In 2021, the International Maritime Organization (IMO) adopted new cyber security provisions into the International Safety Management (ISM) code for merchant shipping. These provisions embedded more specific cyber risk management requirements into the ship safety management system (SMS), formalising deliberate cyber risk management practices into the operation of compliant merchant ships.
As with all new regulations imposed on an outwardly free market, they met with mixed reactions, but the general feeling from the global shipping community was clear: the emerging cyber threat was recognised and more guidance was welcomed. Writing on the subject in The Maritime Executive in January 2021, U.S. Coast Guard Associate Director for Maritime Operations, Commander Michael C. Petta remarked, “These new guidelines are a milestone for maritime safety and security. This new model is a vital step towards forging a uniform approach for combating cyber threats against vessels.”
Some sub-sectors of the shipping industry had also formed voluntary cyber standards or guidelines prior to those of the ISM code. For example, basic cyber security standards for tankers were included in Oil Companies International Marine Forum’s (OCIMF) Tanker Management and Self Assessment (TMSA) requirements as early as 2017.
TMSA 3 introduced Element 13, focusing on maritime security and the management and assessment of cyber systems. Following the adoption of the IMO guidelines, BIMCO, Chamber of Shipping of America, Digital Containership Association, International Association of Dry Cargo Shipowners (INTERCARGO), InterManager, International Association of Independent Tanker Owners (INTERTANKO), International Chamber of Shipping (ICS), International Union of Marine Insurance (IUMI), OCIMF, Superyacht Builders Association (Sybass) and World Shipping Council (WSC) produced “The Guidelines on Cyber Security onboard ships”.
The guidelines were intended to assist a stakeholder with the development of a proper cyber risk management strategy in accordance with relevant regulations and best practices on board a ship with a focus on work processes, equipment, training, incident response and recovery management. The International Association for Classification Societies (IACS) produced IACS Rec 166 (Corr.1 2020): Recommendation on Cyber Resilience but set out non-mandatory recommendations for technical requirements that stakeholders may want to reference and apply to assist with the delivery of cyber resilient ships. However, generally, most of these publications specified nothing more than a need to address cyber security, leaving the operator to determine the most appropriate minimum course of action.
Recently, IACS announced a set of unified requirements (URs) which seek to align classification societies on their general policies on cyber risk management. Dubbed E26 and E27, these regulations will be applicable to all newly launched classed vessels starting from 2024. UR E26 provides guidelines for the secure integration of OT and IT equipment into ship networks throughout their lifecycle–from design and construction to commissioning and operation. The guidelines emphasise cyber resilience across identification, protection, attack detection, response, and recovery aspects.
UR E27 focuses on enhancing the integrity of third-party supplied onboard systems and equipment. It outlines prerequisites for cyber resilience in equipment, as well as user interactions with computer-based systems. Additionally, it sets requirements for the creation and production of new devices. By leveraging international standards like IEC 62443, IACS will use the new URs to establish requirements spanning scope, threat identification, incident detection, response, and system security.
For a deeper dive into the areas highlighted in this article, take a look at our thought leadership report, produced in collaboration with CyberOwl and HFW, titled “Shifting Tides, Rising Ransoms and Critical Decisions”. This comprehensive report offers insights into the evolving landscape of cyber threats in the maritime industry and explains that there is a new approach towards managing cyber risk. You can download your copy of the report Below:


