A cyber security audit checks whether the ship's computers, the people using them and the Safety Management System (SMS) behind them hold together under pressure. For the Designated Person Ashore (DPA) it is now a core ISM task: IMO Resolution MSC.428(98) asks that cyber risk is addressed in the SMS no later than the first annual verification of the Document of Compliance after 1 January 2021, and auditors test that evidence on board. The threat is rising too. Cydome's 2026 maritime trends report cites a 150% increase in OT incidents and an 800% increase in attacks on edge devices such as routers, firewalls and VPNs. This guide covers the regulatory timeline, OT/IT segregation, a system-by-system exposure matrix, the five IMO functional elements, incident-response roles and a DPA checklist. Start a free trial of Marine Inspection to run cyber audits on a tablet with evidence and corrective actions in one record.
Maritime Cyber Audit: The Numbers That Frame the Risk
150%
OT Incident Growth
Cydome Maritime Trends Report 2026
800%
Edge Device Attacks
Routers, firewalls and VPNs targeted
5
IMO Functions
Identify, protect, detect, respond, recover
2021
SMS Deadline
First DOC verification after 1 January 2021
Cyber Regulation Timeline: What Applies to Your Fleet
Jun 2017
IMO MSC.428(98) adopted
Encourages administrations to ensure cyber risk is addressed in the SMS under the ISM Code.
1 Jan 2021
SMS integration deadline
Cyber risk expected in the SMS by the first annual DOC verification after this date.
1 Jul 2024
IACS UR E26 and E27
Cyber resilience of ships and onboard systems, for new ships contracted for construction on or after this date.
Oct 2024
EU NIS2 transposition
Deadline 17 October 2024 for member states. Affects in-scope EU entities, often larger operators.
16 Jul 2025
USCG cyber rule in force
For US-flagged vessels and MTSA facilities. Reportable cyber incidents go to the National Response Center.
12 Jan 2026
USCG training deadline
Personnel training required, then annually.
16 Jul 2027
USCG plan and officer
Cybersecurity Officer, assessments and Cybersecurity Plan submission due.
AUDIT FOCUSThe IMO route integrates cyber into the existing ISM Code rather than creating a separate instrument. Auditors assess whether risks were identified and safeguards set up through SMS processes, not whether the technical defences are sophisticated. Check your flag and class for any added requirements.
OT/IT Segregation: The Zones Your Audit Should Trace
Outside World
VSAT / satcom, shore networks, remote-support links, port and vendor connections
Firewall, VPN, MFA, logged vendor access
IT Zone
Office PCs, email, crew Wi-Fi, PMS and reporting software, personal devices
Segmentation: only approved data flows cross
OT Zone
ECDIS and integrated navigation, engine control and automation, cargo systems, ballast and safety systems
BIMCO's Guidelines on Cyber Security Onboard Ships v5 recommend firewalls as a minimum at OT/IT interfaces and detail network segmentation. Audit question at each gate: who can cross it, how is it logged, and what happens if it is cut?
Segregation is only as good as its last change. See how Marine Inspection links network and access findings to corrective actions so a gap found on one vessel is checked across the fleet.
System Exposure Matrix: Where to Look First
Priority ratings are our suggested starting point, based on the consequence of loss of the system, not an official ranking. Re-rate using your own ship-specific risk assessment.
The Five IMO Functional Elements and the Evidence for Each
Identify
Asset inventory, ranked ship-specific risk assessment, defined roles
Protect
Segmentation, access control, patching, media and visitor rules, training records
Detect
Log review, alarms, crew reporting route for odd system behaviour
Respond
Incident plan, contacts, authority to isolate systems, drills
Recover
Tested backups, restore procedures, manual-operation fallback
Weaknesses Auditors Keep Finding (From BIMCO v5)
Obsolete or unsupported operating systems
Test: list OS versions on bridge and engine PCs.
Default administrator accounts and weak passwords
Test: ask the ETO to show how accounts are managed.
No segmentation of safety-critical systems
Test: trace one cable or VLAN from OT to the office network.
Untested incident response plan
Test: ask for the last drill record and the lessons logged.
Little crew training on cyber risk
Test: ask a rating what to do with a found USB stick.
