Port State Control officers are increasingly asking questions about cyber security. While dedicated cyber inspections remain uncommon, cyber elements are appearing in standard PSC examinations. Understanding what inspectors look for—and what triggers expanded scrutiny—can prevent delays and detentions.

This article is part of the Maritime Cyber Playbook series, developed in collaboration with Margetis Maritime.

The Evolving PSC Landscape

Since January 1, 2021, cyber risk management has been a mandatory element of Safety Management Systems under the ISM Code. This means PSC officers have authority to verify cyber security arrangements during routine inspections.

How Cyber Elements Enter PSC Inspections

Cyber questions typically arise through three pathways:

  1. ISM Code verification: Checking that cyber risks are addressed in the SMS
  2. Equipment inspection: Verifying that navigation and safety systems are operational
  3. Document review: Examining training records, drill logs, and procedures

A deficiency in any of these areas can trigger more detailed cyber-focused questioning.

What PSC Officers Look For

1. SMS Cyber Procedures

The starting point for any PSC cyber examination is the Safety Management System. Officers verify:

  • Cyber risk policy: Statement of company commitment to cyber security
  • Risk assessment: Evidence that cyber risks have been identified and assessed
  • Operational procedures: Specific procedures for managing cyber risks
  • Incident response procedures: Documented approach to cyber incidents
  • Roles and responsibilities: Clear assignment of cyber security duties

Red flags:

  • Generic cyber policy copied from templates without vessel-specific adaptation
  • No evidence of risk assessment or last assessment years old
  • Procedures that don't reflect actual vessel systems
  • No designated person responsible for cyber security

2. Crew Awareness

PSC officers may interview crew to assess cyber security awareness:

  • Master: Understanding of cyber risks, response procedures, company reporting requirements
  • Officers: Awareness of cyber threats, recognition of suspicious activity
  • Ratings: Basic awareness, particularly regarding USB devices and personal equipment

Common questions:

  • "What would you do if you noticed unusual behaviour on a bridge computer?"
  • "How do you update electronic charts? What checks do you perform?"
  • "What is your company's policy on USB devices?"
  • "Have you received cyber security training? When?"

3. Training Records

Documented evidence of cyber security training is increasingly expected:

  • Initial cyber awareness training for all crew
  • Role-specific training for officers and technical staff
  • Refresher training at appropriate intervals
  • Record of training completion with dates and content covered

4. Drill Records

Like fire and abandon ship drills, cyber incident drills should be documented:

  • Drill date and scenario
  • Participants
  • Actions taken
  • Lessons learned
  • Corrective actions if deficiencies identified

Officers expect to see at least one cyber drill per year, though more frequent exercises demonstrate mature security practices.

5. System Integrity

During equipment inspection, officers may verify:

  • Navigation systems operational: ECDIS, radar, AIS functioning correctly
  • No visible tampering: Authorised connections only, no unknown devices
  • Update status: Charts current, software reasonably recent
  • Backup capability: Paper charts available, backup navigation functional

PSC Cyber Deficiencies

Cyber-related deficiencies fall under ISM Code (Code 01) and can be recorded as:

Deficiency CodeDescriptionTypical Examples
01117Safety Management - Cyber RiskNo cyber procedures in SMS
01114Familiarisation/TrainingNo cyber training records
01115Emergency PreparednessNo cyber incident procedures
01116Internal AuditsCyber not covered in audits

Serious deficiencies can result in detention if they indicate a significant failure of the Safety Management System.

Regional Variations

Paris MoU

European Port State Control under the Paris MoU has been actively developing cyber inspection guidance. Concentrated Inspection Campaigns (CICs) periodically focus on specific areas—cyber security may become a CIC topic.

Tokyo MoU

Asian-Pacific PSC has incorporated cyber elements into ISM verification. Singapore and Australian ports have been particularly active in cyber awareness.

US Coast Guard

USCG has explicit cyber security requirements for vessels calling at US ports. The Maritime Transportation Security Act (MTSA) facility cyber requirements are increasingly being applied to vessel inspections.

Preparing for PSC Cyber Examination

Documentation Readiness

Have the following immediately available:

  1. SMS cyber section: Clearly marked, easily located
  2. Cyber risk assessment: Dated, relevant to vessel systems
  3. Training records: Crew list with training dates and certificates
  4. Drill records: Last 12 months of cyber exercises
  5. System inventory: List of computer-based systems aboard
  6. Network diagram: Simplified diagram showing system connections

Crew Briefing

Before arrival at ports known for detailed inspections:

  • Review cyber procedures with bridge and engine room officers
  • Confirm crew can articulate basic cyber awareness
  • Verify officers know location of cyber documentation
  • Review recent drill records and lessons learned

System Checks

Verify before inspection:

  • Navigation systems displaying correct data
  • No unauthorised devices connected to ship systems
  • Electronic charts and publications current
  • Backup systems tested and functional

When Deficiencies Are Found

If a cyber-related deficiency is identified:

  1. Understand the finding: Ask inspector to clarify exactly what is deficient
  2. Document immediately: Record deficiency details and inspector's requirements
  3. Notify company: DPA and Technical Manager must be informed
  4. Agree rectification timeline: Some deficiencies require immediate action, others allow time for correction
  5. Implement corrective actions: Address deficiency and underlying root cause
  6. Document completion: Evidence of corrective action for next inspection

The Detention Threshold

Cyber deficiencies alone rarely result in detention. However, detention may occur when:

  • Cyber deficiency indicates systemic SMS failure
  • Multiple related deficiencies found together
  • Critical safety systems compromised by cyber issues
  • Evidence of negligence or deliberate non-compliance

A vessel with no cyber procedures, no training records, and navigation systems showing errors presents a detention risk.

Best Practice: Proactive Approach

Rather than minimum compliance, consider cyber PSC readiness as a quality indicator:

  1. Annual self-audit: Review cyber documentation against PSC expectations
  2. Pre-arrival checklist: Standard cyber verification before entering ports
  3. Continuous improvement: Document enhancements made following incidents or near-misses
  4. Industry engagement: Monitor PSC campaign announcements and guidance updates

Next in the Series

The most effective cyber defence is crew awareness. The next article addresses training programmes that build genuine competence, not just compliance certificates.


This is the fifth article in the Maritime Cyber Playbook series, a collaboration between IWH and Margetis Maritime. For maritime cybersecurity advisory services, contact us.