SuperbaLearning Demonstration release

Platforms
ENIT
Security and investigation · Open learning path Activity-based path

Cyber Security on Board

Cyber risk management within the Safety Management System

14learning modules
AdvancedLevel
SBL-CYB-ADV-01Code
August 2026Reference date

Learning objectives

  • Describe the IMO regulatory framework on cyber risk management (Resolution MSC.428(98)).
  • Distinguish IT and OT systems on board and understand the logic of network segregation.
  • Recognise the main cyber attack vectors at a conceptual level.
  • Apply a cyber risk management cycle (identify, protect, detect, respond, recover).
  • Manage the response path to an onboard cyber incident.
  • Contribute to an organisational culture of cyber security awareness.
Module 01

The regulatory framework: Resolution MSC.428(98)

Module objectiveRecognise why MSC.428(98) treats cyber risk as part of safety management rather than as a stand-alone matter.

The current IMO document is MSC-FAL.1/Circ.3/Rev.4, issued on 28 May 2026 after FAL 50 and MSC 111. It is high-level guidance with six functional elements and organisational, operational and technical controls.

For ships subject to the ISM Code, the binding basis remains the SMS implemented under flag, class and applicable law. MSC.428(98) addresses Administrations and brought cyber risk into SMS verification; Rev.4 explains how to structure it.

Key takeaways

  • Cyber risks must be addressed in the SMS by the first annual verification of the Document of Compliance after 1 January 2021.
  • The resolution encourages Administrations: the non-conformity is written citing the ISM Code, not the resolution.
  • The MSC-FAL.1/Circ.3 Guidelines are high-level recommendations, yet the reference against which an auditor reads the plan.
Module 02

The regulatory layers: who is bound to what, and from when

Module objectiveDistinguish the instruments that make up the maritime cyber framework, whom they address and from when, and whom an incident is reported to.

The layers have different addressees and legal character: ISM/SMS, IMO Rev.4 guidance, E26/E27 class rules and national or EU law are not interchangeable.

NIS2: check scope first

Annex I includes passenger and freight water-transport companies, port and port-facility managing bodies and VTS operators; individual vessels are not the entities addressed. The medium-size threshold, Article 2 exceptions, establishment, identification and national law generally matter. A ship manager is not automatically covered merely because it manages a vessel.

Significant incident and reporting

  • 24 hours: early warning without undue delay.
  • 72 hours: notification with initial assessment and available indicators.
  • On request: intermediate report.
  • Within one month: final report; if ongoing, a progress report and final within one month after handling.

Significance depends on severe operational disruption, financial loss or considerable harm. The matrix combines flag, SMS, class, NIS2/national law, insurers, contracts, privacy and law enforcement.

Key takeaways

  • The instruments have different addressees: a cyber plan built for the SMS does not automatically satisfy the other two.
  • NIS2 requires an early warning within 24 hours of becoming aware of a significant incident, and notification within 72 hours.
  • In the IMO framework there is no duty to notify a cyber incident: the only channel imposed is the SMS one, ISM Code 9.1.
Module 03

IT and OT systems: an essential distinction

Understanding the distinction between IT (Information Technology) and OT (Operational Technology) systems is the first step towards effective cyber risk management on board, since the two categories require different protection approaches.

IT, DMZ and OT as zones, and the conduits linking them: the IEC 62443 model applied on board.
IT, DMZ and OT as zones, and the conduits linking them: the IEC 62443 model applied on board.
Table 5 — IT and OT systems: an essential distinction
CategoryTypical examples on board
IT (Information Technology)Email, administrative systems, communications with the office, crew entertainment
OT (Operational Technology)ECDIS, GPS, engine automation systems, cargo management systems

Table 3.1 — IT and OT systems on board.

Cyber Focus — network segregation is the first line of defence

A fundamental principle of onboard cyber security is that OT systems critical to navigation and operational safety should not be reachable by an attack originating in a less protected IT system (for example via a phishing email). Verifying that this segregation is actually in place, not merely declared, is a supervisory task for the DPA and the HSEQ manager.

