Play UR E26 — E26 Zone Defense | ShipJobs
IACS UR E26 · Cyber Resilience · ShipJobs

Play UR E26
— E26 Zone Defense

Zones and Conduits, SL-T, CBS categories, defense in depth. I turned UR E26's security architecture directly into game mechanics — a tower defense you play right in the browser, no install required.

5 min readFree · No installMobile · Desktop

As UR E26/E27 became mandatory, owners, shipyards, vendors, and class surveyors alike now have to reckon with Zones & Conduits. Yet these ideas — how to divide systems into Zones, and which security controls to place on which Conduit to protect essential services — rarely click from documents and diagrams alone. So I took a hands-on approach.

Why a game

At its heart, UR E26 is a single mindset: stop threats layer by layer at the Zones and Conduits before they ever reach essential services — that is, defense in depth. Divide your Zones poorly or misplace a control on a Conduit, and the Core gets breached. These are exactly the same kinds of decisions you make when designing a real ZCD (Zone and Conduit Diagram). In five minutes you feel why a DMZ matters, and why higher-category systems belong deeper inside.

SATCOM / ShoreUntrusted Business · ITCat I DMZIT–OT boundary NavigationCat II ControlCat III CoreEssential svcs

The game

You are the cyber security architect of a newbuild. Threats — malware, DoS floods, unauthorized access (APT) — pour in from the SATCOM / shore link (Untrusted) at the top. Place Firewalls · IDS/IPS · Network Segmentation along the Conduit to stop them before they reach the Essential Services Core (propulsion & steering) at the bottom. Defeating threats earns budget, which you reinvest to upgrade your controls. Defend all 10 waves to earn Cyber Resilience Verified.

Mechanics ↔ UR E26 concepts

Conduit pipeline
The communication path between Zones. A color change marks a Zone boundary.
Zone (Cat I/II/III)
System groups by criticality. Closer to the Core = higher category.
Security control (Tower)
Firewall · IDS/IPS · Segmentation — controls used to meet SL-T.
DMZ
The IT–OT boundary. Miss it here and threats reach OT.
Core Integrity
Falls when essential services are breached → 0 means a cyber incident.
Placement strategy
Layered protection across multiple Zones & Conduits = defense in depth.

How to play

  1. Tap/click a ⊕ slot beside the pipeline to place a security control.
  2. Firewalls deal damage, Segmentation makes slow-down kill zones, and IDS/IPS handles swarms.
  3. Defeat threats → earn budget → reinvest in upgrading controls.
  4. Reinforce before the later waves where APTs appear. Starting the next wave early grants bonus budget.
▶ Play fullscreen Switches automatically to a portrait layout on mobile and landscape on desktop.
Disclaimer

This game is intended for fun only.

Tip — Use it as an ice-breaker in internal UR E26 onboarding or a project kick-off. You can share the intuition behind Zones & Conduits in five minutes.

It's open to owners, shipyards, class, and vendors — and anyone learning UR E26 for the first time. Give it a play, and feel free to leave any ideas or feedback.

SJ
ShipJobs · Maritime Cyber Security
Maritime Cyber Security · IACS UR E26/E27

Writing about maritime cyber security — IACS UR E26/E27 compliance, ZCD (Zone and Conduit Diagram), and OT/IT security architecture.

#UR_E26#Cyber_Resilience#Zone_and_Conduit #Maritime_Cyber#ZCD#ShipJobs

📌 Field Note — Julius Shin

The game's value as a practical training tool is that it lets players — even those unfamiliar with the regulation — internalize the sense of "defending zones and conduits in layers" within five minutes. The reality the game mirrors directly: poor zone boundaries or misplaced control points in an actual ZCD design let threats through to critical systems.

Categorizing systems by Cat I/II/III, treating the DMZ as a distinct defensive layer at the IT-OT boundary, and making the Essential Services Core (propulsion, steering) the primary defense priority — this structure conveys defense-in-depth far faster than any abstract explanation. Getting owners, shipyards, class societies, and vendors to draw the same picture in the same room is, in practice, one of the hardest things to achieve.

What the game provides is intuition, not a design blueprint. Actual zone/conduit design requires fresh judgment for each vessel, based on its unique asset inventory and trust boundaries.

A common misconception in practice:
Mistaking a successful game playthrough for actual understanding of ZCD design or E26 requirements. The game is an icebreaker that conveys intuition — it doesn't substitute for the asset and trust-boundary judgment that differs vessel by vessel.

Key practical takeaways:

  • Define in advance what controls (firewall/IDS-IPS/segmentation) go at each zone and conduit boundary, based on system criticality (Cat I/II/III).
  • Treat the DMZ at the IT-OT boundary as an explicit and distinct defensive layer.
  • Use visualization tools like this during onboarding and kickoff to align stakeholder intuition — then conduct actual design validation separately.

⚓ Join the ShipPaulJobs Community

Join →
Share

Comments

  1. That’s a great idea! A gamified approach to technical training will significantly boost learning effectiveness and engagement. I look forward to seeing this creative content.

    ReplyDelete

Post a Comment

Top Ranked · All Posts

Popular Posts