August 7, 2026

Maritime Security: Mission Domain Intelligence Guide

0

The vessel reported itself in the Gulf of Oman. Radar put it alongside a sanctioned tanker four hundred miles away. One of those two things was a broadcast, and broadcasts can be written.

maritime-security-mission-domain-guide

The vessel reported itself in the Gulf of Oman. Radar put it alongside a sanctioned tanker four hundred miles away. One of those two things was a broadcast, and broadcasts can be written.

What Maritime Security covers as a mission domain

Maritime security intelligence covers awareness and protection across the maritime domain: vessel movement and identity, cargo and sanctions compliance, subsea infrastructure, ports and terminals, illegal fishing, and naval and paramilitary activity in contested waters. Practitioners work primarily from vessel-reported position data, satellite radar and optical imagery, port call and registry records, and casualty and incident reporting. The core analytic problem is identity: ships change name, flag, ownership and transmitted identity with ease, so establishing that a hull today is the same hull last month is often the whole investigation.

Sub-areas include dark fleet and sanctions evasion tracking, subsea cable and pipeline protection, port and terminal security, IUU fishing enforcement support, and grey-zone naval activity monitoring. Actor types run from state navies and coastguards through militia and proxy forces to commercial operators layering ownership through management companies, and specialist facilitators who supply false documentation, insurance and flag registration for vessels that would otherwise be uninsurable.

Why it matters

Around eighty percent of world merchandise trade by volume moves by sea, and almost all intercontinental data moves through a small number of submarine cables that sit on the seabed largely unprotected. Chokepoints concentrate the risk further. Sanctions regimes now depend on maritime enforcement, insurers price war risk on maritime intelligence, and coastal states lose substantial revenue and food security to unreported fishing. Poor maritime awareness is directly measurable in seized cargo, cut cables and unpoliced exclusive economic zones.

What analysts actually look for

These are the concrete, observable signals that carry weight in this area of work:

  • AIS transmission gaps that begin and end near the same coordinates repeatedly, particularly around known transhipment or sanctioned load ports.
  • Position reports that are physically impossible: speeds above hull capability, teleporting jumps, or tracks describing perfect circles.
  • Two vessels holding matched course and speed at close range for hours, the standard signature of a ship-to-ship transfer.
  • Draught reports that do not match the declared cargo state, indicating either false reporting or an undeclared loading event.
  • Rapid sequences of flag, name and owner changes across a group of ageing tankers managed from the same address.
  • Anchor drag tracks or repeated loitering above charted submarine cable and pipeline corridors outside any commercial reason to be there.
  • SAR detections of vessels producing no corresponding AIS return inside a protected area or exclusive economic zone.
  • Insurance withdrawal, class society disputes, or port state control detentions clustering around one management company's fleet.

Where the data comes from

Authoritative and openly available collection points. Always confirm licensing and terms before operational or commercial use:

  • IMO GISIS — Ship particulars, IMO numbers, company and registered owner records, port state control and casualty modules.
  • Global Fishing Watch — Free AIS-derived fishing effort, transhipment events, port visits and vessel identity history.
  • Copernicus Sentinel-1 SAR — All-weather radar imagery for detecting vessels that are not transmitting a position at all.
  • Equasis — Free consolidated ship safety and inspection data drawn from port state control regimes and class societies.
  • NGA Maritime Safety Information and NAVTEX — Navigational warnings, broadcast warnings and worldwide notices to mariners with incident context.
  • AIS platforms such as MarineTraffic and VesselFinder — Terrestrial and satellite position history, port calls and vessel photographs for identity work.
  • TeleGeography Submarine Cable Map — Cable routes, landing points, owners and ready-for-service dates for subsea infrastructure exposure analysis.
  • OFAC, OFSI and EU sanctions lists — Designated vessels by IMO number, plus guidance on deceptive shipping practices and price cap compliance.

A working method

A repeatable sequence beats ad-hoc searching. This is a practical starting workflow:

  1. Anchor on the IMO number — Resolve the vessel to its permanent IMO identifier first, then reconstruct the history of names, flags, owners and managers around it.
  2. Reconstruct the track — Assemble the full position history, mark every gap with start and end coordinates, and note transmission quality and source type.
  3. Test the physics — Validate implied speeds, turn rates and draught changes against the vessel's actual specifications to expose spoofed or injected positions.
  4. Confirm with imagery — Task or search SAR and optical imagery over the gap window to establish where the hull actually was and what it was alongside.
  5. Resolve the corporate chain — Work registered owner, beneficial owner, manager, charterer and insurer, watching for shared addresses, directors and abrupt post-designation transfers.
  6. Assess infrastructure exposure — Overlay tracks against cable corridors, pipelines, anchorages and protected areas to identify contact between vessel behaviour and vulnerable assets.
  7. Report with evidentiary rigour — Deliver findings with timestamps, source attribution and confidence per claim, in a form usable by flag states, insurers or enforcement.

