Skip to main content
Maritime Remote Access

SESSION CONTROL
AND AUDIT

Maritime Remote Access

CREDENTIAL LIFECYCLE MANAGEMENT

Maritime Remote Access

THIRD-PARTY
VETTING

Your remote access is deployed.
But is it governed?

Four controls. Here is how we govern it.

Session control and audit

Every connection authenticated, attributed, and logged. Remote sessions are time-limited, scoped to a named individual, and recorded from initiation to close. When your P&I Club or flag state auditor asks for the access record, it exists. Not assembled under pressure. Generated automatically from day one.

Credential lifecycle management

Access issued for a purpose ends when that purpose ends. Crew rotations, contractor handovers, refit teams, classification society inspections. Every credential is scoped, reviewed, and revoked automatically. No orphaned accounts. No access that outlives the job it was granted for.
Supports IMO 2021 ISM Code IACS UR E26/E27 NIS2 ISO 27001

Third-party vetting

No external party connects until we have investigated them. Certifications, known vulnerabilities, breach history, dark web credential exposure. Every contractor and sub-contractor assessed before they touch your network. Supply chain access is where maritime and offshore operations are compromised. We close that before it opens.

IMO 2021 compliance by design

Governance built into the architecture, not layered on top of it. IMO 2021 requires cyber risk management embedded in your Safety Management System under the ISM Code. CyberPlus configures remote access governance to satisfy that requirement structurally. Role-based access, full audit trails, credential lifecycle management that survives every crew change and port call. The compliance documentation generates itself.

Every environment has rules.
OT has ones that cannot be broken.

Corporate security tools are designed for corporate environments. Deployed against operational technology on a vessel bridge or offshore installation, they are not just ineffective. They are dangerous. Aggressive endpoint detection on a dynamic positioning system can cause the failure it was meant to prevent. The consequences of getting the architecture wrong here are not a data breach. They are operational.

IACS UR E26 · The vessel

Mandatory for all vessels contracted from 1 July 2024. UR E26 requires documented cyber resilience across five functions: identification, protection, detection, response, and recovery. It mandates network segmentation between IT and OT and a Cyber Resilience Test Procedure covering the entire operational life of the vessel. DNV, Bureau Veritas, ABS, and Lloyd's Register have all aligned their class notations to it. Non-compliance is not a fine. It is loss of class.

IACS UR E27 · The systems

Where E26 governs the vessel, E27 governs every individual computer-based system on board. Navigation, propulsion, ballast, SCADA, dynamic positioning, fire detection. Third-party suppliers must prove their systems are cyber resilient before installation. As of late 2024, fewer than 25 systems globally held E27 type approval. That scarcity is the reason why equipment going near your OT network must be verified, not assumed.

The hardware that belongs on board

Not every firewall is built for a vessel engine room or offshore control cabinet. CyberPlus deploys the Fortinet FortiGate Rugged series, purpose-built for OT environments and rated for the temperature, vibration, humidity, and electromagnetic conditions of maritime operation. The FortiGate Rugged 70F delivers deep packet inspection of ICS, OT, and SCADA protocols and enforces zero-trust segmentation between security zones. It prevents lateral movement between a compromised IT segment and critical vessel systems. Built for where you actually operate.

CyberPlus Resource
The Maritime Cyber Compliance Matrix

200+ entries. Every regulation, every classification society requirement, every acronym a maritime operator will encounter. IMO 2021, IACS UR E26/E27, ISM Code, ISPS, MLC, NIS2, ISO 27001, P&I Club requirements, flag state obligations. Written by the team that authored the IASME Maritime Cyber Baseline. Free. No form. No gate.

"We didn't find a breach. We found seventeen doors that had never been closed."
CyberPlus maritime estate audit · 2025
01

Offshore energy operator

A typical North Sea installation manager could not account for three active credentials following a contractor rotation. No incident. No audit trail. CyberPlus audited the estate, revoked seventeen stale credentials, and implemented lifecycle governance across the entire remote access perimeter.

Zero unattributed credentials. Full audit trail operational within 48 hours. No downtime.
02

Port and terminal operations

A typical terminal operator faced a P&I Club audit requiring 90 days of remote access logs across six operational systems. The logs did not exist. CyberPlus implemented session audit infrastructure and credential governance before the follow-up audit window closed.

Audit passed. 90-day access log now generated automatically. No manual assembly required.
03

Vessel operations

A typical ship manager operating across multiple flag states could not demonstrate that shore-based access to vessel systems was restricted to named, authorised individuals. No attributable access logs existed beyond the TeamViewer install itself. CyberPlus took over governance, implemented credential lifecycle management, and delivered full audit trail coverage within one operational cycle.

ISM Code compliance demonstrated at next audit. Shore-to-vessel access fully attributed across all flag states.
Book a governance audit

The threat is real. The solution is proven.

Let's Talk