The threat is real. The solution is proven.
Maritime Cyber & Compliance Matrix
All acronyms, organisations, regulations, standards, and technologies
fully defined and grouped by category.
1 master audit index
200+ entries
May 2026
P&I Clubs
P&I Protection & Indemnity mutual third-party liability insurance for shipowners. The International Group of P&I Clubs (IG) comprises 12 independent not-for-profit mutuals covering approximately 87% of world ocean-going tonnage. Claims above ~$10m are pooled across all clubs via the GXL (Group Excess of Loss) reinsurance programme.
H&M Underwriters
H&M Hull & Machinery marine insurance covering physical damage to the vessel itself, its machinery, and equipment. Distinct from P&I (third-party liability). Predominantly underwritten through Lloyd's syndicates, company markets, and MGAs rather than the mutual club model used in P&I.
Classification Societies & Professional Bodies
Classification societies certify that vessels are designed and maintained to established standards. IACS (International Association of Classification Societies) coordinates all 12 member societies and issues Unified Requirements (URs) that every member must embed into their rules. UR E26 and UR E27 mandate cyber resilience for all newbuilds contracted from 1 July 2024, meaning every IACS member society is now building cyber into their standard rules regardless of how prominently they market it. The primary document focuses on societies most visible in CyberPlus's core European and Western blue-water operational focus; the full IACS membership is listed below for completeness. Note on RINA: in this document RINA refers exclusively to the Royal Institution of Naval Architects (a professional body and maritime cyber assessment endorser), not to be confused with Registro Italiano Navale, the Italian classification society that shares the same acronym.
Regulations, Codes & Frameworks
Maritime regulations flow primarily from the IMO (International Maritime Organisation, the UN shipping agency) and the ILO (International Labour Organisation). The SMS (Safety Management System) is the vessel's central compliance document set under the ISM Code it is where IMO 2021 cyber risk management requirements must be embedded. The DoC (Document of Compliance) annual audit is the key trigger date for IMO 2021 compliance.
Cyber & Technical Standards / Frameworks
Maritime cyber compliance is not a single rulebook. It is a stack of overlapping obligations, each issued by a different authority, each binding a different actor, and each enforced through a different mechanism. Understanding the stack matters because a gap at any layer can expose a shipowner, an insurer, or a service provider to liability even when every other layer appears satisfied.
How to read this section. The groups below are arranged in order of authority, from the root international obligation downward. Each card carries a badge: mandatory means it is enacted law or regulation with enforcement teeth; guidance means it is voluntary or soft-law but commercially decisive; newbuilds means the hard rule applies to new construction only, though the underlying standard increasingly shapes surveys of existing vessels too.
The core tension. International maritime law moves slowly, by consensus, through the IMO. National and regional law moves faster and is often stricter. Industry bodies and class societies fill the space between the two, issuing guidance and class notations that become commercially mandatory even when they are not legally so. A vessel can be fully IMO-compliant yet commercially unemployable because it fails a charterer's vetting standard or an insurer's inception survey requirement. Independent cyber assessment providers operate precisely in this gap: the regulatory floor is set by IMO, but the commercial ceiling is set by underwriters, MGAs, and vetting platforms, and it is rising faster than the regulators can follow.
A note on scope. The IMO instruments and IACS rules bind the vessel and its operator. The EU instruments (NIS2, DORA, CRA) bind the shore-side organisation, the financial entity, and the equipment manufacturer respectively. The US instruments bind anyone operating in US waters. The industry guidelines bind no one legally but are required by the people who control whether a ship earns freight. Each layer is noted in the cards below.
IACS UR E26 / E27
Mandatory unified class rules ensuring the technical cyber resilience of shipboard operational technologies (OT). Binding for newbuild contracts, this framework has rapidly become the universal gold standard for evaluating risk cross-fleet.
EU NIS2 Directive
Extends critical cyber management mandates to maritime transport and port infrastructure inside European waters. Structural failure to maintain auditable supply chain protection exposes operators to severe regulatory actions.
EU Cyber Resilience Act (CRA)
Mandates built-in cybersecurity configurations for components with digital elements. OEMs supplying critical hull systems (ECDIS, automation, radar) must verify security tracking parameters or face total market exclusion.
USCG MTS / NVIC 01-20
Enforces comprehensive security plans, active data logging, and dedicated shipboard Cybersecurity Officers (CySO) under strict NVIC 01-20 inspection playbooks for all tonnage routing inside US territorial waters.
Industry Bodies & Inspection Schemes
Organisations, vetting schemes, and investigation bodies that structure the offshore, tanker, and general maritime inspection markets. OCIMF is the central body here it administers both the SIRE tanker vetting programme and co-administers the OVID offshore vessel scheme alongside IMCA.
Technology Systems & Service Landscape
Split into two parts. Part A shipboard and industrial systems referenced in cyber risk, casualty, and inspection contexts. Part B the service provider landscape: a taxonomy of the types of organisations operating adjacent to maritime cyber assessment services, their operational focus, and the key integration gap each category leaves open for combined physical-and-cyber specialists.
Market Segments & Client Types
Vessel types, target client segments, and commercial formats referenced throughout the document, grouped by category for executive clarity.
Select your sector viewport to isolate targeted vulnerabilities and operational vocabulary parameters:
Vessel Operations & Certificate Maintenance
Your driving challenge is protecting commercial uptime, implementing compliant network standards, and passing Document of Compliance (DoC) validation cycles. If system infrastructure fails to display clear cyber-hygiene baselines during audit frameworks, your operational authorisation is compromised.
Vetting inspectors from major energy charterers and global dry bulk agencies are actively screening shipboard network architectures. Use this interactive prep tool to audit your fleet's current readiness stance:
Safety Management System (SMS) Native Workflows
Verify that your cyber risk management protocols are deeply embedded into standard operating routines as required by IMO 2021, featuring clear, tested incident escalation paths back to the shore side.
Crew Operational Competency & Device Control
Confirm shipboard personnel can demonstrate practical knowledge of network access rules (e.g., locking physical USB ports) and spot phishing attempts during live inspector challenges.
IT and OT Firewall Segmentation
Audit the shipboard infrastructure to ensure machinery control environments (engines, propulsion loops, cargo pumps) are fully isolated from crew amenities, administrative workstations, and public Wi-Fi access points.
Bridge/Engine Software Configuration Tracking
Ensure all ECDIS units, radar setups, and automated PLCs run verified, current, OEM-approved firmware packages with matching modification logs stored inside the engine room.
The Assurance Pass Solution
Our collaborative service deployments build this operational standard directly into your day-to-day shipboard life. By certifying your fleet under the IASME Maritime Cyber Baseline standard, we provide the absolute data proof required to secure tier-1 commercial charter clearance and satisfy strict underwriting vetting parameters.