How this connects across the intelligence taxonomy

Intelligence work does not respect neat boundaries. The mission domain you are working, the disciplines you practise, and the data points you pivot on are one connected system. These are the direct relationships for this entry — every link is also a tag, so you can follow any thread across the whole library.

Practised with these disciplines

Worked in these data points

  • Vessel / Ship — A maritime vessel identified by IMO, MMSI, or call sign.
  • Shipping Container — An ISO container identifier — trackable across ports, vessels, and customs events.
  • Shipment / Bill of Lading — A consignment record linking shipper, consignee, goods, and route.
  • Location / Coordinates — A geographic point, place, or region — the basis of GEOINT analysis.
  • Radio Callsign — A licensed radio identifier for a station, vessel, aircraft, or operator.
  • GPS Coordinates — Precise latitude/longitude coordinates identifying an exact point on Earth — the atomic unit of GEOINT analysi
  • HS Commodity Code — The Harmonized System code classifying a traded good — the key to trade-flow analysis.

Adjacent mission domains

Inside the platform: where Maritime Security lives

The Quantus platform is 204 pages behind a 147-item sidebar organised into six working groups: Command (24 items), Dashboards (15), Threat Theaters (14), Intelligence Domains (15), Investigate (34), and Administration (45). This entry is not a page in isolation — it is a thread running through several of them.

The modules that matter most here:

Each dashboard is local-first: it renders from the platform’s own database rather than depending on a live third-party call, so it still works when an upstream API is unreachable or rate-limited. Heavy aggregates are cached with a hard query time cap and degrade to the last good value instead of hanging the page.

Automation, playbooks and AI skills

Analysis that only happens when someone remembers to run it is not a capability. The platform ships a 30-step automation pipeline (cron.php) that collects, ingests, resolves, enriches, correlates and scores on a schedule — 25 seeders, 11 resolvers and 7 enrichment runners, all idempotent and cursor-based so a run can be interrupted and resumed without duplicating or losing work.

Relevant playbooks

Of the 14 incident playbooks in playbooks.php, these apply directly to Maritime Security:

AI skills that apply

The 16 one-click operations in ai-skills.php are deterministic jobs, not free-text generation. The ones that matter here:

  • Threat Hunt
  • Correlate Infrastructure
  • Run Alert Rules
  • Summarise (Copilot)
  • Generate Report

Alerting closes the loop: rules in alerts.php fire on new indicators matching a saved query, so a first sighting in this area raises a notification rather than waiting to be noticed at the next review.

Feeds, data sources and the API

The collection layer runs a feed registry of free, machine-readable sources — bulk blocklists and trackers (Maltrail, IPsum, FireHOL, the full abuse.ch corpora, phishing databases, Emerging Threats, Spamhaus, DigitalSide, ThreatView), authoritative government feeds (CISA KEV, OFAC, UN and EU sanctions lists), and reference datasets (RIR allocations, ip-to-ASN and geolocation tables, MITRE ATT&CK, EPSS). collect.php pulls them server-side on a schedule; feeds.php and source-catalog.php show what is registered, what it covers and when it last ran.

Anything the platform holds is reachable programmatically. The REST API in api.php exposes 11 endpoints — status, stats, search, lookup, recent, export, bulk_check, top_threats, by_category, categories, check — and export.php streams 18 formats in bounded chunks, so a million-row export neither exhausts memory nor times out:

STIX 2.1, MISP, OpenIOC 1.1, CEF (ArcSight), LEEF 2.0 (QRadar), Zeek/Bro intel, Snort/Suricata rules, Palo Alto EDL, BIND RPZ, hosts blackhole, iptables, CSV, JSON, NDJSON/JSONL, XML.

That covers the CTI standards (STIX 2.1, MISP, OpenIOC), SIEM ingestion (CEF, LEEF, Zeek), detection engines (Snort/Suricata), and direct enforcement (Palo Alto EDL, BIND RPZ, hosts, iptables) — so intelligence developed here can be actioned in the tools you already run, without a manual reformatting step. A TAXII 2.1 server and a MISP/RSS feed are also served for pull-based sharing.

