Bad Code in Critical Systems Causes Physical Harm

▶ Watch (0:02)

One bad line of code in a ship, plane, or car can cause real physical harm. In the transportation world, that is not future risk. It is already here. Software quality and engineering practice is a Trojan horse that does not get enough attention. Bad code does not have to break in. It is already inside, running exactly as written. The problem is when what it is written to do is dangerous.

Ships Are Networks of Embedded Computers

▶ Watch (4:12)

Ships have computers embedded in every critical system. The diagram from IACS standard E22 shows vessels with systems, subsystems, and programmable devices. At the bottom are PLCs that control automation, pumps moving critical fluids, variable frequency drives, flow meters, and engine telegraphs. Every one of these depends on software. If the code is wrong, misunderstood, or compromised, that system will still do exactly what the code tells it to do, even if it is dangerous.

Digitalization Imports Cyber Risk

▶ Watch (5:10)

Replacing mechanical systems with networked ones imports risk. A wax pellet thermostat has no IP address, no firmware, no updates, no zero days. A modern PLC-based control system has a sensor, logic controller, motorized valve, and a web interface with the default password set to admin. It offers precision and remote control. The trade-off is that the thermostat becomes a fully-fledged cyber attack surface. It is now part of the internet of targets.

Software Failures Propagate Across Identical Systems

▶ Watch (8:51)

Chris Stein showed a Kongsberg simulator based on the Viking Grace, a ro-pax ship sailing through the Stockholm archipelago. The power management system ran four engines at 50% to prevent blackout near rocks. He set the cooling valve set point to 700°C. The identical software on all four engines propagated the failure. In less than 90 seconds, all engines tripped. The ship blacked out. 600 to 800 alarms overwhelmed the crew. A single manipulated set point caused loss of propulsion.

Vibe Coding and Legacy Stacking Create Fragile Systems

▶ Watch (17:16)

Austin Reid warned about vibe coding in critical systems. Developers may work on windzip one day and propulsion controls the next. Stacking emerging technology on legacy systems creates fragility. A single bad sensor can take down an entire vessel. New regulations from IACS, specifically E26, E27, and E22, apply IEC 62443 SL1 to the maritime sector. They push toward secure by design for new builds. But the biggest risk is not external hackers. It is bad code and bad processes.

Notable Quotes

the system will do exactly what it’s told, even if it’s the wrong thing Michael DeVolld · ▶ 7:38

your thermostat is now part of the internet of targets Michael DeVolld · ▶ 5:54

in less than 90 seconds, a manipulation of the set point can cause a complete ship blackout Chris Stein · ▶ 13:49

the biggest risks in maritime aren’t from external hackers. It’s from the stacking of emerging technology on top of legacy systems with bad code and bad processes and lack of control Austin Reid · ▶ 20:14

Key Takeaways

  • A cooling valve set point change to 700°C blacked out a Kongsberg simulator in 90 seconds.
  • The USS Yorktown was disabled for two weeks by a divide-by-zero error in Windows NT.
  • New IACS regulations E26, E27, and E22 push maritime toward secure by design.

About the Speaker(s)

Michael DeVolld is the Maritime Cybersecurity Director at ABS Consulting. With 25 years in the maritime sector, he is a retired US Coast Guard Officer who conducted safety inspections, investigated casualties including the Costa Concordia, and established a cybersecurity program at USCG Cyber Command. He previously served as a Business Information Security Officer for Royal Caribbean Group.

Austin Reid is a senior consultant at ABS Consulting specializing in maritime operational technology security. He has 10 years of experience in the maritime sector spanning breakbulk, automated container terminal operations, and securing critical vessel systems. He is also a hacker and security researcher focused on maritime navigation control systems.