Skip to content
BRENT 96.28 +16.72%
EUR/USD 1.16210 +0.99%
FRO 46.12 +18.35%
STNG 82.35 +7.79%
SBLK 32.42 +14.88%
ZIM 28.58 +4.73%
Tide Signal

Maritime Cyber Security in 2026: IMO Rules, Ship Risks and Practical Checklist

Maritime cyber security is now part of safe ship operation, not simply an IT function. This guide explains what IMO requires today, how IACS UR E26 and E27 affect new ships, what changed in 2026 around Maritime Single Windows, and what Masters, officers, superintendents and shore teams should actually check onboard.

Maritime cyber security in 2026 with ship bridge systems, IMO rules and cyber resilience controls
Maritime cyber security now extends from office IT to bridge systems, operational technology, remote access, GNSS/AIS resilience and the ship’s Safety Management System.

Maritime cyber security is no longer an office-IT subject. It now sits inside safe navigation, machinery reliability, cargo operations, port clearance, communications, payments and the Safety Management System.

A ship does not need to suffer a spectacular “hack” to face a serious cyber event. A compromised email account can redirect a payment. A remote-support connection can expose an operational network. A corrupted update can affect a bridge workstation. GNSS interference can make position data unreliable. A ransomware event ashore can leave the vessel unable to access documents, instructions or reporting systems.

The practical objective is therefore not to make a ship impossible to attack. It is to make the organisation difficult to compromise, quick to detect abnormal behaviour and capable of continuing safely when a digital system cannot be trusted.

MARITIME CYBER SECURITY — 2026 STATUS

  • Existing ships: cyber risk should already be addressed within the company’s Safety Management System under IMO Resolution MSC.428(98).
  • IMO guidance: MSC-FAL.1/Circ.3/Rev.3, issued in April 2025, is the current high-level IMO cyber risk management guidance.
  • New ships: IACS UR E26 and UR E27 apply through class rules to ships in scope contracted for construction on or after 1 July 2024.
  • Ports and authorities: IMO FAL 50 approved draft mandatory cyber-security measures for Maritime Single Windows in March 2026; adoption is planned for FAL 51 in 2027, with expected entry into force in 2029.
  • Next governance step: IMO has also started work on a non-mandatory Maritime Cyber Code.

What Maritime Cyber Security Means in Practice

Cyber security in shipping is often described too narrowly.

It is not simply antivirus software, a firewall or a strong password policy. Those controls matter, but shipping is an operational environment. Digital systems are embedded in decisions that can affect the ship, crew, cargo and voyage.

The International Maritime Organization defines maritime cyber risk around the possibility that technology assets can be threatened in a way that leads to operational, safety or security failures. The current IMO maritime cyber risk page points users to the revised 2025 Guidelines on Maritime Cyber Risk Management.

The useful question onboard is therefore not:

“Do we have cyber security?”

It is:

If this system becomes unavailable, manipulated or untrustworthy, can the ship continue operating safely — and does the crew know what to do next?

Tide Signal’s broader guide to Maritime Cyber Risk in 2026 examines the commercial and operational exposure created by digital shipping. This page focuses more narrowly on rules, shipboard controls, practical cyber resilience and what should actually exist in the vessel-and-shore system.

What Does IMO Require for Maritime Cyber Security?

The most important starting point remains IMO Resolution MSC.428(98).

The resolution links maritime cyber risk management directly to the Safety Management System. Administrations were encouraged to ensure that cyber risks were appropriately addressed in existing SMS arrangements no later than the first annual verification of the company’s Document of Compliance after 1 January 2021.

That means a company in 2026 should not treat cyber risk as a separate optional IT policy sitting outside ISM.

The SMS should show how cyber risk connects with:

  • risk assessment;
  • roles and responsibilities;
  • procedures and controls;
  • training and familiarisation;
  • incident reporting;
  • contingency planning;
  • recovery;
  • management review;
  • change management;
  • shore support.

The current IMO guidance is MSC-FAL.1/Circ.3/Rev.3 — Guidelines on Maritime Cyber Risk Management, dated 4 April 2025.

The revised guidance reflects a simple operating cycle:

Function What it means onboard
IdentifyKnow the critical systems, connections, users, vendors and vulnerabilities.
ProtectUse access control, network segregation, updates, backups and procedural controls.
DetectRecognise unusual behaviour, alerts, data conflicts and suspicious access.
RespondContain the incident, protect safety-critical functions and escalate correctly.
RecoverRestore trusted systems and data while preserving evidence and safe fallbacks.

