Why Cyber Risk Is Now a Safety Issue at Sea
Maritime cyber risk is no longer a purely IT concern. Modern vessels blend information technology (IT) — email, business systems, crew Wi-Fi — with operational technology (OT) — ECDIS, propulsion and steering control, cargo and ballast systems, GPS and AIS. When those worlds connect, a compromise of the office network or a single infected USB stick can reach systems that keep the ship safe.
The consequences are operational and physical, not just financial: loss of position or navigation data, disabled cargo control, ransomware that halts a shore office and freezes fleet operations, or spoofed GPS that misleads the bridge. That is precisely why the regulator treats cyber risk as a safety-management matter.
The shift to high-bandwidth connectivity (VSAT and LEO constellations such as Starlink) has transformed crew welfare and remote support — and simultaneously widened the attack surface. More always-on connectivity means cyber hygiene can no longer be optional.
What IMO MSC.428(98) Requires
In June 2017 the IMO Maritime Safety Committee adopted Resolution MSC.428(98), which affirms that an approved safety management system should take into account cyber risk management in accordance with the objectives of the ISM Code. In plain terms: cyber risk must be addressed inside your existing Safety Management System (SMS), not in a separate silo.
The compliance trigger has already passed. Companies were required to address cyber risk in the SMS no later than the first annual verification of the company's Document of Compliance after 1 January 2021. Since then, cyber risk management is a standard part of ISM audits and is examined by Port State Control and vetting inspectors.
Alongside the resolution, the IMO published MSC-FAL.1/Circ.3 — Guidelines on Maritime Cyber Risk Management — which provides the framework companies are expected to apply. Industry guidance from BIMCO, ICS and partners (The Guidelines on Cyber Security Onboard Ships) translates that into practical, ship-level measures.
The Five Functions of Maritime Cyber Risk Management
IMO guidance aligns with the widely used NIST framework and sets out five functional elements. A credible programme demonstrates all five, for both IT and OT:
| Function | What it means on board |
|---|---|
| Identify | Inventory of IT and OT systems, data and their importance; roles and responsibilities; a risk assessment per vessel. |
| Protect | Access control, network segmentation (separate OT from IT and crew Wi-Fi), patching, removable-media control, secure remote access. |
| Detect | Monitoring and alerting so abnormal activity — failed logins, unexpected connections — is noticed early. |
| Respond | An incident response plan: who does what, how to isolate systems, how to keep the ship safe and navigable. |
| Recover | Backups, restoration procedures and lessons learned so operations return to normal and the SMS improves. |
These map neatly onto the ISM cycle of procedures, records and continual improvement — which is why cyber risk belongs in the SMS rather than beside it.
The New Class Rules: IACS UR E26 & E27
The regime tightened for newbuildings. The International Association of Classification Societies (IACS) issued two Unified Requirements:
- UR E26 — Cyber resilience of ships: requirements for the vessel as a whole, covering equipment identification, network design, access control and recovery, applied during design and construction.
- UR E27 — Cyber resilience of on-board systems and equipment: requirements at the level of individual systems and their suppliers.
Both apply to ships contracted for construction on or after 1 July 2024. They shift part of the burden to shipyards and equipment makers, embedding cyber resilience into the asset itself rather than relying only on operational controls added later. Owners ordering new tonnage should confirm how yards and vendors are meeting E26/E27.
Common Threats — and Where They Get In
- Phishing & business email compromise — the most common entry point; often targets payment and procurement.
- Ransomware — can freeze a shore office and, through it, fleet operations and reporting.
- Removable media (USB) — a classic route for malware onto isolated OT systems during updates or chart loading.
- Insecure remote access — maker or shore access to OT for diagnostics, if poorly controlled, is a direct path to critical systems.
- GPS/GNSS spoofing & jamming, AIS manipulation — degrade or falsify position and traffic data on the bridge.
- Weak segmentation — flat networks let a crew-Wi-Fi or IT compromise reach navigation and machinery systems.
Most incidents are not exotic. They exploit ordinary weaknesses: shared passwords, unpatched systems, untrained users and networks that were never properly separated.
Building a Ship Cyber Risk Programme
- Inventory IT and OT. You cannot protect what you have not listed. Record systems, connections, owners and criticality per vessel.
- Assess risk. Rate likelihood and consequence, prioritising systems whose failure affects safety or the ship's ability to navigate.
- Segment networks. Keep OT separate from IT and from crew Wi-Fi; control the boundaries between them.
- Control access and media. Individual accounts, least-privilege, disciplined USB and removable-media policy, and locked-down remote access.
- Patch and back up. Keep systems current where safe to do so, and hold tested backups of critical data and configurations.
- Train the crew. People are the first line of defence; phishing awareness and clear reporting routes matter more than any single tool.
- Plan and drill the response. Write the incident response plan into the SMS and exercise it, just like fire and abandon-ship drills.
Evidence is everything at audit. A programme that exists only on paper fails; one with records — risk assessments, training logs, drill reports, corrective actions — demonstrates the continual improvement ISM expects. This is where safety-management software and controlled document distribution earn their keep.
Where Software Helps — and Where It Doesn't
Fleet management software is part of a cyber programme, not a substitute for one. Used well, a platform contributes to several of the five functions:
- Protect — role-based access control and per-user authentication limit who can see and change what.
- Detect & Respond — audit trails show who did what and when, supporting investigation and evidence.
- Identify & Recover — controlled, versioned document distribution keeps cyber and safety procedures current on board, and resilient ship–shore synchronisation protects against data loss.
But software cannot write your risk assessment, segment your OT network, or train your crew. Treat any vendor claim of "cyber-secure" with healthy scepticism, and ask how the product supports your programme. Volaxin's approach to these controls is set out on our Security & Trust page — and we welcome your own security assessment.
Run your fleet on a platform that supports your cyber programme
Volaxin Maritime Suite brings role-based access, audit trails, controlled document distribution and resilient offline sync to one platform — evidence your SMS and vetting inspectors can see. Book a demo and bring your security team.
Request a DemoFrequently Asked Questions
What is IMO Resolution MSC.428(98)?
An IMO resolution stating that cyber risk must be addressed within a company's ISM Safety Management System — required from the first annual DoC verification after 1 January 2021.
What are the five functions of maritime cyber risk management?
Identify, Protect, Detect, Respond and Recover — applied to both IT and OT systems, per IMO MSC-FAL.1/Circ.3 (aligned with the NIST framework).
What are IACS UR E26 and E27?
Classification requirements for the cyber resilience of ships (E26) and of on-board systems and equipment (E27), applying to ships contracted for construction on or after 1 July 2024.
Is cyber security checked at vetting and PSC?
Yes — it features in ISM audits, Port State Control and tanker vetting such as SIRE 2.0, so a documented, drilled programme is a commercial necessity.