The threat is real. The solution is proven.
What you need
to know.
Four pillars. One standard.The questions serious operators actually ask.
The standard others follow.
We wrote it.
IMO 2021, IASME Maritime Cyber Baseline, incident response, and what real cyber defence actually looks like for maritime operators and private clients.
Official certification is granted strictly by flag states and Classification Societies. Our role is to ensure your operations are so thoroughly prepared that the actual audit becomes a mere formality.
For most of the maritime sector, this territory is still entirely new. Traditional maritime advisers rarely understand deep cyber security, while standard tech firms fail to grasp maritime regulation. We are the rare exception that masters both. Because our founders co-authored the IASME Maritime Cyber Baseline, we advise across the entire fragmented matrix. We translate not just the shifting international rules, but the actual technical cyber requirements into a single, cohesive strategy. We bridge the gap between compliance and true defence, ensuring your fleet is both legally bulletproof and genuinely secure.
CyberPlus doesn't just add a supplementary layer to your ship manager's setup; we provide the overarching strategic guidance, advice and monitoring they need to operate safely. A vessel is not a corporate office block. For critical Operational Technology (OT) networks like propulsion and navigation, maritime regulations are uncompromising. Any application that actively interacts with these systems must clear exhaustive type approvals and class certifications before it is allowed on board. In these sensitive environments, we deploy sophisticated, passive monitoring to track threats safely without triggering accidental shutdowns or regulatory deadlocks.
For non-OT systems, we provide comprehensive active management, embedding advanced capabilities like honeypots and deception networks to trap attackers before they can pivot. We bridge the gap between compliance and technical execution, delivering the proactive, multi-layered defence that a general IT desk is simply not engineered to provide.
Detection triggers an immediate, aggressive containment protocol by our SOC. Simultaneously, we arm your team with the secure, out-of-band communication protocols and definitive technical data required to notify your DPA, underwriters and P&I Club without delay. You do not spend the golden hours of a breach figuring out who needs to know what; we provide the clarity required to execute your internal notification checklist instantly. By hour four, containment is finalised and a clear impact brief is delivered. By hour 24, you possess a legally defensible audit trail of the remediation: the exact technical and regulatory standard your insurers demand to honour a claim.
With more than 20 years of high-stakes security lineage defending critical infrastructure and global corporations, we know exactly how modern threat actors operate. In an industry where deep cyber capability is still rare, choosing to discover the difference between an IT checklist and true defence the hard way means you rarely get a second chance to fix it.
On a private vessel, the threat shifts from corporate liability to direct personal vulnerability, where an exploit means targeted physical tracking, guest device compromise and bespoke blackmail. Our superyacht programmes protect the very thing a private vessel is built to provide: total isolation from the outside world. We manage the entire digital perimeter across the full lifecycle of ownership, ensuring that your location, your conversations and your inner circle remain completely invisible to threat actors. We don't just secure the hull; we safeguard the absolute luxury of complete privacy.
We systematically remove the strategic conditions that make an attack viable or profitable. By the time a standard security team or an internal IT desk receives an automated alert, our architecture has already closed the door the attacker was walking towards.
For over twenty years, our analysts have operated in high-consequence environments where the stakes are measured in asset survival and human safety. We do not require an industry primer, an onboarding period or environment orientation. We bridge the gap between complex cyber-physical spaces and international maritime regulation because we helped define the terms.
We replace passive awareness with operational muscle memory. True readiness means designing rigorous, vessel-specific incident response workflows and continuously stress-testing them through live practical drills. We don't just check if your crew can spot a phishing email; we test their workflow knowledge under pressure so they know exactly what to do, and who to contact, the moment a system goes dark. When a real threat materialises, panic is entirely eliminated because calculated tactical action is already in motion.
Sovereign access.
Audited to the session.
As TeamViewer's first global MSP, we govern secure remote access for the world's most demanding operational environments, from vessel control systems to UHNW estates.
