IACS UR E26 requires cyber risk assessment. IMO MSC-FAL.1/Circ.3 provides guidance. But translating framework requirements into practical vessel assessments remains a challenge for many operators. This article presents an actionable methodology for maritime cyber risk assessment.
This article is part of the Maritime Cyber Playbook series, developed in collaboration with Margetis Maritime.
Risk Assessment Fundamentals
Cyber risk assessment answers three questions:
- What can go wrong? (Threat identification)
- How likely is it? (Probability assessment)
- What are the consequences? (Impact analysis)
The combination of likelihood and impact determines risk level, which informs treatment decisions.
Phase 1: Scope and Context
Define Assessment Boundaries
Before beginning assessment, establish scope:
- Vessel scope: Single vessel, vessel class, or entire fleet?
- System scope: All CBS or specific systems (navigation, propulsion, cargo)?
- Operational scope: At sea, in port, during maintenance?
Establish Context
Document the operating environment:
- Trade routes and typical ports
- Cargo types and associated regulations
- Crew composition and technical capability
- Shore support availability
- Regulatory requirements (Flag State, class, charterer)
Phase 2: Asset Identification
Create System Inventory
Document all computer-based systems:
| Category | Example Systems |
|---|---|
| Navigation | ECDIS, radar, AIS, GPS, autopilot, VDR |
| Propulsion | Engine control, power management, steering |
| Cargo | Loading computer, tank monitoring, reefer control |
| Safety | Fire detection, GMDSS, bilge alarms |
| Communications | VSAT, email, internet, VoIP |
| Administrative | PMS, crew management, document systems |
Classify System Criticality
Assign criticality levels based on operational impact:
- Critical: Essential for safe navigation and operation (ECDIS, propulsion control)
- Important: Significant operational impact if unavailable (cargo monitoring, PMS)
- Supporting: Operational inconvenience but not safety-critical (crew welfare, administrative)
Phase 3: Threat Identification
Threat Categories
Consider threats across categories:
Intentional External:
- Targeted attacks (state actors, competitors)
- Opportunistic attacks (ransomware, cryptomining)
- Hacktivism (environmental, political)
Intentional Internal:
- Disgruntled crew sabotage
- Data theft
- Deliberate policy violation
Unintentional:
- Accidental malware introduction (USB, email)
- Configuration errors
- Inadequate maintenance
- Failed updates
Threat Scenarios
Develop specific threat scenarios relevant to vessel operations:
- Ransomware encrypts administrative and potentially OT systems
- Phishing attack compromises email credentials, enables further access
- Infected USB introduced during chart update corrupts ECDIS
- VSAT management interface exploited for network access
- Vendor/service engineer laptop introduces malware
- GPS spoofing provides false position data
- AIS manipulation creates phantom vessels or hides actual position
Phase 4: Vulnerability Assessment
Technical Vulnerabilities
For each system category, assess:
- Operating system currency: Is software supported and patched?
- Network exposure: What connections exist? How are they protected?
- Access control: How are users authenticated? Are passwords strong?
- Physical security: Who can access hardware and ports?
- Configuration: Are default settings changed? Unnecessary services disabled?
Procedural Vulnerabilities
Assess security management:
- Are cyber procedures documented in SMS?
- Is crew trained on cyber threats?
- Are incidents reported and investigated?
- Is vendor/visitor access controlled?
- Are backups maintained and tested?
Phase 5: Impact Analysis
Impact Categories
Assess potential consequences across dimensions:
| Category | Low | Medium | High |
|---|---|---|---|
| Safety | Minor injury risk | Serious injury risk | Life-threatening |
| Environmental | Minor spill risk | Moderate pollution | Major pollution |
| Operational | Hours delay | Days delay | Mission failure |
| Financial | <$10K | $10K-$1M | >$1M |
| Reputational | Internal only | Industry notice | Public attention |
System-Specific Impact
Assess impact of compromising each system:
- ECDIS failure: Loss of navigation capability, potential grounding risk
- Propulsion control: Loss of manoeuvring, collision risk
- Cargo monitoring: Cargo damage, environmental release
- GMDSS: Communication failure in emergency
- Administrative: Operational inefficiency, data breach
Phase 6: Risk Evaluation
Risk Matrix
Combine likelihood and impact to determine risk level:
| Low Impact | Medium Impact | High Impact | |
|---|---|---|---|
| High Likelihood | Medium | High | Critical |
| Medium Likelihood | Low | Medium | High |
| Low Likelihood | Low | Low | Medium |
Risk Register
Document all identified risks with:
- Risk ID and description
- Affected systems
- Threat scenario
- Vulnerability exploited
- Likelihood rating with justification
- Impact rating with justification
- Overall risk level
- Current controls
- Treatment decision
Phase 7: Risk Treatment
Treatment Options
For each risk, select appropriate treatment:
- Accept: Risk is within tolerance; document acceptance decision
- Mitigate: Implement controls to reduce likelihood or impact
- Transfer: Insurance or contractual arrangements (limited for cyber)
- Avoid: Eliminate the risk by removing the activity or system
Control Selection
Common maritime cyber controls:
| Control Type | Examples |
|---|---|
| Technical | Firewalls, segmentation, encryption, AV |
| Physical | Port locks, access restrictions, cable protection |
| Administrative | Policies, procedures, training, audits |
| Detective | Logging, monitoring, alerting |
| Recovery | Backups, incident response, business continuity |
Phase 8: Documentation and Review
Assessment Report
Document the assessment including:
- Scope and methodology
- Asset inventory summary
- Threat landscape overview
- Vulnerability findings
- Risk register
- Treatment plan with timeline and responsibilities
- Residual risk summary
Review Cycle
Risk assessment is not one-time. Review when:
- Significant system changes occur
- New threats emerge
- Incidents occur (on this vessel or industry)
- Regulatory requirements change
- Annually as minimum
Practical Tips
- Start with what you know: Begin assessment with familiar systems, expand systematically
- Use scenarios: Abstract risks become concrete when expressed as stories
- Involve operators: Bridge and engine room crew understand operational impacts
- Document assumptions: Make likelihood and impact judgments explicit
- Prioritise pragmatically: Perfect is impossible; focus on highest risks first
Next in the Series
The final article in this series looks forward: the cyber-enabled ship and how maritime cyber security will evolve with autonomous operations, advanced connectivity, and emerging regulations.
This is the seventh article in the Maritime Cyber Playbook series, a collaboration between IWH and Margetis Maritime. For maritime cybersecurity advisory services, contact us.