Subscribe to our Mailing Lists (It's free!)
Friday, May 2, 2025
SAFETY4SEA
  • Home
  • Safety
    • All
    • Accidents
    • Alerts
    • Loss Prevention
    • Maritime Health
    • Regulation
    • Safety
    • Seafarers
    • Security
    lessons learned

    Lessons learned: Refrain from risky recreational activities

    internet mobile phone

    Gard: Road safety lessons for mobile phone use onboard

    Lessons learned: Closer assessment and vetting was required for crew competency

    Lessons learned: Don’t overlook secondary hazards

    connectivity

    Pilbara Ports take steps to enhance connectivity for seafarers

  • SEAFiT
    • All
    • Intellectual
    • Mental
    • Physical
    • Social
    • Spiritual
    relax

    In the calm lies the cure: Exploring the parasympathetic nervous system

    malaria

    Navigating malaria at sea: Why prevention requires a rethink

    Book Review: Building leaders the MMMA way

    Book Review: Developing soft skills in mariners

    mindfulness

    The new wave of Mindfulness: 7 Key trends

  • Green
    • All
    • Arctic
    • Ballast
    • Emissions
    • Fuels
    • Green Shipping
    • Pollution
    • Ship Recycling
    • Technology
    co2 carrier

    Europe’s first offshore CO₂ carrier to hit waters

    hydrogen

    BV joins European liquid hydrogen research program

    port of rotterdam

    Port of Rotterdam launches bid for reducing port emissions

    LNG

    US looks into updating LNG infrastructure

  • Smart
    • All
    • Connectivity
    • Cyber Security
    • E-navigation
    • Energy Efficiency
    • Maritime Software
    • Smart
    internet mobile phone

    Gard: Road safety lessons for mobile phone use onboard

    connectivity

    Pilbara Ports take steps to enhance connectivity for seafarers

    training simulators

    Companies shake hands for advanced training simulators

    seafarers gps

    NorthStandard: Key measures when the GPS fails

  • Risk
    • All
    • CIC
    • Detentions
    • Fines
    • PSC Focus
    • Vetting
    inspection

    Tokyo MoU Annual Report 2024

    malta flag

    Malta: New requirements for vessel registration and seaworthiness

    LPG tanker

    Bangladesh arrests LPG tanker following 2024 fire incident

    PSC training

    IMO conducts Port State Control training in Comoros

  • Others
    • All
    • Diversity in shipping
    • Maritime Knowledge
    • Offshore
    • Ports
    • Shipping
    • Sustainability
    • Videos
    Baltic Exchange

    Baltic Exchange: Maritime market highlights 28 April – 2 May

    Syria

    CMA CGM invests $260 million in Syrian port development

    Odfjell: A global market-based measure with a carbon price is vital for industry’s energy efficiency

    GMF evaluates its impact regarding sustainability matters

    port of rotterdam

    Port of Rotterdam launches bid for reducing port emissions

  • Columns
    Achilles

    Achilles: Improving supply chain transparency can have a bottom line benefit

    port state control

    Linking ship to shore: Enabling direct communication between onboard crew with Port State Control

    eu shipping

    FuelEU maritime regulation and insights

    Trending Tags

    • Book Review
    • Career Paths
    • Human Performance
    • Industry Voices
    • Interviews
    • Maripedia
    • Maritime History
    • Regulatory Update
    • Resilience
    • Seafarers Stories
    • SeaSense
    • Training & Development
    • Wellness Corner
    • Wellness Tips
  • Events
  • Plus
No Result
View All Result
  • Home
  • Safety
    • All
    • Accidents
    • Alerts
    • Loss Prevention
    • Maritime Health
    • Regulation
    • Safety
    • Seafarers
    • Security
    lessons learned

    Lessons learned: Refrain from risky recreational activities

    internet mobile phone

    Gard: Road safety lessons for mobile phone use onboard

    Lessons learned: Closer assessment and vetting was required for crew competency

    Lessons learned: Don’t overlook secondary hazards

    connectivity

    Pilbara Ports take steps to enhance connectivity for seafarers

  • SEAFiT
    • All
    • Intellectual
    • Mental
    • Physical
    • Social
    • Spiritual
    relax

    In the calm lies the cure: Exploring the parasympathetic nervous system

    malaria

    Navigating malaria at sea: Why prevention requires a rethink

    Book Review: Building leaders the MMMA way

    Book Review: Developing soft skills in mariners

    mindfulness

    The new wave of Mindfulness: 7 Key trends

  • Green
    • All
    • Arctic
    • Ballast
    • Emissions
    • Fuels
    • Green Shipping
    • Pollution
    • Ship Recycling
    • Technology
    co2 carrier

