Why cruise lines must prioritize hiring roles in cybersecurity for ships

An approaching deadline from a U.S. Coast Guard cybersecurity mandate will put cruise companies in a tough spot if they haven't hired the right IT and OT professionals for their ships.

banner image

New risks and mandates require enhanced cybersecurity for cruise ships

The idea of going on a cruise conjures different images for people, but almost all of them involve a ship with a long observation deck, banquet halls and buffets, live entertainment, and other extravagant amenities. For guests wanting to travel to multiple destinations on the same trip, while also enjoying an entertainment-focused experience suitable for all ages, they strike a perfect balance. It’s not surprising that starting in the 1980’s and 90’s, cruises exploded as a vacation option. As their popularity continued into the early 2000’s, ships offering multiple dining venues, pools, and entertainers became commonplace in the industry.1

Now, all the bells and whistles of multiple restaurants, pools, and entertainment are still included, but cruise ships are no longer just floating resorts carrying thousands of passengers. They’ve become sophisticated digital cities that store billions of dollars in financial data and use mission-critical navigation systems across the world’s most remote waters. Technology is an inseparable part of the cruise experience, and that means cybersecurity is intrinsically linked to the cruise experience. Cybersecurity for ships carrying so much precious digital cargo is not something to take lightly.

Despite this, many cruise companies have been slow to modernize their cybersecurity systems and protocols and have paid the price for complacency. This spring, Carnival Corporation notified their customers about a data breach that affected nearly 6 million individuals after an employee fell victim to a social engineering attack.2 This recent breach comes as a heavy blow to the company, since this was not their first time getting bad press for a cybersecurity incident. Carnival was fined $5 million following four separate cybersecurity incidents between 2019 and 2021, including two ransomware attacks,3 but Carnival Cruise Lines aren’t the only ones being targeted. In 2020, Norwegian Cruise Line had over 24,000 partner records exposed on the dark web and MSC Cruises was the victim of a malware attack.4

Cybersecurity for cruise ships is no different than cybersecurity for any other corporate business or commercial company—cybersecurity risk is ubiquitous. When (not if) your ship is targeted, you need to be ready, especially when you’re 1,200 miles from the nearest port.

Mandated cybersecurity guidelines for ships

The era of voluntary compliance is over, and cybersecurity guidelines for ships have become a matter of pressing concern. The U.S. Coast Guard’s first-ever mandatory cybersecurity framework for ports, vessels, and offshore facilities took effect July 16, 2025, with a hard compliance deadline in 2027.5

This is no easy feat to pull off for cruise operators and chief technology officers (CTOs). Many are scrambling to close decades-old security gaps across fleets that span legacy systems and international jurisdictions, and with passenger networks rivaling the scale of a small city’s public internet.

With the urgency to adopt a mandatory cybersecurity framework, cruise operators must take a different approach to keeping their ships’ digital infrastructure safe. Here are three areas of operations that must be reimagined:

  1. New job roles to support cybersecurity for cruise ships

    Modernizing existing IT infrastructure with advanced cybersecurity for ships requires a significant organizational shift, and an abundance of specialized IT expertise.

    Every vessel must now have a vessel Cybersecurity Officer (CySO); a maritime-specific role that bridges digital threats and behavioral threat landscapes, distinct from a standard enterprise Chief Information Security Officer (CISO). The individual in this role must have extensive knowledge of cybersecurit (including best practices, how to conduct audits, advanced monitoring, etc.) as well as maritime operations, environments, and operating conditions. Each ship is responsible for hiring a vessel CySO, not the government or Coast Guard.6 This kind of nuanced, technical role is often difficult for talent acquisition teams in the cruise industry to fill.

    Alongside that, cruise companies must hire security hybrid engineers for operational technology (OT) and information technology (IT) to protect both IT and OT systems, like propulsion controls. Additionally, maritime-specific penetration testers round out the new talent layer, stress-testing navigation systems and onboard networks before attackers can find the gaps.7

  2. AI deployment and software to support cybersecurity for ships

    Modernizing cybersecurity practices to the scale of a cruise ship requires extensive access to a wide talent network. The people sitting in the IT and cybersecurity roles must hold expertise in cloud infrastructure, the latest AI tools and applications, and understand all the intricate, connective systems on board. For most recruiters, this would be the talent acquisition equivalent of finding a needle in a haystack.

    The digital environment of a cruise ship is complex, to say the least. They rely heavily on technology to augment guest experiences, and require diverse infrastructure to operate, including power plants, medical facilities, point of sales systems, and casinos.8 All these attack surfaces create layers of vulnerabilities that cybercriminals can exploit. But, modernizing cybersecurity for ships with AI makes a compelling use case.

