New Frontiers of Port Security: In the Sky, on the Network, Beneath the Waves

Port security is no longer defined only by fences, gates, patrols and access cards. Those controls remain indispensable, but the modern port is exposed in three dimensions at once: above the terminal through drones and other airborne systems; across connected networks through cyber attack and data manipulation; and below the waterline through intrusion, sabotage, smuggling or interference with critical infrastructure.

These threats do not arrive neatly separated. A criminal group may use a drone for reconnaissance, compromised credentials to obtain movement information, and an insider or waterside route to exploit a physical weakness. A cyber incident can disrupt the systems used for gate access, cargo handling or vessel traffic coordination. An unauthorised underwater activity can become a security, safety, environmental and reputational crisis. The essential response is integration: one risk picture, coordinated authorities and resilient operations.

Start with the security objective: protect people, operations and trust

The purpose of port security is not to create the most restrictive environment possible. It is to protect people, vessels, cargo, critical infrastructure and the continuity of lawful trade. Effective security is proportionate, intelligence-led and designed to work with operations rather than against them.

This matters because ports are complex. They may include public roads, leased terminals, customs zones, rail connections, fuel facilities, passenger areas, data centres, vessel traffic services, energy assets, contractors and visiting ships. A control that is effective at a high-security berth may be impractical at a public waterfront. A technology that works in a laboratory may create false alarms in rain, salt spray, moving cranes or dense radio environments.

The International Ship and Port Facility Security Code provides a common risk-management foundation. Emerging threats should be incorporated into the same disciplined process: identify assets and vulnerabilities, assess credible threats, define protective measures, establish communication and response arrangements, train people and review the plan after incidents or exercises. New technology does not remove the need for this foundation; it makes it more important.

The sky: drones create both risk and useful capability

Uncrewed aircraft systems can support port inspection, environmental monitoring, surveying, emergency assessment and security patrols. They can also be used for unauthorised observation, contraband delivery, interference, nuisance, collection of sensitive imagery or attempts to test response procedures. Their low cost and accessibility make them a real planning issue for ports of many sizes.

The first step is to develop an approved-use framework. Define which port or contractor operations may use drones, where, at what altitude, with what registration, training, geofencing, records and coordination with aviation and maritime authorities. Clear internal rules make it easier to distinguish authorised activity from an anomaly.

For unauthorised drones, ports need a lawful, risk-based detect-assess-respond process. Detection may involve trained observers, radar, radio-frequency awareness tools, cameras or coordinated reports from operations teams, depending on local law and risk. Detection alone is not enough; an operator must be able to assess whether an object is a bird, an authorised device, a harmless but non-compliant flight or a genuine threat.

Response authority is especially important. Counter-drone measures can create safety, aviation, radio-spectrum and legal consequences. A port should not improvise or assume that a commercial technology grants authority to disrupt a device. Procedures should define who is notified, who has decision authority, how evidence is preserved, how ships and personnel are protected, and which competent agencies lead intervention. Exercises should test communications and handover, not merely the sensor display.

The network: cyber risk is operational risk

Ports rely on digital systems for access control, cargo planning, gate appointments, cranes, power management, communications, billing, customs exchange, navigation support and incident response. This interdependence means cyber security cannot be left solely to the IT department. A ransomware event, manipulated data feed, supplier compromise or unauthorised remote connection may affect real-world operations and safety decisions.

The objective is cyber resilience: the ability to prevent common attacks, detect abnormal activity, contain impact and restore critical services safely. Begin with governance. The port authority, terminal operators and critical suppliers need clarity about who owns each system, who can make changes, who responds after an incident and how operational decisions are made if data is unreliable.

Maintain an inventory of information technology and operational technology. Identify systems that are safety-critical, business-critical or externally connected. Remove or isolate unsupported assets where possible. Segment networks so that an incident in office systems does not automatically reach control systems. Use strong identity management, multi-factor authentication where appropriate, secure remote access, managed patching, logging, backup and restoration testing.

Human factors are just as important. Many incidents begin with a convincing request, a reused password, a rushed change or an unverified supplier connection. Training should be role-specific. A gate operator, procurement manager, ship agent, engineer and senior executive face different risks and need different escalation paths. Make reporting easy and non-punitive. Fast reporting can turn a near miss into a contained event.

