Maritime & logistics

Find the exploitable exposures across every yard, port and office

Maritime and logistics groups grow through acquisitions and run many local IT teams. Hadrian maps every internet-facing asset, validates what attackers could exploit and gets each fix to the team that owns it.

Customer story

Damen automated its attack surface mapping, cut time spent triaging false positives and uses Secure Share to coordinate fixes across its operating companies.

Damen Shipyards Group
Read the story →
Risks

Where maritime & logistics is exposed

0
1
2023

Terminal systems that stop cargo

In July 2023, ransomware that port officials attributed to LockBit stopped container operations at the Port of Nagoya, Japan's largest port, for about two days. In November 2023, DP World Australia, which handles about 40% of the country's freight, disconnected from the internet and paused terminals after a cyber incident.

0
2
2024

Remote access into operational equipment

The US Coast Guard's 2024 maritime cyber trends report found insecure configurations and network connectivity on ship-to-shore cranes and advised operators to disable unused remote access ports. It also notes that vessels and facilities often connect operational technology directly to company networks.

0
3

Forgotten web assets

At Damen, a forgotten marketing page was exploited for SEO poisoning. It wasn't a sensitive system. It still showed the gap between what the business thought it controlled and what an attacker could reach. Groups that grow through acquisitions inherit assets like these.

How Hadrian helps

Map the attack surface of every operating company

Damen Shipyards Group runs more than 50 shipyards and related businesses in 120 countries. Hadrian builds a digital fingerprint of the organization and scans the internet for matching assets, so forgotten pages and shadow IT show up. The inventory updates in real time.

See how Damen mapped its attack surface
01

Swap noisy ratings for validated risks

Damen's security rating tool listed hundreds of issues, many of them false positives. With Hadrian's Verified Risks, the team sees only exposures that were tested and confirmed exploitable, each with reproduction steps written for that asset.

Read Hadrian vs security rating services
02

Send each fix to the team that owns the asset

Role-based access gives each local team its own view while the central team sees everything. Secure Share sends risk details and remediation steps to the team, IT department or third party that has to fix it. Tickets can also flow into Jira, ServiceNow or GLPI.

See integrations
03
0
4

Keep a live inventory across subsidiaries

Hadrian finds the domains, subdomains, certificates and IPs tied to your group, including those of acquired companies. Passive scans run every hour, and new assets trigger testing automatically.

0
5

Test new services the moment they appear

Event-driven testing starts when a new service shows up on the internet, such as a remote access portal or a web interface. Hadrian checks whether it can be exploited and only alerts you when it can.

0
6

Close abandoned subdomains

Hadrian identifies unclaimed or poorly managed subdomains that attackers could take over for phishing, malware distribution or SEO poisoning, so you can fix the DNS record first.

Case studies

More from customers

All case studies
No items found.
FAQ

Frequently asked questions

Does NIS2 cover shipping and port companies?
+

Yes. NIS2 Annex I lists water transport under the transport sector. It names inland, sea and coastal passenger and freight water transport companies, port managing bodies and vessel traffic service operators. Each EU country sets the details in national law. Hadrian supports the asset management and testing NIS2 asks for. It does not certify compliance.

Does Hadrian test ships or OT networks?
+

Hadrian focuses on your external attack surface: anything an attacker can reach from the internet, including remote access services and web interfaces linked to operational systems. It needs no agents or sensors, on board or ashore.

How does Hadrian work for a group with many local IT teams?
+

A central team sees the whole attack surface, and role-based access gives each local team a view of its own assets. When an issue comes up, Secure Share sends the risk details and remediation steps to whoever has to fix it, including third parties. That is how Damen coordinates remediation across its operating companies.

How is this different from a security rating?
+

Security ratings give boards a score and a benchmark. Damen found the findings behind its rating noisy, with many false positives that took hours to triage. Hadrian tests each exposure and only reports the ones it confirms are exploitable, with reproduction steps, so the team knows exactly what to fix.

How fast can we get started?
+

Atlas deploys from the cloud in under five minutes with no installation. Passive scans run every hour, and new assets or changes trigger testing automatically.

Get a 15 minute demo

See what attackers see across your maritime group

Book a demo to see how Hadrian maps your group's attack surface, validates which exposures are exploitable and gets fixes to the right local team.