Skip to main content
Global Maritime Cyber & Compliance Matrix | Knowledge Hub
CyberPlus · Global Maritime Knowledge Hub

Maritime Cyber & Compliance Matrix

All acronyms, organisations, regulations, standards, and technologies
fully defined and grouped by category.

8 topical sections
1 master audit index
200+ entries
May 2026
01

P&I Clubs

P&I Protection & Indemnity mutual third-party liability insurance for shipowners. The International Group of P&I Clubs (IG) comprises 12 independent not-for-profit mutuals covering approximately 87% of world ocean-going tonnage. Claims above ~$10m are pooled across all clubs via the GXL (Group Excess of Loss) reinsurance programme.

International Group all 12 members
NorthStandard
Formed 2023 by merger of North of England P&I and Standard Club. One of the largest IG clubs by tonnage. Recognised as progressive early-movers in integrating comprehensive cyber risk evaluations into mutual third-party liability loss-prevention frameworks.
Gard
Gard AS Norwegian-headquartered; largest IG club by entered tonnage. Consistently recognised as an industry leader in advocating for proactive cyber security and risk management across global fleets. Current IG Group Chair (as of Nov 2025) is Gard's CEO Rolf Thore Roppestad.
Britannia
Britannia Steam Ship Insurance Association London-based mutual managed by Tindall Riley. Mid-size IG club with strong tanker and dry bulk membership.
West of England
West of England Shipowners' Mutual Insurance Association Luxembourg-domiciled, managed in London. Strong in dry cargo and tanker sectors.
UK P&I Club
United Kingdom Mutual Steam Ship Assurance Association (Bermuda) Ltd managed by Thomas Miller. One of the larger IG clubs; offices in London, Hong Kong, Singapore and Japan.
Skuld
Assuranceforeningen Skuld Norwegian mutual, Bermuda-domiciled. Strong in tankers and offshore; known for rapid claims response and global office network including Singapore, Oslo, and Hong Kong.
Steamship Mutual
Steamship Mutual Underwriting Association (Bermuda) Ltd managed by A. Bilbrough & Co. London-based; broad sector coverage including container and dry bulk.
The Swedish Club
Sveriges Ångfartygs Assurans Förening Gothenburg-based. One of the few IG clubs offering both P&I and H&M cover. Strong in Scandinavian and Northern European fleets.
Japan P&I Club
Japan Ship Owners' Mutual Protection & Indemnity Association Tokyo-based; the only IG club domiciled in Japan. Primarily serves Japanese and Asian shipowners.
London P&I Club
London Steam-Ship Owners' Mutual Insurance Association Ltd managed by A. Bilbrough & Co. Focus on dry bulk, tankers and container vessels.
Shipowners' Club
Shipowners' Mutual Protection & Indemnity Association (Luxembourg) specialist in smaller vessels: tugs, ferries, fishing vessels, yachts, and workboats. This segment represents a significant share of the specialised small-craft and luxury yacht market.
American Club
American Steamship Owners Mutual Protection & Indemnity Association, Inc. the only IG club domiciled in the United States; managed by Shipowners Claims Bureau (SCB).
Non-IG notable clubs
China P&I Club
China Shipowners Mutual Assurance Association state-backed; primarily covers Chinese-flag and Chinese-owned vessels. Largest non-IG P&I provider by Chinese tonnage.
Korean P&I Club
Korea Shipowners' Mutual P&I Association Seoul-based; covers Korean-flag and Korean-owned fleet. Non-IG but significant in Asian shipping.
Key P&I terminology
P&I
Protection & Indemnity
Third-party liability mutual insurance for shipowners and charterers. Covers crew injury/death, cargo damage, collision liability, pollution, and wreck removal. Distinct from H&M insurance which covers physical damage to the vessel itself.
IG
International Group (of P&I Clubs)
The 12-club pooling and reinsurance structure. Claims above ~$10m are shared between clubs via the Pool Agreement, underpinned by the Group Excess of Loss reinsurance programme.
GXL
Group Excess of Loss
The IG's collective reinsurance programme, renewed annually. Provides the uppermost layer of cover for catastrophic claims shared across all 12 member clubs.
DPA
Designated Person Ashore
Shore-based officer with direct access to senior management, responsible for implementing the vessel's Safety Management System under the ISM Code. Primary internal lead for P&I and SMS-related matters including cyber compliance.
Loss Prevention
Risk mitigation services funded by P&I clubs to reduce claims frequency and severity. The primary proactive risk mitigation mechanism: clubs frequently allocate dedicated LP budgets to fund vessel security surveys and crew training to minimize casualty frequencies.
SCB
Shipowners Claims Bureau
Management company for the American Club P&I. Referenced in the context of the American Club's structure as one of the 12 IG member clubs.
02

H&M Underwriters

H&M Hull & Machinery marine insurance covering physical damage to the vessel itself, its machinery, and equipment. Distinct from P&I (third-party liability). Predominantly underwritten through Lloyd's syndicates, company markets, and MGAs rather than the mutual club model used in P&I.

H&M
Hull & Machinery
Marine insurance covering physical loss or damage to a vessel and its machinery. Underwritten by commercial insurers and Lloyd's syndicates rather than mutuals. In the event of a physical casualty (grounding, fire, collision), forensic data analysis is increasingly used to determine whether the incident had a cyber-enabled cause, protecting the contractual positions of both underwriters and owners regarding coverage and exclusions.
Lloyd's
Lloyd's of London
The world's leading specialist insurance and reinsurance market, based in London. Lloyd's syndicates are major underwriters of H&M risk. The Lloyd's market increasingly utilises standardised, independent cyber-rated inception surveys to precisely quantify asset vulnerabilities as the risk landscape matures.
MGA
Managing General Agent
An intermediary with delegated authority from an insurer to underwrite policies on their behalf. MGAs are an important distribution channel in the superyacht cyber assessment market as insurers begin requiring cyber assessment at inception, MGAs will be the channel through which the requirement flows to owners.
IUMI
International Union of Marine Insurance
Global association of national marine insurance organisations; co-author of the Industry Guidelines on Cyber Security Onboard Ships alongside BIMCO, ICS, and others. Relevant to how the H&M market collectively approaches cyber risk in underwriting decisions.
Underwriting clauses
CL 380 Exclusion
Institute Cyber Attack Exclusion Clause
The historic marine clause that blanket-excludes any loss or liability caused by a cyber attack from H&M and cargo policies.
The Claims Trap: If your vessel suffers a physical grounding because its bridge ECDIS was corrupted by malware, a standard policy will completely exclude the physical hull claim. CyberPlus provides the forensic casualty data analysis required to determine exactly where an incident falls, protecting your policy coverage.
IUA 09-082 Buy-Back
International Underwriting Association Endorsement
Standard institutional cyber buy-back endorsement allowing shipowners to conditionally reinstate coverage lines for cyber-enabled physical damage.
The Inception Nexus: Much like LMA 5403, triggering this coverage is legally conditional on proving an objective digital baseline. Independent physical-and-digital validation is required to unlock coverage.
LMA 5402 2019
Lloyd's Market Association Marine Cyber Risk Endorsement (Excluding)
LMA clause that explicitly excludes cyber risks from the policy while providing a more precisely scoped exclusion than the blunt CL 380. The key advance over CL 380 is that it defines what is excluded with greater precision, reducing ambiguity in claims handling. An insurer writing LMA 5402 is making the exclusion deliberate and documented rather than merely implied.
LMA 5403 Inception
Marine Cyber Risk Endorsement (Including)
The structural buy-back companion to standard marine cyber exclusions, allowing cyber-enabled asset damage coverage to be reinstated for an additional premium.
The Commercial Reality: Coverage under this clause is legally conditional upon the vessel passing a strict cyber risk assessment at inception. Our physical-and-digital audit framework delivers the exact independent validation required by underwriters to trigger coverage.
JC2025-026 Cargo Theft
JCC Marine Cargo Cyber Exclusion with Physical Theft Confirmation Endorsement
A Joint Cargo Committee endorsement released October 28, 2025, that clarifies coverage boundaries at the intersection of cyber and physical cargo theft. Paragraph 1 retains a standard cyber exclusion. The critical operative mechanism is Paragraph 4: it restores coverage for physical loss or damage by theft of insured goods where a cyber system was used to facilitate access — for example, hackers stealing terminal container release codes — provided that further physical human intervention is subsequently required to commit the actual theft. This "human intervention" qualifier is the legally defining condition.
The Carve-Back Nexus: Unlike the blunt blanket exclusion of CL 380, JC2025-026 Paragraph 4 protects cargo interests when a cyber intrusion facilitates a physical act of theft. The clause draws a precise line: digital-only losses remain excluded, but cyber-enabled physical theft of goods recovers coverage. Our independent survey data helps underwriters isolate terminal access and network vulnerabilities before digital asset tracking loops are targeted.
Market architecture How the H&M Market Works: Cyber Risk Filter Flow
H&M Market Architecture and Cyber Risk Filter Flow
Step 1: Standards & Risk Framework
Who: IUMI (International Union of Marine Insurance)
IUMI acts as the industry's brain. It analyses global marine data and co-authors cyber security guidelines. It does not sell insurance, but its framework sets the tone for how the rest of the market defines "cyber risk."
Step 2: The Capital Providers
Who: Underwriters Lloyd's Syndicates, Corporate Insurers (e.g. Allianz), or a Shared Subscription model
These entities hold the actual capital to pay for ship damages. Taking cues from IUMI's guidelines, they decide they will no longer cover cyber risks "blindly." Because they don't want to micromanage individual niche policies (like superyachts), they hand their underwriting "pen" (Delegated Authority) to specialised MGAs.
Step 3: The Distribution Channel & Owner Requirements
Who: MGAs (Managing General Agents) & Shipowners
The MGA acts as the gatekeeper. To secure or renew an H&M insurance policy, the MGA mandates that the shipowner must prove their vessel is digitally secure. The shipowner is required to undergo a cyber-rated inception survey before the policy can trigger.
Step 4: The Service Core: Cyber Risk Assessment & Forensic Investigation
Who: Independent Maritime Cyber Assessment Specialists
Independent cyber assessment specialists act as the operational bridge (the funnel in the diagram) between the shipowner and the insurance market. At Inception: it conducts the mandatory risk assessment survey on the vessel to satisfy the MGA's requirements. At Claims Stage: if the ship suffers a physical casualty (fire, grounding, or collision), independent specialists investigate the vessel data to determine whether a cyber-attack or system failure caused the physical accident.
Step 5: The Impact & Final Product
Who: Shipowners & Underwriters
Impact on Shipowners
CyberPlus and its maritime inspection partners provide the cyber-rated survey required by MGAs as a condition of H&M cover. In the event of a casualty, forensic data analysis provides a transparent, admissible record to prove whether a claim falls within or outside the policy scope.
Impact on Underwriters
The assessment data generated by CyberPlus and its maritime inspection partners flows back to capital providers, giving them total clarity on whether an incident triggers standard H&M coverage or falls under a cyber exclusion, protecting their financial positions.
03

Classification Societies & Professional Bodies

Classification societies certify that vessels are designed and maintained to established standards. IACS (International Association of Classification Societies) coordinates all 12 member societies and issues Unified Requirements (URs) that every member must embed into their rules. UR E26 and UR E27 mandate cyber resilience for all newbuilds contracted from 1 July 2024, meaning every IACS member society is now building cyber into their standard rules regardless of how prominently they market it. The primary document focuses on societies most visible in CyberPlus's core European and Western blue-water operational focus; the full IACS membership is listed below for completeness. Note on RINA: in this document RINA refers exclusively to the Royal Institution of Naval Architects (a professional body and maritime cyber assessment endorser), not to be confused with Registro Italiano Navale, the Italian classification society that shares the same acronym.

Umbrella body
IACS
International Association of Classification Societies
Umbrella body for the world's 12 major classification societies. Issues Unified Requirements (URs): technical rules agreed by all members and applied consistently across every classed vessel. Issued UR E26 and UR E27 on cyber resilience, mandatory for newbuilds contracted from 1 July 2024. Because these URs are non-negotiable, all 12 member societies are now required to build cyber resilience into their standard rules, not just as optional premium add-ons.
UR E26 / E27 Newbuilds
IACS Unified Requirements
Mandatory unified class rules ensuring the technical cyber resilience of shipboard architectures and operational technologies (OT).
The Integration Bridge: While legally binding for newbuild contracts from July 2024, these rules are now the gold benchmark for the existing fleet. We apply these rigorous standards to active working vessels to ensure total asset protection.
IACS members: primary market focus
LR
Lloyd's Register
British classification society; one of the oldest and largest. Has developed the ShipRight Cyber-Enable procedure for cyber notation. Developing remote inspection and cyber notation capabilities.
BV
Bureau Veritas
French classification and testing/inspection group. Has cyber class notations (Cyber-AT, Cyber-EL, Cyber-RS).
DNV
Det Norske Veritas
Norwegian-headquartered classification society; one of the largest by classed tonnage. Has a tiered Cyber Secure class notation (Basic, Enhanced, Advanced) increasingly required by charterers and insurers.
ABS
American Bureau of Shipping
US-headquartered classification society. Has a CyberSafety notation assessing IT/OT architecture against its own Guide for Cybersecurity. ABS Consulting is also a cybersecurity consulting practice in its own right.
ClassNK
Nippon Kaiji Kyokai
Japanese classification society; the largest by number of classed vessels. Has published supplementary implementation guidelines for IACS UR E26/27 and offers type-approval for cyber-resilient equipment. Key for Japanese and Asian fleet owners.
IACS members: remaining 7 (complete coverage)
Context note: These societies are absent from the primary document not because they lack cyber capability, but because the document is a curated commercial guide tailored to CyberPlus's primary operational focus (European and Western blue-water shipping and superyachts). Every one of these societies has implemented UR E26/E27 and maintains its own proprietary cyber class notations. The pattern is universal: where DNV and BV market their cyber packages aggressively under branded names, the remaining IACS members are doing the same technical work for their own fleets.
CCS
China Classification Society
Chinese flag-state and open-registry classification society; dominant for Chinese-built and owned tonnage. Offers a dedicated Cyber Security class notation (Class-P) and publishes extensive technical guidelines for shipboard cyber systems. Mandatory adoption of UR E26/E27 applies to all newbuilds it classes from 1 July 2024.
KR
Korean Register
South Korean classification society; dominant for Korean-built tonnage from the major yards (Hyundai, Samsung, Daewoo). Actively issues Cyber Resilience and Cyber Resilience (Managed) class notations, assessing onboard networks against data integrity threats. Critical context for any cyber assessment engagement with Korean-built vessels.
IRS
Indian Register of Shipping
Indian national classification society covering vessels in the Indian Ocean region and globally. Features its own Cyber Safety notation and compliance frameworks. Growing in significance alongside the expansion of Indian-flagged and Indian-operated shipping.
RINA (class)
Registro Italiano Navale
Italian classification society and full IACS member. Shares the acronym RINA with the Royal Institution of Naval Architects (a completely separate professional body). Has implemented UR E26/E27 for Italian and Mediterranean-flagged tonnage. Not to be confused with the RINA named in this document, which refers exclusively to the Royal Institution of Naval Architects.
Critical disambiguation: RINA (class) = Registro Italiano Navale, an IACS classification society. RINA (named in this doc) = Royal Institution of Naval Architects, a professional membership body. Same acronym; entirely different organisations.
CRS
Croatian Register of Shipping
Croatian national classification society and IACS member. Covers Adriatic and Mediterranean flagged tonnage. Has implemented UR E26/E27 requirements for newbuilds and maintains cyber-related class rules in line with IACS standards.
PRS
Polish Register of Shipping
Polish national classification society and IACS member. Covers Baltic and northern European flagged and classed tonnage. Has incorporated UR E26/E27 into its class rules for newbuilds contracted from 1 July 2024.
TL
Turk Loydu (Turkish Lloyd)
Turkish national classification society and IACS member. Covers Turkish-flagged vessels and tonnage operating in the Black Sea and Mediterranean. Has implemented UR E26/E27 cyber resilience requirements and issues cyber class notations for compliant newbuilds.
04

Regulations, Codes & Frameworks

Maritime regulations flow primarily from the IMO (International Maritime Organisation, the UN shipping agency) and the ILO (International Labour Organisation). The SMS (Safety Management System) is the vessel's central compliance document set under the ISM Code it is where IMO 2021 cyber risk management requirements must be embedded. The DoC (Document of Compliance) annual audit is the key trigger date for IMO 2021 compliance.