Complete Acronym Audit
Every acronym and abbreviation used across all eight sections. Use the filters to find entries by status. All entries now have full expansions this table serves as the master quick-reference index.
| Acronym | Status | Full expansion & definition | Section |
|---|---|---|---|
| A. Bilbrough & Co. | Insurance | The traditional management firm directing underwriting operations and member policies for Steamship Mutual and the London P&I Club. | 01 · P&I Clubs |
| ABN AMRO | Insurance | Major financial institution engaged in ship finance bank facilities, tying asset debt loops to active technical cyber validations. | 08 · Market Segments |
| ABSAmerican Bureau of Shipping | Rule/Vetting | US-headquartered IACS classification society. Directs technical topology audits against its unique 'CyberSafety' manual and offers notation pathways. | 03 · Class & Professional Bodies |
| Admiralty Solicitors / Maritime Law Firms | Insurance | International legal partnerships specializing in shipping, maritime commerce, and commodities. Primary commissioning parties for forensically admissible cyber causation and expert witness reports. | 06 · Industry Bodies |
| AHTSAnchor Handling Tug Supply | OT & Systems | Specialized offshore support hull handling rig anchors and dynamic towing processes, carrying extensive deck machinery and station-keeping control loops. | 06 · Industry Bodies |
| AISAutomatic Identification System | OT & Systems | Vessel transponder broadcasting location, course, and identity data over VHF loops. Vulnerable to injection attacks and spoofing scenarios. | 07 · Technology Landscape |
| Allianz | Insurance | Example of a major corporate commercial insurer underwriting blue-water hull risk alongside Lloyd's syndicates. | 02 · H&M Underwriters |
| American Club | Insurance | American Steamship Owners Mutual Protection & Indemnity Association, Inc. The only IG club domiciled in the United States; managed by Shipowners Claims Bureau (SCB). | 01 · P&I Clubs |
| AMPAutoridad Marítima de Panamá | Rule/Vetting | Panama Maritime Authority flag state administration, governing the world's largest open ship registry and mandating IMO-aligned safety rules. | 05 · Cyber Standards |
| Anglo-Eastern | OT & Systems | Tier-1 third-party ship management group responsible for executing technical security baselines across a massive multi-vessel fleet. | 08 · Market Segments |
| APAVE | OT & Systems | Testing, verification, and inspection entity operating inside industrial energy fields, moving adjacently to technical marine cyber survey spaces. | 07 · Technology Landscape |
| ASTMAmerican Society for Testing and Materials | OT & Systems | Standards body defining petroleum measurement procedures (e.g. D1298, D4052) used in bunker custody transfer calculations. Software version control of ASTM formula implementations is a compliance consideration in dispute resolution. | 07 · Technology |
| ATEXAtmosphères Explosibles | Rule/Vetting | EU directive governing equipment certification for explosive atmospheres (tanker cargo spaces, pump rooms). Zone classifications determine permitted device types; non-ATEX electronics in hazardous zones create safety and insurance compliance exposure. | 05 · Cyber Standards |
| BDNBunker Delivery Note | OT & Systems | The official electronic or print summary document recording mass transfer delivery metrics, vulnerable to file modifications on compromised computers. | 07 · Technology Landscape |
| Bernhard Schulte | OT & Systems | Major international ship manager maintaining integrated network configurations and directing fleet safety management compliance. | 08 · Market Segments |
| BIMCOBaltic and International Maritime Council | Rule/Vetting | World's largest international shipping association. Co-author of the joint-industry cyber manuals and provider of standardized contract security clauses. | 05 · Cyber Standards |
| BIMCO cyber clauses | Rule/Vetting | Standardized charter party conditions mapping contractual liability paths between shipping owners and commercial charterers during incidents. | 05 · Cyber Standards |
| BMWBunker Management Workstation | OT & Systems | HMI terminal aggregating flow-meter data and generating the BDN aboard bunker barges. Vulnerable to USB malware; compromised workstations may produce BDNs inconsistent with independent meter records. | 07 · Technology |
| BORBunkers Remaining On Board | OT & Systems | Liquid fuel volume logs stored inside vessel tanks, generating regular commercial audit suits between chartering entities and vessel owners. | 08 · Market Segments |
| BP | Rule/Vetting | Major oil corporation and constituent member of OCIMF, utilizing SIRE vetting to audit digital asset tracking configurations prior to hire. | 06 · Industry Bodies |
| Britannia | Insurance | Britannia Steam Ship Insurance Association. London-based mutual managed by Tindall Riley. Mid-size IG club with strong tanker and dry bulk membership. | 01 · P&I Clubs |
| BSUBundesstelle für Seeunfalluntersuchung | Rule/Vetting | German Federal Bureau of Maritime Casualty Investigation. Evaluates shipping accidents inside Baltic/North Sea channels, checking software error tracks. | 06 · Industry Bodies |
| Bulk & Container Fleet | OT & Systems | The compliance-driven trade shipping segment utilizing large-scale machinery loops, facing growing pressure under RightShip RIQ checking matrices. | 08 · Market Segments |
| BVBureau Veritas | Rule/Vetting | French classification society. Implements mandatory newbuild guidelines and issues proprietary asset notations like Cyber-AT, Cyber-EL, and Cyber-RS. | 03 · Class & Professional Bodies |
| CBSComputer-Based System | OT & Systems | The definitive checking unit outlined inside IACS UR E27 rules, encompassing any networked shipboard microprocessing node governing control actions. | 05 · Cyber Standards |
| CCSChina Classification Society | Rule/Vetting | IACS society dominant across Chinese-built tonnage. Manages dedicated Class-P notation pathways and enforces construction rules under UR E26/E27 parameters. | 03 · Class & Professional Bodies |
| CDIChemical Distribution Institute | Rule/Vetting | Specialized chemical fleet inspection format, enforcing digital and technical checking routines across dangerous liquid cargo lines. | 06 · Industry Bodies |
| CER DirectiveCritical Entities Resilience Directive | Rule/Vetting | EU Directive 2022/2557 targeting physical security steps for transport hubs and ports, operating alongside NIS2 to form a dual compliance layer. | 05 · Cyber Standards |
| Chevron | Rule/Vetting | OCIMF member energy corporation enforcing strict tech compliance and configuration screening before chartering tanker assets. | 06 · Industry Bodies |
| China P&I Club | Insurance | China Shipowners Mutual Assurance Association. State-backed; primarily covers Chinese-flag and Chinese-owned vessels. Largest non-IG P&I provider by Chinese tonnage. | 01 · P&I Clubs |
| CHIRPConfidential Hazardous Incident Reporting Programme | OT & Systems | UK aviation and maritime safety reporting body providing human-element error logs and professional learning resources to the international seafaring community. | 07 · Technology Landscape |