Use cases

Three ways this entry earns its keep in day-to-day work:

  1. Triage under time pressure. An artifact or report lands and you need a defensible read in minutes, not days. Anchor on the IMO number is the first move; the platform pre-computes the enrichment so the analyst spends the time on judgement rather than lookups.
  2. Building the picture. A single indicator is rarely the story. Test the physics turns one artifact into a network — shared infrastructure, repeated selectors, the same operator behind different names — via the correlation graph and the cross-entity link engine.
  3. Producing something actionable. Analysis that ends in a document nobody can use is wasted. Report with evidentiary rigour feeds the case file, the detection rule, the block list or the referral — with sourcing attached so the recipient can verify it.

Case management (cases.php), watchlists, saved searches and scheduled reports mean the work persists between sessions and survives an analyst leaving the team.

How each sector uses Maritime Security

The same entry is worked very differently depending on who you are, what authority you hold, and what you are ultimately producing. A military analyst is supporting a commander’s decision; a journalist is meeting a publication standard; an NGO caseworker is protecting a person. The underlying artifacts are shared — the constraints, outputs and thresholds are not.

🎖 Military and defence

Naval and joint analysts use maritime domain awareness for recognised maritime picture maintenance, force protection in congested and contested waters, and monitoring of grey-zone activity by militia, coastguard and research vessels operating below the threshold of armed conflict. Identity-resolved vessel histories support boarding decisions under authorised regimes, and subsea infrastructure monitoring supports protection tasking for cables and pipelines. Products feed J2 reporting, maritime interdiction planning and freedom of navigation assessments. Constraints include the legal status of vessels in different waters, the risk of misidentification when transmitted identity is falsified, and the requirement to keep commercial shipping analysis separate from targeting processes.

🕵 National intelligence

National intelligence requirements typically cover sanctions circumvention at sea, dark fleet composition and insurance exposure, subsea cable and pipeline threat, port infrastructure ownership by foreign state-linked entities, and the behaviour of state-affiliated fishing and research fleets. Fusion combines vessel-reported positions, satellite radar and optical detection, registry and insurance records, and financial and liaison reporting. The open layer is deep enough that most identity work can be done unclassified, which makes it shareable with coastguards, port states and flag registries. Judgments should distinguish clearly between what position data shows and what it can be made to show.

👮 Law enforcement

Maritime law enforcement and prosecutors need evidence that survives challenge: authenticated position records with provenance, radar detections with acquisition metadata, registry and class records obtained through official channels, and cargo documentation. Jurisdiction is the recurring complication, since flag state, port state, coastal state and nationality of crew can all differ. Lawful process runs through flag state consent regimes, port state control powers, mutual legal assistance and, for sanctions cases, designation authorities. Charging decisions usually rest on documentary fraud, sanctions breach, fisheries offences and money laundering rather than on the vessel behaviour itself.

🔍 Private investigation and corporate security

Corporate security, marine insurers, P and I clubs and trade compliance teams use this for counterparty and cargo due diligence, charter screening, and route risk assessment. The work includes hull-anchored identity checks, ownership and management resolution, port state control history review, and detection of behaviour patterns associated with sanctions risk. Private actors cannot compel disclosure, must respect the licence terms of commercial position data, and should not attempt to interfere with or interrogate vessel systems. Findings normally support a contractual or compliance decision and, where a breach is suspected, a report to the relevant authority.

📰 Journalism and OSINT media

Journalists have an unusually rich open evidence base at sea, and the corresponding risk of confident error. Verification requires reconciling transmitted position claims with independent radar or optical detection, checking registry, class and insurance through more than one source, and dating imagery precisely. Falsified position broadcasts are common enough that a single track should never carry a story. Sources inside shipping companies, agencies and port authorities face dismissal and, in some jurisdictions, criminal exposure. Give owners, managers and flag states a genuine right of reply, since ownership records are frequently stale and misattribution is easy.

🌍 NGO, humanitarian and human rights

NGOs work maritime issues through seafarer welfare and abandonment, forced labour and trafficking in fishing fleets, migrant rescue at sea, and environmental harm from illegal fishing and pollution. Practice is victim centred: seafarers and fishers reporting abuse face blacklisting and immobility, so protect identities and work through unions and port welfare organisations. Do-no-harm applies to publishing vessel identities where crew remain aboard and could face retaliation. Documentation for accountability should preserve position data, employment records and testimony to evidentiary standards. Duty of care covers staff boarding vessels or working in port environments with organised crime presence.