Issuing bodies
IMO
International Maritime Organisation
UN specialised agency responsible for international shipping safety, security, and environmental standards. Issues conventions (SOLAS, MARPOL, STCW), codes (ISM, ISPS), and resolutions (MSC.428(98)). All major maritime regulations originate here.
MSC
Maritime Safety Committee
IMO's senior technical body for safety matters. Issues MSC Circulars and Resolutions including MSC.428(98) the resolution requiring cyber risk management in the SMS from 1 January 2021.
FAL Committee
Facilitation Committee
IMO committee responsible for the FAL Convention on Facilitation of Maritime Traffic. Co-issued MSC-FAL.1/Circ.3 (the IMO 2021 cyber guidance) jointly with the MSC.
Key abbreviations within this section
SMS
Safety Management System
The shipboard management system mandated under the ISM Code. Contains all safety, environmental, and now cyber risk procedures. The vessel's primary compliance document set the IMO 2021 cyber requirement must be embedded here.
DoC / DOC
Document of Compliance
ISM Code certificate issued to a shipping company confirming its SMS has been audited and approved by a flag state or recognised organisation. Annual verification of the DoC is the specific trigger date for IMO 2021 cyber compliance.
SSO
Ship Security Officer
The shipboard officer responsible for implementing the Ship Security Plan (SSP) under the ISPS Code. Reports to the CSO ashore. Key internal lead for ISPS compliance and the cyber-physical security overlap.
CSO
Company Security Officer
Shore-based officer responsible for the company-wide Ship Security Plan under the ISPS Code. Counterpart to the SSO on board. Involved in any port security, piracy response, and ISPS audit coordination.
SSP
Ship Security Plan
The ISPS Code-mandated document detailing security measures, procedures, and responsibilities for the vessel. Contains sensitive information; stored and controlled similarly to the Ship Security Assessment.
CoC
Certificate of Competency
STCW certification issued to seafarers confirming they meet the required standards of training and watchkeeping for their rank and vessel type. Referenced in the STCW row of the regulations table.
PSC
Port State Control
Inspection of foreign vessels by the port authority of the country being visited, to verify compliance with international conventions. EMSA guidance shapes how PSC officers in EU ports assess cyber compliance under IMO 2021 during routine inspections.
Commercial Vetting Standards
DryBMS Vetting
Dry Bulk Management Standard
The voluntary quality framework used by major dry commodity charterers to evaluate the safety management capabilities of ship managers.
The Commercial Impact: Commodity giants utilise DryBMS scores via RightShip to vet operators. Our structural updates imbed auditable cyber-hygiene baselines natively into your SMS to safeguard tier-1 charter clearance.
REG Code Large Yachts
Red Ensign Group Large Yacht Code
The mandatory design and operational compliance standard for commercial yachts over 24 meters in load line length.
The Charter Gate: Recent iterations enforce hard technical security controls over critical emergency and engineering systems. Failure to satisfy these parameters suspends the yacht's commercial charter license. Our targeted assessments keep these high-value assets fully operational.
Green & Environmental Vetting Compliance
Poseidon Principles Finance
Global financial and insurance agreement tracking portfolio alignment with international maritime emissions targets. Because reporting accuracy is heavily reliant on automated shipboard sensor data, the framework is highly vulnerable to cyber-enabled data manipulation.
CII Mandatory
Carbon Intensity Indicator
IMO operational efficiency rating calculated from machinery fuel tracking data. Generated directly by engine room OT loops, this introduces a direct commercial risk where data falsification could be used to artificially inflate a vessel's environmental grade.
EU ETS Mandatory
EU Emissions Trading System
Carbon pricing mechanism tracking engine emissions profiles derived from machinery OT data streams. Because financial liabilities and carbon credits are calculated directly from this data, cyber data integrity is now a material balance-sheet risk.
05

Cyber & Technical Standards / Frameworks

Maritime cyber compliance is not a single rulebook. It is a stack of overlapping obligations, each issued by a different authority, each binding a different actor, and each enforced through a different mechanism. Understanding the stack matters because a gap at any layer can expose a shipowner, an insurer, or a service provider to liability even when every other layer appears satisfied.

How to read this section. The groups below are arranged in order of authority, from the root international obligation downward. Each card carries a badge: mandatory means it is enacted law or regulation with enforcement teeth; guidance means it is voluntary or soft-law but commercially decisive; newbuilds means the hard rule applies to new construction only, though the underlying standard increasingly shapes surveys of existing vessels too.

The core tension. International maritime law moves slowly, by consensus, through the IMO. National and regional law moves faster and is often stricter. Industry bodies and class societies fill the space between the two, issuing guidance and class notations that become commercially mandatory even when they are not legally so. A vessel can be fully IMO-compliant yet commercially unemployable because it fails a charterer's vetting standard or an insurer's inception survey requirement. Independent cyber assessment providers operate precisely in this gap: the regulatory floor is set by IMO, but the commercial ceiling is set by underwriters, MGAs, and vetting platforms, and it is rising faster than the regulators can follow.

A note on scope. The IMO instruments and IACS rules bind the vessel and its operator. The EU instruments (NIS2, DORA, CRA) bind the shore-side organisation, the financial entity, and the equipment manufacturer respectively. The US instruments bind anyone operating in US waters. The industry guidelines bind no one legally but are required by the people who control whether a ship earns freight. Each layer is noted in the cards below.

IMO root obligation. Every other cyber requirement in this section traces back here. IMO Resolution MSC.428(98) does not prescribe technical controls; it simply requires that cyber risk be managed within the ship's existing Safety Management System. The practical effect is that a ship passing its annual ISM audit after January 2021 without any cyber risk documentation is technically non-compliant, regardless of how digitally secure it actually is. This is the regulatory foundation, but it is intentionally minimal: it sets the obligation without defining what compliance looks like, leaving that space to be filled by class societies, flag states, and industry guidelines.
IMO root obligation
IMO MSC.428(98) Mandatory
IMO Cyber Risk Resolution
The root international mandate requiring maritime operators to systematically address cyber risks within approved Safety Management Systems (SMS).
The Audit Trigger: Compliance is verified at every annual Document of Compliance (DoC) audit. We convert this administrative burden into a competitive advantage by engineering lightweight, compliant workflows that pass inspector scrutiny cleanly.
MSC-FAL.1/Circ.3 guidance
IMO Circular joint MSC / FAL Committee guidance
High-level recommendations on maritime cyber risk management, describing five functions: Identify, Protect, Detect, Respond, Recover. The technical companion to MSC.428(98). Not itself legally binding but sets the framework within which MSC.428(98) compliance is assessed.
IACS newbuild class requirements. Where IMO sets the obligation loosely, IACS fills in the technical detail, but only for newbuilds. UR E26 and UR E27 specify exactly how a new vessel must be designed and equipped to be cyber-resilient from the keel up: network segmentation, access controls, software integrity, incident response capability. Every one of the 12 IACS member societies must enforce these rules for vessels contracted after 1 July 2024. The limitation is the word "newbuild": the existing global fleet of roughly 100,000 ships was built before these rules existed, and nothing compels them to retroactively comply. This is why the existing fleet remains the primary commercial opportunity: shipowners with older tonnage face no hard class requirement, but they face growing pressure from every other layer below.
IACS newbuild class requirements
UR E26 newbuilds mandatory
IACS Unified Requirement E26 Cyber Resilience of Ships
Mandatory for vessels contracted for construction on or after 1 July 2024. Requires a cyber risk management system covering the full vessel lifecycle: design, construction, commissioning and operation. Increasingly used as a benchmark for existing fleet assessments even though not technically mandatory for them.
UR E27 newbuilds mandatory
IACS Unified Requirement E27 Cyber Resilience of Onboard Systems and Equipment
Companion to E26, targeting equipment suppliers and system integrators. Specifies 30 minimum security capabilities for all Computer-Based Systems (CBS) and 11 additional capabilities for CBS that interface with untrusted networks. Applies from the same 1 July 2024 contracted-for-construction date.
CBS
Computer-Based System
IACS UR E27 term for any onboard digital system subject to cyber resilience requirements navigation, propulsion control, cargo management, communication systems, and any other networked equipment. The unit of assessment under UR E27.
Flag state national mandatory requirements. Flag states are the countries in which a ship is registered, and they hold direct legal authority over their flagged vessels. Most major open registries (Panama, Liberia, Marshall Islands) have transposed the IMO 2021 obligation into national law and added supplementary guidance. The US is the outlier: through the USCG MTS Rule (enacted July 2025) and its enforcement playbook NVIC 01-20, the United States has gone significantly further than IMO, mandating a named Cybersecurity Officer, a documented Cybersecurity Plan, and annual assessments for any vessel or facility operating in US waters regardless of flag. Critically, the rule operates on a two-phase timeline: mandatory crew training under 33 CFR 101.650 became enforceable on January 12, 2026 — meaning PSC inspectors are checking for training records now — while full Cybersecurity Plan submission and CySO designation is required by July 16, 2027. This extraterritorial reach means even a Panamanian-flagged vessel calling at a US port must comply with both phases. For Singapore MPA, the flag state obligation is directly relevant to operators and inspection providers active in the Asia-Pacific offshore energy market.
Flag states national mandatory requirements
USCG MTS Rule July 2027
US Coast Guard Security Mandate
Enforces comprehensive cyber security plans, active data logging, and designated shipboard Cybersecurity Officers (CySO) under strict NVIC 01-20 inspection playbooks for all tonnage routing inside US territorial waters. The rule operates on a two-phase compliance timeline: the mandatory crew and shore-side training requirement under 33 CFR 101.650 became fully enforceable on January 12, 2026, and is already subject to active Port State Control verification. The hard deadline for full Cybersecurity Plan submission and CySO designation remains July 16, 2027.
The Immediate Enforcement Cliff: The July 2027 deadline does not mean vessels are safe until then. Any vessel trading in US waters whose crew cannot immediately produce verified cyber awareness and response training records during a Port State Control inspection is subject to enforcement action today. The USCG has issued a Training Verification Job Aid to inspectors specifically for this purpose. Our maritime inspection workflows provide the targeted independent validation required to demonstrate compliance and avoid authority detentions.
USCG
United States Coast Guard
US federal maritime authority responsible for maritime safety, security, and environmental protection within US jurisdiction. Issues the MTS cybersecurity rule and enforces MTSA (Maritime Transportation Security Act) requirements at US ports and for US-flagged vessels.
CySO
Cybersecurity Officer
New role mandated by the USCG MTS rule. Responsible for implementing and maintaining the vessel or facility cybersecurity plan. Equivalent in some respects to the SSO under ISPS, but focused on cyber rather than physical security.
MTS
Marine Transportation System
US term for the national maritime infrastructure ports, waterways, vessels, and facilities. Used in "USCG MTS Rule" and "MTS-ISAC". The MTS rule is named "Cybersecurity in the Marine Transportation System."
OCS
Outer Continental Shelf
US term for offshore energy installations (platforms, rigs, facilities) located beyond state territorial waters but within US federal jurisdiction. Subject to USCG MTS cybersecurity rule alongside US-flagged vessels.
CISA
Cybersecurity and Infrastructure Security Agency
US federal agency responsible for national cybersecurity. Its Cybersecurity Performance Goals underpin the USCG MTS rule. CIRCIA (Cyber Incident Reporting for Critical Infrastructure Act) requires critical infrastructure operators to report cyber incidents to CISA within 72 hours.
Panama / Liberia / Marshall Islands / Singapore MPA mandatory
Major open registries and key flag states
All require IMO 2021 cyber compliance for their registered vessels and have issued supplementary guidance. Panama (largest open registry), Liberia, and Marshall Islands together cover the majority of the world's tanker and bulk carrier fleet. Singapore MPA requirements are directly relevant to operators and inspection providers active in the Asia-Pacific region.
MCA
Maritime and Coastguard Agency (UK)
UK flag state administration. Has issued cyber risk management guidance for UK-flagged vessels aligned to IMO 2021. Relevant in the context of IASME (a UK-authored standard) and UK-flagged vessel cyber compliance.
NVIC 01-20 mandatory
US Coast Guard Navigation and Vessel Inspection Circular 01-20
The definitive USCG guidance document that inspectors use to audit and enforce cyber risk management compliance at US ports, facilities, and vessels. Issued in 2020, it provides the practical operational framework that sits beneath the statutory USCG MTS Rule: where the rule sets the legal obligation, NVIC 01-20 tells inspectors what to look for, what questions to ask, and how to assess whether a vessel or facility is compliant. Any vessel or operator active in US waters needs to understand NVIC 01-20 as the enforcement playbook, not just the rule itself.
NRC US Waters
National Response Center
The primary communications node for federal pollution and safety events inside US waters. Mandated under USCG regulations to handle mandatory maritime cyber intrusion declarations alongside physical incidents.
SOC Framework
Security Operations Centre
Central security management hub executing continuous data monitoring actions, log analysis, and threat tracking across fleet infrastructure layouts to satisfy advanced cyber-notation baselines.
EU shore-side and operator obligations. The EU cyber framework is the most structurally complex layer because it operates across three distinct instruments that each hit a different actor. NIS2 hits the maritime operator: ports, shipping companies, offshore energy operators providing essential services in EU member states must meet cybersecurity risk management and incident reporting standards or face fines of up to 2% of global turnover. DORA hits the financial entity: P&I clubs, H&M underwriters, and MGAs operating in the EU must demonstrate digital operational resilience, including oversight of third-party ICT providers. The EU CRA hits the manufacturer: OEMs supplying digital equipment to EU-connected vessels must secure their products and report vulnerabilities, with the critical September 2026 reporting mandate creating a hard deadline. Together these three instruments close the loop: the operator must be secure, the insurer must be resilient, and the equipment in the hull must be built to a verifiable standard. For modern ship operators and surveyors, the CRA is particularly significant because it adds a critical supply chain evaluation dimension to inception surveys that did not previously exist.
European Union shore-side and operator obligations
NIS2 mandatory
EU Network & Information Security Directive 2 (Directive 2022/2555)
Transposed into national law by October 2024; NIS1 repealed. Extends mandatory cyber obligations to maritime operators, ports, and offshore energy operators across EU member states. Requires risk assessments, incident reporting, and supply chain security. Heavy fines for non-compliance. A major commercial driver for the offshore energy cyber services.
The Operational Threat: Maritime, terminal, and logistics entities operating inside EU boundaries risk staggering administrative fines (up to 2% of total worldwide group revenue) for structural failure to manage security vulnerabilities. We embed auditable cyber workflows directly into your operational systems to satisfy European compliance oversight.
CER Directive mandatory
EU Critical Entities Resilience Directive (Directive 2022/2557)
NIS2's physical resilience companion. Covers maritime transport and port operators as critical infrastructure; requires resilience risk assessments and plans. Works alongside NIS2 to create a dual cyber/physical compliance obligation for maritime operators.
DORA mandatory
EU Digital Operational Resilience Act
Applies primarily to financial entities including marine insurers (P&I clubs, H&M underwriters, MGAs) operating in the EU. Requires ICT risk management, incident reporting, and third-party risk oversight. Relevant to how clubs manage cyber risk in their supply chains, including third-party survey and assessment providers.
GDPR mandatory
General Data Protection Regulation
EU data privacy law applying to personal data of crew and customers. Relevant to maritime operators and inspection providers in Europe, particularly regarding digital crew records, remote survey footage, and data held in fleet management systems.
EMSA guidance
European Maritime Safety Agency
EU agency providing technical assistance on maritime safety and security. Published guidance on ship cybersecurity during Port State Control (PSC) audits in November 2023. Shapes how PSC officers in EU ports interpret IMO 2021 compliance during routine vessel inspections.
EU CRA Sept 2026
EU Cyber Resilience Act
Binding European regulation mandating built-in cybersecurity requirements for all supply chain hardware and software products with digital components.
The Supply Chain Trap: Equipment vendors supplying your hulls must meet these rules or face heavy market exclusions. Our independent audits isolate uncertified OEM risks before they compromise your operational compliance.
International technical standards. These are not laws. No flag state or regulator will detain a vessel for failing to implement IEC 62443. What they do instead is provide the technical vocabulary and assessment methodology that every other layer relies on. When the USCG MTS Rule requires a Cybersecurity Plan, it does not specify what that plan must contain technically: it points to standards like the NIST CSF. When a class society issues a cyber notation, the underlying assessment criteria are drawn from IEC 62443. When an insurer's inception survey asks about OT network segmentation, the question is grounded in IEC 62443 zone and conduit architecture. The IASME Maritime Cyber Baseline occupies a distinct role: it is a proportionate, auditable standard specifically designed for the scale and budget of the maritime SME market, and its endorsement by RINA makes it the practical assessment tool sitting beneath the broader framework.
International technical standards
IEC 62443 framework
International Electrotechnical Commission standard series 62443
The primary international standard for OT and Industrial Control System (ICS) cybersecurity. Organised in four parts covering policies, systems, components, and security management. Core framework for offshore and vessel OT assessments. IEC 62443 compliance assessments are increasingly requested by insurers and oil majors as a condition of vessel approval.
The Engineering Reality: Standard enterprise IT security setups will systematically crash or block real-time engineering machinery control systems (steering, fuel valves, engines). We deliver targeted engineering-level audits engineered specifically around shipboard operational technology (OT) loops without risking unexpected equipment shutdowns.
ICS (in this context)
Industrial Control System
Generic term for OT systems including SCADA, DCS, and PLC. Used within the IEC 62443 framework. Note: ICS is also the abbreviation for International Chamber of Shipping context determines meaning.
PLC
Programmable Logic Controller
Industrial computer used in OT environments to automate electromechanical processes valves, pumps, conveyors. Found in terminal SCADA systems and onboard vessel cargo control. A core asset type in IEC 62443 assessments.
NIST CSF framework
National Institute of Standards and Technology Cybersecurity Framework
US-origin risk management framework built around five functions: Identify, Protect, Detect, Respond, Recover. Aligned to the USCG MTS rule and CISA performance goals. NIST also publishes specific maritime sector profiles. "CSF" = Cybersecurity Framework; "NIST" alone is the institute, not the framework.
ISO 27001 framework
International Organisation for Standardisation Information Security Management
ISO/IEC 27001 information security management system standard. Primarily relevant to shore-side ship management company IT infrastructure rather than vessel OT systems. Complementary to IEC 62443 (which focuses on OT) in a holistic security programme.
IASME Maritime Cyber Baseline framework
IASME Consortium Maritime Cyber Baseline standard
UK assurance standard developed by the IASME Consortium. Provides a proportionate, maritime-specific assessment scheme filling the gap between IMO 2021's high-level requirements and full IEC 62443 compliance. Endorsed by RINA (Royal Institution of Naval Architects). Serves as the practical evaluation framework for modern verification assessments.
Industry association guidelines and schemes. This is where the commercial reality of maritime cyber compliance lives. Nothing in this group is legally mandatory. All of it is commercially unavoidable. The Industry Guidelines on Cyber Security Onboard Ships (now in their fifth edition, published November 2024) are the product of every major shipping association publishing a joint document: if a vessel operator cannot demonstrate alignment with these guidelines, they will struggle to satisfy an insurer's inception survey, a charterer's vetting questionnaire, or a P&I club's loss-prevention expectations. BIMCO cyber clauses have moved from optional additions to standard terms in tanker and bulk charter parties. OCIMF SIRE 2.0 and TMSA have embedded cyber questions into the commercial approval process for tanker employment. The key distinction from the layers above is the enforcement mechanism: not a regulator with detention powers, but a charterer who simply will not fix the ship, or an underwriter who will not write the policy. The commercial lever is in many cases more immediately powerful than the regulatory one.
Commercial Urgency Matrix01 · Regulatory Deadlines of Doom
IACS Class Rule July 2024 · In Force