| Cloud SMS PlatformsCloud-Hosted Ship Management Systems | OT & Systems | Fleet-wide cloud-native operations software (e.g. Danaos, Helm CONNECT, AMOS, DNV Nexus) running centralized maintenance, crew scheduling, and documentation management via automatic synchronisation updates. A critical supply chain concentration vector: a compromised provider update can cascade malicious configuration data across an entire managed fleet simultaneously. | 07 · Technology Landscape |
| CIICarbon Intensity Indicator | OT & Systems | Operational efficiency rating calculated from machinery fuel tracking data generated by engine OT loops, introducing a risk of data falsification. | 04 · Regulations & Codes |
| CIRCIACyber Incident Reporting for Critical Infrastructure Act | Rule/Vetting | US statutory act forcing operators of critical maritime infrastructure to pass detailed incident declarations to CISA within 72 hours. | 05 · Cyber Standards |
| CISACybersecurity and Infrastructure Security Agency | Rule/Vetting | US federal agency responsible for national cybersecurity. Its Cybersecurity Performance Goals underpin the USCG MTS rule. CIRCIA requires critical infrastructure operators to report cyber incidents to CISA within 72 hours. | 05 · Cyber Standards |
| Citi | Insurance | Global banking corporation active in large-scale ship finance, structuring marine loans contingent on regulatory cyber risk verification. | 08 · Market Segments |
| CL 380Institute Cyber Attack Exclusion Clause | Insurance | The historic marine clause that blanket-excludes any loss or liability caused by a cyber attack from H&M and cargo policies. Introduces profound coverage gaps during shipboard electronic failures. | 02 · H&M Underwriters |
| Classification-Linked Inspection Bodies | OT & Systems | Testing giants utilizing surveyor networks to market rigid rule structures, lacking commercial neutrality during dispute resolutions. | 07 · Technology Landscape |
| ClassNKNippon Kaiji Kyokai | Rule/Vetting | Japanese classification society. Largest by classed vessel counts; offers type-approval pathways for resilient hardware and publishes UR E26/E27 guides. | 03 · Class & Professional Bodies |
| CoCCertificate of Competency | Rule/Vetting | Official seafarer license issued under STCW conventions, verifying that bridge and engine officers satisfy safety watchkeeping competencies. | 04 · Regulations & Codes |
| Consolidated Crew E-Learning Platforms | OT & Systems | Mass training software providers delivering static video elements, lacking real-time interactive engineering mentorship toolsets. | 07 · Technology Landscape |
| Continuous OT Network Monitoring Platforms | OT & Systems | Enterprise software agents executing deep packet checks across serial protocols, lacking localized maritime inspection visibility. | 07 · Technology Landscape |
| Coriolis MFMCoriolis Mass Flow Meter | OT & Systems | Coriolis-effect sensor measuring fluid mass flow and density. Used for bunker custody transfer; cyber-physical interface via Modbus output creates falsification risk requiring forensic log review in quantity disputes. | 07 · Technology |
| CPDContinuing Professional Development | Insurance | Commercial format for Maritime Training Academy educational events sold directly to P&I and H&M underwriting syndicates to satisfy annual professional training requirements. | 08 · Market Segments |
| CRSCroatian Register of Shipping | Rule/Vetting | National classification society and IACS member governing Adriatic and Mediterranean tonnage fields under unified UR E26/E27 rules. | 03 · Class & Professional Bodies |
| CSFNIST Cybersecurity Framework | Rule/Vetting | Technical framework organizing risk management controls into five functions: Identify, Protect, Detect, Respond, Recover. Referenced directly in USCG playbooks. | 05 · Cyber Standards |
| CSOCompany Security Officer | Rule/Vetting | Shore-side management representative designated under the ISPS Code to manage corporate Ship Security Plans and coordinate with shipboard perimeters. | 04 · Regulations & Codes |
| CyberPlus | Insurance | Specialist maritime technical risk assessment provider executing on-board validation audits and forensic investigations to protect policy coverage stances. | 02 · H&M Underwriters |
| CySOCybersecurity Officer | Rule/Vetting | Shipboard security role mandated under the statutory USCG MTS rule, tasked with maintaining configuration control logs and executing incident reporting steps. | 05 · Cyber Standards |
| DCSDistributed Control System | OT & Systems | Process automation setup managing ballasting loops and cargo thermal metrics, targeted to mask volume deficiencies during liquid transfer actions. | 07 · Technology Landscape |
| DMLCDeclaration of Maritime Labour Compliance | Rule/Vetting | The formal document required under the Maritime Labour Convention (MLC) outlining how shipowners satisfy national seafarer welfare rules. Part I is issued by the flag state and Part II is prepared by the ship manager, intersecting with digital crew management records. | 04 · Regulations & Codes |
| DNVDet Norske Veritas | Rule/Vetting | Norwegian classification society. Promotes an influential tiered 'Cyber Secure' notation (Basic, Enhanced, Advanced) frequently required by modern energy charterers. | 03 · Class & Professional Bodies |
| DoC / DOCDocument of Compliance | Rule/Vetting | ISM Code document issued to shipping firms. The annual Document of Compliance audit is the practical mechanism enforcing active IMO 2021 fleet reviews. | 04 · Regulations & Codes |
| DORADigital Operational Resilience Act | Insurance | EU regulatory standard forcing financial entities, including marine insurers and MGAs operating inside Europe, to maintain strict oversight of third-party ICT service links. | 05 · Cyber Standards |
| DPDynamic Positioning | OT & Systems | Automated position-keeping system linking thrusters with positioning data streams. Cyber disruption creates high risks of location loss. | 07 · Technology Landscape |
| DPADesignated Person Ashore | Rule/Vetting | Mandatory shore-based manager under the ISM Code with direct executive access. Primary internal lead responsible for embedding cyber guidelines into the SMS. | 01 · P&I Clubs |
| DryBMSDry Bulk Management Standard | Rule/Vetting | Voluntary management framework utilized across major dry bulk charter chains to evaluate and grade the cyber-hygiene baselines of third-party managers. | 04 · Regulations & Codes |
| eBLElectronic Bill of Lading | OT & Systems | Digital system replacement for paper cargo titles, driving secondary demands for independent data confirmation to align items with physical volumes. | 07 · Technology Landscape |
| ECDISElectronic Chart Display & Info System | OT & Systems | Mandatory electronic navigation layout. Represents a critical bridgework attack vector vulnerable to chart corruption or spoofed position streams. | 07 · Technology Landscape |
| EMSAEuropean Maritime Safety Agency | Rule/Vetting | Technical advisory arm of the EU. Directs the checklist protocols that Port State Control officers use to evaluate vessel compliance inside European waters. | 05 · Cyber Standards |
| EU CRAEU Cyber Resilience Act | Rule/Vetting | Binding European product legislation mandating built-in cybersecurity configurations for all supply chain hardware and software elements with digital components by September 2026. | 05 · Cyber Standards |
| EU ETSEU Emissions Trading System | OT & Systems | Carbon pricing mechanism tracking engine emissions profiles derived from machinery OT data streams, rendering data integrity a financial factor. | 04 · Regulations & Codes |