A useful maritime cyber security plan therefore needs to describe not only prevention, but how the vessel behaves when prevention fails.

What Changed in the IMO Cyber Guidelines in 2025?

The 2025 revision matters because it is the current IMO reference in 2026.

IMO’s MSC 108 summary says the revision updated definitions, background and application, the functional elements of cyber risk management and references to relevant international and industry standards.

For operators, the practical message is that cyber management is expected to be a continuing risk process rather than a one-time compliance exercise.

A company that completed a cyber assessment several years ago but has since added:

  • new satellite connectivity;
  • cloud PMS access;
  • remote engine monitoring;
  • crew Wi-Fi infrastructure;
  • new cargo or loading software;
  • digital logbooks;
  • third-party dashboards;
  • remote vendor support;

has changed its attack surface. The risk assessment should change with it.

IACS UR E26 and E27: Why New Ships Are Different

The IMO SMS requirement primarily tells companies to manage cyber risk. IACS UR E26 and E27 go further into the design and construction of cyber-resilient ships and onboard equipment.

IACS UR E26 addresses the cyber resilience of the ship as an integrated entity.

IACS UR E27 addresses the cyber resilience of onboard systems and equipment.

The revised requirements apply through IACS member class rules to ships in scope contracted for construction on or after 1 July 2024.

Requirement Primary focus
UR E26Cyber resilience of the ship, integration of IT/OT, network architecture, access, monitoring, response and recovery.
UR E27Cyber resilience and hardening of individual onboard systems and equipment, including supplier responsibilities.

The distinction is important.

A cyber-resilient vessel cannot be created by buying one “secure” component. The interfaces between navigation systems, machinery automation, cargo systems, business networks and remote support are part of the problem.

Likewise, a ship can have good network architecture but still introduce weak equipment with poor password controls, insecure update processes or unnecessary remote access.

ClassNK’s current UR E26/E27 implementation page confirms that these requirements have been incorporated into class rules for ships contracted on or after 1 July 2024.

2026: Maritime Single Windows Become the Next Cybersecurity Front

One of the most important cyber developments in 2026 is happening ashore.

At FAL 50 in March 2026, the IMO Facilitation Committee approved draft amendments to the FAL Convention that would require Contracting Governments to implement cybersecurity measures for Maritime Single Windows in accordance with national legislation.

The amendments are scheduled to go to FAL 51 for adoption in 2027, with expected entry into force on 1 January 2029.

IMO also agreed to begin developing a non-mandatory Maritime Cyber Code.

This is significant because Maritime Single Windows have been mandatory since 1 January 2024. Ships increasingly depend on digital interfaces for arrival, stay and departure information, crew and cargo reporting, certificates and port formalities.

When those systems fail, the effect is not abstract. A ship may be ready to berth but unable to complete a digital clearance workflow. An agent may have correct information but no functioning portal. A port system may be operational yet produce data the ship cannot trust.

IMO’s Maritime Single Window cybersecurity page now places cyber resilience directly inside the future development of ship-port digital exchange.

IT vs OT: The Cyber Distinction Every Ship Officer Should Understand

One of the most useful distinctions in maritime cyber security is the difference between Information Technology (IT) and Operational Technology (OT).

IT generally handles information.

OT monitors or controls physical processes.

IT examples OT examples
Email and office computersEngine automation and monitoring
Crew administrationCargo control systems
Document managementBallast and stability-related systems
Procurement and finance systemsNavigation and bridge-connected systems
Cloud dashboardsPower management and machinery control

The difference is not that OT is “more important”.

The difference is consequence.

If an office laptop fails, the company may lose productivity.

If a poorly controlled network path allows an incident to reach a safety-critical OT system, the problem can affect a physical shipboard process.

That is why network segregation is one of the recurring themes in industry guidance.

Which Ship Systems Need Cyber Attention?

A useful cyber inventory should start from the actual vessel, not a generic template.

Systems that may deserve attention include:

  • ECDIS and electronic chart update workflows;
  • GNSS receivers and position-data distribution;
  • AIS;
  • GMDSS-connected equipment;
  • VDR;
  • radar and integrated bridge systems;
  • engine and machinery automation;
  • power-management systems;
  • cargo monitoring and control;
  • ballast systems;
  • loading computers;
  • PMS and maintenance databases;
  • satellite communications;
  • crew and business Wi-Fi;
  • CCTV and access-control systems;
  • ship-to-shore performance platforms;
  • remote vendor-support tools;
  • USB and removable-media workflows.