IACS UR E26 / E27

Mandatory unified class rules ensuring the technical cyber resilience of shipboard operational technologies (OT). Binding for newbuild contracts, this framework has rapidly become the universal gold standard for evaluating risk cross-fleet.

Our Value Integration: CyberPlus applies these rigorous parameters to active, existing vessels to deliver the independent validation underwriters demand before triggering coverage options.
EU Infrastructure Directive Oct 2024 · In Force

EU NIS2 Directive

Extends critical cyber management mandates to maritime transport and port infrastructure inside European waters. Structural failure to maintain auditable supply chain protection exposes operators to severe regulatory actions.

Our Value Integration: CyberPlus systematically imbeds compliant security baselines into your fleet operations and SMS, safeguarding your enterprise against corporate turnover penalties of up to 2%.
EU Product Regulation Sept 2026 · Deadline

EU Cyber Resilience Act (CRA)

Mandates built-in cybersecurity configurations for components with digital elements. OEMs supplying critical hull systems (ECDIS, automation, radar) must verify security tracking parameters or face total market exclusion.

Our Value Integration: Pre-purchase asset reviews and independent onboarding audits isolate uncertified third-party component vulnerabilities before they compromise fleet compliance.
USCG Security Mandate July 2027 · Deadline

USCG MTS / NVIC 01-20

Enforces comprehensive security plans, active data logging, and dedicated shipboard Cybersecurity Officers (CySO) under strict NVIC 01-20 inspection playbooks for all tonnage routing inside US territorial waters.

Our Value Integration: CyberPlus delivers the specialised on-board technical audits and standalone validation records required to bypass port authority detention actions.
Industry association guidelines & schemes
BIMCO guidance
Baltic and International Maritime Council
The world's largest international shipping association, representing shipowners, operators, managers, brokers, and agents. Co-author of the Industry Guidelines on Cyber Security Onboard Ships (v5, Nov 2024) alongside ICS, INTERCARGO, INTERTANKO, IMCA, OCIMF, IUMI, and others. Also publishes standard BIMCO cyber clauses for charter parties.
ICS guidance
International Chamber of Shipping
The principal international trade association for shipowners. Co-author of the Industry Guidelines alongside BIMCO. Note: ICS also stands for Industrial Control System context determines which is meant.
INTERCARGO guidance
International Association of Dry Cargo Shipowners
Trade association representing bulk carrier owners and operators. Co-author of the Industry Guidelines on Cyber Security Onboard Ships. Relevant to the dry bulk tanker sector, where cyber risk management is increasingly integrated into vetting criteria.
INTERTANKO guidance
International Association of Independent Tanker Owners
Trade association for independent tanker operators (as distinct from oil company-owned tankers). Co-author of the Industry Guidelines. The independent tanker sector is a core maritime inspection market and a primary focus for integrated cyber add-on services.
WSC guidance
World Shipping Council
Trade association representing container shipping lines. Co-author of the Industry Guidelines. Relevant to eBL adoption and digital cargo integrity verification, which are growing areas of maritime cyber risk.
Industry Guidelines v5 guidance
Guidelines on Cyber Security Onboard Ships, Version 5 (November 2024)
The de facto maritime industry reference document for SMS cyber integration. Produced by BIMCO, ICS, INTERCARGO, INTERTANKO, IMCA, OCIMF, IUMI, ClassNK, and others. Widely required by charterers and insurers as evidence of baseline cyber risk management. Now in its 5th edition.
BIMCO cyber clauses guidance
BIMCO standard cyber security clauses for charter parties
Standard contract clauses allowing owners and charterers to allocate cyber liability contractually in charter parties and contracts of affreightment. Increasingly required in tanker and bulk charter parties as cyber risk becomes a contractual as well as regulatory matter.
OCIMF TMSA guidance
Oil Companies International Marine Forum Tanker Management and Self Assessment
OCIMF's shore-side management quality framework for tanker operators. Element 13 (Maritime Security) includes cyber risk questions. Oil majors use TMSA scores in vetting decisions, creating commercial pressure to achieve strong cyber ratings. Connects the cyber compliance agenda directly to charterer approval.
OCIMF SIRE 2.0 guidance
Oil Companies International Marine Forum Ship Inspection Report Programme v2
Updated OCIMF tanker inspection scheme launched in 2023. Includes explicit cyber and digital system questions within the Vessel Inspection Questionnaire (VIQ). SIRE 2.0's revised cyber questions create a formalised, structured inspection requirement for digital system safety.
VIQ
Vessel Inspection Questionnaire
The structured checklist used in OCIMF SIRE and SIRE 2.0 tanker inspections. SIRE 2.0's revised VIQ introduced explicit questions on cyber risk management, creating a formal inspection requirement where none previously existed.
MTS-ISAC guidance
Maritime Transportation System Information Sharing and Analysis Center
US-based threat intelligence sharing body for the maritime sector. An ISAC (Information Sharing and Analysis Center) is a sector-specific body that collects, analyses, and shares cyber threat information among members. MTS-ISAC contributes to the Industry Guidelines and provides real-time cyber threat alerts.
NORMA Cyber guidance
Nordic Maritime Cyber Resilience Centre
Scandinavian maritime cyber threat-sharing and resilience body. Particularly relevant given that Gard, Skuld, and the Swedish Club are all Nordic-headquartered IG P&I clubs the same clubs that are the primary early-mover targets in the document.
Industrial safety certification & engineering frameworks
ATEX
Atmosphères Explosibles
EU directive and equipment classification system governing electrical and mechanical equipment used in potentially explosive atmospheres, including tanker cargo spaces, pump rooms, and gas-carrying vessels. ATEX-rated equipment carries zone classifications (Zone 0/1/2 for gas; Zone 20/21/22 for dust). Installing non-ATEX-certified electronic monitoring devices in hazardous zones creates both safety and insurance compliance exposure.
FMEA
Failure Mode and Effects Analysis
Structured engineering methodology identifying potential failure modes in a system, their causes, and their effects on overall system operation. Required under ISM Code for critical machinery and increasingly applied to OT cyber risk, mapping how a cyber-induced failure (e.g. falsified sensor output) propagates through vessel systems. FMEA outputs inform both physical maintenance schedules and cyber resilience design.
06

Industry Bodies & Inspection Schemes

Organisations, vetting schemes, and investigation bodies that structure the offshore, tanker, and general maritime inspection markets. OCIMF is the central body here it administers both the SIRE tanker vetting programme and co-administers the OVID offshore vessel scheme alongside IMCA.