🎓 University and research

Maritime research benefits from large open position datasets, and the standard methodological trap is treating transmitted identity as ground truth. Publish identity resolution rules, describe how you handled gaps, duplicates and spoofed messages, and validate against independent detection where possible. Licence terms matter, since several key datasets prohibit redistribution of raw positions. Ethics review applies to any work involving crew testimony or labour conditions. Cite data vintages because registry and ownership records change, and be explicit that absence of a position report is a measurement gap rather than an observed behaviour.

Playbook: working Maritime Security end to end

A repeatable sequence, from the moment the requirement lands to the moment a product is delivered and the case is closed out. Each phase states what you are trying to establish, not merely what to click — the point is a defensible chain of reasoning, not a checklist.

Phase 1 — Define the maritime question and area

State whether the task is fleet-level sanctions exposure, a single vessel history, protection of a subsea corridor, port ownership analysis or fisheries enforcement support. Fix the geographic area with its jurisdictional layers: territorial sea, exclusive economic zone, high seas, and any regional fisheries or security arrangement covering it. A good output is a scoped tasking with the area, the jurisdictional layers and the legal regimes that apply. Stop when you know which authority could act on what you find.

Phase 2 — Anchor identity on the hull

For every vessel of interest, establish the permanent identity: IMO number where assigned, dimensions, build year and yard, and the history of names, flags, call signs and transmitted identifiers. Names and flags change in days; hulls do not. Record every change with its date and source. This step prevents the most common and most publicly embarrassing error in the domain. A good output is an identity record with a sourced change history. Stop when today's hull is linked to its previous identities or the break is explicitly documented.

Phase 3 — Build the movement baseline

Assemble position history over a meaningful period and characterise normal behaviour for the vessel and its class: typical routes, speeds, port rotation, loitering patterns and seasonal variation. Anomaly detection without a baseline generates noise, because much apparently odd behaviour is routine for that trade. A good output is a behavioural profile with the normal envelope described. Stop when you can state what this vessel usually does and how much variation is typical.

Phase 4 — Investigate gaps rather than assuming them

For each period without position reports, establish whether coverage existed, whether terrestrial or satellite reception was plausible at that location, and whether the gap coincides with a port call, a known equipment issue or a weather event. Then check independent detection: radar or optical imagery over the expected area. A gap is a question, and most gaps are benign. A good output is a gap register with the tested explanations for each. Stop when the gap is explained or the alternative explanations are documented as exhausted.

Phase 5 — Corroborate with independent sensing

Task or pull radar and optical imagery over the times and areas of interest, and match detections to expected positions. Radar sees vessels regardless of weather, darkness or whether they are transmitting, which makes it the strongest check on falsified or absent broadcasts. Record sensor, acquisition time, resolution and detection confidence. A good output is a correlation table linking imagery detections to candidate vessels with a stated confidence. Stop short of asserting identity from imagery alone unless the vessel is dimensionally distinctive.

Phase 6 — Resolve ownership, management and insurance

Trace registered owner, beneficial owner, technical and commercial manager, charterer, class society and insurer through registry, class and aggregated maritime databases, then look for the recognised risk pattern: a newly formed manager in a permissive jurisdiction, a flag change shortly after a designation, an unfamiliar class society and insurance that cannot be verified. A good output is an ownership graph with dates and sources on every link. Stop when the chain reaches a natural person or a documented opaque jurisdiction.

Phase 7 — Screen against sanctions and enforcement records

Check the vessel, owners, managers and insurers against applicable designation lists, and pull port state control inspection history, detentions and casualty records. Detentions and deficiency patterns are strong indicators of substandard operation that often accompanies sanctions-linked trade. State findings jurisdiction by jurisdiction, since designation status differs across regimes. A good output is a screening record with regime-by-regime status and inspection history. Stop at documented status, and refer suspected breaches to the appropriate authority.

Phase 8 — Assess subsea and port infrastructure exposure

For infrastructure tasks, map cable and pipeline routes against traffic patterns, anchorage areas and reported anchor-drag incidents, and identify where vessel loitering over a route is anomalous rather than routine. For ports, assess ownership, terminal operator control and dependency concentration. Findings on protective weaknesses go to operators and authorities rather than into public products. A good output is an exposure assessment with monitoring recommendations. Stop before publishing anything that would function as a targeting aid.

Phase 9 — Document to an evidential standard

Preserve position records, imagery, registry pages and screenshots with hashes, timestamps and collector identity, and record every database query with its date, since maritime records change without notice. Maintain the distinction between observation, correlation and inference throughout the file. A good output is a case file another analyst can reproduce from the recorded queries. Stop when every assertion in the product traces to a preserved artefact.

