Jadwal Sholat

Memuat jadwal sholat…

Ilmu Komputer & AI editorial

Open AccessOA2026

Batten the Hatches: Cybersecurity with Military Mariners

A qualitative study of how U.S. Navy and Coast Guard personnel understand, recognize, and respond to cyber risk at sea
Ryan Von Brock; Anna Raymaker; Animesh Chhotaray; Frank Li; Saman Zonouz; Raheem Beyah· 2026· DOI 10.48550/arXiv.2609.12810

The core problem

Cyberwarfare has become a key component of contemporary geopolitical conflict. However, there has been extremely limited systematic investigation into how cybersecurity is handled by military organizations and personnel. The military context is unique compared to other operational ones, with immense resource availability (U.S. military spending approached 1 trillion dollars in 2024), a rigid chain of command, and extraordinary consequences for its actions. Thus, military cybersecurity is a distinct yet understudied topic. In this paper, we take an early step at understanding military cybersecurity by investigating how service members understand, recognize, and respond to cyber risk. We focus on maritime services and carefully consider organizational barriers to design an unclassified study and conduct semi-structured interviews with 20 military mariners from U.S. Navy and Coast Guard vessels. Through our investigation, we identify unique consequences of compromising military systems, including weapon takeover and purposeful geopolitical escalation. We find that cybersecurity is organizationally abstract on ships, so mariners build cyber risk models from informal experience rather t

Innovation

The interviews revealed that cybersecurity is organizationally abstract on ships. Mariners reported that formal cybersecurity training is limited or not directly applicable to their operational environment. Instead, they build cyber risk models from informal experience, such as peer discussions, on-the-job observations, and personal interest. Despite this lack of formal instruction, mariners make cybersecurity actionable by recognizing operational impacts. For example, they identified potential consequences like weapon takeover and purposeful geopolitical escalation as unique to the military context. In response to perceived cyber threats, mariners described a safety-oriented incident-response model. This model prioritizes the safety of the vessel and crew, often leading to immediate actions that create resilience but may delay cyber attribution and containment. The findings highlight a gap between organizational cybersecurity policies and the practical realities faced by mariners, who rely on informal knowledge and safety protocols to mitigate cyber risks.
Cyberwarfare has become a key component of contemporary geopolitical conflict. However, there has been extremely limited systematic investigation into how cybersecurity is handled by military organizations and personnel. The military context is unique compared to other operational ones, with immense resource availability (U.S. military spending approached 1 trillion dollars in 2024), a rigid chain of command, and extraordinary consequences for its actions. Thus, military cybersecurity is a distinct yet understudied topic. In this paper, we take an early step at understanding military cybersecurity by investigating how service members understand, recognize, and respond to cyber risk. We focus on maritime services and carefully consider organizational barriers to design an unclassified study and conduct semi-structured interviews with 20 military mariners from U.S. Navy and Coast Guard vessels. Through our investigation, we identify unique consequences of compromising military systems, including weapon takeover and purposeful geopolitical escalation. We find that cybersecurity is organizationally abstract on ships, so mariners build cyber risk models from informal experience rather than formal instruction. They nonetheless make cybersecurity actionable by recognizing operational impacts and responding with a safety-oriented incident-response model that creates resilience but may delay cyber attribution and containment. These findings inform actionable recommendations to help military operators frame cyber threats, merge longstanding nautical doctrine with modern systems, and apply military insights to the civilian sector, all to secure the broader maritime environment.
The study employed a qualitative approach using semi-structured interviews with 20 military mariners from U.S. Navy and Coast Guard vessels. Participants were selected to represent a range of roles and experience levels within maritime operations. The interviews were designed to be unclassified and to carefully consider organizational barriers, such as security clearances and operational sensitivities. The semi-structured format allowed for open-ended responses while ensuring coverage of key topics: understanding of cyber risk, recognition of cyber threats, and response procedures. Data were analyzed thematically to identify patterns in how mariners conceptualize and act on cybersecurity. The methodology prioritized capturing the unique context of military maritime operations, including the rigid chain of command and the high-stakes consequences of cyber incidents. This approach enabled the researchers to uncover informal practices and organizational dynamics that shape cybersecurity behavior at sea.

Why it matters

The results indicate that military maritime cybersecurity is shaped by a distinct operational context. The abstract nature of cybersecurity organizationally leads mariners to develop informal risk models, which, while adaptive, may lack the rigor of formal training. The safety-oriented incident-response model, while effective for immediate threat mitigation, can hinder timely attribution and containment—critical for strategic cyber defense. This tension between safety and security suggests a need for integrating cybersecurity into existing nautical doctrine without compromising operational safety. The study's findings inform actionable recommendations: help military operators frame cyber threats in operational terms, merge longstanding nautical doctrine with modern systems, and apply military insights to the civilian sector. By bridging the gap between formal policy and informal practice, military organizations can enhance cyber resilience while maintaining safety. The unique consequences of military cyber compromise, such as weapon takeover and geopolitical escalation, underscore the importance of tailored cybersecurity strategies for the maritime domain.

Who should read this

CS practitioners and researchers

Opening member content…