Oil major & offshore inspection bodies
OCIMF
Oil Companies International Marine Forum
The oil major body members include BP, Shell, ExxonMobil, Chevron, TotalEnergies, and others. Administers the SIRE tanker inspection programme and co-administers OVID with IMCA. Sets de facto qualification standards that all vessel operators must meet to charter to oil majors.
OVID
Offshore Vessel Inspection Database
OCIMF/IMCA scheme for qualifying offshore support vessels (OSVs) for charter by oil majors and energy contractors. Highly structured, checklist-driven assessments that feed directly into oil major approval databases. Qualified inspectors hold frame service agreements with oil majors to conduct OVID assessments.
SIVAP
Ship Inspection and Vetting Assurance Programme
Related OCIMF offshore vessel inspection scheme, used alongside OVID for certain vessel types and energy contractor qualification requirements. Qualified inspection providers conduct SIVAP assessments as part of their offshore service portfolio.
SIRE
Ship Inspection Report Programme
OCIMF's tanker vetting inspection scheme used by oil majors and charterers to assess tanker quality and compliance before chartering. SIRE 2.0 (launched 2023) introduced explicit cyber and digital systems questions. A core maritime inspection product now incorporating explicit cyber assessment requirements.
TMSA
Tanker Management and Self Assessment
OCIMF's shore-side management quality framework for tanker operators. Companies self-assess against 12 elements; oil majors use TMSA scores in vetting. Element 13 (Maritime Security) now includes cyber risk questions, connecting compliance directly to commercial approval decisions.
IMCA
International Marine Contractors Association
Trade association for the offshore marine contracting industry ROV operations, diving, survey, and construction. Co-administers OVID with OCIMF. Relevant to OVID inspection services and the broader offshore energy cybersecurity market.
CDI
Chemical Distribution Institute
Operates the CDI Marine inspection scheme for chemical tankers similar in function to SIRE but for the chemical tanker sector. Operates alongside SIRE and OTA as part of the broader maritime inspection scheme landscape. Growing cyber dimension as chemical terminal SCADA systems become targets.
OTA
Oil Tanker Assessment
Tanker vetting assessment programme used alongside CDI and SIRE for oil tanker qualification. Used in the context of oil tanker qualification for charter alongside SIRE and CDI.
SIGTTO
Society of International Gas Tanker and Terminal Operators
The primary industry body for LNG and LPG tanker operators and terminal operators, performing a broadly equivalent function to OCIMF for the gas sector. Gas carriers are among the highest-value, most digitally complex vessels afloat: integrated cargo containment systems, re-liquefaction plants, and terminal interface controls create an extensive OT attack surface. SIGTTO publishes operational guidelines and best-practice recommendations that increasingly address cyber risk in gas carrier operations. A high-value segment where cyber assessment capability is increasingly essential given the complexity of gas carrier OT systems.
AHTS
Anchor Handling Tug Supply vessel
Primary offshore support vessel type assessed under OVID. Handles anchors for drilling rigs, tows platforms, and provides supply runs. Carries significant DP (Dynamic Positioning) systems and deck machinery OT. DP cyber vulnerabilities are a specific focus of offshore energy cyber assessments given the safety-critical nature of station-keeping.
PSV
Platform Supply Vessel
Primary offshore support vessel type assessed under OVID alongside AHTS and construction/ROV support vessels. Supplies drilling platforms and rigs with equipment, fuel, chemicals, and provisions. PSVs frequently carry integrated cargo management and DP systems, both of which are OT targets. A primary vessel type assessed under the OVID scheme.
Accident investigation bodies
MAIB
Marine Accident Investigation Branch (UK)
UK government body that investigates marine casualties: groundings, collisions, fires, and structural failures, to determine causes and make safety recommendations. MAIB reports carry significant weight globally and are widely read across the international maritime community. A key stakeholder body for casualty investigation and expert witness services, particularly in cases involving potential cyber causation.
NTSB / USCG
National Transportation Safety Board / US Coast Guard (US)
The two US authorities for marine accident investigation. The NTSB investigates significant US-flagged marine casualties and publishes findings with safety recommendations. The USCG handles the broader enforcement and investigation role for incidents in US waters under MTSA and the MTS Rule. Any vessel or operator involved in a casualty touching US waters will face engagement from one or both bodies. USCG's NVIC 01-20 is the enforcement playbook that underpins maritime cyber causation investigation.
OVV
Onderzoeksraad voor Veiligheid (Dutch Safety Board)
The Netherlands' independent safety investigation body, covering transport, industrial, and maritime incidents. Directly relevant given the Netherlands' position as one of Europe's largest maritime hubs (Port of Rotterdam, major shipping companies). Handles a significant volume of European short-sea, container, and offshore incidents. Dutch Safety Board investigations carry weight across EU member states and are frequently cited in European casualty proceedings.
BSU
Bundesstelle fur Seeunfalluntersuchung (Federal Bureau of Maritime Casualty Investigation, Germany)
German federal marine accident investigation body. Germany is a major European shipping nation with significant container, feeder, and short-sea activity through Hamburg and Bremen. BSU investigates incidents involving German-flagged vessels and incidents in German waters. Given the volume of German-connected tonnage in European trades, BSU findings are frequently relevant to European P&I inspection and casualty investigation work.
Partner & comparable organisations
Van Ameyde Marine
Marine surveying and claims management group with over 130 years of heritage and a global network of surveyors, correspondents, and claims specialists. Delivers technical analyses, on-site damage surveys, and repair attendance across complex vessel casualties in ports and shipyards worldwide.
VIKAND
Maritime crew health and medical services provider offers telemedicine and crew welfare services to the shipping industry. Stands as a highly successful model for how critical, specialised technical programs can be seamlessly delivered to ship operators as an integrated value-add extension of standard fleet technical services.
Intertek
UK global testing, inspection and certification group. Its energy division provides offshore and oil major inspection services with established oil major frame agreements.
Dry bulk & container vetting
RightShip
RightShip Vetting Platform
The dominant vetting platform for the dry bulk and container sectors, performing the equivalent function to OCIMF SIRE in the tanker market. Global commodity charterers (grain traders, mining companies, steel producers) use RightShip to vet bulk carriers before chartering. A poor RightShip grade effectively bars a vessel from the cargo market. Has integrated cybersecurity management and SMS cyber-hygiene into its grading criteria, meaning cyber risk performance now directly affects commercial employability for bulk carriers.
RIQ
RightShip Inspection Questionnaire
The structured inspection questionnaire used in RightShip physical vessel vetting, analogous to the OCIMF VIQ for SIRE. Now includes questions on cyber risk management and Safety Management System (SMS) cyber-hygiene. A bulk carrier whose SMS does not demonstrate adequate cyber risk management will score poorly on the RIQ, directly affecting its RightShip grade and charterer approval. Creates a parallel commercial compliance pressure to SIRE 2.0 for the bulk carrier and container sector.
Professional & endorsing bodies
RINA
Royal Institution of Naval Architects
Professional membership body for naval architects and marine engineers. Not a classification society and not an IACS member. RINA has endorsed the IASME Maritime Cyber Baseline, making it a recognised credentialling anchor for cyber assessment authority in the professional maritime community. Its endorsement signals professional legitimacy to a technical audience rather than a regulatory or commercial obligation.
Not to be confused with Registro Italiano Navale (the Italian classification society listed in Section 03), which shares the same acronym. This card refers exclusively to the Royal Institution of Naval Architects.
Legal & Dispute Stakeholders
LMAA
London Maritime Arbitrators Association
The leading arbitral body for commercial shipping disputes under English law. Arbitrators increasingly require forensically admissible, immutable digital logs to resolve complex navigation and cargo allocation suits.
Admiralty Solicitors
International legal partnerships specializing in shipping, maritime commerce, and commodities. Act as the primary commissioning parties for independent, forensically sound cyber causation and expert witness reports following a casualty.
HVR Seaworthiness
Hague-Visby Rules
The foundational international legal framework governing carrier liability and cargo damage exemptions under bills of lading. Article III Rule 1 imposes a non-delegable duty on the shipowner to exercise due diligence to make the vessel seaworthy before and at the commencement of a voyage — encompassing hull, machinery, and, increasingly, digital systems.
The Cyber-Seaworthiness Standard: If a vessel suffers a physical casualty because its bridge systems or main engines fail due to unpatched OEM software or corrupted digital charts, cargo interests will legally argue the vessel was unseaworthy at inception. Successfully establishing this significantly undermines the owner's ability to rely on the liability limitations and exemptions the HVR would otherwise afford — exposing them to the full measure of cargo claims.
GA Liability
General Average
The ancient maritime legal principle — codified in the York-Antwerp Rules — under which extraordinary sacrifices or expenditures made voluntarily during a common peril are shared proportionally among all cargo and hull stakeholders. Typically declared by a shipowner following a serious casualty requiring salvage, emergency port calls, or cargo sacrifice.
The Contribution Defence: Following a cyber-driven grounding or propulsion loss, shipowners may declare General Average to recoup salvage and extraordinary costs. However, where cargo underwriters can establish a causal link between the casualty and a demonstrable failure to maintain reasonable cyber hygiene — for example, a failure to address known vulnerabilities contrary to the owner's obligations under IMO MSC.428(98) — the owner's legal standing to claim GA contributions from cargo interests is significantly undermined. The determination ultimately rests on causation, not hygiene status alone.
07

Technology Systems & Service Landscape

Split into two parts. Part A shipboard and industrial systems referenced in cyber risk, casualty, and inspection contexts. Part B the service provider landscape: a taxonomy of the types of organisations operating adjacent to maritime cyber assessment services, their operational focus, and the key integration gap each category leaves open for combined physical-and-cyber specialists.

Part A navigation systems
ECDIS
Electronic Chart Display and Information System
Mandatory electronic navigation chart system. The primary cyber attack vector on the bridge ECDIS compromise can cause grounding by displaying false position or chart data. GPS spoofing feeds false position data directly into ECDIS. A primary target in maritime OT cyber assessments.
GPS / GNSS
Global Positioning System / Global Navigation Satellite System
GPS (US system) is one of several GNSS constellations others include GLONASS (Russia), Galileo (EU), and BeiDou (China). Satellite navigation feeds ECDIS, AIS, and DP systems. Spoofing and jamming are documented, growing threats. Compromised position data underpins many cyber causation investigations.
AIS
Automatic Identification System
Mandatory vessel transponder broadcasting identity, position, course, speed, and voyage information. AIS spoofing broadcasting false vessel identity or position is used in piracy, sanctions evasion, and collision risk scenarios. A key data source in both casualty investigation and port security assessments.
NMEA 0183 / 2000 Vulnerability
Marine Electronics Data Protocol
The standard protocol used for communication between marine electronic instruments (GPS, radar, echo sounders, and autopilots).
The Blind Navigation Risk: NMEA data streams lack native data encryption or origin authentication. If an attacker gains physical or network access, they can feed spoofed GPS or AIS data directly into your ECDIS, altering your coordinates on-screen while bridge instruments falsely appear to read normally. Our on-board surveys analyse network interfaces to isolate these vulnerabilities.
CHIRP
Confidential Hazardous Incident Reporting Programme
UK safety reporting body providing anonymized human-element error logs and professional learning resources. Crucial for tracking how crew behavioral patterns interface with digital bridge systems and security workflows.
INS / IBS Architecture
Integrated Navigation System / Integrated Bridge System
A centralized network fabric interconnecting mandatory bridge systems including ECDIS, radar, autopilot, AIS, and positioning sensors into a unified operational platform. The INS/IBS is the architectural layer above individual instruments — it is what transforms standalone navigation equipment into an interconnected bridge environment.
The Lateral Threat Layer: Under IACS UR E26, modern bridge vetting evaluates the entire INS infrastructure rather than standalone components in isolation. Because these systems typically exchange data over unencrypted NMEA 0183 or NMEA 2000 serial networks, a breach of a single non-critical peripheral can compromise the operational integrity of the entire navigation platform — a single point of compromise with fleet-wide safety implications.
Part A OT / industrial control systems
OT
Operational Technology
Hardware and software that directly monitors or controls physical equipment and processes: bridge navigation, engine management, cargo control, ballast systems, mooring automation. The primary focus of vessel-level cyber assessments. Fundamentally different from IT (business networks) in its safety-critical nature and patching constraints.
IT
Information Technology
Data networks, crew internet, administrative systems, email, and business applications. The most common entry point for ransomware and phishing attacks that then pivot to OT systems. Proper IT/OT network segregation is a core criterion in every vessel cyber assessment, and lack of it is the most common finding.
SCADA
Supervisory Control and Data Acquisition
Industrial control system managing physical processes at oil terminals, offshore platforms, and refineries valves, pumps, safety systems, and pipeline flow. Among the most cyber-targeted industrial environments globally. Terminal OT/SCADA security reviews are an increasingly standard component of offshore and liquid cargo cyber assessments.
DCS
Distributed Control System
Process control system used in terminals and tankers to manage cargo loading, ballasting, and temperature. Targeted for manipulation in liquid cargo fraud scenarios digital DCS manipulation can mask cargo shortfall or falsify transfer measurements. Assessed in the liquid cargo and bunker fraud service lines.
DP
Dynamic Positioning
Computer-controlled system maintaining a vessel's position without anchors using thrusters and positioning references. Critical on OSVs and drill ships. Cyber compromise of DP systems could cause loss of position near a platform or subsea infrastructure a catastrophic safety risk and the primary cyber concern in OVID assessments.
ROV
Remotely Operated Vehicle
Subsea robot used in offshore inspection, cable laying, platform support, and pipeline inspection. Onboard control systems are OT environments subject to the same cyber exposure as surface vessels. Relevant to offshore energy cyber assessments and OVID inspection scopes.
OEM Telemetry Vulnerability
Original Equipment Manufacturer Remote Maintenance Loops
Inbound vendor connections — typically persistent VPN tunnels or remote desktop sessions — maintained by machinery manufacturers (engine, propulsion, automation, and power management OEMs) for continuous fuel diagnostic tracking, performance monitoring, and remote technical assistance. These links are a contractual standard in modern vessel delivery and service agreements.
The Supply Chain Backdoor: These permanent remote access pathways are typically provisioned at yard delivery and thereafter operate outside the day-to-day visibility and structural control of the DPA or CSO. They represent a prime supply chain attack vector: a breach of the land-based OEM's enterprise network can provide a direct, authenticated bridge into a vessel's active physical control loops — bypassing shipboard perimeter controls entirely.
Part A evidence & data recording
VDR
Voyage Data Recorder
The ship's "black box" records bridge audio, radar images, AIS data, ECDIS position, GPS, engine telegraph, and other bridge equipment data. Time-critical in cyber causation investigations: VDR data must be preserved within hours of an incident before rolling overwrite cycles erase it. Digital evidence preservation is a time-critical component of any post-incident cyber causation investigation.
Part A cargo & liquid measurement
Coriolis MFM
Coriolis Mass Flow Meter
A Coriolis-effect sensor measuring fluid mass flow and density directly in the pipe. Used for bunker quantity determination and custody transfer. The meter's onboard microprocessor and serial output (typically Modbus RTU) introduce a cyber-physical interface: manipulated calibration constants or tampered pulse outputs can falsify delivered quantity without visible mechanical signs. Post-delivery disputes increasingly require forensic review of meter event logs.
BMW
Bunker Management Workstation
Dedicated PC or HMI terminal aboard a bunker barge or receiving vessel that aggregates flow-meter data, calculates received quantities, and generates the Bunker Delivery Note. Typically Windows-based and network-isolated but vulnerable to USB-borne malware and unauthorised configuration changes. A tampered BDN produced by a compromised workstation may not match independent flow-meter records, a key forensic indicator in quantity-dispute investigations.
Modbus
Modbus Protocol
Serial communication standard (Modbus RTU / Modbus TCP) dominant in maritime OT environments for linking PLCs, flow meters, sensors, and HMI panels. Modbus has no native authentication or encryption: any device on the bus can read or write registers. An attacker with physical or network access can falsify sensor readings, alter setpoints, or disable alarms without credentials. Modbus exposure is a primary finding in maritime OT cyber assessments.
ASTM
American Society for Testing and Materials
Standards widely adopted for bunker sampling, density measurement, and custody transfer calculations (e.g. ASTM D1298, D4052). ASTM-defined procedures determine how flow-meter data is converted to volume at standard conditions. Where digitised calculation workstations apply ASTM formulae, software version control and audit-log integrity become compliance considerations in dispute resolution.
Part A enterprise remote support & network tools
TWF
TeamViewer Frontline Workplace
Augmented-reality (AR) remote support platform enabling shore-based experts to see live vessel environments through crew-worn smart glasses and provide real-time guided assistance. Combines hands-free video streaming, annotation overlay, and document display. Relevant to remote inspections, repair oversight, and crew training. Creates a cyber-physical integration point requiring secure authentication and encrypted data transmission to prevent interception or session hijacking.
SPAN Port
Switched Port Analyser
A network switch feature that mirrors traffic from one or more ports to a designated monitoring port, enabling passive network analysis without disrupting live traffic. Used in maritime OT cyber assessments to capture and inspect Modbus, NMEA, and other industrial protocol traffic for anomaly detection. Misconfigured SPAN ports can inadvertently expose sensitive operational data.
SLA
Service Level Agreement
Contractual commitment defining minimum performance standards (response times, availability, escalation paths) between a service provider and a client. In maritime cyber and survey contexts, SLAs govern incident response timelines, inspection turnaround, and escalation to specialist resources. Clear SLA terms are a prerequisite for insurer-approved cyber monitoring retainer services.
USB
Universal Serial Bus
Ubiquitous removable storage and peripheral interface standard. Aboard vessels, uncontrolled USB device use is one of the most common malware introduction vectors into air-gapped or network-isolated OT systems, including ECDIS, engine management, and cargo computers. USB port controls and media scanning policies are standard recommendations in maritime OT cyber baseline assessments.
LEO Connectivity
Low Earth Orbit Satellite Array
High-bandwidth, low-latency satellite constellations (e.g., Starlink Maritime, OneWeb) providing constant, high-speed cloud connectivity to deep-water fleets at a fraction of legacy VSAT costs. LEO adoption has accelerated dramatically since 2022–2023, fundamentally changing the vessel connectivity baseline and the associated attack surface.
The Shadow Network Risk: The rapid rollout of LEO arrays frequently bypasses the restrictive firewall and traffic inspection architecture of legacy corporate VSAT installations. Crew members or visiting vendors connecting unmanaged LEO hardware directly into onboard switch fabrics create unmonitored network paths — potential backdoors into the vessel's IT and engineering core that exist entirely outside the DPA's and CSO's visibility and control frameworks.
Part A digital documentation
eBL
Electronic Bill of Lading
Digital replacement for the paper cargo title document. Adoption is accelerating rapidly across the container and bulk shipping markets. Creates new demand for digital cargo integrity verification: who confirms the eBL data matches the physical cargo? As eBL adoption accelerates, independent digital cargo integrity verification becomes an increasingly important service.
Cloud SMS Platforms Vulnerability
Cloud-Hosted Ship Management Systems
Centralized, cloud-native software ecosystems — fleet maintenance logs, crew scheduling, procurement trackers, certificate managers, and planned maintenance systems (e.g. Danaos, Helm CONNECT, AMOS, DNV Nexus) — utilized by shore-side management teams to run multi-vessel networks via continuous synchronisation updates pushed automatically to shipboard installations.
The One-to-Many Threat: Centralized management suites represent an acute supply chain concentration risk. A breach of a software provider's land-based infrastructure — or a compromised automatic update package — can propagate malware or malicious configuration data past vessel firewalls simultaneously across an entire managed fleet. Unlike a single-vessel incident, a compromised SaaS provider update can trigger cascading failures across dozens of vessels in a single push cycle. Our structural risk profiling systematically evaluates and insulates shipboard networks from third-party vendor update pathways.
Industrial OT & ICS Security Software Platforms
Continuous OT Network Monitoring Platforms
Enterprise software providers specializing in continuous passive network monitoring, deep packet inspection of industrial control protocols, and automated asset discovery for shore-side plants and large offshore infrastructure.
Operational Focus: Continuous passive asset visibility & threat hunting software.
Market Position: Exceptional automated software depth within static industrial control environments.
The Integration Gap: Software-centric models lack practical maritime survey context. They cannot perform physical structural safety audits or evaluate localised vessel operational conditions.
Maritime Cyber Specialists & Advisories
Niche Maritime Cyber Consultancies
Specialised cyber risk advisors focusing on vessel network architecture, high-level policy design, and basic fleet-wide cyber risk profiling tailored to shipping office frameworks.
Operational Focus: Policy design, compliance gap analysis, and standard threat logging.
Market Position: Tailored exclusively to generic maritime IT and high-level fleet dashboards.
The Integration Gap: Pure cyber advisors operate in a silo. They cannot combine technical network assessments with mandatory physical statutory condition surveys in a single unified deployment.
Traditional Marine Survey & Classification Entities
Classification-Linked Inspection Bodies
Global testing, inspection, and verification giants leveraging existing international surveyor networks to offer technical rules and optional cyber security notations tied directly to hull certification.
Operational Focus: Heavy asset inspections, statutory yard supervision, and notation auditing.
Market Position: Immense institutional scale, vast international networks, and rigid rule authority.
The Integration Gap: Driven by rigid, formal, rule-book frameworks. They often lack the agile, commercially tailored, insurer-neutral approach required for rapid risk profiling and real-time operational dispute resolution.
APAVE
Global testing, verification, and inspection entity operating heavily inside industrial energy and offshore assets, moving adjacently to technical marine cyber survey spaces.
Maritime Training & E-Learning Providers
Consolidated Crew E-Learning Platforms
Large maritime training groups providing generalised crew computer-based training (CBT) modules covering basic safety, security, and digital hygiene principles.
Operational Focus: Pre-recorded compliance training and generic digital hygiene modules.
Market Position: Mass market fleet-wide distribution and deeply embedded e-learning platform access.
The Integration Gap: Limited to static, generic video modules. They lack interactive, vessel-specific OT environment training or real-time remote engineering mentorship tools.
08

