Cyber-attacks against Remote Operations Centres: Risks and Legal Implications
In recent years, the growing use of autonomous ships is transforming the way maritime operations are conducted. At the centre of this transformation are Remote Operations Centres (ROCs), which function as hubs for monitoring, decision-making, and control. Through advanced human–machine interfaces, real-time sensor data, satellite communications, and automated systems, ROCs oversee vessel navigation, safety, and operational compliance. While these technologies promise increased efficiency and reduced risks to seafarers, the high level of digital connectivity and centralised control also creates serious cybersecurity vulnerabilities. As critical elements of the autonomous shipping system, ROCs may therefore become attractive targets for cyber-attacks with potentially wide-ranging maritime, economic, and environmental consequences. Cyber attackers may exploit ROCs using various techniques, including GPS spoofing, communication jamming, malware infections, data breaches, and system hijacking. Such attacks can interfere with navigation, disrupt command systems, or allow unauthorised access to ship controls. In more serious cases, attackers may be able to seize effective control of an autonomous ship and hold it ‘hostage’, threatening to cause collisions, or even the sinking of the ship unless their demands are met. These scenarios raise important questions not only about maritime safety and security, but also about the ability of existing international legal frameworks to respond to cyber threats affecting maritime operations. This paper considers whether cyber-attacks targeting ROCs and autonomous ships can be addressed and punished under international law, with particular attention to the Convention for the Suppression of Unlawful Acts against the Safety of Maritime Navigation (SUA Convention). It examines whether the Convention’s offence-based framework is capable of covering cyber-enabled attacks that are carried out remotely and may originate far from the maritime domain. The analysis explores whether conduct such as remote interference with navigation systems, digital hijacking of vessel controls, or threats to destroy or endanger a ship can fall within existing SUA offences, even where no physical force is used and no attacker is present on board. The paper also highlights key legal challenges, including difficulties in attribution, jurisdiction, and the required connection between the offence and the ship under the SUA Convention. It argues that although the SUA Convention offers a more suitable legal basis than traditional piracy rules for addressing cyber threats to autonomous shipping, further interpretative development and regulatory clarification are needed. The paper concludes by emphasising the importance of international cooperation and legal adaptation to ensure effective accountability for cyber-attacks against ROCs in an increasingly digital maritime environment.