As TeamViewer's first global MSP, we implement access controls to enterprise governance standards: role-based permissions, session duration limits, and a complete audit log that satisfies both your legal team and your insurer. For UHNW principals and their advisors, that log is available on demand. Sovereignty over your own infrastructure is not negotiable.
That appointment reflects a specific capability: the ability to deploy TeamViewer into high-stakes, security-critical environments and govern it to the standard those environments demand. On a vessel, an offshore installation, or an estate with distributed infrastructure, that difference matters.
In Mark Oakton's words at the official launch: "Cybersecurity is the foundation of the trust we build with our clients, protecting their business while unlocking new efficiencies and a competitive edge. Our partnership with TeamViewer strengthens that trust, combining cyber expertise with AI, AR, DEX, and remote monitoring and management of IT, OT, and IoT systems."
Read the TeamViewer announcement
As TeamViewer's first global managed service partner, CyberPlus wraps your existing estate in Zero Trust governance. Utilising TeamViewer One for centralised visibility alongside TeamViewer Tensor, we implement role-based access control, conditional access, and full session auditing. We take over management without a disruptive rip-and-replace process, turning an unmonitored risk into a secure, compliant asset.
Our managed TeamViewer Tensor deployments provide enterprise-grade audit trails, end-to-end 256-bit AES encryption, and comprehensive session logging. This delivers the legally defensible proof of control that auditors require, ensuring your remote connectivity actively supports your compliance posture rather than threatening it. For clients in maritime, energy, legal, or financial environments, that audit trail also becomes your first line of defence in the event of an insurance claim or regulatory investigation.
If you are currently running a different remote access tool, we conduct an access audit of your existing estate, identify the governance gaps, and migrate you to a managed TeamViewer architecture without operational disruption. The starting point is your current risk exposure, not your current software licence.
Because every session is logged and attributed through TeamViewer Tensor, we can provide your legal team, insurers, and any regulatory body with a complete, timestamped account of the incident from first access attempt to resolution. In the event of a claim, that audit trail is the difference between a covered incident and a disputed one.
In practice, your existing provider continues handling day-to-day infrastructure. We govern the security overlay: remote access permissions, threat monitoring, incident response, and compliance posture. Most clients find that their IT provider welcomes the delineation.
Our VISION+ platform was designed with these constraints as first principles, not afterthoughts. Remote expert intervention does not require a stable broadband connection; it requires the right architecture.
Through TeamViewer Tensor, we establish highly restricted, monitored "just-in-time" access. Vendors are granted access only to the specific machinery they need to service, for a defined time window, with every action logged and monitored by our cybersecurity team. This protects the wider vessel network while significantly reducing costly physical dispatch fees.
TeamViewer DEX, managed by CyberPlus, shifts your operations from reactive troubleshooting to proactive maintenance. DEX provides continuous telemetry and device intelligence, allowing our team to identify CPU bottlenecks, network degradation, or software crashes before they impact your crew or operations. For mission-critical assets, the difference between detecting a problem at 2am and being called about it at 6am is not cosmetic. It is the difference between a contained anomaly and a full operational outage.
Onboarding typically follows a three-phase process: access audit and credential inventory, governance framework deployment via TeamViewer One and Tensor, and handover to active managed monitoring. For most clients, this is completed without any interruption to existing operations. The goal is that your team notices the governance, not the transition.
Secure control.
Intelligence everywhere.
Live visual collaboration, interactive digital workflows, automated compliance, and real-time business intelligence built on absolute cyber security.
Multiplies Scarce Expertise: It solves the operational strain of distributed teams, shrinking workforces, and ageing expertise by linking your remote or off-shore team instantly to shore-based specialists. A single expert can visually guide multiple crews through complex tasks simultaneously, ensuring critical operational knowledge is shared across the business before it retires. It also stops external stakeholders, clients, and project managers from having to fly out to remote sites or shipyards all the time, allowing them to collaborate and inspect progress live with complete clarity.
Where cyber
meets physical.
Smart-glass-enabled surveillance, executive protection, and maritime security for principals who require more than CCTV.