Legacy systems not decommissioned
Test: compare the asset list to what is connected.
Put Cyber Findings Into Your SMS Audit Trail
Score each system, attach evidence, assign owners and show top management the fleet-wide cyber picture.
Incident Response: Four Phases and Who Acts
Phases follow the BIMCO Guidelines v5. Role split is our suggested model. Reporting duties vary by flag, coastal state and the USCG rule for US-flagged vessels.
The Evidence Pack an ISM Auditor Expects
01
Ship-specific risk assessment
Ranked hazards, not a generic template
02
SMS cyber procedures
Integrated into existing SMS, not a parallel system
03
Roles and responsibilities
Crew and shore personnel defined
04
Training and familiarisation
Records showing crew knowledge
05
Contingency and recovery
Procedures for system failure
06
Third-party access control
Technician access logged and supervised
DPA Cyber Security Audit Sheet
Checkpoint types:DOCDocument reviewOBSPhysical observationINTInterviewTSTTest or demoRECRecord sample
Governance and SMS
No.CheckpointTypeEvidence to attachResult
C01Cyber risk assessment is ship-specific, ranked and reviewed after changes or incidentsDOCRisk assessment, review datesOK NC N/A
C02Cyber procedures sit inside the SMS, with named roles ashore and on boardDOCSMS manual extract, role listOK NC N/A
C03Top management receives cyber findings through the DPARECManagement review minutesOK NC N/A
C04Master and officers can explain their cyber responsibilitiesINTInterview notesOK NC N/A
OT/IT Segregation and Access
No.CheckpointTypeEvidence to attachResult
C05Asset inventory matches what is actually connected on bridge, engine and cargo networksOBSPhoto of network cabinet, inventoryOK NC N/A
C06Firewall or segmentation between OT and IT, with rules reviewedTSTRule export, review recordOK NC N/A
C07Individual accounts, MFA where available, default passwords changedTSTETO demonstrationOK NC N/A
C08Vendor remote access approved, supervised and loggedRECSession log, approval recordOK NC N/A
Devices, Media and Patching
No.CheckpointTypeEvidence to attachResult
C09USB and technician media scanned before use, including after drydock or lay-upOBSScanning station, media logOK NC N/A
C10Visitor and personal devices screened or kept off critical networksINTCrew answers, visitor logOK NC N/A
C11Unsupported systems identified, with a mitigation or replacement planDOCOS list, mitigation planOK NC N/A
Response and Recovery
No.CheckpointTypeEvidence to attachResult
C12Incident plan known to the master and officers, with contacts and authority to isolate systemsINTInterview notes, plan copyOK NC N/A
C13Backups exist, are stored safely and have been restore-testedTSTRestore test recordOK NC N/A
C14Drill held in the last 12 months, with lessons fed back into the SMSRECDrill report, SMS updateOK NC N/A
Is cyber security mandatory on ships?
IMO Resolution MSC.428(98) encourages administrations to ensure cyber risk is addressed in the SMS by the first DOC annual verification after 1 January 2021. In practice flag states and classification societies verify this during ISM audits. Always confirm your flag's position.
What is the difference between OT and IT on a ship?
IT manages data, such as email, office systems and reporting. OT monitors and controls physical equipment, such as navigation, engines and cargo systems. BIMCO's guidelines recommend OT functions independently, with at least firewalls at interfaces to IT.
What are the five functional elements of IMO cyber risk management?
Identify, protect, detect, respond and recover, set out in IMO's MSC-FAL.1/Circ.3 guidelines, which are now at Rev.3.
Do IACS UR E26 and E27 apply to existing ships?
They apply to new ships contracted for construction on or after 1 July 2024. Existing ships are assessed mainly through the SMS and the IMO route, though some owners adopt E26 and E27 ideas voluntarily.
Who owns cyber risk: the master, the ETO or the DPA?
The company owns it through the SMS, with roles assigned on board and ashore. The DPA's part is to verify it works and to take gaps to top management.
Start a free trial to track those actions to closure.
Make Cyber Audits Repeatable Across the Fleet
One system for checklists, evidence, corrective actions and trends, ready for your next ISM audit.