Cyber-risk controls for shipboard IT and OT systems
What is being checked
The inspector is checking whether cyber risk is embedded in the safety-management system and implemented onboard. Procedures, asset awareness, access control, removable media, remote access, updates, backups, incident response, recovery arrangements and crew behaviour should protect both information technology and operational technology.
Ready onboard
0/9 completePractice questions
Answer aloud, then open the preparation point.
1Which shipboard IT and OT systems are treated as critical, and where is the controlled inventory maintained?
Use the controlled asset inventory to identify critical systems, their operational purpose, responsible person, dependencies and approved support route.
2How are administrator rights, user accounts and passwords managed during crew changes?
Administrator rights should be limited and authorised; individual accounts should be reviewed, changed or removed at crew change under the company procedure.
3What approval is required before a technician connects locally or remotely to a critical system?
Obtain formal company approval, identify the technician and scope, control the connection, monitor the work and retain permitted evidence of access and completion.
4How is removable media checked before use on bridge, cargo or machinery systems?
Use only approved media and the designated malware-checking process on a suitable isolated system before connection to shipboard IT or OT equipment.
5Which critical data and configurations are backed up, and how is recovery verified?
Identify the protected backup for each critical system and show permitted evidence that restoration or recovery has been tested at the required interval.
6What would the ship do if ECDIS, GNSS input, propulsion control or shore connectivity were lost through a cyber incident?
Apply the relevant hard-copy contingency plan, maintain safe manual or alternative operation, isolate affected systems where authorised and contact shore support.
7How would you report and escalate a suspected cyber incident?
Preserve safety, report through the company cyber-incident route, contact technical support, record the event and avoid unauthorised actions that could destroy evidence or spread the incident.
Where an observation may arise
Cyber-risk responsibilities or controls are absent from the SMS or not implemented onboard.
Sensitive IT and OT systems are not identified in a current controlled inventory.
Administrator rights, generic accounts, passwords, exposed ports or remote access are inadequately controlled.
Portable media or contractor equipment is connected without approval and malware checking.
Anti-malware, software or security updates are unmanaged, overdue or unsupported by records.
Critical backups are absent, unprotected or have not been verified for recovery.
Hard-copy contingency plans or recovery actions for critical-system loss are unavailable.
Crew members cannot explain basic cyber hygiene, reporting or their access responsibilities.
The cyber-incident escalation route and technical-support contacts are unavailable.
Past observations for practice
The USB on the computer in the CCR was left unlocked.
Master's practical note
Select one critical system on the bridge, in the cargo control room or in the engine control room. Trace its owner, access rights, remote-support approval, removable-media control, update route, backup and recovery plan. Cyber preparation becomes credible when the officer can explain one complete operational chain.
Equipment boundary and references
Equipment boundary: Do not publish network diagrams, IP addresses, credentials, exposed ports, remote-access methods or system vulnerabilities. Cyber controls vary with equipment age, maker support and network architecture. The latest company procedure, maker restrictions and approved shore support govern the fitted systems.
References
- OCIMF SIRE 2.0 Question Library Part 1, Version 1.0, Question 7.5.1
- IMO Guidelines on Maritime Cyber Risk Management, latest revision
- IMO Resolution MSC.428(98), Maritime Cyber Risk Management in Safety Management Systems
- Guidelines on Cyber Security Onboard Ships, current industry edition
- Company cyber-risk management procedures
Last reviewed: 2026-08-25