Beneath the waves: protect the unseen critical zone

Underwater security is easy to neglect because most port activity is visible above water. Yet quays, jetties, bridge approaches, submarine cables, pipelines, intake structures, moorings, navigational aids and vessels themselves may be exposed below the surface. Risks can include unauthorised diving, sabotage, tampering, contraband movement, surveillance or damage caused by non-malicious activity.

The foundation is an accurate picture of underwater assets and access conditions. Map critical infrastructure, depth zones, work areas, anchoring restrictions, legitimate contractor activity and areas where diving or small-craft movement requires special control. Keep records current after construction, dredging or repairs. A port cannot protect infrastructure that it has not clearly identified.

Layered detection can combine waterside patrols, access control, lighting, cameras, vessel traffic awareness, reporting by pilots and tugs, inspection routines and, where justified, underwater sensing or remotely operated inspection. The appropriate mix depends on risk, water conditions and legal mandates. Technology should support trained judgment, not produce more data than a duty team can interpret.

Response planning needs close coordination with police, coast guard, navy or other competent agencies, harbour master functions, fire and rescue, environmental responders and infrastructure owners. Define how a suspicious report is verified, how vessel movements are managed, how divers or specialist teams are requested, and how the public is informed if an operational restriction becomes visible. Practice these arrangements before an incident.

Join the three dimensions with one common operating picture

Siloed security programmes create blind spots. The drone team may not know that a cyber incident has degraded access-control cameras. The cyber team may not understand that a delayed gate system is creating a crowding issue. The waterside patrol may observe unusual small-craft behaviour but lack a channel to check whether it coincides with a drone or credential anomaly.

Incident command should be scalable. A minor unauthorised drone sighting may require recording and monitoring. A credible threat to a critical berth may require restricted movements, agency coordination and executive communication. Design procedures that can expand without causing every alert to become a full shutdown. This proportionality protects both security and operational continuity.

Supply-chain security and the insider dimension

Ports are nodes in a wider supply chain, so their security depends on many organisations. Contractors install and maintain equipment. Software vendors connect remotely. Truck drivers, agents, crew, inspectors and visitors need legitimate access. Cargo data passes among parties. Criminal networks often exploit the seams between these roles.

Supplier and contractor management should therefore be part of the security programme. Use clear security requirements in contracts, verify identities and access rights, limit access to what is necessary, review third-party connectivity and ensure that contractors know how to report suspicious activity. For high-risk systems, require support arrangements that include vulnerability handling, patching, incident notification and secure offboarding.

Insider risk should be managed respectfully and proportionately. Most people working in ports are committed professionals; a culture of indiscriminate suspicion undermines safety and cooperation. The aim is to reduce opportunity for abuse through segregation of duties, auditable access, practical whistleblowing channels, welfare support, fair vetting where legally appropriate and prompt investigation of anomalies. Good security culture is built on trust plus accountability.

Exercises, recovery and communication are the real test

A security plan is only credible if people can use it under pressure. Run exercises that test a realistic scenario across the three dimensions: for example, an unauthorised drone near a critical facility during a cyber outage, or a suspicious small craft activity combined with a false logistics-data message. Include terminal operators, public agencies, communications teams and relevant city partners.

Test difficult conditions: night shift, bad weather, loss of a primary communications channel, incomplete information, conflicting reports and senior decision-makers who are not immediately available. Evaluate not only whether the incident was detected, but also how long it took to verify, escalate, decide, communicate and recover. Convert lessons into assigned corrective actions with deadlines.

Investment priorities for a modern port-security programme

The best investment is not always the most visible technology. Many ports gain more security by improving asset inventories, access governance, backup and recovery, lighting, contractor controls, training, joint exercises and incident communications. Technology should address a defined operational gap and be supportable across its lifecycle.

Security that enables legitimate trade

New frontiers of port security require ports to look up, across and below the waterline. Drones, cyber threats and underwater risks are different in form but similar in one respect: they exploit uncertainty, weak coordination and untested assumptions.

The answer is not fear-driven technology adoption. It is a disciplined, integrated security model built on risk assessment, lawful authority, resilient operations, capable people and trusted partnerships. When that model is in place, security becomes what it should be: a foundation for safe people, protected infrastructure and reliable trade.

Sources and further reading

IMO Maritime Security and the ISPS Code

IMO maritime-security frequently asked questions

IMO Maritime Cyber Risk Management

IAPH 2026 webinar series: New Frontiers of Port Security

Rate this post

Leave a Reply

Your email address will not be published. Required fields are marked *