Phase 10 — Refer, publish and monitor for successors

Route findings to the authority that can act: flag state, port state control, coastal state, regional fisheries body, sanctions authority or insurer. After action, watch for the standard successor pattern of a renamed vessel with a new manager at the same address, and for fleet-level substitution. A good output is a referral with a monitoring plan for successor entities and hulls. Stop when the monitoring has run long enough to catch a reflagging cycle.

The platform ships this as a step-checked workflow in playbooks.php, so progress is recorded against a case rather than held in someone’s head.

Source register: what to collect from, and how

Sources are listed with their access model so you can plan around cost and licensing before you build a dependency on them. Open means no account required; registration means a free account or API key; licensed means paid or institutional access. Always confirm current terms — licensing changes, and a source that was free for research may not be free for commercial or evidential use.

Source Access What it gives you How it is used here
IMO GISIS Registration Ship particulars, company and registered owner records, port state control results, casualty and piracy modules maintained by member states. The authoritative anchor for hull identity, company registration and official incident records.
Equasis Registration Aggregated ship safety, ownership, management, classification and inspection data drawn from multiple authoritative sources, free to registered users. Fast resolution of management and ownership changes and inspection history for a specific hull.
Global Fishing Watch Registration Processed vessel behaviour including apparent fishing effort, encounters, loitering, port visits and vessel identity attributes. Detects transhipment encounters, fishing in closed areas and vessels operating without visible authorisation.
Copernicus Sentinel-1 SAR Registration All-weather radar imagery detecting vessels regardless of cloud, darkness or whether they are broadcasting position. The primary independent check on absent or falsified position reports, including rendezvous detection.
NGA Maritime Safety Information Open Navigational warnings, broadcast warnings, chart corrections and anti-shipping activity messages for global waters. Provides official warning context, anti-shipping messages and incident reporting for the specific waters under assessment.
OFAC sanctions programmes and SDN list Open US designations including vessels identified by IMO number, with guidance and advisories on shipping sector risk. Primary designation screen for vessels, owners, managers and insurers in sanctions-related maritime work.
EU Sanctions Map Open Consolidated presentation of EU restrictive measures by regime including shipping and sectoral restrictions. Establishes European restriction status, which frequently differs from US designation for the same vessel.
Paris and Tokyo MOU port state control databases Open Inspection results, deficiencies, detentions and company performance rankings for vessels calling in member ports. Reveals substandard operation patterns and company performance that often accompany high-risk trades.
TeleGeography Submarine Cable Map Open Interactive mapping of submarine cable routes, landing stations and ownership consortia with capacity information. Establishes which cable routes pass through an area of interest for subsea protection analysis.
AIS platforms such as MarineTraffic and VesselFinder Licensed Aggregated terrestrial and satellite position data with vessel particulars, port calls and historical track playback. Day-to-day movement monitoring and port call reconstruction, subject to coverage gaps and licence terms.
Regional fisheries management organisation vessel registers Open Authorised vessel lists and IUU vessel lists maintained by regional bodies covering specific fisheries and areas. Establishes whether a vessel is authorised to fish in an area and whether it appears on an illegal fishing list.
UNCTAD and port authority statistics Open Port throughput, connectivity indices and terminal infrastructure data at country and port level. Assesses port dependency concentration, terminal throughput and the chokepoints that shape maritime supply chain exposure.
International Chamber of Shipping and industry guidance Open Industry best practice guidance on security, sanctions compliance and operational conduct for shipowners and operators. Establishes the standard of care against which an operator's conduct and due diligence are assessed.
Copernicus Sentinel-2 optical imagery Registration Ten metre resolution optical imagery with frequent revisit, free access to the full archive. Visual confirmation of vessel presence, port occupancy and terminal activity in clear conditions.

Prefer sources that publish a methodology and a revision history. A dataset that changes silently is a liability in any product that has to survive challenge.

Tooling

Tools commonly used against Maritime Security. None of these replace judgement, and each carries its own failure modes — know what a tool infers versus what it observes.