    Europe’s first offshore CO₂ carrier to hit waters

    hydrogen

    BV joins European liquid hydrogen research program

    port of rotterdam

    Port of Rotterdam launches bid for reducing port emissions

    LNG

    US looks into updating LNG infrastructure

  • Smart
    • All
    • Connectivity
    • Cyber Security
    • E-navigation
    • Energy Efficiency
    • Maritime Software
    • Smart
    internet mobile phone

    Gard: Road safety lessons for mobile phone use onboard

    connectivity

    Pilbara Ports take steps to enhance connectivity for seafarers

    training simulators

    Companies shake hands for advanced training simulators

    seafarers gps

    NorthStandard: Key measures when the GPS fails

  • Risk
    • All
    • CIC
    • Detentions
    • Fines
    • PSC Focus
    • Vetting
    inspection

    Tokyo MoU Annual Report 2024

    malta flag

    Malta: New requirements for vessel registration and seaworthiness

    LPG tanker

    Bangladesh arrests LPG tanker following 2024 fire incident

    PSC training

    IMO conducts Port State Control training in Comoros

  • Others
    • All
    • Diversity in shipping
    • Maritime Knowledge
    • Offshore
    • Ports
    • Shipping
    • Sustainability
    • Videos
    Baltic Exchange

    Baltic Exchange: Maritime market highlights 28 April – 2 May

    Syria

    CMA CGM invests $260 million in Syrian port development

    Odfjell: A global market-based measure with a carbon price is vital for industry’s energy efficiency

    GMF evaluates its impact regarding sustainability matters

    port of rotterdam

    Port of Rotterdam launches bid for reducing port emissions

  • Columns
    Achilles

    Achilles: Improving supply chain transparency can have a bottom line benefit

    port state control

    Linking ship to shore: Enabling direct communication between onboard crew with Port State Control

    eu shipping

    FuelEU maritime regulation and insights

    Trending Tags

    • Book Review
    • Career Paths
    • Human Performance
    • Industry Voices
    • Interviews
    • Maripedia
    • Maritime History
    • Regulatory Update
    • Resilience
    • Seafarers Stories
    • SeaSense
    • Training & Development
    • Wellness Corner
    • Wellness Tips
  • Events
  • Plus
No Result
View All Result
SAFETY4SEA

Cyber security enters SMS: A new era from January 2021

by The Editorial Team
December 24, 2020
in Cyber Security
cyber security
FacebookTwitterEmailLinkedin

Every business and every individual can be subject to cyber threats. Cyber-crime is a massive business; hackers are very well-organized, and they put a lot of time and effort before launching a cyber-attack. The last couple years, cyber security has become a significant challenge for the maritime industry as well. In this regard, IMO took the decision to embed cyber security into Safety Management Systems; not much time has left for this new requirement and one thing is for sure: from next year, a new era begins for ship operators.

Even though we have witnessed several cyber attacks during the last years, cyber-criminal activities seem to have increased, exploiting the vulnerability of users working from home. In this context, The Nautical Institute hosted a Cyber Security webinar in November which referred to the new cyber-attack trends. These are the following: malware attacks, encrypted threats, crypto jacking, intrusion attempts, ransomware attacks and IoT malware. So, what shipping players should be doing in order to name themselves as cyber-secured?

The new IMO Requirement

According to Resolution MSC.428(98), operators need to ensure that their existing SMS appropriately address cyber risks by their 2021 annual verification. The risks as explained above are too many. With MSC-FAL 1/ Circ 3, IMO provides guidelines which consist of six pages and provide detailed recommendations on maritime cyber risk identification and management to safeguard shipping from current and emerging cyber threats and vulnerabilities.

RelatedNews

US looks into updating LNG infrastructure

IMO update: A legally binding instrument on biofouling under development

The recommendations are designed to be incorporated into existing SMS manuals and procedures and associated ISPS systems so as to update and enhance these processes. ‘’The overall goal is to support safe and secure shipping, which is operationally resilient to cyber risks.’’, IMO explains.

In particular, IMO issued “Guidelines on Maritime Cyber Risk Management”, to provide the required guidance on how a Company should respond to MSC. 428 (98), with reference to the following:

  • Guidelines on Cyber Security Onboard Ships issued by BIMCO, CLIA, ICS, INTERCARGO, INTERTANKO, OCIMF and IUMI.
  • ISO/IEC 27001 standard on Information technology
  • United States National Institute of Standards and Technology’s Framework for Improving Critical Infrastructure Cybersecurity (the NIST Framework).

