🛡️ Ship Cyber Resilience 🚢 Major Pillar 02 Complete Guide Practitioner Insight

Ship Cyber Resilience:
The Complete Guide

선박 사이버 복원력 완벽 가이드 — From IACS UR E26 Framework to OT Security, SCARP, and Operational Continuity
How to Build, Maintain, and Verify Cyber Resilience Throughout a Ship's Lifecycle

Captain Paul — Maritime Cybersecurity Expert
Captain Paul ✓ Verified
Maritime Cybersecurity Practitioner · IACS UR E26/E27 Specialist · August 2026
📌 Quick Answer — What Is Ship Cyber Resilience?

Ship Cyber Resilience is the ability of a vessel to anticipate, withstand, adapt to, and recover from adverse conditions, stresses, attacks, or compromises to its cyber systems — while maintaining essential safety and operational functions.

Unlike traditional cybersecurity (which focuses on prevention), cyber resilience accepts that incidents will occur and asks: how does the ship continue to operate safely when they do? IACS UR E26 formalises this requirement for all ships contracted from July 2024.

① Ship Cyber Resilience — Definition and Framework

The concept of ship cyber resilience draws from NIST's definition of resilience — the ability to prepare for, adapt to, withstand, and recover rapidly from disruptions — and applies it specifically to the maritime operational technology (OT) and information technology (IT) environment of a ship.


The Four Pillars of Ship Cyber Resilience
ANTICIPATE
Understand the threat landscape, identify vulnerabilities across all CBS, and proactively reduce attack surface before an incident occurs.
WITHSTAND
Implement security controls, zone segmentation, and redundancy so that an attack on one system does not cascade to compromise safety-critical functions.
ADAPT
Enable the crew to switch to manual or backup modes, isolate affected systems, and maintain minimum safe operating capability during an ongoing incident.
RECOVER
Restore affected systems to operational status within a defined timeframe, document the incident, and update security controls to prevent recurrence.

IACS UR E26 maps these four dimensions onto its own structure of Identify → Protect → Detect → Respond → Recover, creating a regulatory framework that operationalises cyber resilience for the newbuilding lifecycle. Importantly, E26 extends this framework beyond design and construction into ongoing operational maintenance through annual surveys.

Captain Paul's Practitioner Note

The most important mindset shift for maritime professionals is this: cyber resilience is an operational capability, not a compliance document. A ship's crew must be as prepared to handle a cyber incident as they are to handle a fire or flooding. If your SCARP is buried in a binder nobody has read, your cyber resilience is theoretical, not actual.

② Cyber Resilience vs. Cybersecurity — The Critical Difference

Traditional Cybersecurity Mindset
  • Focus: prevent all attacks
  • Assumption: threats can be blocked at the perimeter
  • Metric: number of blocked attacks
  • Failure mode: one breach = system down
  • Crew role: passive (IT department handles it)
  • Post-incident: patch and forget
Cyber Resilience Mindset (IACS UR E26)
  • Focus: maintain operations despite attacks
  • Assumption: some attacks will succeed
  • Metric: recovery time, operational continuity
  • Failure mode: managed degradation with fallback
  • Crew role: active first responders
  • Post-incident: learn, update, improve

This distinction has profound practical implications for ship operations. A navigation system that goes offline due to a cyber attack does not give the crew the option to wait for shore-side support. The crew must have pre-defined procedures, fallback modes, and the training to execute them — at sea, potentially days from port. IACS UR E26 is built around this operational reality.

③ IACS UR E26 Framework for Ship Cyber Resilience

IACS UR E26 creates the mandatory framework for achieving ship cyber resilience in newbuildings. Its requirements are structured around three core deliverables — CBS Inventory, ZCD, and CRSI — which together define the technical architecture of resilience, and the SCARP, which operationalises it for the crew.

E26 Cyber Resilience Architecture
IDENTIFY
CBS Inventory — Complete Asset Enumeration
Every CBS on board identified, categorised (A/B/C), and documented with network interfaces and data flows. Foundation of all subsequent resilience measures.
PROTECT
Zone & Conduit Diagram (ZCD) — Security Architecture
All CBS grouped into security zones with defined conduits between zones. Controls prevent lateral movement and contain compromise to isolated zones.
DETECT
OT Network Monitoring — Continuous Anomaly Detection
Passive monitoring of OT network traffic to detect anomalies, unauthorised access, and abnormal communications. Must be deployed without disrupting operations.
RESPOND
SCARP — Ship Cyber Resilience Plan
Documented incident response procedures, roles, escalation, containment, and crew training. The operational heart of cyber resilience — the document that crew must know and practice.
RECOVER
System Recovery — Backup, Restore, Continuity
Documented backup procedures, configuration snapshots, and restoration timelines for all CBS. Recovery must be achievable by the crew without relying on external vendors or internet access.