Market Segments & Client Types

Vessel types, target client segments, and commercial formats referenced throughout the document, grouped by category for executive clarity.

A · Vessel types
OSV
Offshore Support Vessel
Umbrella term for vessels supporting offshore oil and gas operations includes Platform Supply Vessels (PSV), Anchor Handling Tug Supply vessels (AHTS), and construction/ROV support vessels. The primary vessel type assessed under OVID inspections. Carries significant DP, deck machinery, and cargo control OT systems.
LNG Carriers
Liquefied Natural Gas
Among the most complex OT-intensive vessel types: cryogenic cargo management, reliquefaction systems, and highly integrated automation make these vessels some of the highest-cyber-exposure assets afloat. Shell, TotalEnergies, and the major LNG portfolio operators are the principal client base.
Bulk & Container Fleet
Dry bulk carriers · Container ships
The backbone of global trade. Hundreds of millions of DWT of bulk carriers and container ships operating under IMO 2021 cyber compliance obligations. RightShip's RIQ vetting scheme is driving cyber requirements directly into this sector: bulk carriers and container vessels must now demonstrate cyber compliance to satisfy charterer and cargo-owner approval databases. INTERCARGO (dry bulk) and WSC (container lines) are the key trade associations; BIMCO cyber charter party clauses apply across both segments. This is a high-volume, compliance-driven market where proportionate, structured cyber baseline assessments deliver measurable value.
MASS Autonomous
Maritime Autonomous Surface Ship
Vessels running automated, highly connected, or entirely remote operational pathways. This segment represents the absolute ceiling for maritime cyber exposure, demanding bulletproof technical network architecture.
B · Target client segments
P&I Clubs
Protection & Indemnity mutuals
The 12 International Group P&I Clubs cover approximately 87% of world ocean-going tonnage. P&I clubs fund loss prevention inspections and casualty investigation at scale. Independent maritime cyber assessment is directly relevant here on two fronts: (1) cyber causation investigation: determining whether a physical casualty had a cyber-enabled cause is a new and growing claims discipline for which P&I clubs commission specialist surveys; (2) cyber loss prevention programmes, where clubs fund annual fleet loss prevention at scale and the combined physical inspection and cyber assessment offering (IMO 2021 assessment, crew awareness training, SMS cyber integration review) maps directly onto existing P&I loss prevention budget lines. The leading progressive mutuals consistently pave the way for integrating advanced digital risk matrices into standard loss-prevention criteria. Section 01 of this matrix defines all 12 IG member clubs individually.
H&M Underwriters
Hull & Machinery insurers
Commercial insurers (Lloyd's syndicates, company market, MGAs) covering physical vessel damage. A distinct client type from P&I clubs: commercially driven rather than mutual, with different product needs: inception surveys, cyber-rated physical assessments, and causation investigation rather than loss prevention programmes. Section 02 of this matrix covers the full H&M underwriter landscape including the Lloyd's market, IUMI, and the key MGA distribution channel for superyachts.
Third-Party Ship Managers
V.Ships · Anglo-Eastern · Bernhard Schulte · Fleet Management
Major independent ship management companies that run day-to-day vessel operations including IT/OT systems, crew, and regulatory compliance, on behalf of asset-owning clients. In the real-world operating model, shipowners delegate cyber compliance responsibility to their manager: the manager selects the assessment provider, manages the SMS, and is accountable to the P&I club and flag state. Third-party managers are therefore a critical direct client segment for fleet-wide maritime cyber assessments and crew training programmes. The four largest managers (V.Ships, Anglo-Eastern, Bernhard Schulte, Fleet Management) collectively manage several thousand vessels and represent a highly concentrated route to scale. A single framework agreement with one major manager generates recurring multi-vessel revenue immediately.
Oil Majors
BP · Shell · ExxonMobil · TotalEnergies · Chevron
Large integrated oil and gas companies that charter OSVs and require OVID qualification. Beginning to mandate cyber requirements for offshore vessel qualification, the commercial pull mechanism for integrated OVID + cyber assessment services in offshore markets. Oil major approval is a gate condition for OSV employment: cyber non-compliance risks a vessel being removed from approved vendor lists.
UHNW Superyacht Owners
Ultra High Net Worth
Privacy-sensitive, premium buyers who value discretion and expertise over price. Increasingly asking about cyber security as superyachts carry sophisticated networked AV, bridge, and smart-home OT systems. A high-margin, low-volume segment with growing cyber assessment requirements. MGAs and specialist superyacht H&M underwriters are the primary distribution channel into this segment.
Ship Finance Banks / Lessors
Banks and leasing companies (including KfW IPEX-Bank, ABN AMRO, Citi, and major Chinese lessors) that finance vessel acquisitions. Increasingly tying maritime loans to ESG and cyber-risk verification as part of lender due diligence. The proposed "Lender Cyber Assurance Package" targets this segment, providing cyber risk certification as a condition of financing, creating a recurring product mandated at the birth of a vessel's financing cycle and tied to class renewal.
Flag States
National maritime administrations that register vessels and enforce international conventions on their fleet. Key regulatory bodies overseeing newbuild safety certifications and the issuance of standardised Cyber-Ready verifications at vessel delivery. The major open registries (Panama / AMP, Liberia / LISCR, Marshall Islands / RMI) are the most commercially significant, together covering the majority of the world's deepwater fleet.
BOR
Bunkers Remaining On Board
Liquid fuel volume logs stored within vessel tanks. Falsification of BOR measurements via tampered digital tank-gauging systems is a primary driver for forensic quantity dispute litigation.
C · Commercial formats
CPD
Continuing Professional Development
The commercial format for Maritime Training Academy training events sold to P&I and H&M underwriting teams as team training. CPD events count toward professional qualification requirements (particularly for Lloyd's and company market underwriters), creating a recurring demand cycle separate from regulatory compliance pressure. CPD is a delivery and revenue format, not a market segment; it is the vehicle through which the Academy reaches the client segments listed above.
SOP
Standard Operating Procedure
Documented, repeatable procedural workflows utilized during physical asset deployments to remove variable interpretation and standardize on-site cyber baseline surveys.
Stakeholder Viewports02 · Role-Based Navigation Maps

Select your sector viewport to isolate targeted vulnerabilities and operational vocabulary parameters:

Vessel Operations & Certificate Maintenance

Your driving challenge is protecting commercial uptime, implementing compliant network standards, and passing Document of Compliance (DoC) validation cycles. If system infrastructure fails to display clear cyber-hygiene baselines during audit frameworks, your operational authorisation is compromised.

SMS Integration DoC Audit Trigger IMO 2021 Resolution IACS UR E26/E27
Vetting Checklist03 · Vetting Inspection Compliance Checklist (SIRE 2.0 / RightShip RIQ)

Vetting inspectors from major energy charterers and global dry bulk agencies are actively screening shipboard network architectures. Use this interactive prep tool to audit your fleet's current readiness stance:

Safety Management System (SMS) Native Workflows

Verify that your cyber risk management protocols are deeply embedded into standard operating routines as required by IMO 2021, featuring clear, tested incident escalation paths back to the shore side.

Crew Operational Competency & Device Control

Confirm shipboard personnel can demonstrate practical knowledge of network access rules (e.g., locking physical USB ports) and spot phishing attempts during live inspector challenges.

IT and OT Firewall Segmentation

Audit the shipboard infrastructure to ensure machinery control environments (engines, propulsion loops, cargo pumps) are fully isolated from crew amenities, administrative workstations, and public Wi-Fi access points.

Bridge/Engine Software Configuration Tracking

Ensure all ECDIS units, radar setups, and automated PLCs run verified, current, OEM-approved firmware packages with matching modification logs stored inside the engine room.

The Assurance Pass Solution

Our collaborative service deployments build this operational standard directly into your day-to-day shipboard life. By certifying your fleet under the IASME Maritime Cyber Baseline standard, we provide the absolute data proof required to secure tier-1 commercial charter clearance and satisfy strict underwriting vetting parameters.

09

Complete Acronym Audit

Every acronym and abbreviation used across all eight sections. Use the filters to find entries by status. All entries now have full expansions this table serves as the master quick-reference index.

