
Commercial ports concentrate physical and digital flows, with their interdependence increasing each year. Automated cranes, maritime traffic management systems, access control automata for restricted areas: these industrial equipment operate on historically isolated operational networks (OT), now connected to traditional information systems. This IT/OT convergence exposes port infrastructures to threats that are no longer solely physical sabotage but also ransomware, targeted phishing, and exploitation of outdated industrial protocols.
Decree of July 8, 2026: what the new port security framework changes in France
A recent regulatory text redefines the obligations of French port operators. The decree of July 8, 2026, requires operators of controlled access port areas and port facilities to submit an updated security plan within four months to the prefect. This plan must incorporate new provisions, particularly the strengthening of controls and security exercises.
Related reading : How to Boost the Effectiveness of Your B2B Networking and Achieve More Conversions
The most notable change concerns the obligation to integrate cyber threats into training scenarios. Until now, port security exercises primarily focused on physical intrusions, suspicious packages, or traditional malicious acts. From now on, a cyberattack scenario targeting industrial systems (programmable automata, SCADA, positioning systems for cranes) must be included among the planned exercises.
The decree also specifies the role of the designated port security reference agent by the prefect, who becomes the coordination point between authorities and operators for compliance. Strengthening the security of port industrial systems thus requires an operational translation of these requirements, with tight deadlines and verifiable plans.
See also : Understanding the Causes of a Throttle Lag in Fuel-Injected Motorcycles and How to Fix It

Mandatory reporting of cyber incidents: the Canadian precedent
France is not alone in tightening its framework. The operational maritime security bulletin BOSM 2026-003 from Transport Canada now requires regulated stakeholders (ports, marine facilities, ferries) to report all cybersecurity threats and incidents related to port/ship interfaces. This reporting must be addressed simultaneously to law enforcement, Transport Canada, and the national cybersecurity center.
This approach contrasts with the usual practice in the maritime sector, where cyber incidents remained largely underreported. Field feedback varies on this point: some port stakeholders believe that systematic reporting will better map threats, while others fear an administrative overload without immediate operational gain.
The Canadian model raises an open question for European ports. The NIS 2 directive, which applies to service operators in the maritime transport sector, includes notification obligations, but practical modalities vary from one member state to another. Available data does not yet allow for measuring the actual effect of mandatory reporting on reducing attacks, but the principle of transparency is progressing.
IT/OT convergence in ports: where the concrete flaws lie
The digitization of ports creates specific vulnerability points that traditional cybersecurity approaches do not always cover. Port OT systems have characteristics that complicate their protection.
- Programmable automata and SCADA systems that control cranes, gantries, and locks often use outdated industrial protocols designed without authentication or encryption mechanisms. Their replacement involves costly operational downtimes.
- The interfaces between the port information system (Port Community System) and field equipment multiply attack surfaces. A compromised access on the IT side can spread to handling automata.
- External service providers (maintenance personnel, software publishers, terminal operators) often have remote access to OT networks, sometimes with shared credentials and without connection logging.
This scenario of remote takeover is not theoretical: several ports have experienced operational disruptions related to ransomware in recent years.
Cybersecurity exercises: structuring training beyond compliance
Having a security plan is not enough if teams do not know how to respond to an attack in real time. The cyber threat integrated into security exercises represents the most concrete advancement of the July 2026 decree, but its implementation poses practical difficulties.
An effective port cyber exercise must simulate the simultaneous unavailability of several systems: traffic management, access control, VHF communication. Teams must switch to degraded procedures, often manual, whose mastery diminishes as automation progresses. Coordination among stakeholders (port authority, terminal operators, harbor master, state services) complicates the organization of these exercises.
Some structuring principles emerge from international feedback:
- Test the detection of an intrusion on the OT network under realistic conditions, not just on the office network
- Involve industrial maintenance providers in the scenario, as they have privileged access to the automata
- Measure the time to switch to degraded procedures and identify operational bottlenecks
- Document each exercise to inform the update of the port security plan

The French regulatory framework and international initiatives converge towards a common requirement: the cybersecurity of port industrial systems can no longer remain a technical subject treated in silos. The deadlines imposed by the July 2026 decree compel operators to move from awareness to operational implementation, with updated plans and identified reporting chains.
Ports that have not yet mapped their IT/OT interdependencies have little margin before the first compliance deadlines.