A ransomware attack locks your vessel’s bridge navigation systems at sea. A phishing email compromises your cargo booking platform. A GPS spoofing attack sends your vessel off course in the Strait of Malacca. Maritime cyber attacks are no longer hypothetical — they are a documented and growing threat. In Malaysia, the legal framework has caught up. Is your vessel compliant?
Maritime cyber security has moved from a niche IT concern to a mainstream legal and regulatory obligation. The IMO’s Maritime Cyber Risk Management guidelines — incorporated into the ISM Code through MSC-FAL.1/Circ.3 and Resolution MSC.428(98) — have required shipping companies to address cyber risk management in their Safety Management Systems (SMS) since 1 January 2021. Malaysian-flagged vessels operating under the ISM Code must demonstrate cyber risk management compliance as part of their Document of Compliance (DOC) and Safety Management Certificate (SMC) audit — and port state control officers in Malaysia and globally are increasingly checking for it.
The legal significance of a maritime cyber attack extends well beyond IT. A cyber attack that compromises navigation systems and causes a collision or grounding triggers potential liability claims from damaged vessels, cargo interests, and port authorities. A cyber attack that corrupts cargo documentation could invalidate bills of lading and letters of credit, triggering cargo claim disputes. A ransomware attack that grounds a vessel triggers off-hire deductions under the time charter. The question of whether the shipowner’s P&I Club and hull insurer will respond to cyber-related losses — or rely on a cyber exclusion clause — is one of the most actively litigated insurance questions in the shipping industry today.
In Malaysia, the Personal Data Protection Act 2010 (PDPA) imposes additional obligations where a cyber breach compromises personal data of seafarers, port employees, or customers. The PDPA requires reasonable security measures to protect personal data, and a cyber breach that exposes personal data may trigger a regulatory investigation by the Personal Data Protection Commissioner alongside any maritime law proceedings.
Malaysian shipowners and operators must treat cyber security not as an IT issue but as a legal and commercial risk management priority — with defined consequences for non-compliance in port state control, insurance, and third-party liability.
Key Legal Issues in Maritime Cyber Security
-
ISM Code compliance: Cyber risk management must be integrated into the SMS. PSC officers can detain a vessel for ISM deficiencies — including inadequate cyber risk management documentation.
-
Hull insurance and cyber exclusions: Many hull policies now contain cyber exclusion clauses. Check your policy to understand whether a cyber-caused casualty (navigation system failure leading to collision) is covered.
-
P&I cover for cyber incidents: P&I Clubs are progressively introducing cyber endorsements. Understand your cover before an incident — not after.
-
Third-party liability: A shipowner whose vessel causes damage due to a cyber attack on navigation systems faces the same liability as any negligent collision — the cyber origin does not automatically provide a defence.
-
PDPA obligations: Personal data on ship management systems must be protected against cyber breach under the Personal Data Protection Act 2010.
Frequently Asked Questions: Maritime Cyber Security in Malaysia
Q: Is maritime cyber security compliance mandatory for Malaysian-flagged vessels?
A: Yes — for vessels subject to the ISM Code (which covers all vessels of 500 GT and above on international voyages, passenger vessels of any size, and mobile offshore drilling units), cyber risk management must be addressed in the Safety Management System since 1 January 2021. This requirement flows from IMO Resolution MSC.428(98) and the associated guidelines. The Marine Department of Malaysia, as the flag state administration for Malaysian-registered vessels, expects compliance to be demonstrated during DOC and SMC audits. Port state control officers in Malaysia and in other Tokyo MOU member states are increasingly checking for evidence of cyber risk management in the SMS — deficiencies in this area are PSC detention grounds. Vessels without a documented cyber risk management policy and procedure in their SMS are non-compliant with the ISM Code.
Q: If a cyber attack causes my vessel to collide with another ship, am I liable?
A: Yes — the cyber origin of a casualty does not, by itself, provide the shipowner with a defence against liability claims from damaged parties. The standard of care for a vessel in navigation is one of reasonable seamanship and maintenance of a seaworthy vessel — including seaworthy navigation and communications systems. A shipowner who failed to implement adequate cyber risk management measures — leaving the vessel’s systems vulnerable to an attack — may be found to have breached the duty of seaworthiness, making the cyber attack a foreseeable consequence of inadequate protection rather than an unforeseeable external event. The applicable legal framework for any resulting collision is the ColRegs and the Malaysian law of negligence — exactly as for a non-cyber collision. Limitation of liability under the LLMC 1996 is available, subject to the usual conditions.
Q: Will my P&I Club and hull insurer cover losses from a maritime cyber attack?
A: This is the most commercially significant question in maritime cyber risk — and the answer depends entirely on your specific policy terms. Many hull and machinery policies now include a cyber exclusion clause (typically based on the Institute Cyber Attack Exclusion Clause CL380), which may exclude hull damage caused by a cyber attack. Some policies offer cyber coverage as an add-on endorsement. P&I Club rules are similarly variable: some Clubs have introduced cyber endorsements providing limited cover for liabilities arising from cyber incidents; others treat cyber liabilities as excluded unless specifically endorsed. The Lloyd’s market and the international P&I Group are both actively developing their cyber coverage frameworks, which are evolving rapidly. Malaysian shipowners should: review their hull and P&I policy terms specifically for cyber exclusions; discuss their cyber risk profile with their broker and insurer; and consider standalone maritime cyber insurance if their hull and P&I cover is deficient.
