Subscribe to our Mailing Lists (It's free!)
Friday, May 16, 2025
SAFETY4SEA
  • Home
  • Safety
    • All
    • Accidents
    • Alerts
    • Loss Prevention
    • Maritime Health
    • Regulation
    • Safety
    • Seafarers
    • Security
    crew injury

    Lessons learned: Effective teamwork serves as a strong barrier

    Key trends in seafarer recruitment and retention

    Britannia: Preparing the crew for emergencies and claims

    pakistani seafarers

    India prohibits Pakistani seafarers to disembark from VLCC

    LR regulations

    LR outlines changes to mandatory statutory regulations

  • SEAFiT
    • All
    • Intellectual
    • Mental
    • Physical
    • Social
    • Spiritual
    Book Review: Building leaders the MMMA way

    Book Review: How to avoid a climate disaster

    mental health

    MOL takes step to enhance the mental health of its crew

    Book Review: Building leaders the MMMA way

    Book Review: The Art Of War

    relax

    In the calm lies the cure: Exploring the parasympathetic nervous system

  • Green
    • All
    • Arctic
    • Ballast
    • Emissions
    • Fuels
    • Green Shipping
    • Pollution
    • Ship Recycling
    • Technology
    LNG terminal

    Greek LNG terminal upgrade aims for zero emission operations

    FuelEU

    Oceanscore: Shipping industry could profit €250M from FuelEU

    ABS ammonia

    ABS publishes safety insights for ammonia as a fuel

    Port of Gothenburg biomethane

    Biomethane gets successfully bunkered in Gothenburg port

  • Smart
    • All
    • Connectivity
    • Cyber Security
    • E-navigation
    • Energy Efficiency
    • Maritime Software
    • Smart
    ecdis

    MPA Singapore: Strengthening ECDIS and ENP competency

    DCSA eBL

    DCSA completes first interoperable eBL transaction

    remote pilotage

    Denmark launches world’s first test program for remote pilotage

    red sea houthis

    Windward: GPS jamming is a rising cyber threat in the Red Sea

  • Risk
    • All
    • CIC
    • Detentions
    • Fines
    • PSC Focus
    • Vetting
    PSC

    Black Sea MoU Annual Report: 4,587 inspections in 2024

    RISK4SEA unveils updated editions featuring worldwide data from the last 36M

    RISK4SEA unveils updated editions featuring worldwide data from the last 36M

    Black Sea mou

    Black Sea MoU: 53 vessels detained during CIC period

    Panama Ship Registry

    Panama implements new screening process for vessels joining its registry

  • Others
    • All
    • Diversity in shipping
    • Maritime Knowledge
    • Offshore
    • Ports
    • Shipping
    • Sustainability
    • Videos
    dry bulk market

    Baltic Exchange: Maritime market highlights 12-16 May

    cruise ship

    Watch: Where do cruise ships go when they die?

    female seafarer

    Program for female cadets promises to boost diversity

    10 trends influencing global commercial shipping

    Sea-Intelligence: Long transit times do not inherently cause problems

  • Columns
    supportive

    A supportive employer makes all the difference

    Human Element: Understanding the importance of seafarers’ soft skills

    Human Element: Understanding the importance of seafarers’ soft skills

    Achilles

    Achilles: Improving supply chain transparency can have a bottom line benefit

    Trending Tags

    • Book Review
    • Career Paths
    • Human Performance
    • Industry Voices
    • Interviews
    • Maripedia
    • Maritime History
    • Regulatory Update
    • Resilience
    • Seafarers Stories
    • SeaSense
    • Training & Development
    • Wellness Corner
    • Wellness Tips
  • Events
  • Plus
No Result
View All Result
  • Home
  • Safety
    • All
    • Accidents
    • Alerts
    • Loss Prevention
    • Maritime Health
    • Regulation
    • Safety
    • Seafarers
    • Security
    crew injury

    Lessons learned: Effective teamwork serves as a strong barrier

    Key trends in seafarer recruitment and retention

    Britannia: Preparing the crew for emergencies and claims

    pakistani seafarers

    India prohibits Pakistani seafarers to disembark from VLCC

    LR regulations

    LR outlines changes to mandatory statutory regulations

  • SEAFiT
    • All
    • Intellectual
    • Mental
    • Physical
    • Social
    • Spiritual
    Book Review: Building leaders the MMMA way