Module 04

From segregation to design: IEC 62443 and the class rules

Module objectiveRecognise the vocabulary in which segregation is written in yard specifications and class reports.

IEC 62443 organises industrial systems into zones and conduits. Segmentation is risk-based: architecture, inventory, flows, dependencies, access and security levels must be verifiable.

IACS UR E26 addresses the integrated ship; E27 addresses onboard systems and equipment. They are class requirements applied according to ship type, tonnage, contract date, scope and class-society rules, not one identical direct duty for yard, supplier and owner.

Deliverables, topologies, configurations, tests and handover responsibilities remain lifecycle assets.

Key takeaways

  • A conduit is not a cable but the logical connection between two zones; the security level is assigned to the zone, not the device.
  • E26 addresses the shipyard with 17 requirements for the ship as an integrated system; E27 the supplier with 30 minimum capabilities.
  • E27 requires the supplier to hand over an asset inventory and topology diagrams, which show the real zones and conduits.
Module 05

Most common attack vectors

At a conceptual level, it is useful for non-specialist personnel to know the general categories of the most common attack vectors, to recognise warning signs and adopt prudent behaviours, without going into operational technical details that fall outside the scope of this course.

The four commonest attack vectors, and the zone each one reaches (non-exhaustive overview).
The four commonest attack vectors, and the zone each one reaches (non-exhaustive overview).
Table 9 — Most common attack vectors
CategoryGeneral description
Email phishingDeceptive communications that induce the user to provide credentials or execute malicious code
Uncontrolled removable devicesUnverified USB sticks or external devices that can introduce malicious code
Remote maintenance accessExternal connections for technical assistance that, if not adequately controlled, can be exploited
Unprotected wireless networksOnboard or in-port wireless access points lacking adequate protection

Table 5.1 — General categories of attack vectors (non-technical overview).

Cyber Focus — general awareness is the most widespread defence

Most onboard cyber attacks exploit human behaviour (opening a suspicious attachment, connecting an unverified device) more than sophisticated technical vulnerabilities. Basic training that increases crew caution often has a greater protective impact than many technical measures.

Module 06

The cyber risk management cycle

MSC-FAL.1/Circ.3/Rev.4 uses six concurrent and continuous elements: Govern, Identify, Protect, Detect, Respond and Recover. Govern defines strategy, expectations, policy, roles, resources, continuity and crisis management; the others translate governance into inventory, protection, detection, response and recovery.

NIST CSF 2.0 uses the same six-function architecture. Govern is therefore not an external addition to the current IMO model, although the frameworks remain distinct in nature and application.

Module 07

Access management and updates

Two of the most effective preventive measures, and often the most neglected in daily practice, are rigorous management of access to critical systems and keeping installed software up to date.

General good practice principles

  • Restrict access to critical OT systems to personnel who have an actual operational need.
  • Promptly revoke the access of personnel who disembark or leave the company.
  • Maintain an up-to-date inventory of all onboard digital systems and their update status.
  • Verify the identity and authorisation of every external technician before allowing maintenance access, remote or physical.
Cyber Focus — third-party access is a critical point of attention

External technicians for the maintenance of specific equipment (for example the engine or automation system manufacturer) often require access to critical OT systems: verifying their identity and authorisation and limiting access to the strictly necessary time is an essential protective measure that is often neglected for operational convenience.

Module 08

Anomaly detection

The ability to promptly recognise an anomaly, before it escalates into a full-blown incident, depends both on technical tools and on the crew's awareness in recognising unusual system behaviour.

General warning signs (conceptual level)

  • Abnormal behaviour or unexpected slowdown of critical systems with no apparent cause.
  • Unsolicited and unexpected access requests or communications from apparently legitimate sources.
  • Unauthorised changes to system configurations detected during routine checks.
Cyber Focus — reporting a doubt is always better than ignoring it

As with the safety reporting seen in the Incident Investigation course, a crew that fears appearing overly cautious tends not to report anomalies that could prove significant, even in the cyber domain. Building a simple, non-judgemental reporting channel for cyber-related doubts is just as important as for traditional operational safety doubts.

Module 09

Responding to a cyber incident

Module objectiveRecognise the stages of responding to a cyber incident, from isolating the suspect system to restoring from verified backups and post-incident analysis.

