Cyber risk management within the Safety Management System
Module objectiveRecognise why MSC.428(98) treats cyber risk as part of safety management rather than as a stand-alone matter.
The current IMO document is MSC-FAL.1/Circ.3/Rev.4, issued on 28 May 2026 after FAL 50 and MSC 111. It is high-level guidance with six functional elements and organisational, operational and technical controls.
For ships subject to the ISM Code, the binding basis remains the SMS implemented under flag, class and applicable law. MSC.428(98) addresses Administrations and brought cyber risk into SMS verification; Rev.4 explains how to structure it.
Module objectiveDistinguish the instruments that make up the maritime cyber framework, whom they address and from when, and whom an incident is reported to.
The layers have different addressees and legal character: ISM/SMS, IMO Rev.4 guidance, E26/E27 class rules and national or EU law are not interchangeable.
Annex I includes passenger and freight water-transport companies, port and port-facility managing bodies and VTS operators; individual vessels are not the entities addressed. The medium-size threshold, Article 2 exceptions, establishment, identification and national law generally matter. A ship manager is not automatically covered merely because it manages a vessel.
Significance depends on severe operational disruption, financial loss or considerable harm. The matrix combines flag, SMS, class, NIS2/national law, insurers, contracts, privacy and law enforcement.
Understanding the distinction between IT (Information Technology) and OT (Operational Technology) systems is the first step towards effective cyber risk management on board, since the two categories require different protection approaches.

| Category | Typical examples on board |
|---|---|
| IT (Information Technology) | Email, administrative systems, communications with the office, crew entertainment |
| OT (Operational Technology) | ECDIS, GPS, engine automation systems, cargo management systems |
Table 3.1 — IT and OT systems on board.
A fundamental principle of onboard cyber security is that OT systems critical to navigation and operational safety should not be reachable by an attack originating in a less protected IT system (for example via a phishing email). Verifying that this segregation is actually in place, not merely declared, is a supervisory task for the DPA and the HSEQ manager.
Module objectiveRecognise the vocabulary in which segregation is written in yard specifications and class reports.
IEC 62443 organises industrial systems into zones and conduits. Segmentation is risk-based: architecture, inventory, flows, dependencies, access and security levels must be verifiable.
IACS UR E26 addresses the integrated ship; E27 addresses onboard systems and equipment. They are class requirements applied according to ship type, tonnage, contract date, scope and class-society rules, not one identical direct duty for yard, supplier and owner.
Deliverables, topologies, configurations, tests and handover responsibilities remain lifecycle assets.
At a conceptual level, it is useful for non-specialist personnel to know the general categories of the most common attack vectors, to recognise warning signs and adopt prudent behaviours, without going into operational technical details that fall outside the scope of this course.

| Category | General description |
|---|---|
| Email phishing | Deceptive communications that induce the user to provide credentials or execute malicious code |
| Uncontrolled removable devices | Unverified USB sticks or external devices that can introduce malicious code |
| Remote maintenance access | External connections for technical assistance that, if not adequately controlled, can be exploited |
| Unprotected wireless networks | Onboard or in-port wireless access points lacking adequate protection |
Table 5.1 — General categories of attack vectors (non-technical overview).
Most onboard cyber attacks exploit human behaviour (opening a suspicious attachment, connecting an unverified device) more than sophisticated technical vulnerabilities. Basic training that increases crew caution often has a greater protective impact than many technical measures.
MSC-FAL.1/Circ.3/Rev.4 uses six concurrent and continuous elements: Govern, Identify, Protect, Detect, Respond and Recover. Govern defines strategy, expectations, policy, roles, resources, continuity and crisis management; the others translate governance into inventory, protection, detection, response and recovery.
NIST CSF 2.0 uses the same six-function architecture. Govern is therefore not an external addition to the current IMO model, although the frameworks remain distinct in nature and application.
Two of the most effective preventive measures, and often the most neglected in daily practice, are rigorous management of access to critical systems and keeping installed software up to date.
External technicians for the maintenance of specific equipment (for example the engine or automation system manufacturer) often require access to critical OT systems: verifying their identity and authorisation and limiting access to the strictly necessary time is an essential protective measure that is often neglected for operational convenience.
The ability to promptly recognise an anomaly, before it escalates into a full-blown incident, depends both on technical tools and on the crew's awareness in recognising unusual system behaviour.
As with the safety reporting seen in the Incident Investigation course, a crew that fears appearing overly cautious tends not to report anomalies that could prove significant, even in the cyber domain. Building a simple, non-judgemental reporting channel for cyber-related doubts is just as important as for traditional operational safety doubts.
Module objectiveRecognise the stages of responding to a cyber incident, from isolating the suspect system to restoring from verified backups and post-incident analysis.
