
For quite some time now, the sea transport arena has experienced a significant digital revolution. Contemporary ships depend more on Information Technology (IT), which includes computers and software, and Operational Technology (OT), which refers to systems that control physical processes such as engine operation and cargo handling, to manage navigation, propulsion, cargo, and safety. This digitization can improve efficiency, but it also exposes ships to cyber threats that may interrupt operations, jeopardize crew and passenger safety, and endanger the marine environment. The International Association of Classification Societies (IACS) created E27, a unified requirement and a detailed cyber resilience model to address these risks. Integrating security in design and operation allows systems to protect vessels, personnel, and data from new cyber incidents.
As ships become increasingly digital, cyber threats can no longer be ignored. From navigation systems to engine controls, ensuring resilience is now a critical part of maritime safety and operational continuity.
Why Cyber Resilience Matters in Shipping?
With the increasing digitalization of ships, it is crucial to understand the risks and impacts of cyber threats. A cyberattack is any deliberate action involving IT or OT systems that disables, interrupts, or affects their functioning. When this type of attack harms onboard systems, networks, or their information, it creates the cyber incident. Cyber resilience is a vessel’s capacity to predict, absorb, and recover from such incidents. This helps keep the crew, ship, cargo, and marine environment safe.
Modern threats range from malware that affects propulsion or engine controls to unauthorized access to navigation or cargo systems. These can disrupt operations or cause environmental risks. Securing critical systems, especially those controlling propulsion, steering, or safety, is essential. A defence-in-depth approach uses multiple layers, combining people, processes, and technology. This approach makes systems less vulnerable and ensures safe functioning even during an attack.
Core Principles of E27
The E27 Unified Requirement gives a clear philosophy for realizing cyber resilience in modern ships. It focuses on secure design, operation, and maintenance of onboard systems. The framework distinguishes between ‘Systems’ and ‘Equipment’. A ‘System’ usually combines hardware and software for safe, secure, and reliable operation, like an engine control or dynamic positioning (DP) system. ‘Equipment’ covers items such as routers and switches, firewalls, intrusion prevention systems, automation equipment like PLCs, and even virtual or cloud-hosted equipment.
E27 recognizes that some security needs may require compensating countermeasures. These can offer alternative or complementary protection if system capabilities are lacking. Countermeasures should fulfil the purpose of the original requirement. For type approval, integrate them into the system instead of relying only on operational procedures.
E27 emphasizes keeping vital systems accessible. Security measures should not limit essential functions, including propulsion, steering, or safety oversight. The system design should keep the ship reliable for its mission. At the same time, it must maintain the confidentiality, integrity, and availability of data to protect the crew and ship.
Key Security Capabilities for On-board Systems
To make ships cyber resilient, each computer-based system needs certain basic security capabilities. Here are a few:
User and Account Management ensure that each person using the system is identified and checked, granting access based only on what is needed for their role. Controls like session timeouts, automatic locking, or ending sessions from a distance stop people from accessing accounts if they shouldn’t.
System Integrity and Confidentiality protect important information. Deterministic output ensures systems reach a safe state, such as being unpowered, the last known value, or a fixed value, if normal operations are interrupted.
Network and Device Controls enable safe operation. Wireless and portable devices are restricted to approved functions. Denial-of-service protection and resource management prevent system overloads. Least functionality limits active software, services, and ports to only essentials.
Additional security measures include clear permission for user access (explicit access authorization), ongoing system checks (active monitoring), data protection methods to ensure information isn’t tampered with, and verification that session identifiers are correct when systems are linked to networks that aren’t fully trusted (session ID validation on untrusted networks). Together, these safeguards form a layer-by-layer defence strategy, helping ships work securely and reliably, even if facing online threats.
Product Design & Development Requirements
Cyber resilience starts at the product design and development stage. E27 focuses on a Secure Development Lifecycle (SDLC), which covers all strategic lifecycle stages: requirement analysis and design, implementation, verification, release, maintenance, and end-of-life. Manufacturers must build in security throughout this cycle. This includes securing code-signing keys and enabling update validation before use.
Secure documentation is important. Products should provide clear instructions for using the defence-in-depth strategy, external security actions, and hardening steps during installation and maintenance. This includes setting security options, handling third-party components, and maintaining secure interfaces.
Operators also have user-friendly instructions to cover security patching, attack reporting, routine maintenance, and monitoring tool use. Documentation also describes legacy code risks and mitigation strategies. Secure development and strong user support help E27 ensure manufacturers and operators maintain safe, resilient systems throughout a ship’s lifecycle.
Implementing Cyber Resilience on Ships
Cyber resilience is more than technology.
It is a team effort involving people, processes, and systems. Shipping companies should align E27 requirements with internal policies, crew training, and regular maintenance. Consistent security standards are necessary. Constant monitoring and regular audits help detect vulnerabilities and ensure compliance. Cooperation among shipbuilders, vendors, and operators ensures secure configurations, quick patching, and efficient incident response. These practices reduce cyber risks, protect vital systems, and maintain safe, reliable vessel operations throughout the lifecycle.
The technology protection
The protection for these kinds of attacks cannot be the generic OT or, even worse, the classical IT Security with vulnerabilities, CVEs, and IT risk factors.
The protection here can only come from specialized solutions, able to dissect, digest, and operate on top of the NMEA protocol (versions -0183 and 0200), while considering the whole Maritime OT risks with the different specific attacks due to maritime protocols, usage, device and vessel’s architecture
Concluding Thoughts
Cyber resilience is now a crucial requirement in maritime operations. IACS E27 sets out guidelines for designing, operating, and maintaining secure, reliable ship systems. By following these principles and maintaining constant vigilance, the industry can better protect vessels, crew, cargo, and the environment from evolving cyber threats.