OT incident response is safety-led. A critical system is not automatically disconnected, shut down or restarted.

  1. Detect and record anomaly, time, system and alarms without unnecessary state changes.
  2. Protect navigation and operations, inform the Master and use planned manual or redundant modes.
  3. Escalate under the cyber plan to IT/OT, DPA and other matrix roles.
  4. Contain network, account, service or device only after assessing dependencies, authority and operational consequences.
  5. Preserve logs, configurations and chronology; report according to threshold and regime.
  6. Eradicate and recover to a known, verified state.
  7. Authorise return to service with tests, monitoring and root-cause review.

Key takeaways

  • A clear, well-trained response path reduces the time between detection and containment of the incident.
  • Notification to the DPA or the company's IT/OT manager follows a predefined escalation channel.
  • Reactivating an affected system without verifying its integrity risks reintroducing the vulnerability that caused the incident.
Module 10

Backup and operational continuity

Module objectiveRecognise the principles of an effective backup policy and distinguish a copy's existence from its actual restorability.

Backup is a recovery capability, not merely an existing copy. It covers data, software, configurations, licences, keys, dependencies, versions, manual procedures and support contacts.

RTO, recovery point, segregation and tests must reflect operational criticality. Technical restore and operational authorisation to return to service are separate decisions, with acceptance criteria and enhanced monitoring.

Key takeaways

  • Verified, regularly tested backups are among the most important resilience measures against attacks such as ransomware.
  • Storing backups on media separated from the main network serves to prevent an attack from reaching the copies too.
  • The frequency of backups of critical systems should match the criticality of the system itself.
Module 11

Convergence between physical security and cyber security

Module objectiveRecognise why physical access beats almost every network protection, and treat spaces with critical OT equipment as restricted areas.

Physical access can bypass logical controls but does not make segmentation, authentication, logging or least privilege irrelevant. Technical spaces, service ports and removable media enter the cyber assessment.

Restricted areas and ISPS measures derive from the approved SSA/SSP: not every OT space is automatically restricted. SMS, SSP and technical procedures should form coherent defence in depth without universally requiring one-way flow.

Key takeaways

  • Convergence is viewed from the side of whoever designs the digital protection: what it means that a door may be left open.
  • Anyone who physically reaches an automation cabinet or a service port is already inside the zone, without crossing any conduit.
  • A room with critical OT equipment left freely accessible can allow a malicious device to be connected to critical systems.
Module 12

Training and organisational culture

Module objectiveRecognise the elements of good cyber security awareness training and the role of organisational culture in reporting errors.

As with the safety and physical security seen in previous courses, cyber security also largely depends on organisational culture and widespread training, not just technical tools.

Elements of good cyber security awareness training

  • Periodic training for the whole crew, not only specialist technical personnel.
  • Practical, concrete examples of prudent behaviour (checking senders, caution with external devices), without requiring specialist technical skills.
  • A non-punitive reporting culture for those who make a good-faith error (for example inadvertently clicking a suspicious link), similar to the just culture seen in the Incident Investigation course.
Cyber Focus — punishing the error discourages timely reporting

A crew member who fears punishment for inadvertently clicking a suspicious link will tend not to report it, losing the critical time window to contain the incident. The culture of non-punishment for good-faith errors, already seen for safety, applies identically to cyber security.

Key takeaways

  • Cyber security largely depends on organisational culture and widespread training, not just technical tools.
  • Periodic training covers the whole crew, with concrete examples of prudent behaviour such as checking senders.
  • Punishing a good-faith error discourages timely reporting and loses the window to contain the incident.
Module 13

The DPA's role in cyber risk management

Module objectiveRecognise the DPA's oversight of cyber risk as part of the SMS and the management plan they must verify.

Rev.4 requires a person or entity accountable for cyber planning, resources and execution, with authority, support and competence. It does not prescribe the DPA.

The DPA retains ISM functions: ship–management link, safety/pollution monitoring and availability of resources and support. For safety-relevant cyber risks, the DPA verifies that the SMS governs risk and escalation reaches competent authority.

