Insights

What the April 2025 dam hack should teach the maritime industry

From the founder, Tromsø·15 June 2026·5 min read

In April 2025 a pro-Russian group opened a valve at a small Norwegian dam and left it open for about four hours. There was no clever exploit. The control panel was reachable from the open internet and it was protected by a weak password. That was the whole story. Someone found it, tried the obvious thing, and it worked.

Most coverage treated this as a dam story. It is not. It is a warning label for anyone running connected equipment on the coast, a shipping company, a ferry, a port, a terminal, or a fish farm.

Your business has more of these panels than that dam did

Count the things that talk to a network in your operation. On a ferry: bridge systems, navigation, cargo handling. In a port: the terminal operating system, cranes, gates, access control. On a fish farm: feeding, oxygen, water flow, dosing, cameras. Almost always a remote gateway so someone can check operations on a Sunday. A lot of it is older equipment that was never meant to face the internet, then got connected anyway because it was convenient.

The dam had one exposed system. A single business can have a dozen. Each one is a door, and the attacker in April did not pick a lock. He walked through a door that was left open.

Nobody targets you for being you

This is the part that trips people up. The instinct is to say we are too small to matter, we are not a bank, why would anyone bother. But the dam was not important either. It was found by a scanner that sweeps the internet looking for control panels with default logins, the same way a thief walks a street and pulls door handles. You do not get chosen. You get found.

The question is not whether someone wants to attack your business. It is whether it is easy, and whether you would even know.

What actually goes wrong is boring, and expensive

Forget the movie version. The realistic bad day is a cargo line that stops, a setpoint that drifts, a gate or valve that moves when it should not. Then delayed operations, maybe a shutdown, a very bad week, and phone calls you do not want to make: to your insurer, to a customer, and possibly to the authorities. The damage is operational and financial long before it is dramatic.

The timing is not a coincidence

PST called 2026 the most serious security situation since the war, and named the High North specifically. Norway's Digital Security Act has been in force since October 2025, with real fines attached. NIS2 is coming behind it, with broader scope and stricter requirements for maritime transport, ports, and the food industry. None of that is fear. It is a calendar. Those who look at their exposure now have time to fix things calmly. The ones who wait will do it in a hurry, under pressure, and for more money.

What to check this week

You do not need a big platform to start. You need to close the obvious doors. In rough order:

  • Find out what in your operation is reachable from outside the local network. If you are not sure, assume something is.
  • Kill default and shared passwords on anything with a login. This one fix would have stopped the dam attack.
  • Keep the control network separate from the office and guest wifi. Flat networks turn one weak device into a whole-business problem.
  • Write down what you actually have. You cannot protect a device you have never listed.
  • Know who you call at two in the morning, before you need to.

That list will not make you bulletproof. Nothing does. But it moves you from wide open to a hard-enough target, which is most of the battle against opportunists.

Where we fit

Havvakt does exactly this, one company at a time. We map what is connected, score the exposure the way a regulator would read it, and hand you a plain list of what to fix first, plus evidence you can show a board, an insurer, or a customer. We are early, and we are honest about it.

Where do you stand?

30 minutes, no obligation, in Norwegian or English. You get an honest assessment of where you stand with the Digital Security Act and NIS2.

Book a call

Prefer to read the pitch first? See how it works.

Written by Havvakt's founder. Full name and bio once Havvakt is full-time. For now, the work speaks first.