    Royal Caribbean is a promising example of AI adoption in maritime cybersecurity. They deployed Darktrace’s autonomous AI cybersecurity platform across their fleet to learn every user and device in the organization’s digital environment, thereby differentiating between normal patterns of behavior and abnormal activity that may indicate a cyberattack.9

    Cloud security is also a growing priority for cruise ship IT teams, since many cruise companies use cloud-based infrastructure but admit to not understanding their security responsibilities even with a cloud service provider.10 Strong, reliable network connectivity is essential for providing the kind of frictionless self-service consumers expect. Modern distributed cloud solutions offer a new approach to network reliability by placing a cloud data center on the ship itself. This infrastructure provides the low-latency cloud services needed to run critical onboard systems as well as deliver high-quality digital and AI services locally.11

  3. Infrastructure investments to support cybersecurity for ships

    Updates to OT and critical infrastructure are also nonnegotiable for cruise ships. OT includes the equipment and systems used for navigation, cargo management, power, and safety. Because maritime digital environments often blend newer digital tools with older equipment built for a long service life,12 the individuals hired to implement and manage these infrastructure changes must have extensive knowledge of both legacy systems management and also application modernization.

    For around-the-clock coverage, 73% of Coast Guard mission partners now outsource monitoring to Managed Security Service Providers (MSSPs), a major shift for an industry that historically managed their security in-house.13

Cybersecurity for ships protects passengers, crew members, and digital systems

While it might not be obvious at first, cruise ships contain lots of IT, OT, and data on board. All the passenger and crew data, and the digital systems that store them, must be protected with modern cybersecurity for ships. However, this is only possible if cruises are staffing for cybersecurity and IT roles appropriately. With the U.S. Coast Guard mandate deadline for compliance in 2027, any risks posed by dated digital infrastructure on older vessels and critical roles remaining empty must be addressed.

To learn more about how CAI partners with companies to staff their cybersecurity teams, fill out the form below.


Endnotes

  1. “History of the Cruise Industry.” Cruise Lines International Association. https://cruising.org/about-cruise-industry/history-cruise-industry.
  2. Alicia Hope. “Carnival Cruise Data Breach Exposes Nearly 6 Million People in Cyber Attack Linked to ShinyHunters.” CPO Magazine. June 2, 2026. https://www.cpomagazine.com/cyber-security/carnival-cruise-data-breach-exposes-nearly-6-million-people-in-cyber-attack-linked-to-shinyhunters/.
  3. “Carnival Cruise Pays $5M, Gives Up Insurance Licenses in New York Over Data Breach.” Insurance Journal. June 24, 2022. https://www.insurancejournal.com/news/east/2022/06/24/673350.htm.
  4. Gwen Pratesi, Jeannine Williamson. “Cybersecurity at Sea: What to Know and How to Keep Your Data Safe.” CruiseCritic – a Tripadvisor company. November 20, 2025. https://www.cruisecritic.com/articles/is-internet-aboard-cruise-ships-safe.
  5. “Final Rule: Cybersecurity in the Marine Transportation System – Implementation Timeline.” United States Coast Guard News, Department of Homeland Security. July 16, 2025. https://www.news.uscg.mil/maritime-commons/Article/4247529/final-rule-cybersecurity-in-the-marine-transportation-system-implementation-tim/.
  6. Elan Alvey, Bobbie Crinella. “All Hands-on Deck: The USCG Just Made Cybersecurity Non-Negotiable.” Dragos. April 10, 2026. https://www.dragos.com/blog/maritime-cybersecurity-uscg-mtsa-requirements.
  7. “New Maritime Cybersecurity Requirements: What U.S. Vessel Owners Actually Need to Know.” American Nautical Services. January 28, 2026. https://www.amnautical.com/blogs/the-mariners-blog/cybersecurity-new-rule-for-us-vessels.
  8. Terry Griffith. “Royal Caribbean, Customer Story.” Darktrace. https://www.darktrace.com/customers/royal-caribbean.
  9. Terry Griffith. “Royal Caribbean...” https://www.darktrace.com/customers/royal-caribbean.
  10. Kathy Murray. “Modernization increases cybersecurity challenges in the Marine Transportation System (MTS).” United States Coast Guard. May 19, 2025. https://www.mycg.uscg.mil/News/Article/4190254/modernization-increases-cybersecurity-challenges-in-the-marine-transportation-s/.
  11. Cindy Falschlehner. “The new wave of cruising: How AI and cloud are charting a new course for the cruise industry.” Google Cloud. September 2, 2025. https://cloud.google.com/transform/ai-cloud-cruise-industry-transformation-connected-travellers-new-wave.
  12. “Cybersecurity at Sea: Protecting Maritime Operations in a Satellite Connected World.” Honeywell Technologies. April 12, 2026. https://www.honeywell.com/us/en/insights/articles/cybersecurity-at-sea-protecting-maritime-operations-in-a-satellite-connected-world.
  13. Kathy Murray. “Modernization increases cybersecurity challenges in the Marine Transportation System (MTS).” United States Coast Guard, U.S. Department of Homeland Security. https://www.mycg.uscg.mil/News/Article/4190254/modernization-increases-cybersecurity-challenges-in-the-marine-transportation-s/.

Let's talk!

Interested in learning more? We'd love to connect and discuss the impact CAI could have on your organization.

All fields marked with * are required.

Please correct all errors below.
Please agree to our terms and conditions to continue.

For information about our collection and use of your personal information, our privacy and security practices and your data protection rights, please see our privacy policy and corresponding cookie policy.