What the IMO framework actually requires
The IMO's Guidelines on Maritime Cyber Risk Management, now at MSC-FAL.1/Circ.3/Rev.3 dated 4 April 2025, set out a risk management cycle rather than a technology checklist. The current revision names six functional elements: govern, identify, protect, detect, respond and recover. Govern was added in this revision. It covers the risk management strategy, roles and responsibilities, and business continuity, which moves accountability up from the technical department to the company. Folding that cycle into the SMS means cyber hazards appear in risk assessments, procedures, drills and the continuous improvement loop like any other hazard. The guidelines are explicit that this is an extension of existing safety and security management practice, not a parallel system bolted alongside it. The separation that matters most on board is between IT, meaning business systems, and OT, meaning operational technology: navigation, propulsion, power management and cargo control. OT failures have physical consequences. OT systems are often old, unpatched and never designed for connectivity. That is precisely why inventorying and segregating them is the first serious step.
Class rules raised the bar for newbuildings
For new ships, cyber resilience is now a class matter. IACS Unified Requirement E26 covers the cyber resilience of ships. UR E27 covers the cyber resilience of on board systems and equipment. The original versions were withdrawn and replaced, and the revised requirements apply to new ships contracted for construction on or after 1 July 2024. Applicability is tiered by vessel type and size, so not every hull carries the full set. The effect is to oblige yards and equipment makers to deliver vessels with security zones, access control, network monitoring and incident response capability designed in, rather than added later. The practical consequence reaches existing fleets too. Owners now run mixed fleets in which the newest ships have engineered cyber baselines while older ones rely entirely on procedural controls. The SMS has to make both defensible to an auditor.
Where ships actually get hurt
The recurring real world patterns are unglamorous. Phishing compromises shore systems and spreads via remote access. USB media carry malware into ECDIS or engine room PCs. Default or shared passwords sit on critical equipment. Remote maintenance connections installed by vendors go unmanaged. Crew devices bridge networks that were supposed to be isolated. None of these require a sophisticated adversary. All of them are addressable with inventory, segmentation, access discipline and awareness training. Charterers and vetting regimes increasingly probe exactly these points. The same controls that satisfy the flag also protect the ship's commercial acceptability.
Making it real instead of paper
A credible programme shows its work. That means an asset inventory that includes OT. A risk assessment that names realistic scenarios. Procedures the crew can actually follow, covering USB media, passwords and what to do when ECDIS behaves strangely. At least one exercised incident scenario. Management review that treats cyber findings like any other nonconformity, with named owners and closing dates. What auditors and inspectors are learning to spot is the opposite: a generic cyber annex added to the SMS that nobody on board has read. The gap between those two states is where the risk lives.