The matrix distinguishes senior accountability, cyber risk owner, Master’s authority, IT/OT, DPA, CSO/SSO, privacy/legal and communications.

Key takeaways

  • The DPA ensures that cyber incidents are reported with the same priority as traditional safety incidents.
  • The DPA monitors that cyber security awareness training reaches the whole crew, not just technical personnel.
  • The DPA need not be a technical expert: their role is to ensure the management system exists and works.
Module 14

Emerging trends

Module objectiveRecognise the main directions of change in maritime cyber security, from design requirements to the growth of connectivity on board.

  • Current: MSC-FAL.1/Circ.3/Rev.4, 28 May 2026, six elements and minimum controls.
  • Current within scope: IACS E26/E27 Rev.1 for new ships contracted from 1 July 2024.
  • Guidance: current Guidelines on Cyber Security Onboard Ships; the Cyber Security Workbook is separate.
  • Under development, non-mandatory: FAL/MSC Maritime Cyber Code, not an adopted binding code.
  • Monitor: Maritime Single Window, supply chain, remote operations and ship–shore connectivity.

Key takeaways

  • For ships contracted for construction on or after 1 July 2024, cyber security is a design requirement that class verifies.
  • NIST CSF 2.0 adds the «Govern» function, shifting the focus from the technical measure to senior management accountability.
  • The best-prepared companies assess cyber risk already when choosing and installing a new system, not only afterwards as a remedy.

Recurring mistakes

From the Mistake Library of SuperbaKnowledge, filtered to the subjects this course covers. This view selects and organises content published in SuperbaKnowledge; it does not modify or replace it. The linked Knowledge page remains the reference version, while official texts remain authoritative.

Recurring mistakes published in SuperbaKnowledge
TopicMistakeTypical consequenceTopic sheet
Cyber Risk Management in the SMS (MSC.428(98))Cyber risk managed as a separate IT matter, not integrated into the SMS's general risk assessmentLack of integrated documentary evidence in the event of an audit, despite the existence of technical IT measuresSee the topic sheet
Designated Person Ashore (DPA)DPA appointed only formally, without real access to top managementNC in certification audit, ineffective escalation system in an emergencySee the topic sheet
Management of ChangeChanges implemented informally without a structured assessment processRisks associated with the change not identified before implementationSee the topic sheet
Crew Familiarisation and TrainingFamiliarization treated as a formality to be signed off, without real knowledge transferCrew nominally 'familiarised' but unprepared in a real emergencySee the topic sheet

Glossary of acronyms

Table 11 — Glossary of acronyms
AcronymDefinition
DPADesignated Person Ashore
ECDISElectronic Chart Display and Information System
IACSInternational Association of Classification Societies
ISMInternational Safety Management Code
ITInformation Technology
MSC-FAL.1/Circ.3IMO circular carrying the guidelines on maritime cyber risk management; current revision Rev.4, 28 May 2026
NISTNational Institute of Standards and Technology
NIST CSFNIST Cybersecurity Framework — since version 2.0 (2024), six functions: Govern, Identify, Protect, Detect, Respond, Recover
OTOperational Technology
RansomwareMalicious code that encrypts data and systems and demands a ransom for their release
SMSSafety Management System
URUnified Requirement — an IACS requirement binding on member classification societies

References and sources

Consolidated list of the sources cited. Updated as of August 2026.

Table 12 — Current references
CategoryInstrument and status
IMO/ISMMSC.428(98); ISM Code; MSC-FAL.1/Circ.3/Rev.4, 28 May 2026 — current high-level guidance.
ClassIACS UR E26 Rev.1 and E27 Rev.1 — scope, contract date and class rules apply.
EUDirective (EU) 2022/2555: Articles 2, 20, 21, 23 and Annex I; check national transposition.
FrameworksNIST CSF 2.0; ISO/IEC 27001; IEC 62443 — distinct purpose and scope.
StatusCurrent industry guidance verified at build date; Maritime Cyber Code under development and non-mandatory.

.

Educational material

This course is educational material for training purposes and does not constitute a professional certification or qualifying credential. Read the full disclaimer.