Key Items to be addressed

Safety Management System is the key document of every shipping company, explaining how to conduct safe operations, based on the ISM code and the required policies for safe operations, protection of people, ship, cargo and environment. In essence, SMS are dynamic systems, meaning that they need to adapt to new requirements and address current needs and possible risks.

Addressing cyber risks in Safety Management System, requires additional focus, a new approach and more interaction between company and vessels. The real focus point of the system is to achieve the protection of Company (office) and onboard installed systems from cyber threats (of any kind). The aim is to have specific procedures in place and a cyber security culture to minimize the possibility of being attacked or affected by an attack. Additionally, operators can create response technics to overcome challenges from a cyber attack, ensuring continuity of operations.

The new IMO requirements can either addressed as a stand-alone system (Cyber Security Management Plan as part of existing SMS) or a revised SMS which will incorporate all required steps.

Steps required

  1. Set the policy for cyber security. This is the base of cyber structure. It is a declaration of Company’s setting targets and main actions for cyber security. It may cover additional items (like General Data protection) as all such items are related.
  2. Conduct a thorough assessment both in office and on-board ships, in order to identify related systems that may be subject to cyber threat. Systems are to be identified, listed, prioritized on vulnerability as critical or not. All systems should be approved to be used for specific tasks. The supportive software should be authentic, updated and installed by competent personnel.
  3. Implement procedures for cyber policy. The procedures should include the actions for everyone related to above identified systems, setting the privileges, the authority levels and specific actions (in form Dos and Don’ts) for each position. Procedures should include as minimum:
    1. Privileges and authority, including access level for each system
    2. Password instructions
    3. Removal media instructions
    4. Third party access to systems instructions (eg agents, constructors, system technicians, pilots, terminal personnel and any other individual or organization that requires to be granted access to shore or on board systems)
  4. Set an effective response system. The system should have immediate response actions, backup procedures, rectification procedures and alternative ways of conducting day to day routine in order to retain a flawless operation.
  5. As per shipping industry’s culture, all related incidents should be investigated, and lessons learnt and best practices to be used for avoiding similar issues in the future.
  6. Conduct periodical assessment of systems and procedures through audit / management review in order to check effectiveness.

Office/Ship interaction

It is highly recommended to follow the practice of ship shore drills with cyber scenarios. The Guidelines on Cyber Security Onboard Ships produced and supported by BIMCO, CLIA, ICS, INTERCARGO, INTERTANKO, OCIMF and IUMI, version 4.0 include useful real life incidents that can be used as sample scenarios for such drills.

Additionally as COVID-19 outbreak has altered operations, more and more Companies now use remote inspections and audits to monitor their managed vessels. These actions require procedures that can affectively produce monitoring results but simultaneously protect the systems used to conduct such operations.

Actions required

Ship Managers should:

  • Revise existing SMS to include cyber risk management and related procedures
  • Verify implementation of policies and procedures both ashore and on board
  • Provide all required resources for equipment (hardware) and/or software upgrades in order to support procedures
  • Provide ashore and on-board training to personnel for cyber threats/risks and best practices to address them.

Seafarers and Office personnel should:

  • Follow the procedures and guidance on cyber risk management
  • Do not use personal equipment on Company’s systems (ashore or onboard)
  • Be aware of all risks and threats related to cyber
  • Notify immediately authorized Company’s personnel for any suspicious or identified cyber issue in order to initiate response actions.

The industry is currently fighting with the thought whether operators are ready or not to comply. One way or another, from January 1st of January 2021, SMS will feature a new requirement, resulting to increased awareness over cyber security which is a critical issue as we have accelerated our path towards digitalization.

Cyber security enters SMS: A new era from January 2021Cyber security enters SMS: A new era from January 2021
Cyber security enters SMS: A new era from January 2021Cyber security enters SMS: A new era from January 2021
Tags: cyber securitydigitalizationIMOregulatory update cmsmSMS
Previous Post