AcronymStatusFull expansion & definitionSection
A. Bilbrough & Co.InsuranceThe traditional management firm directing underwriting operations and member policies for Steamship Mutual and the London P&I Club.01 · P&I Clubs
ABN AMROInsuranceMajor financial institution engaged in ship finance bank facilities, tying asset debt loops to active technical cyber validations.08 · Market Segments
ABSAmerican Bureau of ShippingRule/VettingUS-headquartered IACS classification society. Directs technical topology audits against its unique 'CyberSafety' manual and offers notation pathways.03 · Class & Professional Bodies
Admiralty Solicitors / Maritime Law FirmsInsuranceInternational legal partnerships specializing in shipping, maritime commerce, and commodities. Primary commissioning parties for forensically admissible cyber causation and expert witness reports.06 · Industry Bodies
AHTSAnchor Handling Tug SupplyOT & SystemsSpecialized offshore support hull handling rig anchors and dynamic towing processes, carrying extensive deck machinery and station-keeping control loops.06 · Industry Bodies
AISAutomatic Identification SystemOT & SystemsVessel transponder broadcasting location, course, and identity data over VHF loops. Vulnerable to injection attacks and spoofing scenarios.07 · Technology Landscape
AllianzInsuranceExample of a major corporate commercial insurer underwriting blue-water hull risk alongside Lloyd's syndicates.02 · H&M Underwriters
American ClubInsuranceAmerican Steamship Owners Mutual Protection & Indemnity Association, Inc. The only IG club domiciled in the United States; managed by Shipowners Claims Bureau (SCB).01 · P&I Clubs
AMPAutoridad Marítima de PanamáRule/VettingPanama Maritime Authority flag state administration, governing the world's largest open ship registry and mandating IMO-aligned safety rules.05 · Cyber Standards
Anglo-EasternOT & SystemsTier-1 third-party ship management group responsible for executing technical security baselines across a massive multi-vessel fleet.08 · Market Segments
APAVEOT & SystemsTesting, verification, and inspection entity operating inside industrial energy fields, moving adjacently to technical marine cyber survey spaces.07 · Technology Landscape
ASTMAmerican Society for Testing and MaterialsOT & SystemsStandards body defining petroleum measurement procedures (e.g. D1298, D4052) used in bunker custody transfer calculations. Software version control of ASTM formula implementations is a compliance consideration in dispute resolution.07 · Technology
ATEXAtmosphères ExplosiblesRule/VettingEU directive governing equipment certification for explosive atmospheres (tanker cargo spaces, pump rooms). Zone classifications determine permitted device types; non-ATEX electronics in hazardous zones create safety and insurance compliance exposure.05 · Cyber Standards
BDNBunker Delivery NoteOT & SystemsThe official electronic or print summary document recording mass transfer delivery metrics, vulnerable to file modifications on compromised computers.07 · Technology Landscape
Bernhard SchulteOT & SystemsMajor international ship manager maintaining integrated network configurations and directing fleet safety management compliance.08 · Market Segments
BIMCOBaltic and International Maritime CouncilRule/VettingWorld's largest international shipping association. Co-author of the joint-industry cyber manuals and provider of standardized contract security clauses.05 · Cyber Standards
BIMCO cyber clausesRule/VettingStandardized charter party conditions mapping contractual liability paths between shipping owners and commercial charterers during incidents.05 · Cyber Standards
BMWBunker Management WorkstationOT & SystemsHMI terminal aggregating flow-meter data and generating the BDN aboard bunker barges. Vulnerable to USB malware; compromised workstations may produce BDNs inconsistent with independent meter records.07 · Technology
BORBunkers Remaining On BoardOT & SystemsLiquid fuel volume logs stored inside vessel tanks, generating regular commercial audit suits between chartering entities and vessel owners.08 · Market Segments
BPRule/VettingMajor oil corporation and constituent member of OCIMF, utilizing SIRE vetting to audit digital asset tracking configurations prior to hire.06 · Industry Bodies
BritanniaInsuranceBritannia Steam Ship Insurance Association. London-based mutual managed by Tindall Riley. Mid-size IG club with strong tanker and dry bulk membership.01 · P&I Clubs
BSUBundesstelle für SeeunfalluntersuchungRule/VettingGerman Federal Bureau of Maritime Casualty Investigation. Evaluates shipping accidents inside Baltic/North Sea channels, checking software error tracks.06 · Industry Bodies
Bulk & Container FleetOT & SystemsThe compliance-driven trade shipping segment utilizing large-scale machinery loops, facing growing pressure under RightShip RIQ checking matrices.08 · Market Segments
BVBureau VeritasRule/VettingFrench classification society. Implements mandatory newbuild guidelines and issues proprietary asset notations like Cyber-AT, Cyber-EL, and Cyber-RS.03 · Class & Professional Bodies
CBSComputer-Based SystemOT & SystemsThe definitive checking unit outlined inside IACS UR E27 rules, encompassing any networked shipboard microprocessing node governing control actions.05 · Cyber Standards
CCSChina Classification SocietyRule/VettingIACS society dominant across Chinese-built tonnage. Manages dedicated Class-P notation pathways and enforces construction rules under UR E26/E27 parameters.03 · Class & Professional Bodies
CDIChemical Distribution InstituteRule/VettingSpecialized chemical fleet inspection format, enforcing digital and technical checking routines across dangerous liquid cargo lines.06 · Industry Bodies
CER DirectiveCritical Entities Resilience DirectiveRule/VettingEU Directive 2022/2557 targeting physical security steps for transport hubs and ports, operating alongside NIS2 to form a dual compliance layer.05 · Cyber Standards
ChevronRule/VettingOCIMF member energy corporation enforcing strict tech compliance and configuration screening before chartering tanker assets.06 · Industry Bodies
China P&I ClubInsuranceChina Shipowners Mutual Assurance Association. State-backed; primarily covers Chinese-flag and Chinese-owned vessels. Largest non-IG P&I provider by Chinese tonnage.01 · P&I Clubs
CHIRPConfidential Hazardous Incident Reporting ProgrammeOT & SystemsUK aviation and maritime safety reporting body providing human-element error logs and professional learning resources to the international seafaring community.07 · Technology Landscape
Cloud SMS PlatformsCloud-Hosted Ship Management SystemsOT & SystemsFleet-wide cloud-native operations software (e.g. Danaos, Helm CONNECT, AMOS, DNV Nexus) running centralized maintenance, crew scheduling, and documentation management via automatic synchronisation updates. A critical supply chain concentration vector: a compromised provider update can cascade malicious configuration data across an entire managed fleet simultaneously.07 · Technology Landscape
CIICarbon Intensity IndicatorOT & SystemsOperational efficiency rating calculated from machinery fuel tracking data generated by engine OT loops, introducing a risk of data falsification.04 · Regulations & Codes
CIRCIACyber Incident Reporting for Critical Infrastructure ActRule/VettingUS statutory act forcing operators of critical maritime infrastructure to pass detailed incident declarations to CISA within 72 hours.05 · Cyber Standards
CISACybersecurity and Infrastructure Security AgencyRule/VettingUS federal agency responsible for national cybersecurity. Its Cybersecurity Performance Goals underpin the USCG MTS rule. CIRCIA requires critical infrastructure operators to report cyber incidents to CISA within 72 hours.05 · Cyber Standards
CitiInsuranceGlobal banking corporation active in large-scale ship finance, structuring marine loans contingent on regulatory cyber risk verification.08 · Market Segments
CL 380Institute Cyber Attack Exclusion ClauseInsuranceThe historic marine clause that blanket-excludes any loss or liability caused by a cyber attack from H&M and cargo policies. Introduces profound coverage gaps during shipboard electronic failures.02 · H&M Underwriters
Classification-Linked Inspection BodiesOT & SystemsTesting giants utilizing surveyor networks to market rigid rule structures, lacking commercial neutrality during dispute resolutions.07 · Technology Landscape
ClassNKNippon Kaiji KyokaiRule/VettingJapanese classification society. Largest by classed vessel counts; offers type-approval pathways for resilient hardware and publishes UR E26/E27 guides.03 · Class & Professional Bodies
CoCCertificate of CompetencyRule/VettingOfficial seafarer license issued under STCW conventions, verifying that bridge and engine officers satisfy safety watchkeeping competencies.04 · Regulations & Codes
Consolidated Crew E-Learning PlatformsOT & SystemsMass training software providers delivering static video elements, lacking real-time interactive engineering mentorship toolsets.07 · Technology Landscape
Continuous OT Network Monitoring PlatformsOT & SystemsEnterprise software agents executing deep packet checks across serial protocols, lacking localized maritime inspection visibility.07 · Technology Landscape
Coriolis MFMCoriolis Mass Flow MeterOT & SystemsCoriolis-effect sensor measuring fluid mass flow and density. Used for bunker custody transfer; cyber-physical interface via Modbus output creates falsification risk requiring forensic log review in quantity disputes.07 · Technology
CPDContinuing Professional DevelopmentInsuranceCommercial format for Maritime Training Academy educational events sold directly to P&I and H&M underwriting syndicates to satisfy annual professional training requirements.08 · Market Segments
CRSCroatian Register of ShippingRule/VettingNational classification society and IACS member governing Adriatic and Mediterranean tonnage fields under unified UR E26/E27 rules.03 · Class & Professional Bodies
CSFNIST Cybersecurity FrameworkRule/VettingTechnical framework organizing risk management controls into five functions: Identify, Protect, Detect, Respond, Recover. Referenced directly in USCG playbooks.05 · Cyber Standards
CSOCompany Security OfficerRule/VettingShore-side management representative designated under the ISPS Code to manage corporate Ship Security Plans and coordinate with shipboard perimeters.04 · Regulations & Codes
CyberPlusInsuranceSpecialist maritime technical risk assessment provider executing on-board validation audits and forensic investigations to protect policy coverage stances.02 · H&M Underwriters
CySOCybersecurity OfficerRule/VettingShipboard security role mandated under the statutory USCG MTS rule, tasked with maintaining configuration control logs and executing incident reporting steps.05 · Cyber Standards
DCSDistributed Control SystemOT & SystemsProcess automation setup managing ballasting loops and cargo thermal metrics, targeted to mask volume deficiencies during liquid transfer actions.07 · Technology Landscape
DMLCDeclaration of Maritime Labour ComplianceRule/VettingThe formal document required under the Maritime Labour Convention (MLC) outlining how shipowners satisfy national seafarer welfare rules. Part I is issued by the flag state and Part II is prepared by the ship manager, intersecting with digital crew management records.04 · Regulations & Codes
DNVDet Norske VeritasRule/VettingNorwegian classification society. Promotes an influential tiered 'Cyber Secure' notation (Basic, Enhanced, Advanced) frequently required by modern energy charterers.03 · Class & Professional Bodies
DoC / DOCDocument of ComplianceRule/VettingISM Code document issued to shipping firms. The annual Document of Compliance audit is the practical mechanism enforcing active IMO 2021 fleet reviews.04 · Regulations & Codes
DORADigital Operational Resilience ActInsuranceEU regulatory standard forcing financial entities, including marine insurers and MGAs operating inside Europe, to maintain strict oversight of third-party ICT service links.05 · Cyber Standards
DPDynamic PositioningOT & SystemsAutomated position-keeping system linking thrusters with positioning data streams. Cyber disruption creates high risks of location loss.07 · Technology Landscape
DPADesignated Person AshoreRule/VettingMandatory shore-based manager under the ISM Code with direct executive access. Primary internal lead responsible for embedding cyber guidelines into the SMS.01 · P&I Clubs
DryBMSDry Bulk Management StandardRule/VettingVoluntary management framework utilized across major dry bulk charter chains to evaluate and grade the cyber-hygiene baselines of third-party managers.04 · Regulations & Codes
eBLElectronic Bill of LadingOT & SystemsDigital system replacement for paper cargo titles, driving secondary demands for independent data confirmation to align items with physical volumes.07 · Technology Landscape
ECDISElectronic Chart Display & Info SystemOT & SystemsMandatory electronic navigation layout. Represents a critical bridgework attack vector vulnerable to chart corruption or spoofed position streams.07 · Technology Landscape
EMSAEuropean Maritime Safety AgencyRule/VettingTechnical advisory arm of the EU. Directs the checklist protocols that Port State Control officers use to evaluate vessel compliance inside European waters.05 · Cyber Standards
EU CRAEU Cyber Resilience ActRule/VettingBinding European product legislation mandating built-in cybersecurity configurations for all supply chain hardware and software elements with digital components by September 2026.05 · Cyber Standards
EU ETSEU Emissions Trading SystemOT & SystemsCarbon pricing mechanism tracking engine emissions profiles derived from machinery OT data streams, rendering data integrity a financial factor.04 · Regulations & Codes
ExxonMobilRule/VettingOCIMF member energy major enforcing technical sensor checking and network monitoring as prerequisites for terminal clearance agreements.06 · Industry Bodies
FALConvention on Facilitation of Maritime TrafficRule/VettingIMO convention targeting paperless terminal documentation loops. Co-issued the baseline MSC-FAL.1/Circ.3 cyber risk management guidance framework.04 · Regulations & Codes
FAL CommitteeIMO Facilitation CommitteeRule/VettingIMO committee responsible for the FAL Convention on Facilitation of Maritime Traffic. Co-issued MSC-FAL.1/Circ.3 (the IMO 2021 cyber guidance) jointly with the MSC.04 · Regulations & Codes
Flag StatesRule/VettingNational maritime administrations executing international convention inspections and issuing standardized technical verifications across registries.08 · Market Segments
Fleet ManagementOT & SystemsLarge-scale global third-party ship management enterprise handling daily asset network controls and flag-state verification tasks.08 · Market Segments
FMEAFailure Mode and Effects AnalysisRule/VettingEngineering methodology mapping potential failure modes, causes, and system effects. Increasingly applied to OT cyber risk to model how falsified sensor outputs propagate through vessel systems; informs both maintenance schedules and cyber resilience design.05 · Cyber Standards
GAGeneral AverageInsuranceLegal allocation principle — codified in the York-Antwerp Rules — dividing extraordinary salvage and sacrifice expenses proportionally among cargo and hull stakeholders during a common peril. A shipowner's legal standing to claim GA contributions is significantly undermined where a casualty is causally linked to a failure to maintain reasonable vessel cyber-seaworthiness.06 · Legal & Dispute Stakeholders
GardInsuranceGard AS. Norwegian-headquartered mutual; largest IG club by entered fleet tonnage. Highly proactive leader in fleet risk management. CEO Rolf Thore Roppestad serves as International Group Chair.01 · P&I Clubs
GDPRGeneral Data Protection RegulationRule/VettingEU data privacy mandate protecting crew identity data. Regulates file management and tracking behaviors across remote inspection records.05 · Cyber Standards
GNSSGlobal Navigation Satellite SystemOT & SystemsThe overarching framework encompassing GPS, Galileo, and BeiDou networks. Feeds crucial coordinates into bridge systems, vulnerable to electronic jamming.07 · Technology Landscape
