DP World is the reference. Nagoya is the benchmark. CIRMP wants evidence.
As a port operator, shipping line, or maritime service provider, you face layered regulation — the SOCI Act plus MTOFSA (now all-hazards under the TSA Act 2025) plus, for Australian-flagged and calling ships, IMO MSC.428(98). DP World Australia's 2023 Citrix Bleed incident and the 2023 Port of Nagoya LockBit attack are the peer-pattern references.
Your specific challenges
Layered regulation, one environment
The SOCI Act plus MTOFSA plus IMO plus Cyber Security Act — applied to the same terminal operating systems, port community systems, vessel traffic services, and shore-side networks. Each framework expects evidence on its own terms.
IT/OT boundary is where compromise actually happens
DP World Australia (Citrix), Port of Nagoya (LockBit), Maersk (NotPetya) — all IT-compromise-cascading-to-OT stories. The boundary between corporate IT and port / shipboard OT is where the real attack path lives.
Legacy systems and long refresh cycles
Ships and port infrastructure have 20–30 year operating lives. Terminal operating systems, AIS feeds, ship-to-shore links, and VTS systems predate modern security assumptions — and aren't easily replaced.
Built for your situation
IT/OT boundary validation
Segmentation Testing and Internal Pentesting validate whether the corporate-to-OT boundary actually holds under attack — proving what attackers like LockBit (Port of Nagoya) or Citrix-Bleed actors (DP World Australia) would reach.
Rapid Response for edge devices
Citrix, NetScaler, SonicWall, Fortinet — the edge-device CVE pattern behind the most publicly visible port compromises. Rapid Response tests exposure before patches are broadly available.
SMS cyber element evidence for IMO
For Australian-flagged and calling ships, Internal Pentesting of shipboard and shoreside systems produces evidence for the approved risk management element of the Safety Management System under MSC.428(98).
Prove your CIRMP and MTOFSA cyber posture
Book a port and maritime baseline mapped to CIRMP Section 8, MTOFSA all-hazards, and IMO MSC.428(98)