| ExxonMobil | Rule/Vetting | OCIMF member energy major enforcing technical sensor checking and network monitoring as prerequisites for terminal clearance agreements. | 06 · Industry Bodies |
| FALConvention on Facilitation of Maritime Traffic | Rule/Vetting | IMO convention targeting paperless terminal documentation loops. Co-issued the baseline MSC-FAL.1/Circ.3 cyber risk management guidance framework. | 04 · Regulations & Codes |
| FAL CommitteeIMO Facilitation Committee | Rule/Vetting | IMO committee responsible for the FAL Convention on Facilitation of Maritime Traffic. Co-issued MSC-FAL.1/Circ.3 (the IMO 2021 cyber guidance) jointly with the MSC. | 04 · Regulations & Codes |
| Flag States | Rule/Vetting | National maritime administrations executing international convention inspections and issuing standardized technical verifications across registries. | 08 · Market Segments |
| Fleet Management | OT & Systems | Large-scale global third-party ship management enterprise handling daily asset network controls and flag-state verification tasks. | 08 · Market Segments |
| FMEAFailure Mode and Effects Analysis | Rule/Vetting | Engineering methodology mapping potential failure modes, causes, and system effects. Increasingly applied to OT cyber risk to model how falsified sensor outputs propagate through vessel systems; informs both maintenance schedules and cyber resilience design. | 05 · Cyber Standards |
| GAGeneral Average | Insurance | Legal allocation principle — codified in the York-Antwerp Rules — dividing extraordinary salvage and sacrifice expenses proportionally among cargo and hull stakeholders during a common peril. A shipowner's legal standing to claim GA contributions is significantly undermined where a casualty is causally linked to a failure to maintain reasonable vessel cyber-seaworthiness. | 06 · Legal & Dispute Stakeholders |
| Gard | Insurance | Gard AS. Norwegian-headquartered mutual; largest IG club by entered fleet tonnage. Highly proactive leader in fleet risk management. CEO Rolf Thore Roppestad serves as International Group Chair. | 01 · P&I Clubs |
| GDPRGeneral Data Protection Regulation | Rule/Vetting | EU data privacy mandate protecting crew identity data. Regulates file management and tracking behaviors across remote inspection records. | 05 · Cyber Standards |
| GNSSGlobal Navigation Satellite System | OT & Systems | The overarching framework encompassing GPS, Galileo, and BeiDou networks. Feeds crucial coordinates into bridge systems, vulnerable to electronic jamming. | 07 · Technology Landscape |
| GPSGlobal Positioning System | OT & Systems | US satellite constellation feeding positioning data to ECDIS and autopilots, vulnerable to electronic spoofing vectors. | 07 · Technology Landscape |
| GPS / GNSSGlobal Positioning System / Global Navigation Satellite System | Rule/Vetting | GPS (US) is one of several GNSS constellations; others include GLONASS, Galileo, and BeiDou. Feeds ECDIS, AIS, and DP systems. Spoofing and jamming are documented growing threats underpinning cyber causation investigations. | 07 · Technology Landscape |
| GXLGroup Excess of Loss | Insurance | The collective reinsurance pooling program shared annually across the 12 International Group members, covering catastrophic casualty lines exceeding standard thresholds. | 01 · P&I Clubs |
| H&MHull & Machinery | Insurance | Marine insurance policy protecting physical ship architectures, main machinery, and electronics. Underwritten via commercial insurance markets or Lloyd's syndicates. | 02 · H&M Underwriters |
| HVRHague-Visby Rules | Rule/Vetting | International legal convention framing cargo carriage liability under bills of lading, imposing a non-delegable duty to exercise due diligence to maintain a seaworthy vessel — a duty now structurally encompassing digital, firmware, and software system configurations. Failure to satisfy this standard at voyage inception significantly undermines available liability limitations and exemptions. | 06 · Legal & Dispute Stakeholders |
| IACSInternational Association of Classification Societies | Rule/Vetting | Umbrella consortium coordinating the 12 major classification societies. Formulates binding Unified Requirements (URs) enforcing technical rule sets cross-fleet. | 03 · Class & Professional Bodies |
| IASME Maritime Cyber Baseline | Rule/Vetting | UK maritime-specific assurance standard designed by the IASME Consortium. Provides proportionate, auditable certification for existing fleets. | 05 · Cyber Standards |
| ICSIndustrial Control System / International Chamber of Shipping | Rule/Vetting | Dual-use acronym: (1) Industrial Control System, the generic term for OT systems including SCADA, DCS, and PLC, used within IEC 62443; (2) International Chamber of Shipping, the principal trade association for shipowners and co-author of the Industry Guidelines on Cyber Security Onboard Ships. Context determines meaning. | 05 · Cyber Standards |
| ICS (OT context)Industrial Control System | OT & Systems | Overarching definition tracking automated machinery control devices including SCADA loops and PLCs. Distinct from the International Chamber of Shipping trade group. | 05 · Cyber Standards |
| IEC 62443 | OT & Systems | The leading global technical cybersecurity standard series for industrial automation, defining zone and conduit segmentations for machinery networks. | 05 · Cyber Standards |
| IGInternational Group (of P&I Clubs) | Insurance | The overarching mutual pool system comprising 12 independent, not-for-profit P&I structures covering roughly 87% of ocean-going tonnage. | 01 · P&I Clubs |
| ILOInternational Labour Organisation | Rule/Vetting | United Nations specialized agency managing international labor metrics and generating foundational seafarer welfare targets. | 04 · Regulations & Codes |
| INS / IBSIntegrated Navigation System / Integrated Bridge System | OT & Systems | Central network fabric linking mandatory bridge instruments — ECDIS, radar, autopilot, AIS, and positioning sensors — over unencrypted NMEA serial pathways. Under IACS UR E26, the entire INS infrastructure is evaluated as a unified attack surface; a single compromised peripheral can undermine the operational integrity of the complete navigation platform. | 07 · Technology Landscape |
| IMCAInternational Marine Contractors Association | Rule/Vetting | Trade association for offshore marine contractors. Co-administers the OVID vetting platform alongside OCIMF to qualify support assets for energy charters. | 06 · Industry Bodies |
| IMOInternational Maritime Organisation | Rule/Vetting | United Nations specialized shipping agency responsible for directing global conventions (SOLAS, MARPOL, STCW) and setting regulatory frameworks. | 04 · Regulations & Codes |
| IMO 2021IMO Resolution MSC.428(98) | Rule/Vetting | The benchmark international resolution mandating maritime operators to formally integrate cyber risk controls natively inside Safety Management Systems. | 04 · Regulations & Codes |
| IMO MSC.428(98)IMO Cyber Risk Resolution | Rule/Vetting | The root international mandate requiring maritime operators to address cyber risks within approved Safety Management Systems. Compliance verified at every annual Document of Compliance (DoC) audit from January 2021. | 05 · Cyber Standards |