For a superyacht owner or UHNW principal, that distinction matters because the threat landscape they face combines digital and physical vectors simultaneously. A vessel intrusion, a credential-based access attempt, a compromised vendor device: Eyes-On is designed to identify and respond to all three as a unified security event.
All footage is encrypted, timestamped, and stored in a defensible audit trail that protects both the principal and the operator in the event of an incident or insurance claim.
For family offices managing principal security across multiple locations, Eyes-On provides a unified operational picture rather than disconnected site-by-site reports.
Access to footage is role-permissioned and logged. For UHNW principals and their advisors, data sovereignty is non-negotiable: footage of a principal's movements, guests, or security posture must never leave a controlled environment. We architect that control before the first session begins.
These answer the why.
Four environments. The same standard of resolution.

The 3am Lie
The call comes in at 3am. A contractor, standing on a vessel offshore in a different time zone, tells the support engineer that the equipment is dead. He has checked everything, he says.
He hasn't. Admitting an oversight in front of his crew is not something he is willing to do. So here they are: the meter running at £50,000 an hour, neither man able to move without losing something.
Twenty minutes later, the engineer knows. This is not a technical problem.
Proof by default.
- Hands-free guided workflowsStep-by-step verification on headset. The process does the work, not the conversation.
- Timestamped data captureEvery check recorded automatically. The facts are established before the conversation begins.
- You see what I seeThe engineer sees exactly what the contractor sees. Expertise delivered without a flight booking.

The 35 Year Exit
He has thirty-five years of knowing exactly what a P&I Club needs to see to approve a risk. That instinct exists nowhere except inside his head.
The average age of a maritime inspector is rising towards retirement. When they go, they do not take a checklist with them. They take the ability to spot a liability before it becomes a claim.
"He retired in June. He still reviews 12 P&I inspections a month from his kitchen table in Lisbon."
- Institutional risk captureBest-practice workflows built against specific P&I Club requirements. Junior staff capture exactly what insurers need.
- Remote mentorshipSeniors remain high-value consultants. Juniors are the hands. The expert provides final remote verification.
- Defensible audit trailEvery inspection recorded and timestamped. Institutional memory that outlasts any individual career.

The Quiet Vessel
The captain ran a tight ship. Every system had a procedure. Every vendor had a contract. When the owner's schedule appeared on a charter broker's website six weeks before it was announced, no one understood how.
The vessel had not been hacked in any conventional sense. A former crew member still had active credentials to a navigation system connected to the guest WiFi during a refit three years earlier. No one had revoked them when he left.
The vessel was perfectly maintained. It was completely silent about everything it knew.
"We didn't find a breach. We found seventeen doors that had never been closed."
- Credential lifecycle managementEvery access credential is tied to a named individual and a defined role. When the role ends, the access ends automatically.
- Network segmentation auditGuest, crew, operational, and navigation networks are verified as isolated. Not assumed to be.
- AIS and schedule privacyVessel broadcast settings and third-party data exposure are reviewed against the principal's privacy requirements. A defined protocol, not an afterthought.

The Vendor Key
The estate's IT was exemplary by every conventional measure. Cyber Essentials certified. The IT provider was responsive, professional, and well-regarded. The principal's family office was satisfied.
What no one had reviewed was the remote access credentials issued to the building management vendor during a smart-home installation two years earlier. The vendor had sub-contracted the job. The sub-contractor had since changed ownership. Three people who had never met the principal now had remote access to the estate network.
"The IT provider had done everything right. No one had asked the right questions."
- Third-party access governanceEvery vendor credential is inventoried, permissioned to a defined scope, and subject to periodic re-authorisation. Sub-contractors inherit no access by default.
- Session audit logAll remote access sessions are recorded and attributed. The principal's legal team can request the full audit trail at any time.
- Cyber-physical integrationSmart-home, AV, and building management systems are treated as part of the security architecture. Eyes-On monitoring covers the physical access layer simultaneously.