  • QGIS with maritime plugins — Plots tracks, detections and infrastructure routes against jurisdictional boundaries. Capable, but large position datasets need database backing to remain workable.
  • Sentinel Hub and SAR viewers — Radar detection of vessels irrespective of weather or broadcast state. Revisit intervals mean absence of detection is not evidence of absence.
  • Python with pandas and movement analysis libraries — Track cleaning, gap detection, encounter identification and speed profiling at scale. Requires explicit rules for duplicate and spoofed message handling.
  • PostgreSQL with PostGIS — Stores and queries large position histories with spatial indexing. Essential for fleet-scale work, and unnecessary overhead for single-vessel investigations.
  • Equasis and class society lookups — Authoritative ownership, management and inspection records for identity resolution. Data currency varies and beneficial ownership is rarely visible.
  • Sanctions screening tooling — Batch matching of vessels, owners and managers against designation lists. Transliteration and identifier gaps produce both false positives and misses.
  • Hunchly — Hashed, timestamped capture of registry and database pages that change without notice. Captures rendered pages only, so exports need separate preservation.
  • Maltego or graph tooling — Maps ownership, management and insurance relationships across entities. Graph clarity can outpace evidence, so each edge needs a dated source.

AI skills and automation in detail

These are deterministic jobs with defined inputs and outputs, not open-ended prompting. Each is idempotent and cursor-based: interrupt one and it resumes where it stopped rather than duplicating work or losing progress.

  • Threat Hunt — Runs saved hypotheses against the corpus and surfaces what matches, with the query preserved as a versioned artifact.
  • Correlate Infrastructure — Builds the cross-entity link graph: shared hosting, reused certificates, overlapping registrants, repeated selectors.
  • Run Alert Rules — Evaluates saved rules against new data so a first sighting raises a notification rather than waiting for review.
  • Summarise (Copilot) — Produces a narrative summary beside the underlying records. It explains; it never creates indicators or assigns attribution.
  • Generate Report — Assembles a sourced product from the current case or query, with provenance attached to each element.

A note on the boundary: the only skill that involves a language model is Summarise (Copilot), and it writes prose about records that already exist. Nothing else on this list involves generation of any kind. No indicator, relationship or attribution in the platform originates from a model. See the full skill list.

Tradecraft notes

The distinctions that separate a competent analyst from a fast one:

  • The whole investigation is usually identity. Establish that today's hull is last month's hull before analysing behaviour, because a fleet-level finding built on transmitted identifiers can be undone by a single reflagging you missed.
  • A position report is a broadcast, not an observation. It can be delayed, duplicated, absent or deliberately falsified, so any judgment that matters needs corroboration from radar, optical imagery or a port call record.
  • Build a behavioural baseline before flagging anomalies. Loitering, drifting and slow steaming are routine in many trades, and anomaly detection without a per-class baseline produces a queue nobody can work.
  • Ownership records are stale by design. Registered owner is often a single-ship company, the manager changes without public notice, and beneficial ownership sits behind a permissive jurisdiction, so date every link you assert.
  • Port state control history is an underused discriminator. Detention patterns, deficiency types and company performance rankings identify substandard operators long before any designation appears.
  • Absence of an insurer that can be verified is one of the strongest single indicators in dark fleet work, because insurance is the one commercial relationship that is difficult to fabricate convincingly.
  • Anchor-drag damage to cables is common and usually accidental. Establish traffic density, anchorage proximity and weather before treating a cable fault as deliberate, because early sabotage claims are frequently wrong.

Measuring whether it is working

Capability claims should be falsifiable. These are the measures that show whether work on Maritime Security is producing anything, and they are worth baselining before you change process or tooling.

  • Proportion of vessels of interest resolved to a hull identity with a sourced name, flag and manager change history.
  • Share of position gaps closed with an independent radar or optical detection rather than left as unexplained.
  • Number of referrals accepted by flag states, port state control authorities, fisheries bodies or sanctions authorities.
  • False positive rate in anomaly alerting, measured after the behavioural baseline was introduced compared with before.
  • Time from an anomalous rendezvous detection to a documented identity resolution for both vessels involved.
  • Percentage of published vessel findings with preserved artefacts and recorded query dates sufficient for evidential use.
  • Detection rate of successor vessels and renamed hulls after a previous enforcement action against the same operator.

Beware of measuring volume alone. Indicator counts and report counts rise easily and say little; time-to-attribution, proportion of findings that survive review, and how often a product changed a decision say a great deal.

Common pitfalls

  • AIS is self-reported and trivially manipulated. Treat every position as a claim by the vessel until independently corroborated.
  • Coverage holes from satellite revisit and terrestrial receiver density create gaps that look identical to deliberate transponder shutdowns.
  • Registered owner is usually a single-ship company created for liability isolation and tells you almost nothing about control.
  • SAR detections resolve hulls but not identity, so pairing a radar contact to a named vessel requires additional corroboration.
  • Cable damage is overwhelmingly accidental, caused by anchors and fishing gear, so sabotage should be a conclusion of last resort.
  • Historic AIS archives are commercially licensed and inconsistent between providers, which quietly changes analytic conclusions.