| Industry Guidelines v5 | Rule/Vetting | The preeminent joint-industry manual (BIMCO/ICS/IUMI) specifying standard operating processes for shipboard network baseline safety. | 05 · Cyber Standards |
| INTERCARGO | Rule/Vetting | International Association of Dry Cargo Shipowners. Trade group coordinating cyber-hygiene guidance matrices for bulk asset types and RightShip vetting scenarios. | 05 · Cyber Standards |
| INTERTANKO | Rule/Vetting | International Association of Independent Tanker Owners. Industry association directing operational best practices and co-authoring vessel security guidelines. | 05 · Cyber Standards |
| Intertek | OT & Systems | Global verification and testing institution with established oil major frame agreements, delivering technical audit operations across marine logistics. | 06 · Industry Bodies |
| IRSIndian Register of Shipping | Rule/Vetting | Indian national classification society and full IACS member. Appends unique Cyber Safety notations to vessels operating inside the Indian Ocean region. | 03 · Class & Professional Bodies |
| ISM CodeInternational Safety Management Code | Rule/Vetting | Mandatory IMO code ensuring safe vessel operations. Dictates structural maintenance of Safety Management Systems and requires regular corporate audits. | 04 · Regulations & Codes |
| ISO 27001 | Rule/Vetting | International corporate information security management standard, primarily deployed to harden shore-side office structures and enterprise fleet servers. | 05 · Cyber Standards |
| ISPS CodeInternational Ship & Port Facility Security Code | Rule/Vetting | IMO physical security framework governing access controls, physical perimeter alerts, and security plan execution, now interfacing with cyber intrusion vectors. | 04 · Regulations & Codes |
| ITInformation Technology | OT & Systems | Administrative networks, email setups, and crew cabins. Represents the primary entry vector for ransomware payloads pivoting into machinery zones. | 07 · Technology Landscape |
| IUAInternational Underwriting Association | Insurance | Trade association for company market insurers based in London. Publishes standard endorsements including IUA 09-082, the institutional cyber buy-back endorsement allowing shipowners to conditionally reinstate coverage for cyber-enabled physical damage. | 02 · H&M Underwriters |
| IUA 09-082International Underwriting Association Endorsement | Insurance | Standard institutional cyber buy-back endorsement allowing shipowners to conditionally reinstate coverage lines for cyber-enabled physical damage. | 08 · Market Segments |
| IUMIInternational Union of Marine Insurance | Insurance | Global federation of marine underwriting associations. Coordinates market parameters for evaluating hull risks and co-authors joint-industry cyber safety scripts. | 02 · H&M Underwriters |
| Japan P&I Club | Insurance | Japan Ship Owners' Mutual Protection & Indemnity Association. Tokyo-based; the only IG member club domiciled in Japan. Dedicated to Asian fleet networks. | 01 · P&I Clubs |
| JH143Joint Hull Committee Survey Note 143 | Insurance | Technical shipyard construction protocol issued via London underwriting groups, forcing independent cyber-ready checks at structural delivery phases. | 04 · Regulations & Codes |
| JC2025-026JCC Marine Cargo Cyber Exclusion with Physical Theft Confirmation Endorsement | Insurance | Joint Cargo Committee endorsement (October 28, 2025) carving back cargo coverage for physical theft of insured goods facilitated by cyber means — e.g. hackers stealing terminal container release codes — provided further physical human intervention is required to complete the theft. Paragraph 4 is the operative carve-back; digital-only losses remain excluded under Paragraph 1. | 02 · H&M Underwriters |
| KfW IPEX-Bank | Insurance | Prominent German ship finance institution integrating technical cyber risk verifications and ESG markers into lending framework cycles. | 08 · Market Segments |
| Korean P&I Club | Insurance | Korea Shipowners' Mutual P&I Association. Seoul-based mutual; prominent non-IG marine liability underwriter managing Asian fleet operations. | 01 · P&I Clubs |
| KRKorean Register | Rule/Vetting | South Korean IACS class society dominant across major domestic building yards. Issues specialized Cyber Resilience notations checking against data integrity threats. | 03 · Class & Professional Bodies |
| LISCRLiberian International Ship & Corporate Registry | Rule/Vetting | The administrative body managing the Liberian flag, enforcing strict regulatory alignments and transposing IMO resolutions into mandatory national laws. | 05 · Cyber Standards |
| Lloyd's / Lloyd's of London | Insurance | The world's preeminent specialist insurance market. Syndicates back significant tranches of marine asset damage exposures using tailored, cyber-rated inception surveys. | 02 · H&M Underwriters |
| LMALloyd's Market Association | Insurance | Industry body representing managing agents in the Lloyd's market. Publishes standard marine cyber endorsements including LMA 5402 (excluding) and LMA 5403 (including/buy-back), the primary clauses used to exclude or reinstate cyber coverage in H&M policies. | 02 · H&M Underwriters |
| LMA 5402Marine Cyber Risk Endorsement (Excluding) | Insurance | Lloyd's Market Association endorsement clause explicitly isolating and omitting cyber risks from standard policies, minimizing claims handling ambiguities. | 02 · H&M Underwriters |
| LMA 5403Marine Cyber Risk Endorsement (Including) | Insurance | The structural buy-back endorsement companion enabling coverage for cyber-enabled asset damage to be reinstated, legally conditional on passing inception surveys. | 02 · H&M Underwriters |
| LMAALondon Maritime Arbitrators Association | Rule/Vetting | The leading arbitral body for commercial shipping disputes under English law. Arbitrators require forensically admissible, timestamped data records during navigation suits. | 06 · Industry Bodies |
| LEOLow Earth Orbit Connectivity | OT & Systems | High-bandwidth, low-latency satellite platforms (e.g., Starlink Maritime, OneWeb) transforming fleet connectivity and telemetry capabilities. Introduces severe perimeter security risks when integrated into shipboard environments without strict network segregation from legacy corporate VSAT firewall architectures. | 07 · Technology Landscape |
| LNG Carriers | OT & Systems | High-value cargo assets with dense technical automation profiles (cryogenic processors, reliquefaction arrays), representing elevated operational exposure risks. | 08 · Market Segments |
| London P&I Club | Insurance | London Steam-Ship Owners' Mutual Insurance Association Ltd. Managed by A. Bilbrough & Co. Core focus across bulk carriers, tankers, and container platforms. | 01 · P&I Clubs |
| Loss Prevention | Insurance | Proactive risk-reduction workflows funded natively by P&I clubs, utilizing allocated budgets to support crew security training and vessel surveys. | 01 · P&I Clubs |
| LRLloyd's Register | Rule/Vetting | British classification society. Developed the 'ShipRight Cyber-Enable' verification procedure to evaluate technical control levels across automated networks. | 03 · Class & Professional Bodies |
| MAIBMarine Accident Investigation Branch | Rule/Vetting | UK government bureau investigating maritime casualties. Publishes global safety briefs, increasingly tracking digital software errors behind machinery casualties. | 06 · Industry Bodies |
