IMO Cyber Risk Management Resolution MSC.428(98): What Operators Actually Need to Demonstrate

A reading of IMO Resolution MSC.428(98) — the maritime cyber risk requirement — written for the shore-based technology functions and ship management organisations that have to demonstrate compliance.

The International Maritime Organization’s Resolution MSC.428(98), adopted in 2017 and applicable from 1 January 2021, requires shipowners and operators to address cyber risk in their Safety Management Systems under the ISM Code. It is not new regulation, but it has become a focused area of Flag State and class society attention as the industry’s exposure to cyber risk has grown — particularly with the proliferation of connected onboard systems and the convergence of operational and information technology.

This is a reading of what the resolution substantively requires, what Flag State and class society verifications focus on, and where most operators have unaddressed gaps.

Free · 4 minutes

Do you know where AI is already being used in your business — and what it can see?

Fourteen questions on shadow AI, data exposure, oversight, and governance debt — the gap between how fast AI is arriving and how much control you have over it. Banded finding on screen, full sheet by email.

What the resolution requires

Resolution MSC.428(98) is short — a half-page document that requires cyber risk to be appropriately addressed in Safety Management Systems no later than the first annual verification of the company’s Document of Compliance after 1 January 2021. The substance is delivered through reference to industry guidelines, principally the BIMCO-coordinated Guidelines on Cyber Security Onboard Ships, now in its fourth edition.

The guidelines adapt the NIST Cyber Security Framework’s five functions — identify, protect, detect, respond, recover — to the maritime context:

  • Identify. An inventory of vessel and shore IT and OT systems, an assessment of their cyber risk, and an understanding of dependencies.
  • Protect. Controls — access management, network segregation, secure configuration, vulnerability management, training — appropriate to the risk.
  • Detect. Monitoring sufficient to identify cyber events, both at the vessel and shore.
  • Respond. Documented procedures for responding to cyber incidents, including communication and escalation.
  • Recover. The ability to restore systems and operations after a cyber incident, with continuity of safe operations.

The framework applies to both information technology (IT) — business and administrative systems — and operational technology (OT) — the systems that monitor and control physical processes onboard, including ECDIS, AIS, GPS, engine control, ballast water management, and increasingly autonomous and remote-control systems.

Who this is for

  • The IT director or CIO at a shipowner, ship manager, or fleet operator responsible for maritime cyber risk management.
  • The Designated Person Ashore (DPA) under the ISM Code, whose responsibility for the Safety Management System now formally includes cyber.
  • The HSE or safety manager translating between IMO requirements and onboard implementation.

The IT/OT distinction matters more than it sounds

The single most consequential conceptual point in maritime cyber compliance is the distinction between IT and OT systems, and the different cyber controls each demands. IT systems — the office computers, the email, the shore-based fleet management software — can usually be patched, monitored, and protected with standard enterprise security tools. OT systems — the navigation electronics, the engine control, the cargo handling — often cannot.

OT systems frequently run on operating systems that are no longer supported, use protocols that have no native security, and connect via satellite or VSAT in ways that expose them. Patching may be impossible without dry-docking the vessel. The result is that OT cyber controls have to rely more heavily on network segregation, monitoring, and operational procedures — not on the patch-and-protect cycle that IT cyber assumes.

Operators whose cyber programmes are designed around IT assumptions and applied to OT systems consistently fail Flag State verifications.

Where Flag State and class society verification focus

From verifications conducted by the major Flag States (Panama, Marshall Islands, Liberia, Cyprus, Malta, and others) and class societies (DNV, Lloyd’s Register, ABS, Bureau Veritas, ClassNK, KR, RINA), the recurring focus areas:

The inventory. Does the operator know what is on each vessel? OT systems are frequently under-documented. ECDIS, radar, AIS, GPS, engine monitoring, cargo systems, ballast water management — all of these are cyber-relevant and frequently missing from the inventory.

Network segregation. Is the OT network actually separated from IT and from the public internet? Or is there a flat network onboard where a phishing email could reach the engine control system? Demonstrable segregation — VLANs, firewalls, air gaps where appropriate — is the supervisory expectation.

Crew training and awareness. Crew use the IT systems daily. Crew training that treats cyber as a shore-based concern fails. The training must reach the master and the engineering officers in formats they actually engage with.

Third-party access. Satellite communications providers, OEM remote diagnostics, fleet management software vendors — all of these have access to vessel systems. The controls on that access need to be documented and operational.

Incident response that has been tested. An untested incident response procedure is not a procedure. Annual exercise evidence — at minimum desktop, ideally including a vessel-shore simulation — is what verifiers expect.

The class society notation question

Most class societies now offer dedicated cyber notations — DNV’s CYBER SECURE, Lloyd’s Register ShipRight, ABS Cybersafety, BV’s SYS-COMP — that provide third-party verification of cyber controls. These notations are not required by Flag State, but they have become commercially material: charterers increasingly require them, and insurers price them in.

Class notation requires a more rigorous assessment than the baseline Flag State verification. An operator going for class notation typically goes well beyond the minimum required for ISM compliance.

The Cyprus context

Cyprus is one of the largest ship management centres in the world and the home flag for a substantial portion of EU-controlled tonnage. Cyprus-based ship managers and Cyprus-flag operators are subject to verifications from the Cyprus Department of Merchant Shipping as Flag State. Cyprus has been an active participant in IMO cyber risk discussions and its verification approach reflects the international standard.

How we engage with this

We read maritime cyber programmes. As part of a Technology Control Review scoped to IMO MSC.428(98), we read the cyber-related sections of the Safety Management System, the IT/OT inventory and architecture, the controls operating onboard and ashore, and the incident response arrangements. The output is a written assessment of where the programme stands relative to what Flag State and class society verifiers actually look for.

We do not implement OT cyber controls. We do not deliver crew training. We do not pursue class notations. We read what is there, identify what is missing, and write it down for the DPA, the IT director, and the board.

Pricing is published at /pricing/. If your fleet is preparing for the next ISM verification or evaluating class society cyber notation, the place to start is a conversation.

Sixteen Pillars is a technology governance consultancy based in Cyprus. Engagements run remote across the EU, UK, and Middle East, with on-site time where the engagement requires it.

Most technology problems are not technology problems. They are control problems.

The systems exist. The investment has been made. The question is whether leadership can understand, direct, evidence, and sustain what those systems produce. Find out where control exists — and where it only appears to.