IMO MSC.428(98) · ISM · UR E26/E27
Cyber Risk & the Safety Management System
Cyber risk management, reviewed the way flag states and port state control look at it: as part of your safety management system, not as an IT project running alongside it. This is documentation and regulatory work. We check that your SMS addresses cyber risk in substance, and we tell you where it will not hold up.
What's Included
- SMS documentation review against MSC.428(98) and the IACS UR E26 and E27 documentation requirements
- Cyber risk review inside the ISM framework, against IMO Resolution MSC.428(98) and the IMO guidelines at MSC-FAL.1/Circ.3/Rev.3 dated 4 April 2025 and its six functional elements
- SMS gap analysis against flag administration and port state control expectations
- Newbuild documentation readiness against IACS UR E26 and E27, which apply to ships contracted for construction on or after 1 July 2024
- Incident response and reporting procedure review from the regulatory side
- Crew facing procedures short enough that crews follow them and specific enough that auditors accept them
How We Engage
- 1
Review the SMS, the cyber documentation and the last audit findings.
- 2
Gap analyze against the instruments that actually apply to your ships.
- 3
Deliver findings and procedure updates your DPA can implement.
Outcomes
IACS UR E26 and E27 apply to ships contracted for construction on or after 1 July 2024. Existing ships are not caught by them: for existing tonnage the obligation runs through the safety management system under MSC.428(98), which required cyber risk to be addressed in the SMS no later than the first annual verification of the company's Document of Compliance after 1 January 2021. This is documentation and regulatory work. SolarisTech performs no technical security assessment, no penetration testing and no incident forensics.
Technical security assessment, OT and IT engineering and forensics sit with specialist security firms, and we will tell you when you need one. Our reports are prepared for the party that instructs us and for the purpose stated in the engagement. Reliance by any other party requires our written agreement.

YOUR REVIEWER
Thomas Blenk
American Bureau of Shipping, latterly Corporate Vice President, Global Marine Sectors. Deputy Commissioner of Maritime Affairs, Republic of the Marshall Islands.
Make cyber survive an audit.
Send your SMS cyber section and your last audit report; we will tell you where the gaps are.