GPSGlobal Positioning SystemOT & SystemsUS satellite constellation feeding positioning data to ECDIS and autopilots, vulnerable to electronic spoofing vectors.07 · Technology Landscape
GPS / GNSSGlobal Positioning System / Global Navigation Satellite SystemRule/VettingGPS (US) is one of several GNSS constellations; others include GLONASS, Galileo, and BeiDou. Feeds ECDIS, AIS, and DP systems. Spoofing and jamming are documented growing threats underpinning cyber causation investigations.07 · Technology Landscape
GXLGroup Excess of LossInsuranceThe collective reinsurance pooling program shared annually across the 12 International Group members, covering catastrophic casualty lines exceeding standard thresholds.01 · P&I Clubs
H&MHull & MachineryInsuranceMarine insurance policy protecting physical ship architectures, main machinery, and electronics. Underwritten via commercial insurance markets or Lloyd's syndicates.02 · H&M Underwriters
HVRHague-Visby RulesRule/VettingInternational legal convention framing cargo carriage liability under bills of lading, imposing a non-delegable duty to exercise due diligence to maintain a seaworthy vessel — a duty now structurally encompassing digital, firmware, and software system configurations. Failure to satisfy this standard at voyage inception significantly undermines available liability limitations and exemptions.06 · Legal & Dispute Stakeholders
IACSInternational Association of Classification SocietiesRule/VettingUmbrella consortium coordinating the 12 major classification societies. Formulates binding Unified Requirements (URs) enforcing technical rule sets cross-fleet.03 · Class & Professional Bodies
IASME Maritime Cyber BaselineRule/VettingUK maritime-specific assurance standard designed by the IASME Consortium. Provides proportionate, auditable certification for existing fleets.05 · Cyber Standards
ICSIndustrial Control System / International Chamber of ShippingRule/VettingDual-use acronym: (1) Industrial Control System, the generic term for OT systems including SCADA, DCS, and PLC, used within IEC 62443; (2) International Chamber of Shipping, the principal trade association for shipowners and co-author of the Industry Guidelines on Cyber Security Onboard Ships. Context determines meaning.05 · Cyber Standards
ICS (OT context)Industrial Control SystemOT & SystemsOverarching definition tracking automated machinery control devices including SCADA loops and PLCs. Distinct from the International Chamber of Shipping trade group.05 · Cyber Standards
IEC 62443OT & SystemsThe leading global technical cybersecurity standard series for industrial automation, defining zone and conduit segmentations for machinery networks.05 · Cyber Standards
IGInternational Group (of P&I Clubs)InsuranceThe overarching mutual pool system comprising 12 independent, not-for-profit P&I structures covering roughly 87% of ocean-going tonnage.01 · P&I Clubs
ILOInternational Labour OrganisationRule/VettingUnited Nations specialized agency managing international labor metrics and generating foundational seafarer welfare targets.04 · Regulations & Codes
INS / IBSIntegrated Navigation System / Integrated Bridge SystemOT & SystemsCentral network fabric linking mandatory bridge instruments — ECDIS, radar, autopilot, AIS, and positioning sensors — over unencrypted NMEA serial pathways. Under IACS UR E26, the entire INS infrastructure is evaluated as a unified attack surface; a single compromised peripheral can undermine the operational integrity of the complete navigation platform.07 · Technology Landscape
IMCAInternational Marine Contractors AssociationRule/VettingTrade association for offshore marine contractors. Co-administers the OVID vetting platform alongside OCIMF to qualify support assets for energy charters.06 · Industry Bodies
IMOInternational Maritime OrganisationRule/VettingUnited Nations specialized shipping agency responsible for directing global conventions (SOLAS, MARPOL, STCW) and setting regulatory frameworks.04 · Regulations & Codes
IMO 2021IMO Resolution MSC.428(98)Rule/VettingThe benchmark international resolution mandating maritime operators to formally integrate cyber risk controls natively inside Safety Management Systems.04 · Regulations & Codes
IMO MSC.428(98)IMO Cyber Risk ResolutionRule/VettingThe root international mandate requiring maritime operators to address cyber risks within approved Safety Management Systems. Compliance verified at every annual Document of Compliance (DoC) audit from January 2021.05 · Cyber Standards
Industry Guidelines v5Rule/VettingThe preeminent joint-industry manual (BIMCO/ICS/IUMI) specifying standard operating processes for shipboard network baseline safety.05 · Cyber Standards
INTERCARGORule/VettingInternational Association of Dry Cargo Shipowners. Trade group coordinating cyber-hygiene guidance matrices for bulk asset types and RightShip vetting scenarios.05 · Cyber Standards
INTERTANKORule/VettingInternational Association of Independent Tanker Owners. Industry association directing operational best practices and co-authoring vessel security guidelines.05 · Cyber Standards
IntertekOT & SystemsGlobal verification and testing institution with established oil major frame agreements, delivering technical audit operations across marine logistics.06 · Industry Bodies
IRSIndian Register of ShippingRule/VettingIndian national classification society and full IACS member. Appends unique Cyber Safety notations to vessels operating inside the Indian Ocean region.03 · Class & Professional Bodies
ISM CodeInternational Safety Management CodeRule/VettingMandatory IMO code ensuring safe vessel operations. Dictates structural maintenance of Safety Management Systems and requires regular corporate audits.04 · Regulations & Codes
ISO 27001Rule/VettingInternational corporate information security management standard, primarily deployed to harden shore-side office structures and enterprise fleet servers.05 · Cyber Standards
ISPS CodeInternational Ship & Port Facility Security CodeRule/VettingIMO physical security framework governing access controls, physical perimeter alerts, and security plan execution, now interfacing with cyber intrusion vectors.04 · Regulations & Codes
ITInformation TechnologyOT & SystemsAdministrative networks, email setups, and crew cabins. Represents the primary entry vector for ransomware payloads pivoting into machinery zones.07 · Technology Landscape
IUAInternational Underwriting AssociationInsuranceTrade association for company market insurers based in London. Publishes standard endorsements including IUA 09-082, the institutional cyber buy-back endorsement allowing shipowners to conditionally reinstate coverage for cyber-enabled physical damage.02 · H&M Underwriters
IUA 09-082International Underwriting Association EndorsementInsuranceStandard institutional cyber buy-back endorsement allowing shipowners to conditionally reinstate coverage lines for cyber-enabled physical damage.08 · Market Segments
IUMIInternational Union of Marine InsuranceInsuranceGlobal federation of marine underwriting associations. Coordinates market parameters for evaluating hull risks and co-authors joint-industry cyber safety scripts.02 · H&M Underwriters
Japan P&I ClubInsuranceJapan Ship Owners' Mutual Protection & Indemnity Association. Tokyo-based; the only IG member club domiciled in Japan. Dedicated to Asian fleet networks.01 · P&I Clubs
JH143Joint Hull Committee Survey Note 143InsuranceTechnical shipyard construction protocol issued via London underwriting groups, forcing independent cyber-ready checks at structural delivery phases.04 · Regulations & Codes
JC2025-026JCC Marine Cargo Cyber Exclusion with Physical Theft Confirmation EndorsementInsuranceJoint Cargo Committee endorsement (October 28, 2025) carving back cargo coverage for physical theft of insured goods facilitated by cyber means — e.g. hackers stealing terminal container release codes — provided further physical human intervention is required to complete the theft. Paragraph 4 is the operative carve-back; digital-only losses remain excluded under Paragraph 1.02 · H&M Underwriters
KfW IPEX-BankInsuranceProminent German ship finance institution integrating technical cyber risk verifications and ESG markers into lending framework cycles.08 · Market Segments
Korean P&I ClubInsuranceKorea Shipowners' Mutual P&I Association. Seoul-based mutual; prominent non-IG marine liability underwriter managing Asian fleet operations.01 · P&I Clubs
KRKorean RegisterRule/VettingSouth Korean IACS class society dominant across major domestic building yards. Issues specialized Cyber Resilience notations checking against data integrity threats.03 · Class & Professional Bodies
LISCRLiberian International Ship & Corporate RegistryRule/VettingThe administrative body managing the Liberian flag, enforcing strict regulatory alignments and transposing IMO resolutions into mandatory national laws.05 · Cyber Standards
Lloyd's / Lloyd's of LondonInsuranceThe world's preeminent specialist insurance market. Syndicates back significant tranches of marine asset damage exposures using tailored, cyber-rated inception surveys.02 · H&M Underwriters
LMALloyd's Market AssociationInsuranceIndustry body representing managing agents in the Lloyd's market. Publishes standard marine cyber endorsements including LMA 5402 (excluding) and LMA 5403 (including/buy-back), the primary clauses used to exclude or reinstate cyber coverage in H&M policies.02 · H&M Underwriters
LMA 5402Marine Cyber Risk Endorsement (Excluding)InsuranceLloyd's Market Association endorsement clause explicitly isolating and omitting cyber risks from standard policies, minimizing claims handling ambiguities.02 · H&M Underwriters
LMA 5403Marine Cyber Risk Endorsement (Including)InsuranceThe structural buy-back endorsement companion enabling coverage for cyber-enabled asset damage to be reinstated, legally conditional on passing inception surveys.02 · H&M Underwriters
LMAALondon Maritime Arbitrators AssociationRule/VettingThe leading arbitral body for commercial shipping disputes under English law. Arbitrators require forensically admissible, timestamped data records during navigation suits.06 · Industry Bodies
LEOLow Earth Orbit ConnectivityOT & SystemsHigh-bandwidth, low-latency satellite platforms (e.g., Starlink Maritime, OneWeb) transforming fleet connectivity and telemetry capabilities. Introduces severe perimeter security risks when integrated into shipboard environments without strict network segregation from legacy corporate VSAT firewall architectures.07 · Technology Landscape
LNG CarriersOT & SystemsHigh-value cargo assets with dense technical automation profiles (cryogenic processors, reliquefaction arrays), representing elevated operational exposure risks.08 · Market Segments
London P&I ClubInsuranceLondon Steam-Ship Owners' Mutual Insurance Association Ltd. Managed by A. Bilbrough & Co. Core focus across bulk carriers, tankers, and container platforms.01 · P&I Clubs
Loss PreventionInsuranceProactive risk-reduction workflows funded natively by P&I clubs, utilizing allocated budgets to support crew security training and vessel surveys.01 · P&I Clubs
LRLloyd's RegisterRule/VettingBritish classification society. Developed the 'ShipRight Cyber-Enable' verification procedure to evaluate technical control levels across automated networks.03 · Class & Professional Bodies
MAIBMarine Accident Investigation BranchRule/VettingUK government bureau investigating maritime casualties. Publishes global safety briefs, increasingly tracking digital software errors behind machinery casualties.06 · Industry Bodies
Maritime Training AcademyInsuranceThe professional educational institute providing programmatic training modules and technical cyber coursework to commercial underwriting teams.08 · Market Segments
MARPOLInternational Convention for the Prevention of Pollution from ShipsRule/VettingIMO environmental mandate. Annex VI requires strict emissions tracking calculations linked to electronic OT data logs, exposed to manipulation hazards.04 · Regulations & Codes
MASSMaritime Autonomous Surface ShipOT & SystemsVessels running automated or remote operations pathways across coastal channels, requiring absolute technical network protection.08 · Market Segments
MCAMaritime and Coastguard AgencyRule/VettingUK flag state administration. Mandates formal compliance with IMO safety targets and sets regulatory parameters for UK-registered fleets and coastal channels.05 · Cyber Standards
MGAManaging General AgentInsuranceAn intermediary entity holding delegated capital authority from underwriters, acting as the primary channel forcing cyber assessment rules onto high-value assets.02 · H&M Underwriters
MLCMaritime Labour ConventionRule/VettingILO convention protecting crew welfare. Interfaces with cyber assessment frameworks regarding payroll banking protection and crew identity system integrity.04 · Regulations & Codes
ModbusModbus Protocol (RTU/TCP)OT & SystemsDominant maritime OT serial communication standard linking PLCs, sensors, and HMI panels. No native authentication or encryption; any bus-connected device can read or overwrite registers. Primary finding in OT cyber baseline assessments.07 · Technology
MPAMaritime and Port Authority of SingaporeRule/VettingSingapore flag state and port administrator, enforcing localized cyber resilience checklists across APAC offshore energy and logistics shipping lanes.05 · Cyber Standards
MSCMaritime Safety CommitteeRule/VettingThe senior technical safety body of the IMO. Formulates structural amendments to conventions and authorized Resolution MSC.428(98).04 · Regulations & Codes
MSC-FAL.1/Circ.3IMO Joint MSC / FAL CircularRule/VettingHigh-level IMO guidance on maritime cyber risk management describing five functions: Identify, Protect, Detect, Respond, Recover. Technical companion to MSC.428(98); not itself legally binding but frames how compliance is assessed.05 · Cyber Standards
MTSMarine Transportation SystemRule/VettingUS infrastructure definition encompassing ports, vessels, and locks. Defines the scope of the mandatory USCG Marine Transportation System cyber rulemaking.05 · Cyber Standards
MTS-ISACRule/VettingThreat intelligence sharing repository, aggregating technical indicators of compromise and pushing alerts across global shipping operations networks.05 · Cyber Standards
Niche Maritime Cyber ConsultanciesOT & SystemsAdvisory teams focusing on shore-side policy outlines and basic asset checking matrices, operating separately from physical structural inspection providers.07 · Technology Landscape
NIS2Network & Information Security Directive 2Rule/VettingMandatory EU infrastructure directive. Forces ports, logistics groups, and offshore hubs to enact strict supply chain audits under severe revenue penalty tracks.05 · Cyber Standards
NIST CSFNational Institute of Standards and Technology Cybersecurity FrameworkRule/VettingUS-origin risk management framework built around five functions: Identify, Protect, Detect, Respond, Recover. Aligned to the USCG MTS rule and CISA performance goals. Provides the technical vocabulary USCG inspectors use when auditing cybersecurity plans.05 · Cyber Standards
NMEA 0183 / 2000Marine Electronics Data ProtocolOT & SystemsStandard data protocol for bridge sensor communications (radar, GPS). Lacks encryption or authentication, creating blind injection hazards on bridge screens.07 · Technology Landscape
NORMA CyberRule/VettingNordic Maritime Cyber Resilience Centre. Coordinates real-time threat analysis matrices across Scandinavian shipowners and major Nordic-headquartered IG clubs.05 · Cyber Standards
NorthStandardInsuranceLarge International Group club created by the 2023 amalgamation of North of England and Standard Club. Early mover in backing digital safety management steps.01 · P&I Clubs
NRCNational Response CenterRule/VettingThe primary communications node for federal pollution and safety events inside US waters, designated to handle maritime cyber intrusion declarations.05 · Cyber Standards
NTSBNational Transportation Safety BoardRule/VettingIndependent US federal accident agency. Audits critical transport casualties, detailing software faults and automation errors within formal safety briefs.06 · Industry Bodies