OT incident response is safety-led. A critical system is not automatically disconnected, shut down or restarted.
Module objectiveRecognise the principles of an effective backup policy and distinguish a copy's existence from its actual restorability.
Backup is a recovery capability, not merely an existing copy. It covers data, software, configurations, licences, keys, dependencies, versions, manual procedures and support contacts.
RTO, recovery point, segregation and tests must reflect operational criticality. Technical restore and operational authorisation to return to service are separate decisions, with acceptance criteria and enhanced monitoring.
Module objectiveRecognise why physical access beats almost every network protection, and treat spaces with critical OT equipment as restricted areas.
Physical access can bypass logical controls but does not make segmentation, authentication, logging or least privilege irrelevant. Technical spaces, service ports and removable media enter the cyber assessment.
Restricted areas and ISPS measures derive from the approved SSA/SSP: not every OT space is automatically restricted. SMS, SSP and technical procedures should form coherent defence in depth without universally requiring one-way flow.
Module objectiveRecognise the elements of good cyber security awareness training and the role of organisational culture in reporting errors.
As with the safety and physical security seen in previous courses, cyber security also largely depends on organisational culture and widespread training, not just technical tools.
A crew member who fears punishment for inadvertently clicking a suspicious link will tend not to report it, losing the critical time window to contain the incident. The culture of non-punishment for good-faith errors, already seen for safety, applies identically to cyber security.
Module objectiveRecognise the DPA's oversight of cyber risk as part of the SMS and the management plan they must verify.
Rev.4 requires a person or entity accountable for cyber planning, resources and execution, with authority, support and competence. It does not prescribe the DPA.
The DPA retains ISM functions: ship–management link, safety/pollution monitoring and availability of resources and support. For safety-relevant cyber risks, the DPA verifies that the SMS governs risk and escalation reaches competent authority.
The matrix distinguishes senior accountability, cyber risk owner, Master’s authority, IT/OT, DPA, CSO/SSO, privacy/legal and communications.
Module objectiveRecognise the main directions of change in maritime cyber security, from design requirements to the growth of connectivity on board.
From the Mistake Library of SuperbaKnowledge, filtered to the subjects this course covers. This view selects and organises content published in SuperbaKnowledge; it does not modify or replace it. The linked Knowledge page remains the reference version, while official texts remain authoritative.
| Topic | Mistake | Typical consequence | Topic sheet |
|---|---|---|---|
| Cyber Risk Management in the SMS (MSC.428(98)) | Cyber risk managed as a separate IT matter, not integrated into the SMS's general risk assessment | Lack of integrated documentary evidence in the event of an audit, despite the existence of technical IT measures | See the topic sheet |
| Designated Person Ashore (DPA) | DPA appointed only formally, without real access to top management | NC in certification audit, ineffective escalation system in an emergency | See the topic sheet |
| Management of Change | Changes implemented informally without a structured assessment process | Risks associated with the change not identified before implementation | See the topic sheet |
| Crew Familiarisation and Training | Familiarization treated as a formality to be signed off, without real knowledge transfer | Crew nominally 'familiarised' but unprepared in a real emergency | See the topic sheet |
| Acronym | Definition |
|---|---|
| DPA | Designated Person Ashore |
| ECDIS | Electronic Chart Display and Information System |
| IACS | International Association of Classification Societies |
| ISM | International Safety Management Code |
| IT | Information Technology |
| MSC-FAL.1/Circ.3 | IMO circular carrying the guidelines on maritime cyber risk management; current revision Rev.4, 28 May 2026 |
| NIST | National Institute of Standards and Technology |
| NIST CSF | NIST Cybersecurity Framework — since version 2.0 (2024), six functions: Govern, Identify, Protect, Detect, Respond, Recover |
| OT | Operational Technology |
| Ransomware | Malicious code that encrypts data and systems and demands a ransom for their release |
| SMS | Safety Management System |
| UR | Unified Requirement — an IACS requirement binding on member classification societies |
Consolidated list of the sources cited. Updated as of August 2026.
| Category | Instrument and status |
|---|---|
| IMO/ISM | MSC.428(98); ISM Code; MSC-FAL.1/Circ.3/Rev.4, 28 May 2026 — current high-level guidance. |
| Class | IACS UR E26 Rev.1 and E27 Rev.1 — scope, contract date and class rules apply. |
| EU | Directive (EU) 2022/2555: Articles 2, 20, 21, 23 and Annex I; check national transposition. |
| Frameworks | NIST CSF 2.0; ISO/IEC 27001; IEC 62443 — distinct purpose and scope. |
| Status | Current industry guidance verified at build date; Maritime Cyber Code under development and non-mandatory. |
.
This course is educational material for training purposes and does not constitute a professional certification or qualifying credential. Read the full disclaimer.