
Cyberattacks pose increasing risks to maritime and logistics operations at Dutch seaports. To address cyber threats, the Seaports Trade Organisation (Brancheorganisatie Zeehavens, BOZ), the Ministry of Infrastructure and Water Management and the National Coordinator for Counterterrorism and Security (NCTV) jointly “developed and defined a strategy titled Cyber Strategy for Dutch Seaports.”
The Seaports Trade Organisation unites the five nationally significant seaports: Groningen Seaports, North Sea Port, Port of Rotterdam, Port of Moerdijk and Port of Amsterdam. Based on this strategic plan, the FERM Foundation—already operational at the ports of Rotterdam and Moerdijk—has been “transformed into a national cybersecurity platform for Dutch seaports as united within BOZ. The cooperative agreement was signed by all parties on December 10th, 2024,” according to a Port of Rotterdam announcement.
Van den Berg said of his role as Rotterdam CISO: “I’m responsible for cybersecurity at the Port of Rotterdam. In the last ten years … we have seen … a strongly increased threat landscape because of increasing geopolitical threats, an ongoing war in Ukraine and the rise of AI. I think in generic terms, we are in a new reality with different types of threats.”
The growing threat of cyberattacks has resulted in the implementation of what van den Berg calls a “Zero Trust” architecture, under which threat actors are presumed to be both outside and inside the company or organization:
“Zero Trust is an architectural way of how to build and how to design your systems. In the past, we, from a cybersecurity perspective, … had the idea that … everything … from the outside of the company, that's something that we do not trust. And someone that's inside the company or inside our network, we said, ‘well, we can trust him because he's inside our network.’ Today that assumption no longer holds. And if we look at our newer way of working in the base, we are … from a technical perspective, making a system where both inside and outside … you should prove who you say you are … The principle is simple: trust is never assumed; it must be earned through verification. This approach helps us to remain resilient in an increasingly complex and challenging threat landscape.”
Information Sharing and Analysis Centers
Van den Berg said that, in most cases, Information Sharing and Analysis Centers (ISACs) are part of a global network of colleagues:
“So from a global perspective, we are joining several ISACs. For instance, I'm in contact … with the Port of Los Angeles … We also have them on a European level … In that case, we are sharing information within our … bigger European ports, and specifically on the domain of resiliency. We do not see them as a competitor. So, we actually think we can strengthen ourselves by sharing information, sharing our … incidents that we … see. So, we can learn … that from each other.”
Initially, van den Berg said, each port in the Netherlands was combating cybersecurity threats on its own, including the Port of Rotterdam. However, it became clear that the Dutch ports could benefit from closer collaboration:
“In the past … it was a Rotterdam initiative. So, it was primarily focused on strengthening the cyber resilience of Rotterdam companies. And two years ago, this changed, and while I continue to work for the Port of Rotterdam … I am also working with Dutch ports who compose … FERM.”
Van den Berg said: “FERM Zeehavens is responsible for increasing the cyber resilience of the … companies in all the different … seaports. We have several activities there. So, for instance, we’re doing cyber exercises over the complete supply chain (and) cyber exercises over different companies that are part of a vital supply chain.”
Boudewijn Siemons, Chair of BOZ and CEO of Port of Rotterdam Authority, has noted: “Cybersecurity is critical to the continuity and security of our ports. At a time when digital threats are becoming more sophisticated, we must take proactive and concerted action to protect our infrastructure and operations. Only by working together can we strengthen the resilience of our ports and prepare for the challenges of the future. It’s great that the seaports have come together on this issue, and we all realize just how hugely important it is. Together we will build on what FERM has already achieved in recent years.”
Van den Berg emphasized to AJOT: “I am not responsible for the activities of FERM. That is Marijn van Schoote as Managing Director.”
Evelien Bras, the former Director of FERM, handed over “the baton to Marijn van Schoote,” who had served as CISO at the Port of Rotterdam Authority. Marijn van Schoote is now Managing Director of FERM Foundation.
FERM Objectives
The FERM collaboration embraces the following objectives:
Strategic/tactical threat landscape
Insight into current and future threats at both strategic and tactical levels. At the strategic level, this concerns trends such as geopolitical tensions, technological innovations and structural vulnerabilities that could affect the sector. At the tactical level, it focuses on concrete threats and risks relevant in the short term, such as specific vulnerabilities or trends in cyberattacks.
Risk analysis sessions
During risk analysis sessions, a network map of the port chain is used to identify and visualize threats. By plotting these threats onto the chain, a concrete picture of vulnerabilities and dependencies emerges. This makes it possible to formulate targeted measures and strengthen the digital resilience of the entire chain.
Ferm-Art cyber test
A large-scale chain test in which the digital resilience of the entire port chain is tested through red teaming. Realistic attack scenarios are simulated to expose vulnerabilities, improve cooperation and provide insight into the collective response to cyber threats.
Annual chain exercise
Together with the relevant parties, Ferm organizes a large-scale chain exercise annually. During this exercise, a realistic cyber incident involving the entire port chain is simulated. The goal is to test and strengthen cooperation, communication and recovery capacity so that all parties are better prepared for potential disruptions.
External attack surface management
With this service, the external digital environment of organizations is continuously monitored. The goal is to identify and mitigate external vulnerabilities and potential attack points at an early stage. This provides organizations with insight into their digital “attack surface” and allows them to take proactive measures to strengthen their security.
Structural port consultation
Structured consultations are held to share knowledge, discuss incidents and coordinate joint actions. These are organized for each crucial chain so that specific threats can be shared.
Future role in incident coordination across parties
In due course, Ferm will fulfill an active role in coordinating incidents among parties within the shipping-handling sector. This means that, in the event of a cyber incident, Ferm will not only provide information and advice but also facilitate cooperation among the organizations involved. By acting as a central link, Ferm can ensure a coordinated approach in which communication, decision-making and recovery actions are better aligned.
Exchange of operational threat information via email/Signal
Fast and secure communication channels are used to share relevant threat information, enabling organizations to respond promptly. This concerns practical and directly applicable information that is crucial for daily operations.
Exchange of operational security advice via email/Signal
In addition to threat information, organizations also receive concrete security advice. This advice is aimed at directly strengthening defenses against current threats—for example, by adjusting configurations, patching systems or tightening access policies.
Attendance at physical FermConnect meetings
During FermConnect meetings, organizations from the port chain meet in person to share knowledge, discuss current themes and strengthen new partnerships. These meetings provide space for in-depth exploration, the exchange of experiences and the establishment of direct contacts, further increasing collective digital resilience.
Bottom Line
The bottom line for van den Berg is continual vigilance:
“If we look at the last year, we haven't had any big incidents that had an impact on our mission-critical activities … But if you look at an attack … in most cases security, everything is automated in such a way that our infrastructure is being scanned continuously by our adversary. So, yeah, if … it's just how it works. It's a new reality. We continuously need to be on the tip of our toes and adapt to this new reality. It's the way we have to work and operate.”