    Book Review: How to avoid a climate disaster

    mental health

    MOL takes step to enhance the mental health of its crew

    Book Review: Building leaders the MMMA way

    Book Review: The Art Of War

    relax

    In the calm lies the cure: Exploring the parasympathetic nervous system

  • Green
    • All
    • Arctic
    • Ballast
    • Emissions
    • Fuels
    • Green Shipping
    • Pollution
    • Ship Recycling
    • Technology
    LNG terminal

    Greek LNG terminal upgrade aims for zero emission operations

    FuelEU

    Oceanscore: Shipping industry could profit €250M from FuelEU

    ABS ammonia

    ABS publishes safety insights for ammonia as a fuel

    Port of Gothenburg biomethane

    Biomethane gets successfully bunkered in Gothenburg port

  • Smart
    • All
    • Connectivity
    • Cyber Security
    • E-navigation
    • Energy Efficiency
    • Maritime Software
    • Smart
    ecdis

    MPA Singapore: Strengthening ECDIS and ENP competency

    DCSA eBL

    DCSA completes first interoperable eBL transaction

    remote pilotage

    Denmark launches world’s first test program for remote pilotage

    red sea houthis

    Windward: GPS jamming is a rising cyber threat in the Red Sea

  • Risk
    • All
    • CIC
    • Detentions
    • Fines
    • PSC Focus
    • Vetting
    PSC

    Black Sea MoU Annual Report: 4,587 inspections in 2024

    RISK4SEA unveils updated editions featuring worldwide data from the last 36M

    RISK4SEA unveils updated editions featuring worldwide data from the last 36M

    Black Sea mou

    Black Sea MoU: 53 vessels detained during CIC period

    Panama Ship Registry

    Panama implements new screening process for vessels joining its registry

  • Others
    • All
    • Diversity in shipping
    • Maritime Knowledge
    • Offshore
    • Ports
    • Shipping
    • Sustainability
    • Videos
    dry bulk market

    Baltic Exchange: Maritime market highlights 12-16 May

    cruise ship

    Watch: Where do cruise ships go when they die?

    female seafarer

    Program for female cadets promises to boost diversity

    10 trends influencing global commercial shipping

    Sea-Intelligence: Long transit times do not inherently cause problems

  • Columns
    supportive

    A supportive employer makes all the difference

    Human Element: Understanding the importance of seafarers’ soft skills

    Human Element: Understanding the importance of seafarers’ soft skills

    Achilles

    Achilles: Improving supply chain transparency can have a bottom line benefit

    Trending Tags

    • Book Review
    • Career Paths
    • Human Performance
    • Industry Voices
    • Interviews
    • Maripedia
    • Maritime History
    • Regulatory Update
    • Resilience
    • Seafarers Stories
    • SeaSense
    • Training & Development
    • Wellness Corner
    • Wellness Tips
  • Events
  • Plus
No Result
View All Result
SAFETY4SEA

IACS: Protecting network systems onboard from cyber risks

by The Editorial Team
October 26, 2018
in Cyber Security
cyber security

Credit: Shutterstock

FacebookTwitterEmailLinkedin

IACS issued a recommendation report suggesting guidelines to ensure network security onboard ships. The report provides a minimum set of recommended measures for the resilience of networks and networked systems onboard against cyber-related risks.

This recommendation regards computer networks, connecting computer based systems onboard for -IT and OT systems, which are vulnerable to potential cyber events that could lead to dangerous situations for the safety of human life, vessel or cargo, or threat to the environment.

Networks onboard ships and vulnerabilities

Networks on board ships can be categorized according to many different properties and can include the following:

RelatedNews

ABS publishes safety insights for ammonia as a fuel

IMO WISTA Survey: Falling numbers for women in maritime

  • Extension (local, ship-to-shore within the company, ship-to-shore with other companies, connected to public networks);
  • Technology (fieldbus, Ethernet, WiFi, mobile, short-range wireless);
  • Supported protocols (fieldbus protocols, IP, TCP, UDP);
  • Type of service (supporting IT or OT systems);
  • Category of systems connected (Cat. I, II or III systems – see UR E22);
  • Accessibility (restricted, controlled, public).