| Maritime Training Academy | Insurance | The professional educational institute providing programmatic training modules and technical cyber coursework to commercial underwriting teams. | 08 · Market Segments |
| MARPOLInternational Convention for the Prevention of Pollution from Ships | Rule/Vetting | IMO environmental mandate. Annex VI requires strict emissions tracking calculations linked to electronic OT data logs, exposed to manipulation hazards. | 04 · Regulations & Codes |
| MASSMaritime Autonomous Surface Ship | OT & Systems | Vessels running automated or remote operations pathways across coastal channels, requiring absolute technical network protection. | 08 · Market Segments |
| MCAMaritime and Coastguard Agency | Rule/Vetting | UK flag state administration. Mandates formal compliance with IMO safety targets and sets regulatory parameters for UK-registered fleets and coastal channels. | 05 · Cyber Standards |
| MGAManaging General Agent | Insurance | An intermediary entity holding delegated capital authority from underwriters, acting as the primary channel forcing cyber assessment rules onto high-value assets. | 02 · H&M Underwriters |
| MLCMaritime Labour Convention | Rule/Vetting | ILO convention protecting crew welfare. Interfaces with cyber assessment frameworks regarding payroll banking protection and crew identity system integrity. | 04 · Regulations & Codes |
| ModbusModbus Protocol (RTU/TCP) | OT & Systems | Dominant maritime OT serial communication standard linking PLCs, sensors, and HMI panels. No native authentication or encryption; any bus-connected device can read or overwrite registers. Primary finding in OT cyber baseline assessments. | 07 · Technology |
| MPAMaritime and Port Authority of Singapore | Rule/Vetting | Singapore flag state and port administrator, enforcing localized cyber resilience checklists across APAC offshore energy and logistics shipping lanes. | 05 · Cyber Standards |
| MSCMaritime Safety Committee | Rule/Vetting | The senior technical safety body of the IMO. Formulates structural amendments to conventions and authorized Resolution MSC.428(98). | 04 · Regulations & Codes |
| MSC-FAL.1/Circ.3IMO Joint MSC / FAL Circular | Rule/Vetting | High-level IMO guidance on maritime cyber risk management describing five functions: Identify, Protect, Detect, Respond, Recover. Technical companion to MSC.428(98); not itself legally binding but frames how compliance is assessed. | 05 · Cyber Standards |
| MTSMarine Transportation System | Rule/Vetting | US infrastructure definition encompassing ports, vessels, and locks. Defines the scope of the mandatory USCG Marine Transportation System cyber rulemaking. | 05 · Cyber Standards |
| MTS-ISAC | Rule/Vetting | Threat intelligence sharing repository, aggregating technical indicators of compromise and pushing alerts across global shipping operations networks. | 05 · Cyber Standards |
| Niche Maritime Cyber Consultancies | OT & Systems | Advisory teams focusing on shore-side policy outlines and basic asset checking matrices, operating separately from physical structural inspection providers. | 07 · Technology Landscape |
| NIS2Network & Information Security Directive 2 | Rule/Vetting | Mandatory EU infrastructure directive. Forces ports, logistics groups, and offshore hubs to enact strict supply chain audits under severe revenue penalty tracks. | 05 · Cyber Standards |
| NIST CSFNational Institute of Standards and Technology Cybersecurity Framework | Rule/Vetting | US-origin risk management framework built around five functions: Identify, Protect, Detect, Respond, Recover. Aligned to the USCG MTS rule and CISA performance goals. Provides the technical vocabulary USCG inspectors use when auditing cybersecurity plans. | 05 · Cyber Standards |
| NMEA 0183 / 2000Marine Electronics Data Protocol | OT & Systems | Standard data protocol for bridge sensor communications (radar, GPS). Lacks encryption or authentication, creating blind injection hazards on bridge screens. | 07 · Technology Landscape |
| NORMA Cyber | Rule/Vetting | Nordic Maritime Cyber Resilience Centre. Coordinates real-time threat analysis matrices across Scandinavian shipowners and major Nordic-headquartered IG clubs. | 05 · Cyber Standards |
| NorthStandard | Insurance | Large International Group club created by the 2023 amalgamation of North of England and Standard Club. Early mover in backing digital safety management steps. | 01 · P&I Clubs |
| NRCNational Response Center | Rule/Vetting | The primary communications node for federal pollution and safety events inside US waters, designated to handle maritime cyber intrusion declarations. | 05 · Cyber Standards |
| NTSBNational Transportation Safety Board | Rule/Vetting | Independent US federal accident agency. Audits critical transport casualties, detailing software faults and automation errors within formal safety briefs. | 06 · Industry Bodies |
| NTSB / USCGNational Transportation Safety Board / US Coast Guard | Rule/Vetting | The two US authorities for marine accident investigation. NTSB investigates significant US-flagged marine casualties; USCG handles broader enforcement and investigation for incidents in US waters under MTSA and the MTS Rule. | 06 · Industry Bodies |
| NVIC 01-20 | Rule/Vetting | US Coast Guard Navigation and Vessel Inspection Circular 01-20. The playbook inspectors use to audit and enforce cyber risk compliance at US ports, facilities, and vessels. | 05 · Cyber Standards |
| OCIMFOil Companies International Marine Forum | Rule/Vetting | The oil major consortium (BP, Shell, Chevron). Formulates rigid baseline qualification standards and administers the critical SIRE/OVID database platforms. | 05 · Cyber Standards |
| OCIMF SIRE 2.0Ship Inspection Report Programme Version 2 | Rule/Vetting | Updated OCIMF tanker inspection scheme launched 2023, including explicit cyber and digital system questions within the VIQ. Creates a formalised, structured inspection requirement for digital system safety. See also: SIRE / SIRE 2.0. | 05 · Cyber Standards |
| OCIMF TMSATanker Management and Self Assessment | Rule/Vetting | OCIMF's shore-side management quality framework for tanker operators. Element 13 (Maritime Security) includes cyber risk questions. Oil majors use TMSA scores in vetting decisions, creating commercial pressure to achieve strong cyber ratings. See also: TMSA. | 05 · Cyber Standards |
| OCSOuter Continental Shelf | Rule/Vetting | US federal energy exploration zones. Offshore platforms, drill rigs, and wind farms located here are subject to full USCG cybersecurity mandates. | 05 · Cyber Standards |
| Oil Majors | Rule/Vetting | Large integrated energy giants (BP, Shell, ExxonMobil). Dictate OVID/SIRE vetting criteria, mandating cyber resilience as a commercial condition of hire. | 08 · Market Segments |
| ORBOil Record Book | Rule/Vetting | The mandatory logbook required under MARPOL regulations for recording all shipboard oil transfer and disposal operations. Frequently audited alongside electronic automation records during environmental compliance and Port State Control checks. | 04 · Regulations & Codes |
| OSVOffshore Support Vessel | OT & Systems | Umbrella term for energy exploration assets (PSVs, AHTS), carrying heavy automation loops and checked via specialized OVID templates. | 08 · Market Segments |
