Updated cyber risk management guidance from the International Maritime Organization is prompting several African maritime authorities to move toward formal, mandatory cyber risk assessments for port facilities, rather than the largely voluntary approach many have taken to date.

The guidance recommends that port facility security plans explicitly address cyber risk alongside traditional physical security measures, an approach that some regional authorities are now working to incorporate into their own facility approval processes.

Consultants who work with port operators on compliance say the biggest gap in the region is less about awareness and more about budget — smaller terminal operators in particular often lack dedicated cybersecurity staff.