[smlsubform prepend=”GET THE SAFETY4SEA IN YOUR INBOX!” showname=false emailtxt=”” emailholder=”Enter your email address” showsubmit=true submittxt=”Submit” jsthanks=false thankyou=”Thank you for subscribing to our mailing list”]

Each network type has specific properties and can be affected by specific vulnerabilities. If compromised, its failure can lead to consequences that have different impacts on safety and/or security.

Network vulnerabilities can be related to access to and use of the information generated, archived or transported in the network and quality of the communication service implemented by means of the network.

Read in this series
    • How to conduct proper software maintenance
    • Efficient control of software dependent systems
    • Contingency plan for onboard computer based systems
    • Guidelines on ship board network architecture
    • Data assurance of computer-based system onboard
    • Protecting network systems onboard from cyber risks
    • How to ensure proper operation of integration systems
    • Developing an inventory list of computer-based systems
    • Recommendations for remote access to onboard IT systems

Preventing cyber incidents

In order to prevent these networks from being breached, there are a number of measures that can be taken. These are:

Risk assessment

Risks should be evaluated taking into account the possible impact of unauthorized access; the possible impact of degradation of data flow; factors related to the ship as a whole, like type of service and navigation.

Key network resources

The following items should be identified:

  • Networks on board;
  • Networked IT and OT systems;
  • Data flows and network devices or resources potentially limiting them;
  • Connections with external systems or networks;
  • Access points and interfaces, including machine-to-machine (M2M) interfaces;
  • Roles and responsibilities of users;
  • Network vulnerabilities and threats, including those related to information security and those related to the quality of communication service, e.g. leveraging vulnerability scan tools, security information databases, etc.

Network protection safeguards

System Integrators and Suppliers should consider and implement the following safeguards to prevent cyber events:

  • Management of identities and credentials of network users, including M2M networks;
  • Enhanced authentication control, or restricted privileges, for remote access or from access points of the lower level of security;
  • Physical access control to network access points;
  • Pervasive implementation of Least Privilege Policy;
  • Bring-your-own-device (BYOD) management policy;
  • Encryption for data at rest (stored) and data in transit (exchanged);
  • Integrity checks for data at rest and data in transit;
  • Separation of networks, firewalling, De-Militarized Zones (DMZs), etc.;
  • Separation of networks supporting IT systems (e.g. for administrative tasks, passenger and crew connectivity, etc.), OT systems (e.g. for engine control, cargo control, etc.) and alarm systems;
  • Event logging and Quality of Service (QoS);
  • Data backup procedures;
  • Network configuration change and patch management;
  • Use of certified approved and/or appropriate products suitable for their intended operational environment;
  • Use of routing technology for ship to shore and ship to ship communication.

Cyber incident response

The following measures aim to take appropriate actions regarding detected cybersecurity events:

  • Confine the breach to the minimum extension;
  • Procedures for a timely acknowledgment and management of incident alerts;
  • Assignment of roles and responsibilities;
  • Continuous training of personnel;
  • Periodic cyber incident drills;
  • Preservation of logs and any elements related to cyber incidents.

Testing and assessment

Finally, for networks connecting systems of Cat. II and III, vulnerability assessment and test campaigns should be conducted in the operational configuration at least once before delivery, in order to verify the actual resilience of onboard networks to cyber incidents.

See more in the PDF below

IACS: Protecting network systems onboard from cyber risks

IACS: Protecting network systems onboard from cyber risksIACS: Protecting network systems onboard from cyber risks
IACS: Protecting network systems onboard from cyber risksIACS: Protecting network systems onboard from cyber risks
Tags: cyber securityIACSreports
Previous Post

USCG finalizes rule on fire protection standards for towing vessels

Next Post

IACS: How to ensure proper operation of integration systems

Related News

LR regulations
Regulation

LR outlines changes to mandatory statutory regulations

May 16, 2025
PSC
PSC Focus

Black Sea MoU Annual Report: 4,587 inspections in 2024

May 16, 2025
LNG
Emissions

Global LNG fleet’s annual CO2 emissions exceed 12 billion tonnes

May 14, 2025
maritime electricfication
Green Shipping

BV: Leveraging electrification for maritime sustainability

May 14, 2025
seafarers
Seafarers

Seafarers Happiness Index Q12025: Glimmer of hope for crew welfare

May 8, 2025
IEA methane
Emissions

IEA: Upstream operations account for 85% of methane emissions

May 7, 2025

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Explore more

No Result
View All Result
MARITIME EVENTS

Explore

  • Safety
  • SEAFiT
  • Green
  • Smart
  • Risk
  • Others
  • SAFETY4SEA Events
  • SAFETY4SEA Plus Subscription