| OTOperational Technology | OT & Systems | Hardware and software components directly manipulating physical events (steering gears, propulsion loops). Safety-critical and distinct from IT frameworks. | 07 · Technology Landscape |
| OEM TelemetryOriginal Equipment Manufacturer Remote Maintenance Loops | OT & Systems | Dedicated inbound remote access links — VPN tunnels or remote desktop sessions — maintained by machinery manufacturers for real-time engine diagnostics and technical support. These permanent pathways operate outside DPA and CSO visibility, functioning as a high-risk supply chain vector: a breach of the land-based OEM enterprise can bridge directly into a vessel's active physical control systems. | 07 · Technology Landscape |
| OTAOil Tanker Assessment | Rule/Vetting | Tanker vetting assessment framework used alongside chemical tracking protocols to check operator profiles before issuing charter matches. | 06 · Industry Bodies |
| OVIDOffshore Vessel Inspection Database | Rule/Vetting | Highly structured OCIMF inspection platform mapping security and technical readiness metrics across specialized offshore assets prior to hire. | 06 · Industry Bodies |
| OVVOnderzoeksraad voor Veiligheid | Rule/Vetting | Dutch Safety Board. Investigates significant transport and industrial events near major European trade locations, assessing data errors in vessel networks. | 06 · Industry Bodies |
| P&IProtection & Indemnity | Insurance | Mutual third-party liability insurance for shipping companies, covering human casualty events, cargo damage, environmental spills, and wreck clearance tasks. | 01 · P&I Clubs |
| Panama / Liberia / Marshall Islands / Singapore MPAMajor open registries and key flag states | Rule/Vetting | All require IMO 2021 cyber compliance for their registered vessels and have issued supplementary guidance. Together cover the majority of the world's tanker and bulk carrier fleet. Singapore MPA requirements are directly relevant to operators active in the Asia-Pacific region. | 05 · Cyber Standards |
| PLCProgrammable Logic Controller | OT & Systems | Hardened computing block automating electromechanical actions (valves, pumps), acting as a primary testing target within IEC 62443 steps. | 05 · Cyber Standards |
| Poseidon Principles | Insurance | Global financial and insurance agreement tracking portfolio alignment with emissions targets. Critically dependent on the data integrity of shipboard sensors. | 04 · Regulations & Codes |
| PRSPolish Register of Shipping | Rule/Vetting | National classification society and IACS member. Governs Baltic-connected shipping fleets, incorporating UR E26/E27 rules into standard survey processes. | 03 · Class & Professional Bodies |
| PSCPort State Control | Rule/Vetting | Foreign terminal authority inspection processes verifying compliance with international laws, using EMSA circulars to flag inadequate cyber documentation. | 04 · Regulations & Codes |
| PSVPlatform Supply Vessel | OT & Systems | Offshore logistics craft supplying drilling installations, carrying integrated tank control loops and dynamic station-keeping modules. | 06 · Industry Bodies |
| REG CodeRed Ensign Group Large Yacht Code | Rule/Vetting | The mandatory operational compliance standard for commercial yachts over 24m, enforcing rigid technical security checks over emergency and bridge systems. | 04 · Regulations & Codes |
| RightShipRightShip Vetting Platform | Rule/Vetting | The dominant vetting entity for dry bulk and container operations. Incorporates structural SMS cyber-hygiene baselines directly into asset grading matrix models. | 06 · Industry Bodies |
| RINARoyal Institution of Naval Architects | Rule/Vetting | Professional body endorsing the IASME Maritime Cyber Baseline scheme, validating technical credential pathways distinct from class rules. | 06 · Industry Bodies |
| RINA (class)Registro Italiano Navale | Rule/Vetting | Italian classification society and IACS member. Enforces mandatory UR E26/E27 cyber resilience requirements across Mediterranean-flagged fleets. | 03 · Class & Professional Bodies |
| RIQRightShip Inspection Questionnaire | Rule/Vetting | The physical vetting audit checklist deployed across bulk configurations. Poor technical markings here directly block access to major dry commodity cargo chains. | 06 · Industry Bodies |
| RMIRepublic of the Marshall Islands Registry | Rule/Vetting | Major international open registry holding prominent tank and gas shipping portfolios. Enforces baseline IMO 2021 cyber guidelines across all registered hulls. | 05 · Cyber Standards |
| Rolf Thore Roppestad | Insurance | CEO of Gard AS and current serving Chair of the International Group of P&I Clubs. | 01 · P&I Clubs |
| ROVRemotely Operated Vehicle | OT & Systems | Subsea robotic system used to audit pipelines and subsea setups, running control software loops vulnerable to common intrusion vectors. | 07 · Technology Landscape |
| SCADASupervisory Control & Data Acquisition | OT & Systems | Industrial control framework overseeing liquid flow behaviors at terminal sites, representing a highly targeted infrastructure platform. | 07 · Technology Landscape |
| SCBShipowners Claims Bureau | Insurance | The dedicated commercial management firm handling administrative operations and loss-prevention deployments for the American Club P&I. | 01 · P&I Clubs |
| Shell | Rule/Vetting | OCIMF member energy major directing core focus across automated gas carrier structures and utilizing specialized vetting screening templates. | 06 · Industry Bodies |
| Ship Finance Banks / Lessors | Insurance | Capital lenders and financial lessors linking vessel acquisition loans to active cyber risk certification and ESG validation loops at birth. | 08 · Market Segments |
| Shipowners' Club | Insurance | Specialist mutual IG P&I club protecting smaller craft asset classes, specializing in specialized small-craft, harbor tugs, fishing vessels, and luxury superyachts. | 01 · P&I Clubs |
| SIGTTOSociety of International Gas Tanker & Terminal Operators | Rule/Vetting | The primary trade body for liquefied gas shipping. Formulates operational risk guidelines for complex cargo and terminal interface OT loops. | 06 · Industry Bodies |
| SIRE / SIRE 2.0 | Rule/Vetting | OCIMF tanker inspection scheme. Version 2.0 appends mandatory digital questions into checking protocols, forcing crew to prove software management controls. | 05 · Cyber Standards |
| SIVAPShip Inspection & Vetting Assurance Programme | Rule/Vetting | Specialized offshore support vessel inspection format utilized alongside OVID platforms to qualify support assets for international energy logistics. | 06 · Industry Bodies |
| Skuld | Insurance | Assuranceforeningen Skuld. Norwegian mutual underwriter, Bermuda-domiciled. Maintains a large presence across tanker and offshore sectors with a quick global response footprint. | 01 · P&I Clubs |
| SLAService Level Agreement | OT & Systems | Contractual performance commitment (response times, availability, escalation paths) between service provider and client. Governs incident response timelines in maritime cyber monitoring retainer contracts. | 07 · Technology |
| SMSSafety Management System | Rule/Vetting | The centralized compliance manual set mandated by the ISM Code. Acts as the documentation core where IMO 2021 cyber controls must be formally embedded. | 04 · Regulations & Codes |
