Skip to content Skip to footer

Who we are

Our website address is: https://shipip.com.

What personal data we collect and why we collect it

Comments

When visitors leave comments on the site we collect the data shown in the comments form, and also the visitor’s IP address and browser user agent string to help spam detection.

An anonymized string created from your email address (also called a hash) may be provided to the Gravatar service to see if you are using it. The Gravatar service privacy policy is available here: https://automattic.com/privacy/. After approval of your comment, your profile picture is visible to the public in the context of your comment.

Media

If you upload images to the website, you should avoid uploading images with embedded location data (EXIF GPS) included. Visitors to the website can download and extract any location data from images on the website.

Contact forms

Cookies

If you leave a comment on our site you may opt-in to saving your name, email address and website in cookies. These are for your convenience so that you do not have to fill in your details again when you leave another comment. These cookies will last for one year.

If you visit our login page, we will set a temporary cookie to determine if your browser accepts cookies. This cookie contains no personal data and is discarded when you close your browser.

When you log in, we will also set up several cookies to save your login information and your screen display choices. Login cookies last for two days, and screen options cookies last for a year. If you select "Remember Me", your login will persist for two weeks. If you log out of your account, the login cookies will be removed.

If you edit or publish an article, an additional cookie will be saved in your browser. This cookie includes no personal data and simply indicates the post ID of the article you just edited. It expires after 1 day.

Embedded content from other websites

Articles on this site may include embedded content (e.g. videos, images, articles, etc.). Embedded content from other websites behaves in the exact same way as if the visitor has visited the other website.

These websites may collect data about you, use cookies, embed additional third-party tracking, and monitor your interaction with that embedded content, including tracking your interaction with the embedded content if you have an account and are logged in to that website.

Analytics

Who we share your data with

How long we retain your data

If you leave a comment, the comment and its metadata are retained indefinitely. This is so we can recognize and approve any follow-up comments automatically instead of holding them in a moderation queue.

For users that register on our website (if any), we also store the personal information they provide in their user profile. All users can see, edit, or delete their personal information at any time (except they cannot change their username). Website administrators can also see and edit that information.

What rights you have over your data

If you have an account on this site, or have left comments, you can request to receive an exported file of the personal data we hold about you, including any data you have provided to us. You can also request that we erase any personal data we hold about you. This does not include any data we are obliged to keep for administrative, legal, or security purposes.

Where we send your data

Visitor comments may be checked through an automated spam detection service.

Your contact information

Additional information

How we protect your data

What data breach procedures we have in place

What third parties we receive data from

What automated decision making and/or profiling we do with user data

Industry regulatory disclosure requirements

Cyber Security: Government ramps up the pressure on the maritime sector

The EU Network and Information Security Directive (NIS) requires maritime transport and other essential services to demonstrate that they have implemented ‘appropriate and proportionate’ cyber security measures. The NIS will come into force on 6 May 2018 and the Government has just published a consultation paper on the implementation of the NIS in the UK. The largest port or harbour authorities and maritime transport companies headquartered in the UK will be directly impacted by these new provisions and there will inevitably be a trickle-down effect on small companies that contract with those organisations. The penalties for breach of the new laws will be substantial – 4% of global turnover or £17 million, whichever is the greater. These measures will be in addition to the other new cyber laws, such as the General Data Protection Regulation (GDPR), which are about to come into effect.

Over the last 18 months, the maritime sector has worked hard to focus its response to the growing cyber risk that it undoubtedly faces. In June 2017, we saw updated cyber security guidelines from the International Maritime Organisation (IMO) Safety Committee. These guidelines are tied into the ISM Code. Although the guidelines are currently“recommendatory”, they require cyber risk to be appropriately addressed in safety management systems no later than the first annual verification of a company’s “document of compliance” after 1 January 2021.

Network and Information Security Directive (NIS)

The latest development for UK-based maritime organisations comes with the publication of a Government consultation paper on the implementation of the Network and Information Security Directive (NIS) (EU 2016/1148). This EU Directive, which was approved in 2016, requires “essential services” to develop certain standards of cyber security. The NIS leaves it to individual EU member states to decide how to implement its requirements in their own domestic law. The recent consultation paper sets out the UK’s proposals in that regard.

Maritime transport is listed as one of the “essential services” to which the NIS will apply. Not all operators in this sector, however, will be affected directly by the current proposals that are intended to apply only to the largest operations with headquarters in the UK.

In the UK context, that will mean harbour authorities and ports with annual passenger numbers greater than 10 million or with 15% of the UK’s Ro-Ro or Lo Lo traffic or that account for 10% of UK liquid bulk or 20% of UK bio-mass fuel. Under the Government proposals, the NIS will also impact “water transport companies” that handle more than 30% of freight at any UK port in scope and five million tonnes of annual freight in UK ports as a whole. They will also apply to companies with 30% of annual passenger numbers at any individual UK port in scope and more than two million passengers at all UK ports. As at September 2017, the term “water transport companies” has not been defined.

Despite these limitations on the direct application of the NIS, it seems inevitable that its adoption by large organisations will have a knock on effect on smaller companies that work with or supply those organisations. This is because contracts for the supply of goods and services to the large organisations are likely to be amended to make small organisations responsible for any malware or other breach of cyber security that may be passed up the supply chain.

In addition, the Government is proposing to retain a reserve power to include within the scope of the NIS specific operators that do not meet the thresholds set out above, but which are still considered to provide an essential service.

Failure to comply with the NIS will, it is proposed, expose companies to very significant financial penalties of up to £17 million or 4% of global turnover, whichever is the greater.

Companies will be exposed to those fines if they “fail to implement appropriate and proportionate security measures”.  These requirements are in addition to other provisions relating, for example, to GDPR.

The consultation paper does not set out in any detail the measures that the Government will expect to see implemented. Rather, the Government proposes to:

“… set out the high level security principles which will be complimented by more detailed guidance, that will be either generic or sector specific. … These principles describe the mandatory security outcomes that all operators will be required to achieve”. 

The Government’s view is that operators of essential services are responsible for managing their risks and will need to implement security measures in line with the high level principles established for the purposes of NIS, having regard to the more detailed sector-specific and generic guidance to be published by the relevant NIS competent authorities. It is clear, however, that the new rules will cover governance, risk management, asset management and supply chain issues. In addition, there will be a mandatory incident reporting regime (that will be additional to existing reporting requirements and recommendations).

The consultation closes on 30 September 2017 and the Government will issue its further directives thereafter, with the intention that the scheme should go live from May 2018.

Although NIS is an EU Directive, its implementation by the UK Government will not be affected materially by the UK’s departure from the European Union.

 

Source: incegd