The threat is real. The solution is proven.
Newbuild & Refit
The vessel you commissioned
is already a target
Most threats to a newbuild begin years before delivery. So does our programme.
Exposure starts before the shipyard
CyberPlus delivers independent oversight from first specification to first season.
A newbuild or refit project runs for years before a vessel reaches the water. During that time, your ownership structure, your design intent and your financial arrangements are in circulation across shipyards, subcontractors and system integrators.
The vessel doesn’t arrive with a clean security posture. It arrives with the accumulated exposure of every decision made during the build.
CyberPlus sits outside the project structure and answers only to the owner. We are not the shipyard’s IT contractor. We are not the integrator’s security check.
Our involvement begins at specification, runs through every phase of the build, and transitions directly into the managed programme that protects the vessel in operation. One continuous line of accountability. No handover gap.
The Project
Exposure
starts early
Trusted by industry leaders

The threat surface opens before
the first meeting ends.
Sensitive information is in circulation from the moment the project begins. Most programmes do not arrive until years later.
The design studio hired in month two. The naval architect's shared drive. The financial advisor's email account. None of them independently vetted. All of them holding information that could identify the owner, their intentions and their security arrangements, years before delivery. The project is not the preparation for the threat. The project is the threat.
A newbuild of this scale involves dozens of organisations before a single piece of steel is cut. The world's largest private vessel programmes run for five years before launch. During that entire window, ownership structures, General Arrangement drawings, financial frameworks and personal security arrangements are all in active circulation.
CyberPlus is not the shipyard's security contractor. We answer only to the owner, the only position from which genuine, unconflicted oversight is possible. We establish secure communications protocols across the entire project perimeter, assess every contracted organisation, and run continuous 24/7 monitoring for any unauthorised disclosure related to the build, the vessel or the owner. Our engagement begins where the exposure begins: at conception.

Your identity as owner is the first thing at risk
Every contractor is a potential breach point
Communications security is assumed, not managed
The risk does not arrive at Stage 4.
It is present at Stage 1.
A 60-month build has six defined stages. CyberPlus workstreams map to every one. The threat profile at Concept Design is different from the threat profile at Construction, and both require active management. Most programmes arrive at Stage 5 at best.
Concept Design
UBO data, financial frameworks and preliminary design concepts begin circulating. The owner's identity and intentions are known to a growing number of unvetted parties from day one.
CyberPlus engagement must begin here. The threat surface is already open.
Contract Design and GA Freeze
The design team expands. The General Arrangement is fixed and widely shared. The shipyard is formally engaged. Volume of sensitive information in active circulation reaches its first peak.
Engineering and Technical Design
AV/IT integrators, system designers and specialist consultants sharing detailed drawings and specifications. Highest information security risk of the entire programme.
Construction
Vendors connecting devices to partially installed systems. Number of individuals with physical access at its highest. Access management is the primary operational challenge.
Commissioning and Delivery
Systems live and under test. Penetration testing completed. Compliance attestation compiled for class, flag state and insurers. Every decision made in the previous 52 months is now auditable.
Post-Delivery Operation
The project audit function is complete. The operational partnership is active. The team that secured the build transitions directly into the managed programme, carrying institutional knowledge no new provider can replicate.
No knowledge gap. No handover reset. One continuous line of accountability.
Your stakeholders should not have to fly to the shipyard
to see what we see.
A five-year build generates continuous decisions that require oversight. Vision+ means the owner's representative, naval architect or family office advisor can see exactly what CyberPlus sees, in real time, from anywhere in the world. Progress verified. Issues escalated. Sign-offs witnessed. Without a single flight.
Learn about Vision+ →Live build oversight, remotely
The owner's representative sees exactly what our specialists see during site visits, system reviews and access audits. Real-time, verified, documented.
Stakeholder progress without travel
Naval architects, project managers and family office advisors stay informed and in control across every stage of the build without needing to be at the shipyard.
Every interaction documented
Each Vision+ session is captured and logged. The full audit trail becomes part of the compliance evidence package delivered at handover.
Shipyards are not immune.
They are targets.
