Port State Control officers are increasingly asking questions about cyber security. While dedicated cyber inspections remain uncommon, cyber elements are appearing in standard PSC examinations. Understanding what inspectors look for—and what triggers expanded scrutiny—can prevent delays and detentions.
This article is part of the Maritime Cyber Playbook series, developed in collaboration with Margetis Maritime.
The Evolving PSC Landscape
Since January 1, 2021, cyber risk management has been a mandatory element of Safety Management Systems under the ISM Code. This means PSC officers have authority to verify cyber security arrangements during routine inspections.
How Cyber Elements Enter PSC Inspections
Cyber questions typically arise through three pathways:
- ISM Code verification: Checking that cyber risks are addressed in the SMS
- Equipment inspection: Verifying that navigation and safety systems are operational
- Document review: Examining training records, drill logs, and procedures
A deficiency in any of these areas can trigger more detailed cyber-focused questioning.
What PSC Officers Look For
1. SMS Cyber Procedures
The starting point for any PSC cyber examination is the Safety Management System. Officers verify:
- Cyber risk policy: Statement of company commitment to cyber security
- Risk assessment: Evidence that cyber risks have been identified and assessed
- Operational procedures: Specific procedures for managing cyber risks
- Incident response procedures: Documented approach to cyber incidents
- Roles and responsibilities: Clear assignment of cyber security duties
Red flags:
- Generic cyber policy copied from templates without vessel-specific adaptation
- No evidence of risk assessment or last assessment years old
- Procedures that don't reflect actual vessel systems
- No designated person responsible for cyber security
2. Crew Awareness
PSC officers may interview crew to assess cyber security awareness:
- Master: Understanding of cyber risks, response procedures, company reporting requirements
- Officers: Awareness of cyber threats, recognition of suspicious activity
- Ratings: Basic awareness, particularly regarding USB devices and personal equipment
Common questions:
- "What would you do if you noticed unusual behaviour on a bridge computer?"
- "How do you update electronic charts? What checks do you perform?"
- "What is your company's policy on USB devices?"
- "Have you received cyber security training? When?"
3. Training Records
Documented evidence of cyber security training is increasingly expected:
- Initial cyber awareness training for all crew
- Role-specific training for officers and technical staff
- Refresher training at appropriate intervals
- Record of training completion with dates and content covered
4. Drill Records
Like fire and abandon ship drills, cyber incident drills should be documented:
- Drill date and scenario
- Participants
- Actions taken
- Lessons learned
- Corrective actions if deficiencies identified
Officers expect to see at least one cyber drill per year, though more frequent exercises demonstrate mature security practices.
5. System Integrity
During equipment inspection, officers may verify:
- Navigation systems operational: ECDIS, radar, AIS functioning correctly
- No visible tampering: Authorised connections only, no unknown devices
- Update status: Charts current, software reasonably recent
- Backup capability: Paper charts available, backup navigation functional
PSC Cyber Deficiencies
Cyber-related deficiencies fall under ISM Code (Code 01) and can be recorded as:
| Deficiency Code | Description | Typical Examples |
|---|---|---|
| 01117 | Safety Management - Cyber Risk | No cyber procedures in SMS |
| 01114 | Familiarisation/Training | No cyber training records |
| 01115 | Emergency Preparedness | No cyber incident procedures |
| 01116 | Internal Audits | Cyber not covered in audits |
Serious deficiencies can result in detention if they indicate a significant failure of the Safety Management System.
Regional Variations
Paris MoU
European Port State Control under the Paris MoU has been actively developing cyber inspection guidance. Concentrated Inspection Campaigns (CICs) periodically focus on specific areas—cyber security may become a CIC topic.
Tokyo MoU
Asian-Pacific PSC has incorporated cyber elements into ISM verification. Singapore and Australian ports have been particularly active in cyber awareness.
US Coast Guard
USCG has explicit cyber security requirements for vessels calling at US ports. The Maritime Transportation Security Act (MTSA) facility cyber requirements are increasingly being applied to vessel inspections.
Preparing for PSC Cyber Examination
Documentation Readiness
Have the following immediately available:
- SMS cyber section: Clearly marked, easily located
- Cyber risk assessment: Dated, relevant to vessel systems
- Training records: Crew list with training dates and certificates
- Drill records: Last 12 months of cyber exercises
- System inventory: List of computer-based systems aboard
- Network diagram: Simplified diagram showing system connections
Crew Briefing
Before arrival at ports known for detailed inspections:
- Review cyber procedures with bridge and engine room officers
- Confirm crew can articulate basic cyber awareness
- Verify officers know location of cyber documentation
- Review recent drill records and lessons learned
System Checks
Verify before inspection:
- Navigation systems displaying correct data
- No unauthorised devices connected to ship systems
- Electronic charts and publications current
- Backup systems tested and functional
When Deficiencies Are Found
If a cyber-related deficiency is identified:
- Understand the finding: Ask inspector to clarify exactly what is deficient
- Document immediately: Record deficiency details and inspector's requirements
- Notify company: DPA and Technical Manager must be informed
- Agree rectification timeline: Some deficiencies require immediate action, others allow time for correction
- Implement corrective actions: Address deficiency and underlying root cause
- Document completion: Evidence of corrective action for next inspection
The Detention Threshold
Cyber deficiencies alone rarely result in detention. However, detention may occur when:
- Cyber deficiency indicates systemic SMS failure
- Multiple related deficiencies found together
- Critical safety systems compromised by cyber issues
- Evidence of negligence or deliberate non-compliance
A vessel with no cyber procedures, no training records, and navigation systems showing errors presents a detention risk.
Best Practice: Proactive Approach
Rather than minimum compliance, consider cyber PSC readiness as a quality indicator:
- Annual self-audit: Review cyber documentation against PSC expectations
- Pre-arrival checklist: Standard cyber verification before entering ports
- Continuous improvement: Document enhancements made following incidents or near-misses
- Industry engagement: Monitor PSC campaign announcements and guidance updates
Next in the Series
The most effective cyber defence is crew awareness. The next article addresses training programmes that build genuine competence, not just compliance certificates.
This is the fifth article in the Maritime Cyber Playbook series, a collaboration between IWH and Margetis Maritime. For maritime cybersecurity advisory services, contact us.