Insights

Maritime Cyber Risk Management Under the ISM Code

Cyber risk stopped being an IT department topic the day the IMO resolved that it belongs inside the Safety Management System.

Resolution MSC.428(98), adopted on 16 June 2017, encourages Administrations to see that cyber risks are appropriately addressed in safety management systems no later than the first annual verification of the company's Document of Compliance after 1 January 2021. Ships have since become connected platforms: ECDIS, engine monitoring, ballast and cargo systems, satellite links.

The exposure has moved from email fraud to operational technology, where a compromise is a safety event.

4 MIN READ

What the IMO framework actually requires

The IMO's Guidelines on Maritime Cyber Risk Management, now at MSC-FAL.1/Circ.3/Rev.3 dated 4 April 2025, set out a risk management cycle rather than a technology checklist. The current revision names six functional elements: govern, identify, protect, detect, respond and recover. Govern was added in this revision. It covers the risk management strategy, roles and responsibilities, and business continuity, which moves accountability up from the technical department to the company. Folding that cycle into the SMS means cyber hazards appear in risk assessments, procedures, drills and the continuous improvement loop like any other hazard. The guidelines are explicit that this is an extension of existing safety and security management practice, not a parallel system bolted alongside it. The separation that matters most on board is between IT, meaning business systems, and OT, meaning operational technology: navigation, propulsion, power management and cargo control. OT failures have physical consequences. OT systems are often old, unpatched and never designed for connectivity. That is precisely why inventorying and segregating them is the first serious step.

Class rules raised the bar for newbuildings

For new ships, cyber resilience is now a class matter. IACS Unified Requirement E26 covers the cyber resilience of ships. UR E27 covers the cyber resilience of on board systems and equipment. The original versions were withdrawn and replaced, and the revised requirements apply to new ships contracted for construction on or after 1 July 2024. Applicability is tiered by vessel type and size, so not every hull carries the full set. The effect is to oblige yards and equipment makers to deliver vessels with security zones, access control, network monitoring and incident response capability designed in, rather than added later. The practical consequence reaches existing fleets too. Owners now run mixed fleets in which the newest ships have engineered cyber baselines while older ones rely entirely on procedural controls. The SMS has to make both defensible to an auditor.

Where ships actually get hurt

The recurring real world patterns are unglamorous. Phishing compromises shore systems and spreads via remote access. USB media carry malware into ECDIS or engine room PCs. Default or shared passwords sit on critical equipment. Remote maintenance connections installed by vendors go unmanaged. Crew devices bridge networks that were supposed to be isolated. None of these require a sophisticated adversary. All of them are addressable with inventory, segmentation, access discipline and awareness training. Charterers and vetting regimes increasingly probe exactly these points. The same controls that satisfy the flag also protect the ship's commercial acceptability.

Making it real instead of paper

A credible programme shows its work. That means an asset inventory that includes OT. A risk assessment that names realistic scenarios. Procedures the crew can actually follow, covering USB media, passwords and what to do when ECDIS behaves strangely. At least one exercised incident scenario. Management review that treats cyber findings like any other nonconformity, with named owners and closing dates. What auditors and inspectors are learning to spot is the opposite: a generic cyber annex added to the SMS that nobody on board has read. The gap between those two states is where the risk lives.

Get New Insights by Email

Practical maritime compliance guidance from our team, sent when we publish. You can unsubscribe at any time.

More Insights

All insights

Put This Into Practice

We support internal ISM, ISPS and MLC audits, and we carry out SMS documentation review against MSC.428(98) and the IACS UR E26 and E27 documentation requirements. We do not perform technical security assessment, penetration testing or forensics. Our work is non statutory: it informs your own audit and your flag's decisions, it does not replace them.

Our reports are prepared for the party that instructs us and for the purpose stated in the engagement. Reliance by any other party requires our written agreement.