, and third-party liability.

 

Key Legal Issues in Maritime Cyber Security  

  1. ISM Code compliance: Cyber risk management must be integrated into the SMS. PSC officers can detain a vessel for ISM deficiencies — including inadequate cyber risk management documentation.

  2. Hull insurance and cyber exclusions: Many hull policies now contain cyber exclusion clauses. Check your policy to understand whether a cyber-caused casualty (navigation system failure leading to collision) is covered.

  3. P&I cover for cyber incidents: P&I Clubs are progressively introducing cyber endorsements. Understand your cover before an incident — not after.

  4. Third-party liability: A shipowner whose vessel causes damage due to a cyber attack on navigation systems faces the same liability as any negligent collision — the cyber origin does not automatically provide a defence.

  5. PDPA obligations: Personal data on ship management systems must be protected against cyber breach under the Personal Data Protection Act 2010.

Frequently Asked Questions: Maritime Cyber Security in Malaysia   

 

Q: Is maritime cyber security compliance mandatory for Malaysian-flagged vessels?

A: Yes — for vessels subject to the ISM Code (which covers all vessels of 500 GT and above on international voyages, passenger vessels of any size, and mobile offshore drilling units), cyber risk management must be addressed in the Safety Management System since 1 January 2021. This requirement flows from IMO Resolution MSC.428(98) and the associated guidelines. The Marine Department of Malaysia, as the flag state administration for Malaysian-registered vessels, expects compliance to be demonstrated during DOC and SMC audits. Port state control officers in Malaysia and in other Tokyo MOU member states are increasingly checking for evidence of cyber risk management in the SMS — deficiencies in this area are PSC detention grounds. Vessels without a documented cyber risk management policy and procedure in their SMS are non-compliant with the ISM Code.

Q: If a cyber attack causes my vessel to collide with another ship, am I liable?

A: Yes — the cyber origin of a casualty does not, by itself, provide the shipowner with a defence against liability claims from damaged parties. The standard of care for a vessel in navigation is one of reasonable seamanship and maintenance of a seaworthy vessel — including seaworthy navigation and communications systems. A shipowner who failed to implement adequate cyber risk management measures — leaving the vessel’s systems vulnerable to an attack — may be found to have breached the duty of seaworthiness, making the cyber attack a foreseeable consequence of inadequate protection rather than an unforeseeable external event. The applicable legal framework for any resulting collision is the ColRegs and the Malaysian law of negligence — exactly as for a non-cyber collision. Limitation of liability under the LLMC 1996 is available, subject to the usual conditions.

 

Q: Will my P&I Club and hull insurer cover losses from a maritime cyber attack?

A: This is the most commercially significant question in maritime cyber risk — and the answer depends entirely on your specific policy terms. Many hull and machinery policies now include a cyber exclusion clause (typically based on the Institute Cyber Attack Exclusion Clause CL380), which may exclude hull damage caused by a cyber attack. Some policies offer cyber coverage as an add-on endorsement. P&I Club rules are similarly variable: some Clubs have introduced cyber endorsements providing limited cover for liabilities arising from cyber incidents; others treat cyber liabilities as excluded unless specifically endorsed. The Lloyd’s market and the international P&I Group are both actively developing their cyber coverage frameworks, which are evolving rapidly. Malaysian shipowners should: review their hull and P&I policy terms specifically for cyber exclusions; discuss their cyber risk profile with their broker and insurer; and consider standalone maritime cyber insurance if their hull and P&I cover is deficient.

Q: What does a maritime cyber risk management policy need to include to comply with the ISM Code?

A: The IMO’s Maritime Cyber Risk Management guidelines (MSC-FAL.1/Circ.3) specify that a cyber risk management policy integrated into the SMS should address five functional elements: Identify — define roles and responsibilities for cyber risk management and inventory the vessel’s IT and OT systems (navigation, engine management, cargo management, communications); Protect — implement technical and procedural safeguards against identified cyber risks, including access controls, software patching, and network segmentation; Detect — establish mechanisms to detect cyber incidents, including monitoring of onboard systems and crew reporting procedures; Respond — define the response procedures for a cyber incident, including incident containment, reporting to the Company Security Officer and flag state, and communication with relevant authorities; Recover — define procedures for restoring systems and data following a cyber incident, and for reviewing the incident to prevent recurrence. Each of these elements should be documented in the SMS and tested through regular drills and exercises. A maritime lawyer can advise on the legal adequacy of your cyber risk management documentation.

Q: What should a shipowner do immediately after a maritime cyber attack?

A: The immediate response to a maritime cyber attack should follow the ship’s documented cyber incident response procedure. Key steps include: isolating affected systems to prevent the spread of the attack — but without destroying evidence; activating manual backups for critical navigation and communication systems; notifying the Company Security Officer, the ship’s Master, and — where the vessel is in Malaysian waters — the MMEA and the Marine Department; preserving all system logs, network traffic records, and any ransom demands as evidence; notifying the P&I Club and hull insurer as soon as possible — late notification may prejudice your coverage; and engaging a maritime lawyer immediately, particularly where the attack has caused or may cause third-party damage. If the attack appears to be a state-sponsored act or a criminal extortion, engagement with the PDRM cybercrime division may also be appropriate.

About the Author: Mr. Yong Chee Kong  

Yong Chee Kong is an experienced Advocate & Solicitor with over three decades of legal experience, with principal areas of practice in Corporate Law and Shipping & Maritime Law. Called to the Bar in 1995, he has advised shipping companies, developers, financial institutions, and corporate entities on complex legal matters, including shipping disputes, development projects, project financing, mergers, takeovers, and acquisitions.

As a seasoned litigation lawyer, Yong Chee Kong regularly appears before the High Court, Court of Appeal, and Federal Court of Malaysia. His broad experience also extends to Banking, Finance, and Construction Law, enabling him to advise clients across a range of complex commercial and corporate matters.

Beyond legal practice, he is a registered Patent, Trade Marks and Industrial Design agent, as well as a Commissioner for Oaths and Notary Public. He has also served as a member of the Bar Council Disciplinary Committee and chaired numerous disciplinary investigations involving members of the Malaysian Bar.

His academic and professional qualifications include an LL.B (Hons) from the University of London, a Certificate in Legal Practice from University Malaya, and successful completion of the Patent Agent Examination conducted by the Intellectual Property Corporation of Malaysia.

  • Expertise: Corporate Law, Shipping & Maritime Law, Banking & Finance, Construction Law, Commercial Litigation, Intellectual Property

  • Professional Experience: 30+ years

  • Called to the Bar: High Court of Malaya, 1995

  • Professional Roles: Patent, Trade Marks & Industrial Design Agent; Commissioner for Oaths; Notary Public

 

The Current Role of a Modern Maritime Lawyer

The Current Role of a Modern Maritime Lawyer

The maritime industry is the lifeblood of global trade. In Southeast Asia, its importance is especially pronounced. The role of maritime lawyers has never been more crucial. They are no longer simply legal responders. Today's maritime lawyers act as proactive...