Skip to main content
Superyacht Charter

Guest Privacy

Every charter party leaves something behind.
Superyachts
Superyacht Charter

Vendor & Remote Access

You don't know who still has access to your systems.
Superyacht Charter

Compliance

A cyber incident mid-season is a commercial incident.
IASME
Authors of the international standard for maritime cyber resilience
Supported by the Royal Institution of Naval Architects.
IMO
Recognised path to IMO maritime cyber risk management compliance
Open to vessels of all classifications, from superyachts to commercial fleets.
20+
Years securing critical operations
Our founders have been in the field since 2004. CyberPlus was built on that experience.

Trusted by industry leaders

Guest Privacy

Every charter party
leaves something behind.

Most vessels have a guest network on paper. Few have one that is actively verified, maintained and monitored. The gap between what was configured and what is actually enforced is where exposure lives.

A compromised guest device doesn't stay on the guest network. It moves. Across the same infrastructure that carries navigational data, engine management, crew communications and the owner's private traffic. The guest is innocent. The device is not.

But the threat runs in both directions. Opportunistic threats arrive through guest devices. Targeted threats arrive through the vessel's own infrastructure . a compromised vendor connection, a persistent implant from a previous season, a back door left open after the last refit. When a vessel is already compromised, every guest who connects becomes a victim without knowing it. Their location, their communications, their device identities and their behavioural patterns are collected silently. Management companies who understand this are best placed to prevent it.

Aggregated across a charter season, guest data builds a detailed intelligence picture. Who was on board. When. With whom. Where they went next.

CyberPlus verifies and continuously monitors network segregation, sweeps the vessel between charters and covers both tiers of threat. When something is detected, we investigate, establish the facts and document them . the kind of findings that management companies, insurers and flag state inspectors can act on. What guests bring on board cannot reach what it has no business reaching. What the vessel carries cannot be turned against the people who trusted it.

Protect your next charter
What Gets Exposed
On an unmonitored vessel,
everything is visible.
  • 01
    Real-time location and movement
    A guest's position, travel patterns and departure times are visible on an unmonitored network. For principals whose movements need to remain private, this is a personal security threat.
  • 02
    Private communications
    Calls, messages and emails routed through the vessel's satellite infrastructure pass through a shared environment. On a compromised vessel, content and contact networks are readable.
  • 03
    Device identity and behavioural patterns
    Every device that connects leaves a unique identifier. Aggregated across charters, that data tells an adversary exactly who used the vessel, when, and with what devices . even if no content was intercepted.
  • 04
    Banking credentials and legal correspondence
    Guests routinely conduct banking, legal and private business from personal devices while on board. These are not incidental targets. They are actively sought by the threat actors most likely to target this audience. On an unmonitored network, that traffic is readable.
  • 05
    The uncleared vessel between charters
    When a charter party departs, their data, their device fingerprints and any threats they carried on board do not leave with them. The next guests arrive into an environment nobody has cleared. CyberPlus sweeps and verifies the vessel between every charter so each new party starts in a clean environment.
Vendor and Remote Access

You don't know who still
has access to your systems.

On every vessel CyberPlus has audited for the first time, active vendor connections have been found that nobody on board knew existed. This is not an edge case. It is the default state of a vessel that has never been independently reviewed.

Vendor remote access is the unowned gap in superyacht cybersecurity. The captain manages what the crew can reach. The management company manages the charter calendar. Nobody manages the back doors that integrators, AV contractors and satellite engineers opened during the last refit and never closed. This is not a charter problem. It exists on every superyacht. Charter operation amplifies it because the number of vendors, the frequency of refits and the pressure of the season calendar means it is never reviewed.

The scope of that access matters as much as its existence. A satellite engineer with a connection scoped to one terminal is a different risk to an AV integrator with a route into the full network. Most vessels have no record of which is which.

When we audit a vessel for the first time, the number of active external connections is almost always higher than anyone on board believes possible.

CyberPlus audits every external access relationship, maps the scope of each connection and closes what has no current justification. Legitimate vendor access that has a clear operational purpose is scoped precisely, time-limited and continuously monitored. When a vendor relationship ends, the access ends with it. For the first time, you know exactly who can reach your systems. And so do we.

Find out who has access
Who Has Access Right Now
Every connection mapped.
Every risk owned.
  • 01
    AV and systems integrators
    Installed during the build or last refit. Remote access was granted for commissioning and troubleshooting. The work is done. The access remains.
  • 02
    Satellite and communications providers
    VSAT, Starlink and cellular terminal engineers have remote diagnostic access to the vessel's communications infrastructure. That access is rarely scoped, rarely audited and almost never revoked.
  • 03
    Navigation and engineering system manufacturers
    OEM remote access for maintenance and firmware updates is standard across navigation, propulsion and engineering systems. Compromising an OEM gives a threat actor access to every vessel running that system globally. Your yacht is one entry point in a much larger supply chain attack surface.
  • 04
    Former contractors with live credentials
    Vendor relationships end. Credentials frequently do not. A contractor who worked on the vessel two seasons ago may still hold active login credentials to systems they configured.
Charter Compliance

A cyber incident mid-season
is a commercial incident.

Flag states, P&I clubs and hull underwriters are asking harder questions about cyber risk. A vessel that cannot demonstrate a managed cyber programme is a liability, not an asset. For some underwriters, it is now a condition of coverage.

The regulatory landscape for chartered superyachts is not static. The frameworks exist. The question inspectors and correspondents are increasingly asking is not whether you know about them but whether you can demonstrate continuous compliance against them. When a flag state inspector arrives or a P&I correspondent opens a file, the documentation either exists or it does not. CyberPlus makes sure it does.

Before the correspondence becomes adversarial is the only time to establish the facts. CyberPlus makes sure you are never unprepared.

Every vessel on the CyberPlus programme receives continuous compliance monitoring against every applicable standard, a rolling compliance report that management companies can present to owners, flag states and insurers, and independent verification that demonstrates duty of care. Season to season, without gaps. When an inspector or correspondent asks the question, the answer is already documented.

Check your compliance position
The Compliance Landscape
What applies to your vessel.
What we satisfy.
  • 01
    IASME Maritime Cyber Baseline
    The internationally recognised framework for maritime cyber resilience. Developed by the founders of CyberPlus. The benchmark against which flag state inspectors and P&I correspondents assess your cyber posture.
  • 02
    IMO Maritime Cyber Risk Management
    IMO MSC-FAL.1/Circ.3 requires cyber risk management to be addressed within the vessel's safety management system. CyberPlus provides the continuous programme and documentation that satisfies this requirement.
  • 03
    LMA 5403 and hull underwriting
    Hull and machinery underwriters have moved beyond scrutiny. Several are now making a managed, documented cyber programme a condition of coverage, not merely a factor in assessment. LMA 5403 sets the exclusion framework. CyberPlus satisfies it continuously.
  • 04
    P&I club correspondence
    When a P&I correspondent opens a file, the window to establish facts independently is short. CyberPlus provides the investigation and documentation that settles the question before the correspondence becomes adversarial. P&I clubs are increasingly asking whether cyber failure contributed to incidents. The answer needs to be documented before they ask.
The platform behind the programme
Vision+

Every compliance report, every audit trail, every timestamped record your management company needs. Generated automatically as work is performed. No additional burden on crew. No gaps in documentation.

See how Vision+ works
Superyachts moored at night

The threat is real. The solution is proven.

Let's Talk