Panama and The Bahamas strengthened maritime cybersecurity preparedness in September 2026 through specialised programmes led by the Latin America and Caribbean Cyber Competence Centre (LAC4). The exercises tested responses to ransomware, disruption of port and customs systems, manipulation of maritime positioning data and disinformation, extending a regional capacity-building effort that has already reached Ecuador, Colombia and Peru.
Panama tests maritime systems under cyber pressure
From September 14 to 17, 2026, the Latin America and Caribbean Cyber Competence Centre worked with the Panama Maritime Authority on a four-day programme focused on the resilience of the country’s maritime and logistics infrastructure.
The Panama programme brought together the Panama Maritime Authority, National Customs Authority, National Aeronaval Service, Aquatic Resources Authority and National Authority for Government Innovation, alongside more than a dozen organisations from the maritime, port and logistics sectors.
Participants examined digital transformation, port technologies, critical maritime infrastructure, supply-chain security, insider threats, risk management and security standards. The programme also addressed the growing interaction between information technology systems and operational technologies used in maritime environments.
A multi-agency simulation placed Panama’s institutions in a scenario combining ransomware, operational disruption, customs-system failure, manipulation of maritime positioning data and disinformation.
The September 2026 exercise was designed to test more than technical recovery. Panama’s participating institutions also worked on decision-making, communication and inter-agency coordination during a maritime cyber incident.
For Panama, these risks carry implications beyond an individual terminal. LAC4 linked the resilience of national maritime infrastructure to the continuity of international trade routes and supply chains connected through the country.
The Bahamas brings cyber resilience into an island context
Less than a week later, from September 21 to 23, 2026, LAC4 worked with the Computer Incident Response Team of The Bahamas, or CIRT-BS, on a specialised maritime cybersecurity programme in Nassau.
The Bahamas programme focused on maritime cyber threats, IT and operational technology security, supply-chain resilience, governance, incident response, threat intelligence and inter-agency crisis coordination.
Participants in The Bahamas were also confronted with scenarios involving ransomware, interruption of port and customs systems, manipulation of maritime positioning data and disinformation.
The island context adds another dimension to maritime cyber resilience. Sametria McKinney, Director of CIRT-BS, highlighted the sector’s role in moving “essential goods, energy and supplies” that support communities and the Bahamian economy.
The September 2026 maritime programme also sits within a wider cybersecurity effort in The Bahamas. Since January 2026, LAC4 and EU CyberNet have supported a national cybersecurity risk assessment covering critical sectors including transport, telecommunications, energy, finance and maritime infrastructure.
From the Andes to the Caribbean
LAC4’s port cybersecurity work in Latin America and the Caribbean predates the September 2026 programmes.
In January 2025, LAC4 brought together port representatives and public authorities from Ecuador, Colombia and Peru in Guayaquil for training on maritime cyber threats, risk management, security standards and national coordination during cyber incidents.
LAC4 Director Liina Areng identified “increased interconnectivity, legacy systems, and evolving cybercrime tactics” among the factors increasing the cyber exposure of ports.
The sequence from Guayaquil to Panama and The Bahamas shows a growing focus on operational preparedness across different maritime environments. The common challenge is no longer limited to protecting an IT network: authorities are preparing for incidents capable of affecting cargo clearance, port operations, maritime data, public agencies and logistics chains simultaneously.
Cybersecurity enters the maritime digitalisation agenda
The regional initiatives are unfolding as the International Maritime Organization strengthens the cybersecurity dimension of global maritime digitalisation.
In March 2026, the IMO Facilitation Committee approved a Strategy on Maritime Digitalization focused on interoperability, standardisation, data exchange and stronger resilience to disruption and cyber threats.
The IMO Facilitation Committee also approved amendments that would require governments to introduce cybersecurity measures protecting Maritime Single Windows, the digital platforms used to exchange information between ships and public authorities.
Maritime Single Windows have been mandatory since January 1, 2024. The cybersecurity amendments are expected to be considered for adoption in 2027, with entry into force currently expected on January 1, 2029.
For ports in Latin America and the Caribbean, the direction is becoming increasingly clear: as maritime operations become more connected and digital, cyber resilience is becoming part of operational resilience itself.
Source : LAC4
What maritime cyber risks were tested in Panama and The Bahamas?
The September 2026 LAC4 exercises included scenarios involving ransomware, disruption of port and customs systems, manipulation of maritime positioning data and disinformation.
Which countries have taken part in LAC4 port cybersecurity programmes?
LAC4 has documented maritime cybersecurity capacity-building involving Ecuador, Colombia and Peru in 2025, followed by specialised programmes in Panama and The Bahamas in September 2026.
Why is port cybersecurity important for supply chains?
Cyber incidents affecting ports can disrupt customs processes, cargo movements, operational systems and communication between public authorities, potentially affecting the wider logistics chain.
What is the IMO doing on maritime cybersecurity?
The International Maritime Organization is integrating cybersecurity into its wider digitalisation agenda, including proposed cybersecurity requirements for Maritime Single Windows and work toward a broader maritime cyber framework.
When could the new Maritime Single Window cybersecurity requirements take effect?
The amendments approved at IMO committee level in March 2026 are expected to be considered for adoption in 2027, with entry into force currently anticipated for January 1, 2029.



