Criminal Law Responses to Maritime Cyber Crimes in the Era of MASS
해사 사이버안전이란 해사 사이버 공격으로부터 선박 운항에 필요한 시스템 을 보호함으로써 선박운항시스템과 정보의 기밀성·무결성·가용성 등 안전성을 유지하는 상태를 말한다. 이는 과거 물리적인 안전에 집중해오던 것과 달리 자율운항선박 시대에 맞춰 더욱 큰 의미를 가지게 되었다. 이러한 사이버 기술 및 시스템의 발전은 해운산업에 상당한 효율성 향상을 제공하지만, 동시에 해 운 운영에 필수적인 시스템에 대한 위협과 위험을 초래할 수 있다. 사이버 위 험은 악의적 행위에 의해 발생할 수 있으며, 예를 들어 해킹이나 악성코드의 유포가 이에 해당한다. 또한 선의의 부주의한 행위에서부터 의도치 않은 결과 로도 발생할 수 있는데, 예를 들어 소프트웨어 유지보수나 사용자 권한 관리상 의 실수가 이에 해당한다. 일반적으로 이러한 행위들은 사이버보안의 취약성을 노출시키거나 악용하여 더 큰 범죄에 활용되기도 한다. 이에 대응하기 위한 현행법상 규정은 정보통신망법, 정보통신기반 보호법, 물류정책기본법, 국가사이버안전관리규정, 형법 그리고 테러방지법 등이 있다. 그러나 이들 역시 사이버 테러에 대한 모든 범죄를 포함한다고 이해하기 어렵 고, 사이버 범죄로 인해 발생할 범죄의 결과발생을 확인하고 비로소 처벌하는 것은 막대한 법익의 손상과 어쩌면 회복불가능한 결과를 감내해야 하는 문제를 야기한다. 이에 필자는 해사 사이버 범죄의 유형을 살피고 그에 대한 현행법상 형사책 임을 검토한 후 실제 자율운항선박의 상용화 시대가 도래하면 야기될 사이버 범죄 형태와 그에 대한 보다 효율적인 법적 대응에 대해 점검해 보았다.
Maritime cyber security refers to the state of maintaining the safety, confidentiality, integrity, and availability (CIA) of ship operation systems and information by protecting them from maritime cyberattacks. Unlike the traditional paradigm that focused predominantly on physical security, maritime cyber security has assumed far greater significance in the era of Maritime Autonomous Surface Ships (MASS). While advancements in cyber technology and systems offer substantial efficiency gains to the maritime industry, they concurrently introduce novel threats and risks to systems indispensable for shipping operations. These cyber risks can stem from malicious actions—such as hacking or the dissemination of malware—as well as from bona fide negligence or unintended consequences, including lapses in software maintenance and user privilege management. Generally, such acts expose or exploit cybersecurity vulnerabilities, thereby serving as facilitators for more egregious offenses. As examined, the current legal framework governing these actions comprises the Act on Promotion of Information and Communications Network Utilization and Information Protection, the Information Infrastructure Protection Act, the Framework Act on Logistics Policies, the National Cyber Security Management Regulation, and criminal law provisions regarding obstruction of business, damage to electronic records, and obstruction of traffic. However, under existing laws, it remains challenging to apply punitive measures if programmatic disruption, such as hacking, does not involve external intrusion, making it difficult to satisfy the statutory elements of "trespass" or "damage." Furthermore, relying on post-hoc punishment only after the criminal consequences of a cybercrime have manifested forces society to bear severe damage to legal interests and potentially irreversible outcomes. To address these limitations, this study analyzes the typology of maritime cybercrimes, evaluates the corresponding criminal liabilities under current legislation, and anticipates the distinct forms of cyber offenses that will arise upon the commercialization of MASS. Ultimately, this paper proposes more effective and proactive legal responses to counter these evolving threats.