Legal and ethical considerations

Flag state jurisdiction, coastal state rights and the high seas regime under UNCLOS determine who may act on your findings, so state the applicable regime rather than implying enforcement authority. Publicly naming a vessel or operator as sanctions-evading carries commercial and defamation exposure and can prejudice ongoing enforcement, so route findings to competent authorities first. Crew members are usually uninvolved third parties whose personal data merits protection. Most historical AIS is licensed and non-redistributable.

Data integrity: no fabrication, no drift, no hallucination

Intelligence that cannot be traced back to a source is not intelligence, it is assertion. Everything in this entry — and everything in the platform behind it — is built on a small number of non-negotiable rules.

Provenance on every record

Every indicator carries the source that supplied it, a first-seen and last-seen timestamp, and a sighting count. Where several feeds report the same artifact, each contribution is recorded separately rather than collapsed, so you can see whether a finding rests on one source or twelve. Source attribution travels with the data into every export, so a recipient can audit a claim without asking you for the working.

Nothing is invented to fill a gap

If the platform has no data for Maritime Security, it says so. Empty is displayed as empty — never padded with plausible-looking placeholder values, sample records or illustrative examples that a reader might mistake for observations. A dashboard with no rows is a true statement about collection coverage, and it is treated as a gap to close, not a blemish to hide.

Scoring is deterministic and reproducible

Threat scores, reputation grades and risk tiers are computed from stated inputs with fixed weights, not estimated. The same inputs always produce the same output, and the formula is visible rather than a black box. Aggregates are cached with an explicit time-to-live so a figure on screen is never silently stale — and when a heavy query exceeds its time budget the platform serves the last known-good value and labels it, rather than inventing a fresh number or hanging.

Where AI is used, and where it is not

Language models summarise and explain. They do not create indicators, assign attribution or manufacture relationships. No IP address, wallet, hash or identity in the platform originates from a model — every one is ingested from a named feed, resolved from a reference dataset, or entered by an analyst with a source recorded. Copilot output is presented as narrative alongside the underlying records, never in place of them, so a reader can always check the summary against the evidence.

Guarding against drift

Enrichment is additive and timestamped rather than overwriting. Reference data — sanctions lists, allocations, taxonomies — is re-synchronised from the authority on a schedule instead of being edited in place, so local copies cannot quietly diverge from the source of truth. Attribution is recorded with a confidence level and the reporting it rests on, and inferred relationships are labelled as inferred. When a source retracts or corrects, the correction propagates rather than leaving a stale assertion behind.

What this means for you

You can put a finding from this platform in front of a regulator, a court, a board or a partner agency and show where each element came from. That is the standard the tooling is built to — because in this work, being confidently wrong is more damaging than being usefully uncertain.

By the numbers

The taxonomy this entry belongs to is not a marketing list — it is the actual structure of the platform: 52 mission domains, 52 intelligence disciplines and 65 data points, each with a live dashboard behind it. Supporting that: 18 indicator types, 14 playbooks, 16 AI skills, 18 export formats and a 30-step automated pipeline.

This particular entry connects directly to 7 intelligence disciplines, 7 data points, 7 closely related entries — every one of them a tag you can follow, and a dashboard you can open.

Questions analysts actually ask

How reliable is vessel position data?

Reliable for routine commercial movement and unreliable exactly where it matters most. The system was designed for collision avoidance, not enforcement, so identifiers are self-declared and can be altered, transmissions can be switched off, coverage varies with satellite pass and terrestrial receiver density, and messages are sometimes duplicated or corrupted in aggregation. Treat a track as a claim by the vessel about itself. Corroborate with radar or optical detection, port call records, and physical evidence such as draught changes. Any judgment that could affect a designation, a prosecution or a publication needs at least one independent observation type.

Does a gap in transmission prove concealment?

No, and treating it that way is the fastest route to a wrong finding. Coverage over open ocean is uneven, equipment fails, power is lost, and crews sometimes switch systems off for safety reasons in areas with piracy risk. The analytic value of a gap comes from what surrounds it: whether coverage should have existed, whether the gap recurs on the same route segment, whether the vessel reappears at an unexpected position or draught, and whether independent radar detection places it somewhere inconsistent with its own account. Document the explanations tested.

How do I resolve beneficial ownership of a vessel?

Start with registered owner from the flag registry and official records, then map technical and commercial managers, the charterer, class society and insurer. Registered owners are typically single-ship companies, so the substantive control usually sits with the manager. Trace those companies through corporate registries, beneficial ownership filings where they exist, litigation records and shared addresses, directors and phone numbers. Expect the chain to terminate in a jurisdiction with no public register, and document that terminus explicitly rather than implying a conclusion. Date every link, because ownership changes silently and frequently.

