Background: The maritime sector is highly dependent on technological infrastructure, including port management systems, ship monitoring systems, and satellite-based communication systems. This infrastructure is crucial for ensuring the smooth flow of goods between countries and maintaining port operations and safe ship navigation. Objective: This study identifies cyberattack pathways targeting shipboard navigation and operational technology (OT) systems in Indonesian waters, develops attack-tree scenarios for those pathways, and evaluates ship captains' readiness to detect and respond to them. Methods: Attack-tree modeling was used to describe, analyze, and represent potential attack scenarios. The model draws on a literature review and interviews with twelve maritime experts: four captains and deck officers, four cybersecurity specialists, and four technical consultants. Validation was conducted through two Delphi rounds until an agreement level of 80% was reached. Results: Four attack trees produced eighteen validated attack paths across three primary attack goals: crashing the ship (five paths), sinking the ship (three paths), and disabling the ship (six paths), along with four shared enabling paths. Experts rated the attack scenarios for crashing and disabling the ship as highly feasible, whereas sinking the ship was considered unlikely. Overall, nine attack paths were classified as high risk. Conclusion: The attack tree serves not only as a vulnerability assessment tool but also as a structured, prioritized risk assessment instrument for maritime cybersecurity. Mapping each validated attack path to International Maritime Organization (IMO) and National Institute of Standards and Technology (NIST) cybersecurity controls enables shipping companies