Career Paths: Sara Baade, Sailors’ Society

Next Post

USCG: Update to mariners credentials amid COVID-19

Related News

malta flag
Fines

Malta: New requirements for vessel registration and seaworthiness

April 29, 2025
ferry safety
Safety

IMO campaign shines light on domestic ferry safety practices

April 29, 2025
digitalization
Smart

ILO: How digitalization and automation shape workplaces

April 29, 2025
nuclear power
Safety

MSC 110 is expected to discuss nuclear shipping framework

April 29, 2025
China tariff
Shipping

Swedish Club: U.S. Port fees structure and implementation timeline

April 28, 2025
ReCAAP ISC
Security

IMO Piracy Report: Sixteen incidents during February 2025

April 28, 2025

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Explore more

No Result
View All Result
MARITIME EVENTS

Explore

  • Safety
  • SEAFiT
  • Green
  • Smart
  • Risk
  • Others
  • SAFETY4SEA Events
  • SAFETY4SEA Plus Subscription

Useful Links

  • About
  • Disclaimer
  • Editorial Policies
  • Advertising
  • Content Marketing
  • Contact

© 2025 SAFETY4SEA

No Result
View All Result
  • Safety
    • Accidents
    • Alerts
    • Loss Prevention
    • Maritime Health
    • Regulation
    • Safety
    • Seafarers
    • Security
  • SEAFiT
    • Intellectual
    • Mental
    • Physical
    • Social
    • Spiritual
  • Green
    • Arctic
    • Ballast
    • Emissions
    • Fuels
    • Green Shipping
    • Pollution
    • Ship Recycling
    • Technology
  • Smart
    • Connectivity
    • Cyber Security
    • E-navigation
    • Energy Efficiency
    • Maritime Software
    • Smart
  • Risk
    • CIC
    • Detentions
    • Fines
    • PSC Case Studies
    • PSC Focus
    • Vetting
  • Others
    • Diversity in shipping
    • Maritime Knowledge
    • Offshore
    • Ports
    • Shipping
    • Sustainability
    • Videos
  • Columns
    • Book Review
    • Career Paths
    • Human Performance
    • Industry Voices
    • Interviews
    • Maripedia
    • Maritime History
    • Opinions
    • Regulatory Update
    • Resilience
    • Seafarers Stories
    • SeaSense
    • Tip of the day
    • Training & Development
    • Wellness Corner
    • Wellness Tips
  • SAFETY4SEA Events
  • SAFETY4SEA Plus Subscription

© 2025 SAFETY4SEA

Manage your privacy
We use technologies like cookies to store and/or access device information. We do this to improve browsing experience and to show (non-) personalized ads. Consenting to these technologies will allow us to process data such as browsing behavior or unique IDs on this site. Not consenting or withdrawing consent, may adversely affect certain features and functions.
Functional Always active
The technical storage or access is strictly necessary for the legitimate purpose of enabling the use of a specific service explicitly requested by the subscriber or user, or for the sole purpose of carrying out the transmission of a communication over an electronic communications network.
Preferences
The technical storage or access is necessary for the legitimate purpose of storing preferences that are not requested by the subscriber or user.
Statistics
The technical storage or access that is used exclusively for statistical purposes. The technical storage or access that is used exclusively for anonymous statistical purposes. Without a subpoena, voluntary compliance on the part of your Internet Service Provider, or additional records from a third party, information stored or retrieved for this purpose alone cannot usually be used to identify you.
Marketing
The technical storage or access is required to create user profiles to send advertising, or to track the user on a website or across several websites for similar marketing purposes.
Manage options Manage services Manage {vendor_count} vendors Read more about these purposes
Manage options
{title} {title} {title}
No Result
View All Result
  • Safety
    • Accidents
    • Alerts
    • Loss Prevention
    • Maritime Health
    • Regulation
    • Safety
    • Seafarers
    • Security
  • SEAFiT
    • Intellectual
    • Mental
    • Physical
    • Social
    • Spiritual
  • Green
    • Arctic
    • Ballast
    • Emissions
    • Fuels
    • Green Shipping
    • Pollution
    • Ship Recycling
    • Technology
  • Smart
    • Connectivity
    • Cyber Security
    • E-navigation
    • Energy Efficiency
    • Maritime Software
    • Smart
  • Risk
    • CIC
    • Detentions
    • Fines
    • PSC Case Studies
    • PSC Focus
    • Vetting
  • Others
    • Diversity in shipping
    • Maritime Knowledge
    • Offshore
    • Ports
    • Shipping
    • Sustainability
    • Videos
  • Columns
    • Book Review
    • Career Paths
    • Human Performance
    • Industry Voices
    • Interviews
    • Maripedia
    • Maritime History
    • Opinions
    • Regulatory Update
    • Resilience
    • Seafarers Stories
    • SeaSense
    • Tip of the day
    • Training & Development
    • Wellness Corner
    • Wellness Tips
  • SAFETY4SEA Events
  • SAFETY4SEA Plus Subscription

© 2025 SAFETY4SEA