The build environment is not a protected perimeter. Shipyards handling the world's most sensitive private projects have been compromised by ransomware and supply chain attacks. Independent oversight is not a precaution. It is the only way to establish that your project information is being handled appropriately by every party involved.
Major European Superyacht Shipyard: Ransomware Attack
One of the world's most prominent builders of large private vessels was forced to shut down operations following a ransomware attack that disrupted shipyard systems across their facilities. Active builds were affected.
MarineMax: Data Breach at Scale
The Rhysida ransomware group stole data relating to over 123,000 individuals from a major US yacht dealer. Financial details, personal information and sensitive communications were exposed and published.
Mandiant: 122-Day Espionage Dwell Time
For targeted espionage intrusions, the threat profile most relevant to UHNW principals, median attacker dwell time in 2025 was 122 days. On a five-year build programme, the window is not weeks. It is the length of the build.
The project layer cannot be
secured retrospectively.
Every week of build activity without independent oversight is a week of unmonitored exposure. The decisions made at Stage 1 determine the security posture of the vessel at Stage 6. CyberPlus engagement begins at conception, because that is when it is needed.
Begin a project security consultation →The Vessel Layer → The Owner Layer →
The vessel arrives with
vulnerabilities embedded.
Every vendor, every system, every remote access session during the build is a potential entry point. We verify independently. Not the shipyard, not the integrator.
During construction, vendors connect devices to partially installed systems. Integrators establish remote access sessions: sometimes ongoing, rarely governed, almost never independently logged. Components are selected by procurement teams with no mandate to verify their security posture. By the time the vessel reaches trials, dozens of decisions have been made that determine its entire security architecture. None reviewed by an independent party.
CyberPlus does not work for the shipyard or the integrator. Our role is independent verification. We review what has been specified, what has been installed, and what has been left running. We either approve or specify remediation before sign-off.
From architecture review at design stage through component sign-off at installation and penetration testing before delivery, CyberPlus maintains a continuous independent audit of the vessel's technology environment. The vessel that reaches handover carries our attestation, not the shipyard's self-certification. That distinction matters to class societies, flag states and marine insurers. It matters more to owners.

Six distinct network zones.
Each requires independent security.
A superyacht's onboard technology environment is not a single network. It is a collection of distinct zones, each with unique security requirements and specific consequences if compromised. The critical requirement is proper separation and independent verification that the separation holds under active attack.
Bridge and Navigation
ICS and SCADA
Crew Communications
Guest Networks
AV, Entertainment and Vendor Access
Five workstreams.
One independently verified vessel.
Each produces a specific, documented deliverable: not a report that sits in a drawer, but a sign-off that class societies, flag states and marine insurers can audit.
Network Architecture and Remote Access Review
CyberPlus reviews the proposed technology architecture and defines minimum security standards. The critical requirement is proper separation of all six network zones. Remote access by vendors and system integrators is governed by authorisation, time-limiting and logging requirements defined at this stage, before a single session takes place.
Architecture Security Review and Minimum Standard Definition. Formal sign-off upon compliance with IMO Cyber Risk Management Guidelines, IACS UR E26/E27, IEC 62443 and ISO 27001/27002.
Component Security Review
Due diligence on every significant component and its supplier, covering known vulnerabilities, the security posture and recent incident history of the supplying company, and the configuration security of each system as installed. Configuration review is conducted at installation, not retrospectively. What is reviewed before installation is fixable. What is reviewed after is a permanent part of the vessel.
Component security review log with configuration sign-off record per system. Supplier risk assessment for all significant equipment vendors.
Asset Management, Change Control and Access Review
CyberPlus evaluates the methodologies in use for asset management and reviews the access control framework across the entire build. Access is removed the moment an engagement ends. Changes to installed systems are governed by a process that prevents unauthorised or undocumented modifications.
Security review of asset register and change control procedures. Access management framework governing all vendor and contractor credentials throughout the build.
Penetration Testing
An exhaustive penetration test of the vessel's complete technology environment before delivery, attempting to breach the vessel's systems using the same methods a real attacker would use. External and internal testing. A certified third-party specialist independently validates the findings.
Penetration test report covering external and internal assessments. Remediation sign-off. Third-party validation attestation from a certified independent specialist.
