Skip to main content
Solutions

Cybersecurity

Cybersecurity, Compliance & Control
Superyachts
Solutions

VISION+

Hands-free intelligence.
Expertise on demand.
Solutions

Remote Access

Remote Access for Maritime
IASME
Authors of the international standard for maritime cyber resilience
Endorsed by the Royal Institution of Naval Architects.
1st
TeamViewer global maritime MSP worldwide
The only specialist maritime managed service provider worldwide.
20+
Years securing critical operations
Our founders have been in the field since 2004. CyberPlus was built on that experience.

Trusted by industry leaders

TeamViewer logo RealWear logo RINA logo Fortinet logo ZeroFox logo

The frameworks exist.
Most operations do not meet them.

Five controls. Here is how we close the gap.

SMS cyber integration

IMO MSC.428(98) requires cyber risk inside your Safety Management System. Most operations have paperwork. Fewer have coverage. A CyberPlus SMS cyber integration review identifies the gap between what the documentation says and what the network shows. Corrective actions delivered before your next P&I renewal deadline.
Satisfies IMO MSC.428(98) ISM Code SIRE 2.0

IASME Maritime Cyber Baseline assessment

Annually certified. Independently assessed. Referenced by the flag states, P&I clubs, and hull underwriters who will audit you. Delivered as a renewable compliance document covering IT networks, OT systems, IoT devices, crew behaviour, and information security. The baseline the industry now measures against.
Covers IT Networks OT Systems IoT Devices People Information

OT network monitoring

Passive, continuous monitoring of operational technology networks with zero risk to live systems. A ruggedised appliance connects to a mirrored switch port, sitting entirely outside the active data path. It does not touch propulsion, navigation, or cargo control. Everything that crosses those networks is logged off-vessel in real time to a tamper-evident store.
Supports IACS UR E26 IEC 62443 NIST

Incident response readiness

A compliance certificate is not the same as operational readiness. The incident response readiness check tests whether your operation can execute a coordinated defence during a live cyber crisis. Not on paper. Under simulated conditions, with real systems, real people, and a CyberPlus specialist observing. The gaps that emerge are the ones that would have mattered.

Cyber causation investigation

Was the engine failure caused by malware? Did ransomware disable safety systems before the fire? Post-incident forensic investigation of whether a physical casualty had a cyber cause. Without pre-installed monitoring, CyberPlus works from native system evidence to produce indicators of causation sufficient to inform legal strategy and coverage decisions. Where our passive monitoring appliance was logging off-vessel before the incident, the investigation produces a timestamped, tamper-evident evidence chain meeting LMAA and Admiralty court chain-of-custody standards.

The IASME Maritime Cyber Baseline

The standard exists because we built it.

The IASME Maritime Cyber Baseline is the internationally recognised framework against which maritime cyber resilience is now assessed. It was developed by the founders of CyberPlus. Endorsed by the Royal Institution of Naval Architects. When a flag state inspector, P&I correspondent, or hull underwriter assesses your cyber posture, the framework they are working from is ours.

Read the standard at IASME.co.uk →
Royal Institution of Naval Architects Endorsed by the Royal
Institution of Naval Architects
The complete ecosystem

Three systems.
One operational posture.

Cybersecurity, remote inspection, and access governance are not separate purchases. Each one feeds the others. This is what an integrated maritime security operation looks like in practice.

↖ The Seas Are Changing

Maritime OT is not
a corporate IT problem.

The wrong security architecture on a dynamic positioning system or cargo automation network does not produce a data breach. It produces an operational failure. Most corporate security tools were not designed for this environment. Some of them will make it worse.

The regulatory framework

IACS UR E26 · The vessel

Mandatory for all vessels contracted from 1 July 2024. UR E26 requires documented cyber resilience across five functions: identification, protection, detection, response, and recovery. It mandates network segmentation between IT and OT and a Cyber Resilience Test Procedure covering the operational life of the vessel. DNV, Bureau Veritas, ABS, and Lloyd's Register have all aligned their class notations to it. Non-compliance is not a fine. It is loss of class.

IACS UR E27 · The systems

Where E26 governs the vessel, E27 governs every individual computer-based system on board. Navigation, propulsion, ballast, SCADA, dynamic positioning, fire detection. Third-party suppliers must prove their systems are cyber resilient before installation. As of late 2024, fewer than 25 systems globally held E27 type approval. Equipment going near your OT network must be verified, not assumed.

IASME Maritime Cyber Baseline

The internationally recognised framework for maritime cyber resilience across the complete threat surface. Developed by the founders of CyberPlus. Endorsed by the Royal Institution of Naval Architects. Referenced by P&I clubs, flag states, and hull underwriters as the baseline standard for cyber posture assessment. When a compliance auditor references a maritime cyber standard, this is the one they mean.

The expert was available.
Getting them there was not.

