If IT Is Out of Scope, Your E26 Compliance Is Incomplete

📋 Compliance IACS UR E26 & E27 IT/OT Convergence

Why Someone Said "IT Is Not the Target System" — And Why That Interpretation Gets It Wrong

A Regulatory Interpretation Review for System Integrators, Ship Owners, and Cyber Compliance Officers under IACS UR E26/E27

Richard
Richard
Principal Maritime Engineering Leader · Digital Ship Innovation & Cyber Security
Technical Advisor: shippauljobs.com — Crew Behind ShipJobs

A growing concern is emerging within the maritime cybersecurity community: some System Integrators (SIs) are advising ship owners and operators that IT systems onboard vessels are not subject to IACS UR E26 requirements. The argument is simple — read the regulation literally, identify the explicit scope, and conclude that only OT systems require cybersecurity management.

This interpretation is not only narrow. When examined against the full body of IACS Unified Requirements — E10, E22, E26, and E27 — combined with post-delivery operational realities and annual survey obligations, it becomes clear that this reading actively distorts the purpose and direction the regulations were designed to achieve.

This article presents a comprehensive interpretation based on NIST cybersecurity principles and the holistic intent of IACS UR E26 and E27, with the goal of achieving genuine cyber resilience — not mere checkbox compliance.

Ⅰ. Where the Confusion Starts: A Literal Reading of E26

IACS UR E26 — Cyber Resilience of Ships — defines its primary subject as Computer Based Systems (CBS). At first glance, the regulation's language centers on systems used for "control, monitoring, alarming, and reporting" functions aboard ships. A surface-level reading leads some SIs to conclude:

"E26 applies to OT control systems. Administrative IT systems — email servers, crew welfare networks, office computers — are outside its scope."

This conclusion feels logical when read in isolation. The problem is that IACS UR E26 was never designed to be read in isolation.

Ⅱ. What IACS UR E26 Actually Defines

Section 2 of IACS UR E26 Rev.1 (Nov 2023) defines Computer Based System (CBS) as:

"A programmable electronic device, or interoperable set of programmable electronic devices, organized to achieve one or more specified purposes such as collection, processing, maintenance, use, sharing, dissemination, or disposition of information. CBSs onboard include IT and OT systems."

The Explicit Statement

This is not an inference or a legal interpretation technique — it is the verbatim text of the regulation. E26 Section 2 explicitly states: "CBSs onboard include IT and OT systems." The definition does not partition by system function or domain. IT systems are CBSs. CBSs are the subject of E26.

By the plain text definition in E26 Section 2, IT systems are explicitly named as CBS. The narrow OT-only interpretation contradicts the regulation's own foundational terminology.

E26 Section 1.3.2 — Systems in Scope: The Two-Layer Structure
(a) Primary Scope — OT Systems
Propulsion, steering, navigation, power management, fire detection, bilge/ballast, and all OT systems required for safety of the vessel. This is the layer the SI argument focuses on.
(b) Explicit Secondary Scope — IT Systems via IP Connection
E26 Section 1.3.2(b) reads: "Any Internet Protocol (IP)-based communication interface from CBSs in scope of this UR to other systems." The regulation then explicitly lists: passenger-facing networks, administrative networks, crew welfare systems, and any other system connected to OT — permanently or temporarily. These IT systems are not outside scope. They are named in the text.
⚠️ Note: E26 Section 1.3.2 closes with: "The cyber incidents considered in this UR are events resulting from any offensive manoeuvre that targets OT systems onboard ships." This describes the ultimate impact target — not the attack entry point. The attack path runs through IT. The regulation addresses both.

Ⅲ. The Full Picture: E10, E22, E26, and E27 Read Together

Regulatory frameworks are rarely standalone documents. IACS Unified Requirements are a connected body of rules designed to work together. Reading E26 without E10, E22, and E27 produces an incomplete — and potentially dangerous — understanding.

IACS UR E22 — On Board Use and Application of Computer-based Systems

E22 Rev.3 (June 2023) addresses the design, construction, commissioning, and maintenance of computer-based systems onboard. Its scope applies to systems that provide "control, alarm, monitoring, safety, or internal vessel communication functions subject to classification requirements" — meaning it governs classification-required CBS, primarily OT-type systems. E22 is explicitly referenced in E26 Section 1.3.3 as the basis for system categorization.

What E22 establishes is a structured CBS lifecycle management framework — from design through operations. E26 builds on this foundation and extends it with cyber resilience requirements. Critically, E22 Rev.3 (2023) now lists E26 and E27 as normative references (Section 1.3.1), meaning the two URs are formally interdependent. An SI delivering E26 compliance in isolation from the E22 lifecycle framework is delivering an incomplete solution.