The correct question is not whether each system is connected to the public internet.

It is whether an attacker, infected device, compromised vendor account or poorly designed internal connection can create a path toward it.

GNSS and AIS: When the Cyber Problem Looks Like a Navigation Problem

Not every digital navigation anomaly is a cyber attack against the ship itself.

GNSS jamming and spoofing can occur externally. AIS data can be incomplete, false or manipulated. A navigation system can therefore receive incorrect information even though nobody has breached the vessel’s internal network.

Operationally, the result is similar: the bridge team must recognise when digital data cannot be trusted.

Tide Signal’s live Strait of Hormuz shipping analysis documents an environment where GNSS interference, AIS uncertainty and security risk are already part of voyage planning.

A bridge response should never be reduced to “restart the unit”. Officers need to cross-check independent sources:

  • radar ranges and bearings;
  • visual fixes where available;
  • depth and echo-sounder information;
  • parallel indexing;
  • other independent position sources;
  • traffic and VTS information;
  • expected vessel movement and rate-of-turn behaviour.

The cyber-security lesson is simple: resilience includes the ability to operate safely when a digital input is wrong, not only when a computer is offline.

The Most Expensive Cyber Incident May Start With an Email

Shipping companies move large amounts of money through operational workflows.

Bunker invoices, agent disbursements, spares, crew travel, freight, port costs and vendor payments can all be targeted by impersonation or payment-redirection fraud.

Artificial intelligence has made fraudulent messages easier to write convincingly. Poor grammar is no longer a reliable warning sign.

A more useful control is transaction verification.

Any unexpected change involving:

  • bank details;
  • beneficiary name;
  • payment urgency;
  • new portal access;
  • document download links;
  • cargo release instructions;
  • routing or port instructions;

should trigger verification through a previously trusted channel.

The important phrase is previously trusted. Replying to the suspicious email is not independent verification.

QR Codes, MFA Fatigue and AI Phishing Are Now Crew Issues Too

The 2025/2026 industry guidance has expanded well beyond classic email phishing.

The seventh edition of the Cyber Security Workbook for On Board Ship Use, published by ICS, BIMCO and Witherbys, covers QR-code phishing, MFA phishing, ransomware, AI use, cyber drills, port Wi-Fi, satellite communications, ECDIS, GNSS and AIS.

That reflects the real operating environment onboard.

A seafarer may scan a QR code ashore. An officer may approve repeated MFA prompts because a login is urgent. A superintendent may send a genuine file minutes before a convincing imitation arrives from a compromised account.

Cyber training therefore needs scenarios, not slogans.

Remote Access Is Useful — and One of the Most Important Controls to Get Right

Modern vessels increasingly rely on remote access for troubleshooting, software support and performance monitoring.

The business case is strong. A specialist ashore can diagnose a problem without waiting for the next port.

The risk is equally obvious: remote access creates a deliberate pathway into the ship’s systems.

That pathway should be:

  • approved;
  • time-limited where possible;
  • authenticated;
  • logged;
  • restricted to required systems;
  • disabled when not needed;
  • controlled by a named responsible person.

A permanent vendor connection that “has always been there” should not automatically be trusted.

ClassNK’s current UR E26/E27 Q&A makes the issue concrete: where a remote PC can operate an OT system, that connection can be treated as access from an untrusted network and requires appropriate cyber controls.

USB Devices Still Deserve Serious Attention

Removable media remains common at sea because ships still need offline transfer, updates, service tools and documents.

The problem is not the USB stick itself.

The problem is uncontrolled trust.

A reasonable onboard process should define:

  • which removable media is approved;
  • where it may be used;
  • how it is scanned;
  • whether personal devices are permitted;
  • who authorises use on critical systems;
  • how software and chart updates are verified;
  • what happens when malware is detected.

“Never use USB” is often unrealistic.

“Use any USB because the ship is busy” is worse.

Network Segregation: Crew Wi-Fi Should Not Be One Step Away From Machinery

Ships commonly operate several networks with very different purposes.

Business systems, crew internet, guest access, machinery control and navigation equipment should not behave as one flat environment.

Segregation reduces the chance that a compromise in a low-trust area can move directly toward a critical system.

Good design may use firewalls, VLANs, dedicated gateways, tightly controlled interfaces or complete isolation depending on the system.

But the documentation matters too.