NTSB / USCGNational Transportation Safety Board / US Coast GuardRule/VettingThe two US authorities for marine accident investigation. NTSB investigates significant US-flagged marine casualties; USCG handles broader enforcement and investigation for incidents in US waters under MTSA and the MTS Rule.06 · Industry Bodies
NVIC 01-20Rule/VettingUS Coast Guard Navigation and Vessel Inspection Circular 01-20. The playbook inspectors use to audit and enforce cyber risk compliance at US ports, facilities, and vessels.05 · Cyber Standards
OCIMFOil Companies International Marine ForumRule/VettingThe oil major consortium (BP, Shell, Chevron). Formulates rigid baseline qualification standards and administers the critical SIRE/OVID database platforms.05 · Cyber Standards
OCIMF SIRE 2.0Ship Inspection Report Programme Version 2Rule/VettingUpdated OCIMF tanker inspection scheme launched 2023, including explicit cyber and digital system questions within the VIQ. Creates a formalised, structured inspection requirement for digital system safety. See also: SIRE / SIRE 2.0.05 · Cyber Standards
OCIMF TMSATanker Management and Self AssessmentRule/VettingOCIMF's shore-side management quality framework for tanker operators. Element 13 (Maritime Security) includes cyber risk questions. Oil majors use TMSA scores in vetting decisions, creating commercial pressure to achieve strong cyber ratings. See also: TMSA.05 · Cyber Standards
OCSOuter Continental ShelfRule/VettingUS federal energy exploration zones. Offshore platforms, drill rigs, and wind farms located here are subject to full USCG cybersecurity mandates.05 · Cyber Standards
Oil MajorsRule/VettingLarge integrated energy giants (BP, Shell, ExxonMobil). Dictate OVID/SIRE vetting criteria, mandating cyber resilience as a commercial condition of hire.08 · Market Segments
ORBOil Record BookRule/VettingThe mandatory logbook required under MARPOL regulations for recording all shipboard oil transfer and disposal operations. Frequently audited alongside electronic automation records during environmental compliance and Port State Control checks.04 · Regulations & Codes
OSVOffshore Support VesselOT & SystemsUmbrella term for energy exploration assets (PSVs, AHTS), carrying heavy automation loops and checked via specialized OVID templates.08 · Market Segments
OTOperational TechnologyOT & SystemsHardware and software components directly manipulating physical events (steering gears, propulsion loops). Safety-critical and distinct from IT frameworks.07 · Technology Landscape
OEM TelemetryOriginal Equipment Manufacturer Remote Maintenance LoopsOT & SystemsDedicated inbound remote access links — VPN tunnels or remote desktop sessions — maintained by machinery manufacturers for real-time engine diagnostics and technical support. These permanent pathways operate outside DPA and CSO visibility, functioning as a high-risk supply chain vector: a breach of the land-based OEM enterprise can bridge directly into a vessel's active physical control systems.07 · Technology Landscape
OTAOil Tanker AssessmentRule/VettingTanker vetting assessment framework used alongside chemical tracking protocols to check operator profiles before issuing charter matches.06 · Industry Bodies
OVIDOffshore Vessel Inspection DatabaseRule/VettingHighly structured OCIMF inspection platform mapping security and technical readiness metrics across specialized offshore assets prior to hire.06 · Industry Bodies
OVVOnderzoeksraad voor VeiligheidRule/VettingDutch Safety Board. Investigates significant transport and industrial events near major European trade locations, assessing data errors in vessel networks.06 · Industry Bodies
P&IProtection & IndemnityInsuranceMutual third-party liability insurance for shipping companies, covering human casualty events, cargo damage, environmental spills, and wreck clearance tasks.01 · P&I Clubs
Panama / Liberia / Marshall Islands / Singapore MPAMajor open registries and key flag statesRule/VettingAll require IMO 2021 cyber compliance for their registered vessels and have issued supplementary guidance. Together cover the majority of the world's tanker and bulk carrier fleet. Singapore MPA requirements are directly relevant to operators active in the Asia-Pacific region.05 · Cyber Standards
PLCProgrammable Logic ControllerOT & SystemsHardened computing block automating electromechanical actions (valves, pumps), acting as a primary testing target within IEC 62443 steps.05 · Cyber Standards
Poseidon PrinciplesInsuranceGlobal financial and insurance agreement tracking portfolio alignment with emissions targets. Critically dependent on the data integrity of shipboard sensors.04 · Regulations & Codes
PRSPolish Register of ShippingRule/VettingNational classification society and IACS member. Governs Baltic-connected shipping fleets, incorporating UR E26/E27 rules into standard survey processes.03 · Class & Professional Bodies
PSCPort State ControlRule/VettingForeign terminal authority inspection processes verifying compliance with international laws, using EMSA circulars to flag inadequate cyber documentation.04 · Regulations & Codes
PSVPlatform Supply VesselOT & SystemsOffshore logistics craft supplying drilling installations, carrying integrated tank control loops and dynamic station-keeping modules.06 · Industry Bodies
REG CodeRed Ensign Group Large Yacht CodeRule/VettingThe mandatory operational compliance standard for commercial yachts over 24m, enforcing rigid technical security checks over emergency and bridge systems.04 · Regulations & Codes
RightShipRightShip Vetting PlatformRule/VettingThe dominant vetting entity for dry bulk and container operations. Incorporates structural SMS cyber-hygiene baselines directly into asset grading matrix models.06 · Industry Bodies
RINARoyal Institution of Naval ArchitectsRule/VettingProfessional body endorsing the IASME Maritime Cyber Baseline scheme, validating technical credential pathways distinct from class rules.06 · Industry Bodies
RINA (class)Registro Italiano NavaleRule/VettingItalian classification society and IACS member. Enforces mandatory UR E26/E27 cyber resilience requirements across Mediterranean-flagged fleets.03 · Class & Professional Bodies
RIQRightShip Inspection QuestionnaireRule/VettingThe physical vetting audit checklist deployed across bulk configurations. Poor technical markings here directly block access to major dry commodity cargo chains.06 · Industry Bodies
RMIRepublic of the Marshall Islands RegistryRule/VettingMajor international open registry holding prominent tank and gas shipping portfolios. Enforces baseline IMO 2021 cyber guidelines across all registered hulls.05 · Cyber Standards
Rolf Thore RoppestadInsuranceCEO of Gard AS and current serving Chair of the International Group of P&I Clubs.01 · P&I Clubs
ROVRemotely Operated VehicleOT & SystemsSubsea robotic system used to audit pipelines and subsea setups, running control software loops vulnerable to common intrusion vectors.07 · Technology Landscape
SCADASupervisory Control & Data AcquisitionOT & SystemsIndustrial control framework overseeing liquid flow behaviors at terminal sites, representing a highly targeted infrastructure platform.07 · Technology Landscape
SCBShipowners Claims BureauInsuranceThe dedicated commercial management firm handling administrative operations and loss-prevention deployments for the American Club P&I.01 · P&I Clubs
ShellRule/VettingOCIMF member energy major directing core focus across automated gas carrier structures and utilizing specialized vetting screening templates.06 · Industry Bodies
Ship Finance Banks / LessorsInsuranceCapital lenders and financial lessors linking vessel acquisition loans to active cyber risk certification and ESG validation loops at birth.08 · Market Segments
Shipowners' ClubInsuranceSpecialist mutual IG P&I club protecting smaller craft asset classes, specializing in specialized small-craft, harbor tugs, fishing vessels, and luxury superyachts.01 · P&I Clubs
SIGTTOSociety of International Gas Tanker & Terminal OperatorsRule/VettingThe primary trade body for liquefied gas shipping. Formulates operational risk guidelines for complex cargo and terminal interface OT loops.06 · Industry Bodies
SIRE / SIRE 2.0Rule/VettingOCIMF tanker inspection scheme. Version 2.0 appends mandatory digital questions into checking protocols, forcing crew to prove software management controls.05 · Cyber Standards
SIVAPShip Inspection & Vetting Assurance ProgrammeRule/VettingSpecialized offshore support vessel inspection format utilized alongside OVID platforms to qualify support assets for international energy logistics.06 · Industry Bodies
SkuldInsuranceAssuranceforeningen Skuld. Norwegian mutual underwriter, Bermuda-domiciled. Maintains a large presence across tanker and offshore sectors with a quick global response footprint.01 · P&I Clubs
SLAService Level AgreementOT & SystemsContractual performance commitment (response times, availability, escalation paths) between service provider and client. Governs incident response timelines in maritime cyber monitoring retainer contracts.07 · Technology
SMSSafety Management SystemRule/VettingThe centralized compliance manual set mandated by the ISM Code. Acts as the documentation core where IMO 2021 cyber controls must be formally embedded.04 · Regulations & Codes
SOCSecurity Operations CentreOT & SystemsCentral security management hub executing data monitoring actions and tracking alert patterns across fleet infrastructure layouts.05 · Cyber Standards
SOLASSafety of Life at SeaRule/VettingFoundational IMO safety convention. Integrates the core ISM Code structures (Chapter IX) and physical security architectures under the ISPS Code (Chapter XI-2).04 · Regulations & Codes
SOPStandard Operating ProcedureOT & SystemsDocumented procedural workflows utilized inside digital checking applications to eliminate variable interpretation during on-site asset surveys.08 · Market Segments
SPAN PortSwitched Port AnalyserOT & SystemsNetwork switch feature mirroring traffic to a monitoring port for passive OT network analysis. Used in cyber assessments to inspect Modbus and NMEA traffic; misconfiguration can expose sensitive operational data.07 · Technology
SSOShip Security OfficerRule/VettingShipboard officer responsible under ISPS metrics for managing security perimeters, physical logging, and checking the cyber-physical system overlap.04 · Regulations & Codes
SSPShip Security PlanRule/VettingControlled, sensitive vessel document mandated by the ISPS Code, tracking security steps, emergency actions, and physical access profiles.04 · Regulations & Codes
STCWStandards of Training, Certification & WatchkeepingRule/VettingIMO convention managing crew competency rules. Regulates training standards and requires security awareness updates across modern ship positions.04 · Regulations & Codes
Steamship MutualInsuranceSteamship Mutual Underwriting Association (Bermuda) Ltd. Managed by A. Bilbrough & Co. Deploys broad coverage matrices across bulk carriers and container fleets.01 · P&I Clubs
The Swedish ClubInsuranceSveriges Ångfartygs Assurans Förening. Gothenburg-based mutual. Notable as one of the few IG clubs writing both third-party P&I and physical hull (H&M) coverage options.01 · P&I Clubs
Third-Party Ship ManagersV.Ships · Anglo-Eastern · Bernhard Schulte · Fleet ManagementInsuranceMajor independent ship management companies running day-to-day vessel operations on behalf of asset-owning clients. A critical direct client segment for fleet-wide maritime cyber assessments; a framework agreement with one major manager generates recurring multi-vessel revenue.08 · Market Segments
Thomas MillerInsuranceThe specialized commercial management firm directing business files, office networks, and claims handling for the UK P&I Club.01 · P&I Clubs
Tindall RileyInsuranceThe specialized management organization executing operations, underwriting oversight, and technical reviews for Britannia P&I.01 · P&I Clubs
TLTürk LoyduRule/VettingTurkish national classification society and full IACS member. Directs maritime survey actions and integrates UR E26/E27 rules across regional contracts.03 · Class & Professional Bodies
TMSATanker Management & Self AssessmentRule/VettingOCIMF management assessment manual. Element 13 forces operators to demonstrate verified cyber policies to unlock high charter grading scores.05 · Cyber Standards
TotalEnergiesRule/VettingEuropean energy major mandating deep passive configuration checking and software inventory tracing on all contracted logistics fleets.06 · Industry Bodies
TWFTeamViewer Frontline WorkplaceOT & SystemsAR remote support platform using smart glasses for live vessel inspection and guided crew assistance. Creates cyber-physical integration points requiring encrypted sessions and strong authentication.07 · Technology
UHNWUltra High Net WorthOT & SystemsPremium privacy-focused client segment commanding modern superyacht hulls with highly interconnected domotic and entertainment networks.08 · Market Segments
UHNW Superyacht OwnersUltra High Net WorthInsurancePrivacy-sensitive premium buyers increasingly asking about cyber security as superyachts carry sophisticated networked AV, bridge, and smart-home OT systems. A high-margin, low-volume segment; MGAs and specialist H&M underwriters are the primary distribution channel into this segment.08 · Market Segments
UK P&I ClubInsuranceUnited Kingdom Mutual Steam Ship Assurance Association (Bermuda) Ltd. Managed by Thomas Miller. One of the largest global mutuals with extensive hub branches across Asia.01 · P&I Clubs
UR / UR E26 / UR E27Rule/VettingUnified Requirements issued by IACS. E26 mandates lifecycle fleet asset resilience. E27 forces component vendors to verify 30 system capability benchmarks.03 · Class & Professional Bodies
USBUniversal Serial BusOT & SystemsCommon removable storage interface. Uncontrolled USB use is a primary malware introduction vector into air-gapped OT systems (ECDIS, engine management, cargo computers). Port controls are a standard OT cyber baseline recommendation.07 · Technology
USCGUnited States Coast GuardRule/VettingFederal maritime regulator. Enforces strict national cyber rulemaking, mandating dedicated CySOs and cybersecurity plans for entities routing inside US waters.05 · Cyber Standards
USCG MTS RuleUS Coast Guard Marine Transportation System Cybersecurity RuleRule/VettingEnforces comprehensive cybersecurity plans, active data logging, and designated shipboard Cybersecurity Officers (CySO) under NVIC 01-20 parameters for all vessels and facilities operating in US waters. Two-phase timeline: crew training under 33 CFR 101.650 enforceable from January 12, 2026; full Cybersecurity Plan submission and CySO designation required by July 16, 2027.05 · Cyber Standards
V.ShipsOT & SystemsProminent independent ship management organization coordinating operational technology updates and crew safety systems cross-fleet.08 · Market Segments
Van Ameyde MarineInsuranceMarine surveying and claims management group with over 130 years of heritage and a global network of surveyors, correspondents, and claims specialists. Delivers technical analyses, on-site damage surveys, and repair attendance across complex vessel casualties in ports and shipyards worldwide.06 · Industry Bodies
VDRVoyage Data RecorderOT & SystemsThe vessel's armored black box recording audio and navigation metrics. Demands rapid physical data backup following accidents to escape overwrite steps.07 · Technology Landscape
VIKANDOT & SystemsCrew health and medical program provider, acting as a business framework model for flowing integrated technical packages directly to shipping operators.06 · Industry Bodies
VIQVessel Inspection QuestionnaireRule/VettingThe formal checking profile used inside SIRE review operations, appending digital safety questions to eliminate undocumented asset configurations.05 · Cyber Standards
West of EnglandInsuranceWest of England Shipowners' Mutual Insurance Association. Luxembourg-domiciled, managed in London. Broad footprint across liquid and dry bulk carrier segments.01 · P&I Clubs
WSCWorld Shipping CouncilRule/VettingLiner trade body representing global container shipping lines, managing cyber guideline matrices for eBL systems and data cargo titles.05 · Cyber Standards

The threat is real. The solution is proven.

Let's Talk