IACS UR E10 — Automatic and Remote Control Installations

E10 governs automatic and remote control systems. In modern vessels, these systems do not operate in a closed vacuum. They interface with:

  • Remote monitoring platforms (cloud-based, IT-dependent)
  • Crew and operator workstations (IT endpoints)
  • Shore-based operations centers (IT/OT bridge)

Excluding IT from the cybersecurity management scope while maintaining E10-covered OT systems creates unprotected interfaces — exactly the attack surface that threat actors exploit.

IACS UR E27 — Cyber Resilience of Onboard Systems and Equipment

E27 extends E26's requirements to the equipment manufacturer level, requiring that equipment suppliers implement cybersecurity throughout the product lifecycle. Critically, E27 does not distinguish between IT and OT equipment. It applies to any Computer Based System or equipment component that forms part of the ship's operational infrastructure.

If equipment manufacturers must apply cybersecurity principles to all CBS — including those with IT components — it is logically inconsistent to argue that ship operators can exclude IT from their own cybersecurity management obligations.

Ⅳ. The NIST Lens: Cyber Resilience Does Not Draw an IT/OT Line

IACS UR E26 and E27 are explicitly aligned with the NIST Cybersecurity Framework (CSF). The NIST CSF's five core functions — Identify, Protect, Detect, Respond, Recover — apply uniformly across all digital assets, systems, and networks. NIST does not partition its framework by IT vs. OT.

Furthermore, NIST SP 800-82 (Guide to Industrial Control Systems Security) and NIST SP 800-53 (Security and Privacy Controls) both address the convergence of IT and OT environments. SP 800-82 recognizes that ICS/OT security cannot be designed or assessed in isolation from the enterprise IT environment — because IT systems are the primary network through which threats reach OT. NIST SP 800-53 applies its security control catalog uniformly across both IT and OT assets.

If IACS UR E26 references NIST principles as its cybersecurity foundation, and NIST treats IT/OT convergence as a security baseline — not an option — then any interpretation of E26 that excludes IT systems contradicts its own foundational reference framework.

The five NIST functions, applied to the maritime context, require:

NIST Function IT Relevance Onboard
IdentifyAsset inventory must include IT systems, not just OT
ProtectAccess control, patching, and hardening apply to IT endpoints
DetectNetwork monitoring must cover IT segments — primary threat entry points
RespondIncident response plans must address IT-originated incidents
RecoverBusiness continuity requires IT system restoration alongside OT

Excluding IT from E26's scope invalidates all five functions.

Ⅴ. Post-Delivery Operations and Annual Survey Reality

The IT-exclusion argument also fails when examined against the operational lifecycle of a ship beyond the initial delivery and class certification.

5.1 Annual Surveys

IACS member classification societies are increasingly incorporating cyber resilience assessments into annual and periodic surveys. These assessments evaluate the overall cyber posture of the vessel — not a subset of OT systems. Surveyors are trained to examine:

  • Network segmentation (IT/OT boundary controls)
  • Patch management status across all CBS
  • Access control policies covering IT and OT systems
  • Incident response documentation

A ship delivered with an IT-exclusion posture will face growing compliance gaps with each subsequent survey cycle.

5.2 The Attack Vector Reality

Maritime cyber incidents consistently demonstrate that IT systems are the primary entry point for attackers, not OT systems:

  • Phishing emails target crew and officer IT endpoints
  • VSAT and satellite communication terminals (IT infrastructure) are compromised for initial access
  • USB devices and crew personal devices introduce malware through IT interfaces
  • Ransomware enters through administrative networks before pivoting to operational systems

Once an attacker has a foothold in the IT network, lateral movement to OT systems is the standard progression. BIMCO, IMO, and classification societies have all documented this attack pattern.

⚠️ Declaring IT out of scope does not make IT systems safe. It makes them unmonitored and unprotected — exactly the condition attackers rely on.

5.3 ISM Code Integration

The International Safety Management (ISM) Code requires ship operators to maintain procedures for all safety-critical operations, including communications and data management. Cyber incidents affecting IT systems — cargo management data, crew documentation, communications — directly impact ISM compliance. The ISM Code's requirement for a Safety Management System (SMS) must evolve to incorporate cyber considerations across all onboard digital systems.

Ⅵ. Why the Narrow Interpretation Is Commercially Problematic

There is an important question worth asking: Who benefits from the IT-exclusion interpretation?

Narrowing E26's scope to OT-only systems reduces the cost and complexity of compliance delivery for SIs. Fewer systems to assess, fewer controls to implement, fewer documentation requirements. In competitive bidding environments, a narrowly-scoped compliance package appears more cost-effective.

But this creates a fundamental market distortion:

01
Ship owners receive a false assurance of compliance that will not hold under annual survey scrutiny or Port State Control (PSC) inspections
02
The cybersecurity posture of the fleet is structurally weakened by design
03
When an IT-originated breach occurs — and the statistical probability is high — the ship owner bears the liability while the SI's narrow-scope delivery appears technically complete on paper

This is not compliance. It is the appearance of compliance, engineered to reduce delivery costs at the expense of genuine cyber resilience.