If nobody onboard or ashore can produce a current network diagram, it becomes much harder to know what is actually connected to what.

Ransomware: The First Question Is Not “How Do We Pay?”

If ransomware affects a shipping company, the immediate operational priority is to understand which systems are affected and protect safe ship operation.

The first questions should be:

  • Is navigation affected?
  • Is machinery control affected?
  • Is cargo operation affected?
  • Can the ship communicate safely with shore?
  • Are backup channels available?
  • Are credentials still trustworthy?
  • Can infected systems be isolated without creating another safety problem?

A company with tested offline backups and a recovery process is in a very different position from one that discovers during the incident that its backups were connected to the same compromised environment.

A Cyber Incident Onboard: The First 60 Minutes

Every incident is different, but the response structure should be familiar before the event occurs.

0–10 min

Protect navigation, machinery and cargo safety. Do not make uncontrolled changes to critical systems.

10–20 min

Report through the company cyber/SMS escalation path. Establish an alternate trusted communication channel if needed.

20–40 min

Contain affected systems where safe. Record symptoms, times, users, alerts and actions taken.

40–60 min

Move essential workflows to approved fallbacks. Coordinate technical support without destroying evidence.

One of the worst responses is random troubleshooting by multiple people at once.

Unplanned reboots, deleting files, reconnecting systems or installing tools can destroy evidence or spread the incident.

25-Point Maritime Cyber Security Checklist

This checklist is designed as a practical pre-audit and onboard conversation starter. It does not replace the vessel’s approved SMS, flag, class, company or manufacturer requirements.

Governance and SMS

  1. Cyber risks are explicitly addressed in the SMS.
  2. Ship and shore responsibilities are named.
  3. A current cyber risk assessment exists for the vessel or fleet.
  4. Cyber incidents and near misses have a clear reporting path.
  5. Recovery and continuity procedures are documented and tested.

Accounts and access

  1. Users have individual accounts where practical.
  2. Default passwords have been changed.
  3. Administrator privileges are restricted.
  4. Departed personnel and old vendor accounts are removed.
  5. Multi-factor authentication is used where supported and appropriate.

Networks and equipment

  1. A current network diagram exists.
  2. Critical OT is segregated from crew and guest networks.
  3. Unnecessary network services and connections are disabled.
  4. Remote vendor access is controlled and logged.
  5. Satellite communications equipment uses secure configuration and current credentials.

Software, data and removable media

  1. Software and firmware updates follow a controlled process.
  2. ECDIS/chart-update workflows are verified.
  3. Removable media is controlled and scanned.
  4. Backups exist and at least one recovery path is protected from the live network.
  5. Critical configuration and licence information is available for recovery.

Crew and operations

  1. Crew know how to report a suspicious message or system behaviour.
  2. Payment and bank-detail changes require independent verification.
  3. Bridge teams know how to respond to unreliable GNSS/AIS data.
  4. A cyber drill or practical scenario has been conducted.
  5. The Master knows who to call ashore if a critical system becomes untrustworthy.

Ten Questions a Master or Superintendent Should Be Able to Answer

  1. Which five digital systems would hurt the voyage most if unavailable?
  2. Which systems can be reached remotely from shore?
  3. Who authorises vendor remote access?
  4. Can crew Wi-Fi reach any business or OT network?
  5. Where are critical backups stored?
  6. When was recovery last tested rather than merely assumed?
  7. How would the bridge continue if GNSS position became unreliable?
  8. How are bank-detail changes independently verified?
  9. Who owns the cyber incident response ashore?
  10. What evidence shows the SMS cyber process works in practice?

If the answers require several hours of searching, the cyber plan is probably too theoretical.

What Evidence Should a Company Be Able to Show?

Cyber compliance should not depend on a perfect binder created the night before an audit.

Useful evidence can include:

  • cyber risk assessments;
  • system and network inventories;
  • current network diagrams;
  • access-control procedures;
  • records of account review;
  • software and update procedures;
  • backup and restore test records;
  • crew familiarisation and training records;
  • cyber drill records;
  • incident and near-miss reports;
  • vendor remote-access procedures;
  • change-management records;
  • SMS procedures linked to cyber risk.

The logic is similar to other operational inspections: documents, equipment, procedures and crew answers should describe the same reality.

Tide Signal’s Port State Control 2026 preparation guide makes the same point in another context — compliance becomes weak when the manual, physical condition and officer understanding do not align.