Q: What does a maritime cyber risk management policy need to include to comply with the ISM Code?
A: The IMO’s Maritime Cyber Risk Management guidelines (MSC-FAL.1/Circ.3) specify that a cyber risk management policy integrated into the SMS should address five functional elements: Identify — define roles and responsibilities for cyber risk management and inventory the vessel’s IT and OT systems (navigation, engine management, cargo management, communications); Protect — implement technical and procedural safeguards against identified cyber risks, including access controls, software patching, and network segmentation; Detect — establish mechanisms to detect cyber incidents, including monitoring of onboard systems and crew reporting procedures; Respond — define the response procedures for a cyber incident, including incident containment, reporting to the Company Security Officer and flag state, and communication with relevant authorities; Recover — define procedures for restoring systems and data following a cyber incident, and for reviewing the incident to prevent recurrence. Each of these elements should be documented in the SMS and tested through regular drills and exercises. A maritime lawyer can advise on the legal adequacy of your cyber risk management documentation.
Q: What should a shipowner do immediately after a maritime cyber attack?
A: The immediate response to a maritime cyber attack should follow the ship’s documented cyber incident response procedure. Key steps include: isolating affected systems to prevent the spread of the attack — but without destroying evidence; activating manual backups for critical navigation and communication systems; notifying the Company Security Officer, the ship’s Master, and — where the vessel is in Malaysian waters — the MMEA and the Marine Department; preserving all system logs, network traffic records, and any ransom demands as evidence; notifying the P&I Club and hull insurer as soon as possible — late notification may prejudice your coverage; and engaging a maritime lawyer immediately, particularly where the attack has caused or may cause third-party damage. If the attack appears to be a state-sponsored act or a criminal extortion, engagement with the PDRM cybercrime division may also be appropriate.
About the Author: Mr. Yong Chee Kong
Yong Chee Kong is an experienced Advocate & Solicitor with over three decades of legal experience, with principal areas of practice in Corporate Law and Shipping & Maritime Law. Called to the Bar in 1995, he has advised shipping companies, developers, financial institutions, and corporate entities on complex legal matters, including shipping disputes, development projects, project financing, mergers, takeovers, and acquisitions.
As a seasoned litigation lawyer, Yong Chee Kong regularly appears before the High Court, Court of Appeal, and Federal Court of Malaysia. His broad experience also extends to Banking, Finance, and Construction Law, enabling him to advise clients across a range of complex commercial and corporate matters.
Beyond legal practice, he is a registered Patent, Trade Marks and Industrial Design agent, as well as a Commissioner for Oaths and Notary Public. He has also served as a member of the Bar Council Disciplinary Committee and chaired numerous disciplinary investigations involving members of the Malaysian Bar.
His academic and professional qualifications include an LL.B (Hons) from the University of London, a Certificate in Legal Practice from University Malaya, and successful completion of the Patent Agent Examination conducted by the Intellectual Property Corporation of Malaysia.
-
Expertise: Corporate Law, Shipping & Maritime Law, Banking & Finance, Construction Law, Commercial Litigation, Intellectual Property
-
Professional Experience: 30+ years
-
Called to the Bar: High Court of Malaya, 1995
-
Professional Roles: Patent, Trade Marks & Industrial Design Agent; Commissioner for Oaths; Notary Public
Salvage Claims in Malaysia: What Shipowners and Cargo Interests Need to Know
Salvage is the service rendered by one party to rescue another party's vessel or cargo from peril at sea. In Malaysia, salvage is governed by common law principles and — for vessels party to Lloyd's Open Form (LOF) — by the International Salvage Convention 1989, which...
What Is Limitation of Liability and How Does It Protect Shipowners in Malaysia?
When a vessel is involved in a collision, grounding, or other serious incident, the financial claims that follow can be staggering — cargo loss, hull damage, personal injury, wreck removal, and environmental liability can all arise from the same event. Without a cap...
Limitation of Liability in Malaysian Maritime Law: A Complete Guide for Shipowners
Few legal concepts carry as much financial weight for a shipowner as limitation of liability. In the aftermath of a serious maritime incident — a collision in the Strait of Malacca, a grounding off the Sabah coast, an oil spill in Port Klang — claims from cargo...
Buying or Selling a Ship in Malaysia: The Legal Process Explained
The sale and purchase of a vessel in Malaysia is a multi-step legal transaction governed primarily by the Merchant Shipping Ordinance 1952 (MSO 1952), and the Contracts Act 1950, together with the specific terms of the Memorandum of Agreement (MOA) entered into...
Oil Pollution Liability at Sea in Malaysia: What Shipowners and Operators Need to Know
Malaysia's strategic position along the Strait of Malacca — through which an estimated 40% of global seaborne trade passes — makes it one of the most environmentally sensitive maritime jurisdictions in the world. A vessel grounding, collision, or structural failure in...
Maritime Arbitration vs Court Litigation in Malaysia: Which Route Is Right for Your Dispute?
Most maritime disputes in Malaysia are resolved through one of two routes: arbitration or litigation before the Admiralty Court. The route that applies to your dispute is largely determined by what your contract says — and understanding the difference before a dispute...