Structured inspection and SOP workflows

A survey or inspection without a structured workflow produces a report. A Vision+ inspection produces evidence. CyberPlus designs and deploys custom SOP workflows for maritime inspection and survey operations. Every step prompted, every observation timestamped, every annotation recorded against the procedure that required it. The completed report compiles automatically. What reaches the P&I club, the underwriter, or the flag state is not an engineer's notes. It is a structured, timestamped, legally coherent record.

Remote on-the-job training

The expert does not need to be in the room. They need to be able to see, instruct, and verify. Vision+ delivers remote training in live operational environments. The trainee works hands-free with full visual guidance from the expert ashore. Procedures are annotated in real time directly into the field of view. Every session is recorded and timestamped. Competency is documented, not assumed.

You see what I see collaboration

The person on location has the access. The expert ashore has the knowledge. Vision+ closes the gap between them. Live visual collaboration with bi-directional audio, AR annotation directly into the remote operator's field of view, and screen sharing for technical documentation. A surveyor in London can guide a crew member through a fault diagnosis in Singapore. A loss prevention specialist can observe a casualty scene in real time from any desk in the world.

The platform that makes it Vision+

TeamViewer Frontline, TeamViewer Tensor, and RealWear hardware are the components. Vision+ is what CyberPlus puts on top. The maritime-specific SOP library. The workflow design and deployment service. The cryptographic session logging that produces a tamper-evident evidence chain from the moment the session opens. The LMAA chain-of-custody architecture built into the recording infrastructure. The ATEX certification for hazardous zone deployment. Any operator can buy the component tools. None of them come configured for the legal and evidential requirements of commercial maritime operations. That configuration is Vision+.
Vision+ Ecosystem

How the evidence
architecture works.

Read our platform overview to see how Vision+ uses smart glasses and mobile apps to record undeniable evidence and guide crews through step-by-step checklist workflows on board.

Every fleet operation is different. If you need to map Vision+ to your specific class rules, flag state audits, or existing company standard operating procedures, speak with us directly.

The session closed.
The access did not.

Deployed is not the same as governed.

Most maritime operations have remote access. Fewer have governance. The distinction matters the moment something goes wrong. An ungoverned session is a liability that exists in your network long after the contractor who opened it has moved on. A governed session is a dated, attributed, auditable record that demonstrates exactly who accessed what, when, and why. CyberPlus is TeamViewer's first global maritime MSP not because we resell the platform, but because we built the architecture to govern it where ungoverned access has physical consequences.

Vessel operations

OEM engineers connect to bridge systems, engine management, and cargo automation for maintenance and fault diagnosis. Crew rotations happen every four months. Nobody revokes the outgoing engineer's access. The remote access application on the bridge carries credentials from contractors who finished their work two years ago. This is not a hypothetical. It is what CyberPlus finds on almost every vessel it assesses.

Offshore installations

Third-party OEM connections to SCADA systems, dynamic positioning, and safety infrastructure persist long after commissioning visits end. Control system vendors retain access that was never formally revoked. In port operations, the audit trail for a P&I club inspection does not exist in any retrievable form. The access happened. The record did not.

Shore-based operations

Fleet management platforms, voyage planning systems, and shore-to-vessel administrative networks carry the same credential problem at scale. A single compromised shore-based account is the entry point for lateral movement into vessel operational networks. Governance at the shore layer is not separate from vessel security. It is the first line of it.

Three controls. Here is how governance actually works.

Session control and audit

Every connection authenticated, attributed, and logged. Remote sessions are time-limited, scoped to a named individual, and recorded from initiation to close. When a P&I club, flag state auditor, or Admiralty solicitor asks for the access record, it exists. Not assembled under pressure. Generated automatically from day one.
Satisfies IMO 2021 ISM Code IACS UR E26

Credential lifecycle management

Access issued for a purpose ends when that purpose ends. Crew rotations, contractor handovers, refit teams, OEM commissioning visits. Every credential is scoped, reviewed, and revoked automatically. No orphaned accounts. No access that outlives the job it was granted for.
Supports IACS UR E26/E27 NIS2 ISO 27001

Third-party vetting

No external party connects until we have investigated them. Certifications, known vulnerabilities, breach history, dark web credential exposure. Every contractor and sub-contractor assessed before they touch your network. Supply chain access is where maritime and offshore operations are most commonly compromised. We close that before it opens.

Reference Tool

The Maritime Cyber
Compliance Matrix

From SIRE 2.0 to the latest IACS UR E26/E27 mandates, the regulatory landscape shifts faster than most operations teams can track. We have mapped every applicable framework, class rule, flag state requirement, and P&I standard in one place.

Explore the Matrix →
200+ Regulations, standards
and frameworks defined
9 Topical sections covering
P&I, class, flag and cyber
1 Master audit index for
instant cross-reference

Every untracked session leaves an open door. True network protection demands governance that terminates access the moment a task finishes.

Ready to bring absolute governance to your remote operations?

The threat is real. The solution is proven.

Let's Talk