What indicates a vessel is in a high-risk trade?

Look for a cluster rather than any single sign: a recent flag change to a registry with limited oversight, a newly incorporated manager in a permissive jurisdiction, an unfamiliar or newly established class society, insurance that cannot be verified with the named provider, an ageing hull with a deteriorating port state control record, repeated position gaps on the same route segment, and rendezvous with other vessels in areas without a commercial reason. Any one of these has innocent explanations. Three or four together, documented with dates, justify escalation to compliance or an authority.

How should subsea cable incidents be assessed?

Begin with the mundane explanations, because they dominate the record: anchor drag in or near anchorage areas, fishing gear interaction, seabed movement and equipment failure. Establish traffic density along the route, weather and sea state at the time, proximity to anchorages, and whether any vessel loitered over the route in a way inconsistent with its trade. Correlate cable fault timing with position data and radar detection. Only then consider deliberate action, and even then state the confidence carefully. Early sabotage attribution in this area is frequently wrong and diplomatically consequential.

Which authority can actually act on a maritime finding?

It depends on where the vessel is and what it did. Flag states have primary jurisdiction over their vessels on the high seas, port states can inspect and detain vessels calling at their ports, coastal states have powers within their territorial sea and defined powers in the exclusive economic zone, and regional fisheries bodies maintain authorised and illegal fishing vessel lists. Sanctions authorities act on designations, and insurers can withdraw cover. Map the finding to the authority with both jurisdiction and appetite, and present it in the format that authority uses.

Standards, frameworks and further reading

Work that references a recognised framework is easier to defend, easier to hand over, and easier for a partner to consume:

  • UN Convention on the Law of the Sea, which allocates jurisdiction between flag, port and coastal states and defines maritime zones.
  • SOLAS Convention and its identification requirements, which underpin ship identification numbers and mandatory reporting equipment.
  • IMO ship identification number scheme, which provides the permanent hull identifier used to anchor identity work.
  • Port state control regimes under the Paris and Tokyo Memoranda of Understanding, which govern inspection, detention and company performance recording.
  • FAO Port State Measures Agreement, which governs port access for vessels implicated in illegal, unreported and unregulated fishing.
  • Maritime Labour Convention, which sets seafarer employment and welfare standards used in abandonment and forced labour work.
  • OFAC, OFSI and EU shipping sanctions guidance, which set expected due diligence practice for owners, insurers and traders.
  • Berkeley Protocol on Digital Open Source Investigations, which sets preservation and verification standards for open-source maritime evidence.

References

Primary sources and authoritative references for this entry. Publishers revise and retire material, so treat the retrieval date as part of the citation and re-check before relying on any of it in a formal product.

  1. Global Integrated Shipping Information System — International Maritime Organization. Official ship, company, inspection and casualty records from member states
  2. Equasis maritime information system — Equasis supervisory committee. Aggregated ship safety, ownership and inspection data from authoritative sources
  3. Global Fishing Watch platform — Global Fishing Watch. Vessel behaviour analytics including encounters, loitering and fishing effort
  4. Paris Memorandum of Understanding on Port State Control — Paris MOU Secretariat. Inspection, detention and company performance data for European port calls
  5. Submarine Cable Map — TeleGeography. Global mapping of submarine cable routes, landing points and ownership
  6. Maritime Safety Information portal — US National Geospatial-Intelligence Agency. Navigational and anti-shipping warnings for global waters
  7. Shipping sanctions advisories and SDN list — US Department of the Treasury Office of Foreign Assets Control. Vessel designations and maritime sector compliance guidance
  8. Review of Maritime Transport — UN Conference on Trade and Development. Annual analysis of shipping, ports and maritime trade connectivity
  9. Port State Measures Agreement materials — Food and Agriculture Organization. International agreement and guidance on port access for illegal fishing vessels

Link integrity: every reference above was verified with a live request when this page was generated. Where a publisher had moved or withdrawn a document, the link was repointed at a preserved copy in the Internet Archive and marked as archived. Anything with no reachable copy anywhere had its link removed rather than left to rot — the source is still credited, it simply cannot be linked.

Put it into practice

The Quantus Intel threat intelligence platform operationalises this entry: identity-resolved vessel histories, dark-period detection and infrastructure exposure analysis across fleets, corridors and chokepoints. Explore the platform, or browse the rest of the library by following any tag above.

Leave a Reply

Your email address will not be published. Required fields are marked *