Useful Links

  • About
  • Disclaimer
  • Editorial Policies
  • Advertising
  • Content Marketing
  • Contact

© 2025 SAFETY4SEA

No Result
View All Result
  • Safety
    • Accidents
    • Alerts
    • Loss Prevention
    • Maritime Health
    • Regulation
    • Safety
    • Seafarers
    • Security
  • SEAFiT
    • Intellectual
    • Mental
    • Physical
    • Social
    • Spiritual
  • Green
    • Arctic
    • Ballast
    • Emissions
    • Fuels
    • Green Shipping
    • Pollution
    • Ship Recycling
    • Technology
  • Smart
    • Connectivity
    • Cyber Security
    • E-navigation
    • Energy Efficiency
    • Maritime Software
    • Smart
  • Risk
    • CIC
    • Detentions
    • Fines
    • PSC Case Studies
    • PSC Focus
    • Vetting
  • Others
    • Diversity in shipping
    • Maritime Knowledge
    • Offshore
    • Ports
    • Shipping
    • Sustainability
    • Videos
  • Columns
    • Book Review
    • Career Paths
    • Human Performance
    • Industry Voices
    • Interviews
    • Maripedia
    • Maritime History
    • Opinions
    • Regulatory Update
    • Resilience
    • Seafarers Stories
    • SeaSense
    • Tip of the day
    • Training & Development
    • Wellness Corner
    • Wellness Tips
  • SAFETY4SEA Events
  • SAFETY4SEA Plus Subscription

© 2025 SAFETY4SEA

Manage your privacy
We use technologies like cookies to store and/or access device information. We do this to improve browsing experience and to show (non-) personalized ads. Consenting to these technologies will allow us to process data such as browsing behavior or unique IDs on this site. Not consenting or withdrawing consent, may adversely affect certain features and functions.
Functional Always active
The technical storage or access is strictly necessary for the legitimate purpose of enabling the use of a specific service explicitly requested by the subscriber or user, or for the sole purpose of carrying out the transmission of a communication over an electronic communications network.
Preferences
The technical storage or access is necessary for the legitimate purpose of storing preferences that are not requested by the subscriber or user.
Statistics
The technical storage or access that is used exclusively for statistical purposes. The technical storage or access that is used exclusively for anonymous statistical purposes. Without a subpoena, voluntary compliance on the part of your Internet Service Provider, or additional records from a third party, information stored or retrieved for this purpose alone cannot usually be used to identify you.
Marketing
The technical storage or access is required to create user profiles to send advertising, or to track the user on a website or across several websites for similar marketing purposes.
Manage options Manage services Manage {vendor_count} vendors Read more about these purposes
Manage options
{title} {title} {title}
No Result
View All Result
  • Safety
    • Accidents
    • Alerts
    • Loss Prevention
    • Maritime Health
    • Regulation
    • Safety
    • Seafarers
    • Security
  • SEAFiT
    • Intellectual
    • Mental
    • Physical
    • Social
    • Spiritual
  • Green
    • Arctic
    • Ballast
    • Emissions
    • Fuels
    • Green Shipping
    • Pollution
    • Ship Recycling
    • Technology
  • Smart
    • Connectivity
    • Cyber Security
    • E-navigation
    • Energy Efficiency
    • Maritime Software
    • Smart
  • Risk
    • CIC
    • Detentions
    • Fines
    • PSC Case Studies
    • PSC Focus
    • Vetting
  • Others
    • Diversity in shipping
    • Maritime Knowledge
    • Offshore
    • Ports
    • Shipping
    • Sustainability
    • Videos
  • Columns
    • Book Review
    • Career Paths
    • Human Performance
    • Industry Voices
    • Interviews
    • Maripedia
    • Maritime History
    • Opinions
    • Regulatory Update
    • Resilience
    • Seafarers Stories
    • SeaSense
    • Tip of the day
    • Training & Development
    • Wellness Corner
    • Wellness Tips
  • SAFETY4SEA Events
  • SAFETY4SEA Plus Subscription

© 2025 SAFETY4SEA