ISCAP Proceedings - 2026

Asheville, NC - November 2026



ISCAP Proceedings: Abstract Presentation


Causal Analysis Based on Systems Theory (CAST) of Three Maritime Cybersecurity Incidents


Logan Chaffin
University of North Carolina Wilmington

Ben Williams
University of North Carolina Wilmington

Nathan Sims
University of North Carolina Wilmington

Ulku Clark
University of North Carolina Wilmington

Jeff Greer
University of North Carolina Wilmington

Bilge Karabacak
University of North Carolina Wilmington

Abstract
Causal Analysis Based on Systems Theory (CAST) is an accident analysis method that examines how interactions among technical, organizational, and human factors contribute to failures rather than pointing to a single mistake or vulnerability. This paper applies CAST to three significant maritime cybersecurity incidents: the 2017 NotPetya attack that disrupted Maersk’s global shipping operations, the Port of Antwerp container terminal hack where attackers accessed the Terminal Operating System to steal drug filled containers, and the 2017 Black Sea Global Navigation Satellite System (GNSS) spoofing incident that affected commercial vessel navigation. Each case study analyzes system control structures, unsafe control actions, process model flaws, and violated safety and security constraints to identify the systemic factors that enabled the incidents and increased their operational impact. Although the incidents differed in attack vectors and operational environments, we found similar problems across all of them. The analyses revealed recurring weaknesses in cybersecurity governance, access control, monitoring and detection, operational procedures, physical security, network resilience, and organizational coordination. Based on what we found, the paper proposes system-level safety constraints and cybersecurity recommendations, including stronger identity and access management, multi-factor authentication, improved network segmentation, enhanced anomaly detection, resilient navigation through multi-source position verification, strengthened physical security, and more effective coordination between operational technology and information technology stakeholders. The results demonstrate that CAST is a useful tool for breaking down maritime cyber incidents and figuring out what needs to change to prevent similar ones in the future.