| SOCSecurity Operations Centre | OT & Systems | Central security management hub executing data monitoring actions and tracking alert patterns across fleet infrastructure layouts. | 05 · Cyber Standards |
| SOLASSafety of Life at Sea | Rule/Vetting | Foundational IMO safety convention. Integrates the core ISM Code structures (Chapter IX) and physical security architectures under the ISPS Code (Chapter XI-2). | 04 · Regulations & Codes |
| SOPStandard Operating Procedure | OT & Systems | Documented procedural workflows utilized inside digital checking applications to eliminate variable interpretation during on-site asset surveys. | 08 · Market Segments |
| SPAN PortSwitched Port Analyser | OT & Systems | Network switch feature mirroring traffic to a monitoring port for passive OT network analysis. Used in cyber assessments to inspect Modbus and NMEA traffic; misconfiguration can expose sensitive operational data. | 07 · Technology |
| SSOShip Security Officer | Rule/Vetting | Shipboard officer responsible under ISPS metrics for managing security perimeters, physical logging, and checking the cyber-physical system overlap. | 04 · Regulations & Codes |
| SSPShip Security Plan | Rule/Vetting | Controlled, sensitive vessel document mandated by the ISPS Code, tracking security steps, emergency actions, and physical access profiles. | 04 · Regulations & Codes |
| STCWStandards of Training, Certification & Watchkeeping | Rule/Vetting | IMO convention managing crew competency rules. Regulates training standards and requires security awareness updates across modern ship positions. | 04 · Regulations & Codes |
| Steamship Mutual | Insurance | Steamship Mutual Underwriting Association (Bermuda) Ltd. Managed by A. Bilbrough & Co. Deploys broad coverage matrices across bulk carriers and container fleets. | 01 · P&I Clubs |
| The Swedish Club | Insurance | Sveriges Ångfartygs Assurans Förening. Gothenburg-based mutual. Notable as one of the few IG clubs writing both third-party P&I and physical hull (H&M) coverage options. | 01 · P&I Clubs |
| Third-Party Ship ManagersV.Ships · Anglo-Eastern · Bernhard Schulte · Fleet Management | Insurance | Major independent ship management companies running day-to-day vessel operations on behalf of asset-owning clients. A critical direct client segment for fleet-wide maritime cyber assessments; a framework agreement with one major manager generates recurring multi-vessel revenue. | 08 · Market Segments |
| Thomas Miller | Insurance | The specialized commercial management firm directing business files, office networks, and claims handling for the UK P&I Club. | 01 · P&I Clubs |
| Tindall Riley | Insurance | The specialized management organization executing operations, underwriting oversight, and technical reviews for Britannia P&I. | 01 · P&I Clubs |
| TLTürk Loydu | Rule/Vetting | Turkish national classification society and full IACS member. Directs maritime survey actions and integrates UR E26/E27 rules across regional contracts. | 03 · Class & Professional Bodies |
| TMSATanker Management & Self Assessment | Rule/Vetting | OCIMF management assessment manual. Element 13 forces operators to demonstrate verified cyber policies to unlock high charter grading scores. | 05 · Cyber Standards |
| TotalEnergies | Rule/Vetting | European energy major mandating deep passive configuration checking and software inventory tracing on all contracted logistics fleets. | 06 · Industry Bodies |
| TWFTeamViewer Frontline Workplace | OT & Systems | AR remote support platform using smart glasses for live vessel inspection and guided crew assistance. Creates cyber-physical integration points requiring encrypted sessions and strong authentication. | 07 · Technology |
| UHNWUltra High Net Worth | OT & Systems | Premium privacy-focused client segment commanding modern superyacht hulls with highly interconnected domotic and entertainment networks. | 08 · Market Segments |
| UHNW Superyacht OwnersUltra High Net Worth | Insurance | Privacy-sensitive premium buyers increasingly asking about cyber security as superyachts carry sophisticated networked AV, bridge, and smart-home OT systems. A high-margin, low-volume segment; MGAs and specialist H&M underwriters are the primary distribution channel into this segment. | 08 · Market Segments |
| UK P&I Club | Insurance | United Kingdom Mutual Steam Ship Assurance Association (Bermuda) Ltd. Managed by Thomas Miller. One of the largest global mutuals with extensive hub branches across Asia. | 01 · P&I Clubs |
| UR / UR E26 / UR E27 | Rule/Vetting | Unified Requirements issued by IACS. E26 mandates lifecycle fleet asset resilience. E27 forces component vendors to verify 30 system capability benchmarks. | 03 · Class & Professional Bodies |
| USBUniversal Serial Bus | OT & Systems | Common removable storage interface. Uncontrolled USB use is a primary malware introduction vector into air-gapped OT systems (ECDIS, engine management, cargo computers). Port controls are a standard OT cyber baseline recommendation. | 07 · Technology |
| USCGUnited States Coast Guard | Rule/Vetting | Federal maritime regulator. Enforces strict national cyber rulemaking, mandating dedicated CySOs and cybersecurity plans for entities routing inside US waters. | 05 · Cyber Standards |
| USCG MTS RuleUS Coast Guard Marine Transportation System Cybersecurity Rule | Rule/Vetting | Enforces comprehensive cybersecurity plans, active data logging, and designated shipboard Cybersecurity Officers (CySO) under NVIC 01-20 parameters for all vessels and facilities operating in US waters. Two-phase timeline: crew training under 33 CFR 101.650 enforceable from January 12, 2026; full Cybersecurity Plan submission and CySO designation required by July 16, 2027. | 05 · Cyber Standards |
| V.Ships | OT & Systems | Prominent independent ship management organization coordinating operational technology updates and crew safety systems cross-fleet. | 08 · Market Segments |
| Van Ameyde Marine | Insurance | Marine surveying and claims management group with over 130 years of heritage and a global network of surveyors, correspondents, and claims specialists. Delivers technical analyses, on-site damage surveys, and repair attendance across complex vessel casualties in ports and shipyards worldwide. | 06 · Industry Bodies |
| VDRVoyage Data Recorder | OT & Systems | The vessel's armored black box recording audio and navigation metrics. Demands rapid physical data backup following accidents to escape overwrite steps. | 07 · Technology Landscape |
| VIKAND | OT & Systems | Crew health and medical program provider, acting as a business framework model for flowing integrated technical packages directly to shipping operators. | 06 · Industry Bodies |
| VIQVessel Inspection Questionnaire | Rule/Vetting | The formal checking profile used inside SIRE review operations, appending digital safety questions to eliminate undocumented asset configurations. | 05 · Cyber Standards |
| West of England | Insurance | West of England Shipowners' Mutual Insurance Association. Luxembourg-domiciled, managed in London. Broad footprint across liquid and dry bulk carrier segments. | 01 · P&I Clubs |
| WSCWorld Shipping Council | Rule/Vetting | Liner trade body representing global container shipping lines, managing cyber guideline matrices for eBL systems and data cargo titles. | 05 · Cyber Standards |