Maritime Cyber Security Is Becoming a Ship-Port Problem, Not Only a Ship Problem

The direction of IMO policy in 2026 is clear.

Ships are becoming more connected. Ports are becoming more digital. Maritime Single Windows are becoming more important. Standardised data exchange is expanding.

That means the ship-shore interface becomes part of cyber resilience.

A vessel may have strong onboard controls and still depend on:

  • port community systems;
  • agent portals;
  • customs platforms;
  • terminal booking systems;
  • digital certificates;
  • crew and passenger reporting platforms;
  • third-party cloud systems.

IMO’s 2026 digitalisation strategy and the planned MSW cybersecurity amendments show that cyber resilience is moving deeper into the infrastructure of maritime trade.

Five Cyber Security Mistakes Shipping Companies Still Make

1. Treating cyber as an IT-department problem

The IT team cannot safely navigate the ship, operate cargo systems or understand every operational consequence. Cyber needs operational ownership as well as technical ownership.

2. Assuming an isolated system is automatically safe

Service laptops, USB devices, maintenance connections and temporary vendor access can create paths into systems that are normally offline.

3. Buying tools without defining recovery

Detection software is useful. A tested recovery path is what keeps the ship operating after something gets through.

4. Training crews with generic corporate slides

Use realistic maritime scenarios: fake agent instructions, changed bank details, suspicious chart updates, GNSS anomalies and vendor remote-access requests.

5. Confusing compliance with resilience

A company can have procedures and still fail badly if nobody knows how to use them under pressure.

Tide Signal Analysis: The Strongest Cyber Control Is Operational Trust

Shipping depends on trust.

The bridge trusts position data. The engineer trusts machinery alarms. The Master trusts the agent. The office trusts the vessel’s report. Finance trusts the supplier invoice. The terminal trusts the data submitted through a digital interface.

Cyber incidents attack that trust.

Sometimes they remove access completely.

More dangerously, they can leave the system operating while the information inside it is wrong.

That is why maritime cyber security should be judged by more than the number of firewalls or security products installed.

The stronger measure is whether people know:

  • which systems are trusted;
  • how to recognise when that trust is broken;
  • what independent information can be used instead;
  • who has authority to isolate a system;
  • how essential operations continue during recovery.

A cyber-resilient ship is not one that never loses a digital system. It is one that does not lose control of the operation when it does.

Frequently Asked Questions

What is maritime cyber security?

Maritime cyber security is the protection and resilient operation of digital systems, networks, data and connected equipment used by ships, shipping companies, ports and other maritime stakeholders.

Is cyber security mandatory under IMO rules?

IMO Resolution MSC.428(98) links cyber risk management to the Safety Management System and called for cyber risks to be appropriately addressed in existing SMS arrangements from 2021 onward.

What is MSC-FAL.1/Circ.3/Rev.3?

It is the current IMO Guidelines on Maritime Cyber Risk Management, issued in April 2025, providing high-level recommendations for identifying, protecting against, detecting, responding to and recovering from maritime cyber risk.

What are IACS UR E26 and E27?

UR E26 covers cyber resilience of ships as integrated entities. UR E27 covers cyber resilience of onboard systems and equipment. Revised requirements apply through IACS member class rules to ships in scope contracted for construction on or after 1 July 2024.

Can GNSS spoofing be a maritime cyber security issue?

Yes. The ship itself does not need to be hacked for manipulated or disrupted digital navigation data to create cyber-related operational risk. Bridge teams need independent cross-checking and fallback procedures.

Should cyber risk be included in the SMS?

Yes. Cyber risk should be integrated into the company’s safety management approach rather than treated only as a separate office IT policy.

What changed in maritime cyber security in 2026?

IMO FAL 50 approved draft mandatory cybersecurity measures for Maritime Single Windows and began work toward a non-mandatory Maritime Cyber Code, while the 2025 revised IMO cyber guidelines and IACS newbuilding requirements remain central to ship and company implementation.

What is the biggest cyber risk onboard a ship?

There is no single universal threat. The highest risk depends on ship design, connectivity and operation. Common exposures include phishing, weak remote access, poorly controlled removable media, unsegregated networks, outdated software, compromised vendor accounts and unreliable navigation data.


Related Tide Signal Coverage

Official and Industry Sources

Reporting status: 4 September 2026. This guide is intended for general maritime operational awareness. It does not replace a vessel’s approved SMS, flag-State requirements, class rules, company procedures, equipment-maker instructions or professional cyber-security advice.

Email article