The retrofit conundrum: what happens if you’re not planning newbuilds?
This article explores the broader implications of adopting cybersecurity standard E26, highlighting challenges and costs shipowners face if applying regulations only to newbuilds rather than fleet-wide.
There are wider implications for E26 that a shipowner needs to plan for. Adopting E26 only for newbuilds while ignoring the rest of the fleet could give rise to hidden costs for the entire lifespan of the fleet. Shipowners now face the challenge of deciding whether to apply E26 to all ships in their fleet or manage dual systems. However, since compliance requires global policies and not just vessel-specific ones, applying different cybersecurity processes to different ships adds complexity, training costs, and may lead to confusion. In the long run, it is likely to be cheaper and simpler to standardise cybersecurity measures fleet-wide.
It’s also important to note that implementing the regulation is about more than compliance. E26 seeks to improve resilience across mission-critical systems and mitigate the risks of breaches that could result in navigational concerns, operational shutdowns, or ransom attacks. Furthermore, because E27 ensures that third-party equipment suppliers and system integrators incorporate robust security measures, it improves cybersecurity across the supply chain. For the shipowner, this simplifies a constructive dialogue with OEMs about how to achieve improved security of OT systems, which are currently treated as opaque “black boxes”. Rather than treating it as a newbuild-only requirement, shipowners should use E26 as a fleet-wide benchmark for simpler audits, predictable compliance, and raising the minimum security standard across the fleet. Implementing E26 also demonstrates a shipowner’s commitment to cybersecurity, reinforcing trust with customers, insurers, regulators and other stakeholders.
Understanding contractual requirements
The introduction of E26 has made cyber-resilience at the design stage an essential factor in a vessel’s seaworthiness. However, according to global law firm Holman Fenwick & Willan (HFW), issues arising out of E26 and E27 are not making it into the contracts of newbuilds. This means that either shipyards are dealing with the issues during the building phase and/or the rules are not being implemented yet.
Defining vessel seaworthiness
Charterparty agreements obligate shipowners to deliver a seaworthy vessel. This requirement is absolute, meaning that once the vessel is handed over to the charterer, the shipowner is typically held liable for any breach of this obligation, regardless of fault. Failure to comply with E26 means that shipowners could be exposed to claims of unseaworthiness from charterers and cargo interests. In addition, if a vessel is not E26 compliant, classification societies may refuse to sign off the vessel, which would affect its ability to trade. It may also impact the vessel’s ability to obtain insurance. Shipowners must ensure their vessel is seaworthy, which may include meeting E26 standards (depending on the terms agreed in the charterparty). Charterers should ask for proof of E26 compliance in charterparty negotiations and include clauses that hold shipowners liable if non-compliance results in financial loss.
7 IACS (accessed Jan, 2025) IACS adopts new requirements on cyber safety
8 CyberOwl (Apr, 2024) I’m not planning newbuilds. Why should I care about IACS UR E26?
9 West P&I (accessed Feb, 2025) Clause paramount in a nutshell
10 Ship Technology (Mar, 2024) Cyberattacks: how can maritime address the growing cyber threat?
For further insight into the areas discussed in this article, download our latest thought leadership report, The Lifecycle Dilemma, created in partnership with CyberOwl and HFW.

