Designing a cyber-secure vessel
In this article, we explore how the shipping industry approaches designing cyber-secure vessels, including the recent introduction of new cybersecurity standards (UR E26 and E27), stakeholder challenges, and the importance of clear cybersecurity responsibilities.
Connectivity demands a new approach to cybersecurity management
The global shipping industry is increasingly reliant on high-speed networks and instant communication. Additionally, the push to decarbonise has led to multi-fuel vessels requiring greater connectivity. While this connectivity streamlines ship operations, it also increases vulnerability to cyberattacks. These challenges have driven the International Association of Classification Societies (IACS) to implement a new approach to cybersecurity management. Existing baseline standards defined by Unified Requirements (UR) are no longer sufficient, prompting the introduction of UR E26 and E27.
What are E26 and E27?
E26 governs system integration and maintenance requirements, aiming to support maritime organisations in creating secure onboard environments through robust cyber risk management frameworks. E26 applies only to newbuild vessels from 1 July 2024, raising concerns about retrofitted vessels that remain outside these regulations, leaving a significant portion of the global fleet without clear cybersecurity standards.
E27 supports original equipment manufacturers (OEMs) by assessing and enhancing the cyber resilience of onboard systems and equipment. Manufacturers must certify compliance with these requirements. However, complying with E26 and E27 necessitates adherence to specific rules set by individual class societies. Although IACS has harmonised this to some extent, stakeholders still face navigating distinct class requirements to achieve certification.
Â
Why pay attention to these new requirements?
These requirements consolidate scattered regulations into a unified framework, enhancing shipboard network visibility and assigning clear cybersecurity responsibilities to stakeholders. Clarifying these roles helps stakeholders understand and manage cybersecurity risks associated with interconnected vessel systems.
One shipowner explained, “Ultimately, these regulations will force harmonisation across OEMs and yards, which is a huge step forward. At least shipowners will be able to expect some level of documentation.” However, due to the long operational lifespan of vessels, benefits will materialise slowly. Another shipowner noted, “Regulators want E26 certification for newbuilds, but not all class societies, shipyards, and integrators have a clear strategy or process for effectively implementing it at scale, making compliance challenging.”
Both shipowners and shipyards surveyed indicated a lack of clarity on E26 compliance. Shipyards must develop and document secure architectures for the vessel’s operational life. Yet, only 17% of shipyards feel they have adequate in-house cybersecurity expertise, with 83% relying on shipowners or class societies for guidance.
Are stakeholders aware of the new class rules around cybersecurity?
Our survey showed mixed understanding of the new cybersecurity requirements, suggesting achieving E26 compliance outcomes will be challenging. Low awareness among responsible organisations contributes significantly to this challenge. Consequently, shipowners with better understanding must take greater responsibility, collaborating closely with shipyards and OEMs to address these cybersecurity needs.
2 Inmarsat (Jun, 2024) Maritime cybersecurity beyond compliance: IACS unified requirements E26 and E27
3 Wärtsilä (Aug, 2023) Shape up your vessel’s maritime cybersecurity with these 8 clever tips
4 Inmarsat (Jun, 2024) Maritime cybersecurity beyond compliance: IACS unified requirements E26 and E27
5 Wärtsilä (Aug, 2023) Shape up your vessel’s maritime cybersecurity with these 8 clever tips
6 DNV (Oct, 2023) Building strong cybersecurity into ship design
Â
For further insight into the areas discussed in this article, download our latest thought leadership report, The Lifecycle Dilemma, created in partnership with CyberOwl and HFW.