Ⅶ. The Correct Approach: Cyber Resilience as the Objective

IACS UR E26 Section 1.2 states its aim as follows:

"The aim of this UR is to provide a minimum set of requirements for cyber resilience of ships, with the purpose of providing technical means to stakeholders which would lead to cyber resilient ships."

E26 Section 2 further defines cyber resilience as: "The capability to reduce the occurrence and mitigating the effects of cyber incidents arising from the disruption or impairment of operational technology (OT) used for the safe operation of a ship."

Note that the definition anchors on OT as the ultimate protected asset — and this is exactly where the SI argument tries to draw a line. But the definition describes the consequence of a cyber incident, not the attack path. Every documented maritime cyber incident shows that the path to OT runs through IT. A ship with resilient OT and unprotected IT is not a cyber-resilient ship — it is a ship with an unguarded front door.

The correct approach for SIs, ship owners, and compliance officers involves:

1
Comprehensive CBS Inventory (NIST: Identify)
Document all Computer Based Systems onboard — OT and IT alike. Navigation systems, power management, administrative servers, crew networks, VSAT terminals, and all interfaces between them.
2
IT/OT Network Segmentation and Boundary Protection (NIST: Protect)
Define and implement controls at the boundary between IT and OT networks. This boundary, not the IT systems themselves, is the critical control point — and it can only be managed if IT is within scope.
3
Unified Security Monitoring (NIST: Detect)
Monitoring systems must cover IT network segments. Anomalous behavior on IT networks is frequently the earliest detectable indicator of a developing attack.
4
Integrated Incident Response (NIST: Respond)
Incident response plans must address IT-originated incidents. Crew training must cover IT threat vectors — phishing, removable media, unauthorized access.
5
Continuity and Recovery Planning (NIST: Recover)
Recovery procedures must restore both IT and OT systems. An operator who can restore OT but not IT cannot resume full commercial operations or satisfy ISM reporting requirements.
Closing Thoughts

The argument that "IT is not the target system under E26" is not a legitimate regulatory interpretation. It is a selective reading that contradicts the plain language of E26's CBS definition, ignores the connected framework of E10, E22, E26, and E27, conflicts with NIST's foundational principles that E26 references, and disregards the operational reality of post-delivery annual surveys and real-world cyber attack patterns.

IACS established E26 and E27 with a clear objective: cyber resilience for ships. That resilience cannot be achieved by protecting one half of a ship's digital ecosystem while leaving the other half unmanaged.

For ship owners evaluating cybersecurity proposals, the question to ask any SI is direct:

"Does your E26 compliance scope include all Computer Based Systems — IT and OT — as defined in E26 Section 2?"

If the answer is no, the compliance package on offer does not meet the standard the regulation was written to achieve.

Regulatory Basis & References

IACS UR E10 — Automatic and Remote Control Installations, governing interfaces between shore-based, IT, and OT control systems.
IACS UR E22 — Onboard Computers and Networks, the foundational requirement for integrity and security of all onboard computer systems.
IACS UR E26 — Cyber Resilience of Ships, defining Computer Based System (CBS) scope and the objective of cyber resilient delivery.
IACS UR E27 — Cyber Resilience of On-board Systems and Equipment, extending E26 requirements to equipment manufacturers.
NIST CSF & NIST SP 800-82 / SP 800-53 — Cybersecurity Framework and ICS/enterprise IT security convergence guidance referenced by E26/E27.

About the Author

Richard
Richard
Principal Maritime Engineering Leader · Digital Ship Innovation & Cyber Security

Richard is a principal maritime engineering leader driving digital ship innovation and cybersecurity from ship operations to automation. His expertise spans naval architecture, ICS/OT security, offshore system design, vessel automation, IACS UR E26/E27 compliance, and smart ship & digital twin technologies — bringing an integrated systems perspective across a vessel's IT and OT infrastructure.

Related Posts on ShipPaulJobs

IACS UR E26 IACS UR E27 IACS UR E22 IACS UR E10 Maritime Cybersecurity OT Security IT Security NIST CSF Cyber Resilience Ship Compliance Annual Survey ISM Code

⚓ Join the ShipPaulJobs Community

Join →
Share

Comments

  1. ACS UR E26 Section 2 explicitly states:

    “CBSs onboard include IT and OT systems.”

    The regulation does not distinguish the scope of application based on a system’s function or operational domain. Rather, it explicitly defines both IT and OT systems as components of Cyber Systems (CBSs).

    Therefore, IT systems are CBSs, and since CBSs are the subject of IACS UR E26, IT systems are inherently within the scope of E26. This is not a matter of interpretation or inference; it is a direct conclusion derived from the regulation’s explicit definition.

    ReplyDelete

Post a Comment

Top Ranked · All Posts

Popular Posts