2026 Operational Cyber-Physical and Governance Risk Modeling for the Maritime Transportation System
Grant
Overview
Affiliation
View All
Overview
Abstract
Maritime Transportation Systems (MTS) are critical infrastructure for global trade and depend on tightly interconnected cyber-physical environments, including shipboard operational technology, navigation systems, port infrastructure, and communication networks. These systems operate within complex international governance structures and are increasingly exposed to systemic cyber risks. Preventing cascading operational disruptions requires integrated analysis of both cyber-physical system behavior and governance-driven decision processes, as emphasized in recent federal initiatives such as the U.S. Coast Guard Final Rule and the U.S. Maritime Action Plan.This project develops and experimentally validates an integrated cyber-physical risk modeling framework for MTS. The proposed approach analyzes how cyber incidents emerge and propagate across maritime environments using System-Theoretic Process Analysis for Security (STPA-Sec), complemented by structured threat modeling (STRIDE), quantitative risk analysis (FAIR), and cyber-range experimentation. The research is guided by the Maritime Transportation System Cybersecurity Technology Roadmap (TRM) [1], so that it ensures alignment with identified gaps in system visibility, cross-domain risk assessment, and governance coordination.
The research directly supports priority areas identified in the solicitation: • Cyber Hacking: Development and execution of realistic maritime cyber-attack scenarios • Cyber Analytics: System-level modeling and analysis of cyber-physical risk propagation • Software Assurance: Identification of unsafe control actions and design constraints in maritime control systems
The project will produce: • An integrated governance and cyber-physical risk modeling framework for MTS • A structured cyber risk analysis methodology integrating STPA-Sec, STRIDE, and FAIR • Validated maritime cyber-attack scenarios and cyber-range experiments • Cyber-range laboratory exercises supporting cybersecurity education • Curriculum modules and training materials for NCAE-C institutions (to be published at clark.center)
Students will actively participate in system modeling, cyber-range experimentation, and applied cybersecurity analysis, contributing to workforce development aligned with NCAE-C objectives.