“To protect a ship, you first have to understand one.”
In the early days of his startup, the question CYTUR CEO Yonghyun Jo (pictured) heard most often at shipyards was, “Have you ever been on a ship?” The message behind it was clear: a career in information security alone was not enough to protect vessels. Rather than answer in words, he answered with action — boarding passenger ferries and climbing aboard ships still under construction at shipyards. He visited container ships, LNG carriers, and even a U.S. aircraft carrier to learn the field firsthand. CYTUR, the company he leads, is a cybersecurity specialist working to prevent hacking attacks from crippling a vessel’s operations and critical systems.
In an interview at CYTUR’s headquarters in Geumcheon-gu, Seoul, on July 19th, CEO Jo said, “The thing I heard most often was that no matter how much you know about cybersecurity, you can’t secure a ship if you don’t understand ships. From that point on, I started going out into the field to learn the structure, culture, and terminology of vessels.”
Jo’s interest in vessel cybersecurity began with a chance moment of curiosity. While pursuing his Ph.D., he saw a ship model at a shipping company and found himself wondering, “Could a ship be hacked, too?” At the time, research on the subject was rare even by global standards. To study ship hacking, he sought out ship captains and industry professionals in the field, going so far as to look into the possibility of boarding a research vessel bound for an Antarctic station.
“There was almost no literature to go on, so I kept my research going by seeking out captains and industry practitioners and picking up what I could from them,” he said. “I believed you could only build proper security if you understood the field.” That experience shaped CYTUR’s business direction. While most security companies add security solutions onto already-completed systems, CYTUR has championed a “secure by design” approach that builds security in from the vessel design stage — on the reasoning that since a ship takes years to build and then operates for decades afterward, security has to account for its entire lifecycle.
CEO Jo explained, “Installing a single antivirus program isn’t enough to protect a ship. Network architecture and operating procedures need to be designed together from the design stage in order to both meet regulatory requirements and actually reduce real-world risk.”
The rollout of new regulations became a fresh opportunity for CYTUR. Inquiries surged after cybersecurity regulations from the International Maritime Organization (IMO) and the International Association of Classification Societies (IACS) went into full effect last year. Jo named this as the biggest turning point since the company’s founding.
“As the regulations took effect, inquiries from investors, shipyards, and shipowners increased sharply,” Jo said. “It wasn’t so much brilliant foresight as good timing. What mattered most was that we were ready right when the market began to shift.”
His field-first philosophy remains unchanged today. Developers themselves board the vessels where CYTUR’s products are installed, on the belief that technology proven in real operating environments matters more than technology built at a desk. “The idea that the answers are in the field hasn’t changed,” he emphasized. “Shipbuilding is an industry where trust is essential, so how well you understand the field ultimately becomes your competitive edge.”
CYTUR plans to expand into autonomous vessels, maritime defense, maintenance-repair-and-overhaul (MRO), and offshore data centers going forward. Its ultimate goal is to become a company synonymous with its field — in the way that global networking equipment giant Cisco is synonymous with networking.
“Just as people think of networking when they hear Cisco, I want CYTUR to be the first name that comes to mind for vessel cybersecurity,” Jo added. “Our goal is to become the de facto standard in maritime cybersecurity.”
Hangeul Bae, Reporter (koreanbae@fnnews.com)