The threat is real. The solution is proven.
Commercial Maritime
The seas are changing.
So are the threats.
CyberPlus secures the operations that maritime depends on.
The certificate said compliant.
The logs said otherwise.
Most organisations pass the assessment. Fewer survive the incident.
The convergence of IT and operational technology has created a threat surface that most organisations have never fully mapped. Not because they chose not to. Because nobody told them it needed mapping.
The exposure sits in the places nobody looks. Credentials that were never revoked. Remote access sessions that were never closed. Inspections that never happened because the asset was too remote, the schedule too tight, or the travel cost too high.
CyberPlus was built specifically for this environment. We authored the IASME Maritime Cyber Baseline, the framework flag states, P&I clubs, and hull underwriters now use to assess maritime cyber resilience. We understand what an auditor actually looks for. We have been inside the control rooms, the server rooms, and the shore operations centres where the gaps live.
We also built Vision+, the first remote inspection and collaboration platform designed from the ground up for maritime legal and insurance requirements. Three capabilities. One integrated system. Here is how each one works.
Solutions
Cybersecurity
Trusted by industry leaders

The frameworks exist.
Most operations do not meet them.
Five controls. Here is how we close the gap.
SMS cyber integration
IASME Maritime Cyber Baseline assessment
OT network monitoring
Incident response readiness
Cyber causation investigation
The IASME Maritime Cyber Baseline
The standard exists because we built it.
The IASME Maritime Cyber Baseline is the internationally recognised framework against which maritime cyber resilience is now assessed. It was developed by the founders of CyberPlus. Endorsed by the Royal Institution of Naval Architects. When a flag state inspector, P&I correspondent, or hull underwriter assesses your cyber posture, the framework they are working from is ours.
Read the standard at IASME.co.uk →
Endorsed by the RoyalInstitution of Naval Architects
Three systems.
One operational posture.
Cybersecurity, remote inspection, and access governance are not separate purchases. Each one feeds the others. This is what an integrated maritime security operation looks like in practice.
↖ The Seas Are Changing
Maritime OT is not
a corporate IT problem.
The wrong security architecture on a dynamic positioning system or cargo automation network does not produce a data breach. It produces an operational failure. Most corporate security tools were not designed for this environment. Some of them will make it worse.
IACS UR E26 · The vessel
Mandatory for all vessels contracted from 1 July 2024. UR E26 requires documented cyber resilience across five functions: identification, protection, detection, response, and recovery. It mandates network segmentation between IT and OT and a Cyber Resilience Test Procedure covering the operational life of the vessel. DNV, Bureau Veritas, ABS, and Lloyd's Register have all aligned their class notations to it. Non-compliance is not a fine. It is loss of class.
IACS UR E27 · The systems
Where E26 governs the vessel, E27 governs every individual computer-based system on board. Navigation, propulsion, ballast, SCADA, dynamic positioning, fire detection. Third-party suppliers must prove their systems are cyber resilient before installation. As of late 2024, fewer than 25 systems globally held E27 type approval. Equipment going near your OT network must be verified, not assumed.
IASME Maritime Cyber Baseline
The internationally recognised framework for maritime cyber resilience across the complete threat surface. Developed by the founders of CyberPlus. Endorsed by the Royal Institution of Naval Architects. Referenced by P&I clubs, flag states, and hull underwriters as the baseline standard for cyber posture assessment. When a compliance auditor references a maritime cyber standard, this is the one they mean.
The expert was available.
Getting them there was not.
Structured inspection and SOP workflows
Remote on-the-job training
You see what I see collaboration
The platform that makes it Vision+
How the evidence
architecture works.
Read our platform overview to see how Vision+ uses smart glasses and mobile apps to record undeniable evidence and guide crews through step-by-step checklist workflows on board.
Every fleet operation is different. If you need to map Vision+ to your specific class rules, flag state audits, or existing company standard operating procedures, speak with us directly.
The session closed.
The access did not.
Deployed is not the same as governed.
Vessel operations
OEM engineers connect to bridge systems, engine management, and cargo automation for maintenance and fault diagnosis. Crew rotations happen every four months. Nobody revokes the outgoing engineer's access. The remote access application on the bridge carries credentials from contractors who finished their work two years ago. This is not a hypothetical. It is what CyberPlus finds on almost every vessel it assesses.
Offshore installations
Third-party OEM connections to SCADA systems, dynamic positioning, and safety infrastructure persist long after commissioning visits end. Control system vendors retain access that was never formally revoked. In port operations, the audit trail for a P&I club inspection does not exist in any retrievable form. The access happened. The record did not.
Shore-based operations
Fleet management platforms, voyage planning systems, and shore-to-vessel administrative networks carry the same credential problem at scale. A single compromised shore-based account is the entry point for lateral movement into vessel operational networks. Governance at the shore layer is not separate from vessel security. It is the first line of it.
Three controls. Here is how governance actually works.
Session control and audit
Credential lifecycle management
Third-party vetting
Reference Tool
The Maritime Cyber
Compliance Matrix
From SIRE 2.0 to the latest IACS UR E26/E27 mandates, the regulatory landscape shifts faster than most operations teams can track. We have mapped every applicable framework, class rule, flag state requirement, and P&I standard in one place.
Explore the Matrix →and frameworks defined
P&I, class, flag and cyber
instant cross-reference
Every untracked session leaves an open door. True network protection demands governance that terminates access the moment a task finishes.
Ready to bring absolute governance to your remote operations?