Certification and Compliance Attestation
IACS UR E26 and E27 are mandatory for vessels with build contracts signed after 1 July 2024. Compliance must be evidenced at handover. The deliverables from each of the four preceding workstreams collectively form the evidence base. CyberPlus compiles, presents and attests to it on behalf of the owner.
Compliance attestation package covering IASME MCB, IACS UR E26/E27 and class society requirements. Suitable for submission to class, flag state and marine insurers at delivery.
witnessed remotely in real time.
Every standard that matters at delivery.
Evidenced from the start.
CyberPlus was founded by the authors of the IASME Maritime Cyber Baseline, the internationally recognised certification scheme endorsed by the Royal Institution of Naval Architects. We are not a firm that advises on compliance. We wrote the standard.
Maritime Cyber Baseline
The internationally recognised certification scheme for maritime cyber security, endorsed by the Royal Institution of Naval Architects. CyberPlus authored the MCB. We manage the programme that produces the evidence base for it.
Cyber Resilience of Ships and On-Board Systems
Mandatory for all vessels with build contracts signed after 1 July 2024. E26 governs the vessel as a whole; E27 governs individual computer-based systems. Non-compliance results in class society rejection. Insurers are increasingly requiring attestation for underwriting.
Maritime Cyber Risk Management Guidelines
Remote access architecture, OT/IT segmentation and change control procedures all governed by this framework and directly addressed by the CyberPlus vessel layer workstreams.
Information Security and OT Frameworks
The architecture review is designed to comply with both ISO 27001/27002 for IT environments and IEC 62443 for operational technology, the two frameworks most directly relevant to a superyacht's technology architecture.
The vessel you take delivery of
is the vessel you chose to verify.
Every system installed, every vendor access session, every configuration decision is either independently verified or it is not. There is no partial state.
Discuss vessel layer oversight →The Project Layer → The Owner Layer →
Everything on this programme
exists to protect one person.
Your threat profile is assessed first. It determines the scope, intensity and configuration of everything that follows.
The shipyard manages the build. The project manager manages the schedule. The AV integrator manages the technology installation. Each is expert within their domain. None of them is positioned, or mandated, to protect the owner.
CyberPlus is the only provider on this programme whose mandate begins with the owner, and whose programme is calibrated to their specific risk, not a standard maritime package.
A superyacht at 100 metres or above attracts a level of attention from criminal actors, competitors and in some cases state-level interest which most security firms are not equipped to address. For targeted espionage intrusions, the threat category most relevant to UHNW principals, Mandiant's M-Trends 2026 records a median attacker dwell time of 122 days. On a five-year build programme, the window is not months. It is the length of the build.

Financial exposure
Privacy and location
Operational integrity
Principal, family and reputational protection
A threat actor targeting the owner
does not stop at the gangway.
The vessel is one asset in a larger world. The owner's estate, their family, their aviation assets, their family office: each carries risk. CyberPlus extends its programme across all of them, working alongside the teams already in place rather than replacing them.
Close protection team liaison
Family office integration
Estate, aviation and travel
For principals where cyber and physical protection must converge.
Eyes-On fuses cyber intelligence with real-time visual collaboration through AI and AR-enabled technology. Command sees exactly what every operative sees, in real time. Every property, every transit, every event: visible, documented and actionable before it escalates.
Available exclusively through consultation for principals who require security as sophisticated as their world.
Arrange a private briefing →Active human monitoring
Real-time analyst-led monitoring with direct escalation capability. Not automated alerts. Active oversight, around the clock.
Close protection team liaison
The cyber intelligence layer your existing CPO team is currently operating without. We do not replace them. We make them significantly more effective.
Air-gapped environments
Complete network isolation for the most sensitive communications. Designed for principals operating under elevated state-level threat.
Integrated ecosystem protection
Security across the vessel, the private estate, aviation assets and family office. Treating all of it as a single integrated environment, because that is what it is to a threat actor.
The threat assessment begins
with a quiet conversation.
Confidential, conducted by senior CyberPlus specialists, and treated with the same discretion as every other element of this programme. Not a sales process. The first workstream of a programme that begins at the moment you engage and does not end at delivery.
Begin a confidential conversation →The Project Layer → The Vessel Layer →