Breaches often go unnoticed for long periods (the Guidelines cite an average of 277 days to contain in 2019). A targeted attack typically moves through survey or reconnaissance (open sources, social media, traffic sniffing), delivery (online services, malicious emails and links, infected media, fake websites), breach (manipulating navigation data, stealing or altering manifests and crew lists, or taking control of systems such as machinery management, possibly with no visible change) and pivot (using a compromised system to reach others, which is why integrated IT and OT risk matters), with aims such as data theft, manipulating cargo or crew lists for fraud or smuggling, denial of service, enabling piracy or theft, disrupting operations or extorting a ransom.
The graph holds this control, the 0 it maps to, and the evidence behind each claim, over MCP and REST.