IACS UR E26 requires cyber risk assessment. IMO MSC-FAL.1/Circ.3 provides guidance. But translating framework requirements into practical vessel assessments remains a challenge for many operators. This article presents an actionable methodology for maritime cyber risk assessment.

This article is part of the Maritime Cyber Playbook series, developed in collaboration with Margetis Maritime.

Risk Assessment Fundamentals

Cyber risk assessment answers three questions:

  1. What can go wrong? (Threat identification)
  2. How likely is it? (Probability assessment)
  3. What are the consequences? (Impact analysis)

The combination of likelihood and impact determines risk level, which informs treatment decisions.

Phase 1: Scope and Context

Define Assessment Boundaries

Before beginning assessment, establish scope:

  • Vessel scope: Single vessel, vessel class, or entire fleet?
  • System scope: All CBS or specific systems (navigation, propulsion, cargo)?
  • Operational scope: At sea, in port, during maintenance?

Establish Context

Document the operating environment:

  • Trade routes and typical ports
  • Cargo types and associated regulations
  • Crew composition and technical capability
  • Shore support availability
  • Regulatory requirements (Flag State, class, charterer)

Phase 2: Asset Identification

Create System Inventory

Document all computer-based systems:

CategoryExample Systems
NavigationECDIS, radar, AIS, GPS, autopilot, VDR
PropulsionEngine control, power management, steering
CargoLoading computer, tank monitoring, reefer control
SafetyFire detection, GMDSS, bilge alarms
CommunicationsVSAT, email, internet, VoIP
AdministrativePMS, crew management, document systems

Classify System Criticality

Assign criticality levels based on operational impact:

  • Critical: Essential for safe navigation and operation (ECDIS, propulsion control)
  • Important: Significant operational impact if unavailable (cargo monitoring, PMS)
  • Supporting: Operational inconvenience but not safety-critical (crew welfare, administrative)

Phase 3: Threat Identification

Threat Categories

Consider threats across categories:

Intentional External:

  • Targeted attacks (state actors, competitors)
  • Opportunistic attacks (ransomware, cryptomining)
  • Hacktivism (environmental, political)

Intentional Internal:

  • Disgruntled crew sabotage
  • Data theft
  • Deliberate policy violation

Unintentional:

  • Accidental malware introduction (USB, email)
  • Configuration errors
  • Inadequate maintenance
  • Failed updates

Threat Scenarios

Develop specific threat scenarios relevant to vessel operations:

  1. Ransomware encrypts administrative and potentially OT systems
  2. Phishing attack compromises email credentials, enables further access
  3. Infected USB introduced during chart update corrupts ECDIS
  4. VSAT management interface exploited for network access
  5. Vendor/service engineer laptop introduces malware
  6. GPS spoofing provides false position data
  7. AIS manipulation creates phantom vessels or hides actual position

Phase 4: Vulnerability Assessment

Technical Vulnerabilities

For each system category, assess:

  • Operating system currency: Is software supported and patched?
  • Network exposure: What connections exist? How are they protected?
  • Access control: How are users authenticated? Are passwords strong?
  • Physical security: Who can access hardware and ports?
  • Configuration: Are default settings changed? Unnecessary services disabled?

Procedural Vulnerabilities

Assess security management:

  • Are cyber procedures documented in SMS?
  • Is crew trained on cyber threats?
  • Are incidents reported and investigated?
  • Is vendor/visitor access controlled?
  • Are backups maintained and tested?

Phase 5: Impact Analysis

Impact Categories

Assess potential consequences across dimensions:

CategoryLowMediumHigh
SafetyMinor injury riskSerious injury riskLife-threatening
EnvironmentalMinor spill riskModerate pollutionMajor pollution
OperationalHours delayDays delayMission failure
Financial<$10K$10K-$1M>$1M
ReputationalInternal onlyIndustry noticePublic attention

System-Specific Impact

Assess impact of compromising each system:

  • ECDIS failure: Loss of navigation capability, potential grounding risk
  • Propulsion control: Loss of manoeuvring, collision risk
  • Cargo monitoring: Cargo damage, environmental release
  • GMDSS: Communication failure in emergency
  • Administrative: Operational inefficiency, data breach

Phase 6: Risk Evaluation

Risk Matrix

Combine likelihood and impact to determine risk level:

Low ImpactMedium ImpactHigh Impact
High LikelihoodMediumHighCritical
Medium LikelihoodLowMediumHigh
Low LikelihoodLowLowMedium

Risk Register

Document all identified risks with:

  • Risk ID and description
  • Affected systems
  • Threat scenario
  • Vulnerability exploited
  • Likelihood rating with justification
  • Impact rating with justification
  • Overall risk level
  • Current controls
  • Treatment decision

Phase 7: Risk Treatment

Treatment Options

For each risk, select appropriate treatment:

  • Accept: Risk is within tolerance; document acceptance decision
  • Mitigate: Implement controls to reduce likelihood or impact
  • Transfer: Insurance or contractual arrangements (limited for cyber)
  • Avoid: Eliminate the risk by removing the activity or system

Control Selection

Common maritime cyber controls:

Control TypeExamples
TechnicalFirewalls, segmentation, encryption, AV
PhysicalPort locks, access restrictions, cable protection
AdministrativePolicies, procedures, training, audits
DetectiveLogging, monitoring, alerting
RecoveryBackups, incident response, business continuity

Phase 8: Documentation and Review

Assessment Report

Document the assessment including:

  • Scope and methodology
  • Asset inventory summary
  • Threat landscape overview
  • Vulnerability findings
  • Risk register
  • Treatment plan with timeline and responsibilities
  • Residual risk summary

Review Cycle

Risk assessment is not one-time. Review when:

  • Significant system changes occur
  • New threats emerge
  • Incidents occur (on this vessel or industry)
  • Regulatory requirements change
  • Annually as minimum

Practical Tips

  1. Start with what you know: Begin assessment with familiar systems, expand systematically
  2. Use scenarios: Abstract risks become concrete when expressed as stories
  3. Involve operators: Bridge and engine room crew understand operational impacts
  4. Document assumptions: Make likelihood and impact judgments explicit
  5. Prioritise pragmatically: Perfect is impossible; focus on highest risks first

Next in the Series

The final article in this series looks forward: the cyber-enabled ship and how maritime cyber security will evolve with autonomous operations, advanced connectivity, and emerging regulations.


This is the seventh article in the Maritime Cyber Playbook series, a collaboration between IWH and Margetis Maritime. For maritime cybersecurity advisory services, contact us.