IACS UR E26/E27 Compliance Matrix — Full Framework Overview

UR E26 After the Mandate — One Mandatory Rule, Five Perspectives

④ OT Network Security on Ships

Operational Technology (OT) systems — propulsion controls, navigation systems, ballast water treatment, cargo management — are the heart of ship cyber resilience. Unlike IT systems, OT systems have long lifecycles (10-30 years), real-time constraints, and safety implications that make conventional IT security approaches impossible to apply directly.

OT vs. IT Security — Key Differences in the Maritime Context
OT SYSTEM CHARACTERISTICS
  • Cannot be patched without vendor approval
  • Real-time operation — downtime not acceptable
  • Proprietary protocols (MODBUS, DNP3, NMEA)
  • Equipment lifecycle: 10-30 years
  • Safety-critical — failure can endanger crew
E26 OT SECURITY APPROACH
  • Segmentation (not perimeter only)
  • Passive monitoring (no active scanning)
  • Network-level control (firewalls, data diodes)
  • Fallback modes documented and tested
  • Vendor access via jump server with logging

Ship OT Network Design Under IACS UR E26/E27 — Architecture and Segmentation

If IT Is Out of Scope, Your E26 Compliance Is Incomplete

⑤ OT Monitoring — The Detection Layer of Ship Cyber Resilience

OT network monitoring is the Detect function of IACS UR E26. It involves deploying passive sensors on OT network segments to capture and analyse traffic for anomalies — without generating any traffic that could disrupt connected equipment. This is fundamentally different from IT network monitoring, which typically involves active scanning and endpoint agents.

What OT Monitoring Can — And Cannot — Do
✓ OT MONITORING CAN
  • Detect anomalous network communication patterns
  • Alert on unexpected protocol usage
  • Identify new devices connecting to OT segments
  • Log all network traffic for post-incident analysis
  • Generate baseline of normal OT behaviour
  • Support annual survey documentation
✗ OT MONITORING CANNOT
  • Replace the ZCD or CBS Inventory
  • Prevent attacks — it only detects
  • Analyse payload content of encrypted traffic
  • Automatically respond or contain incidents
  • Substitute for crew training and SCARP
  • Guarantee real-time alert delivery at sea

Automating IACS E26/E27 Annual Survey: What OT Monitoring Can and Cannot Do

⑥ SCARP — Ship Cyber Resilience Plan

The Ship Cyber Awareness and Resilience Plan (SCARP) is the operational document that translates IACS UR E26's technical requirements into crew procedures. It is the ship's cyber incident response playbook — and the most directly crew-facing deliverable of the entire E26 compliance effort.

SCARP Required Content — Key Sections
§1
Cyber Incident Classification — Categorisation of incident severity, from low-impact anomalies to safety-critical compromise, with escalation thresholds
§2
Roles and Responsibilities — Who does what during a cyber incident: Master, Chief Engineer, ETO, and the Cyber Resilience Officer (if designated)
§3
System Isolation Procedures — Step-by-step procedures for isolating affected CBS without affecting adjacent safety-critical systems
§4
Fallback and Manual Modes — Documented fallback procedures for all Category A (safety-critical) systems, enabling manual or reduced-functionality operation
§5
Reporting and Notification — Who to notify, when, and through which channels: DPA, flag state, IACS class society, and ISM company
§6
Recovery and Restoration — System restoration priorities, backup procedures, configuration recovery, and return-to-normal-operations criteria
§7
Training and Drills — Crew training programme, drill frequency, tabletop exercise scenarios, and competency assessment requirements

⑦ Crew Cyber Training — The Human Layer of Resilience

Technology alone cannot achieve ship cyber resilience. The crew is both the first line of defence and the first line of response. IACS UR E26 requires that crews are trained and drilled on cyber resilience procedures — a requirement that is still not consistently implemented across the industry.

AWARENESS TRAINING
Recognising phishing, social engineering, suspicious USB devices, and anomalous system behaviour. Applicable to all crew members regardless of rank.
TECHNICAL TRAINING
ETO and relevant officers trained on CBS Inventory, ZCD, OT monitoring dashboards, system isolation procedures, and backup/restore operations.
TABLETOP DRILLS
Scenario-based exercises simulating cyber incidents (ransomware, GPS spoofing, ECDIS failure) to test SCARP procedures and crew decision-making under pressure.

⚠️ Training Gap Reality

In my experience, crew cyber training is the most consistently underfunded and delayed element of E26 compliance. SCARP is written at the shipyard, then delivered to a crew who has never seen it. This is not cyber resilience — it is a document exercise. Training must begin at the pre-delivery stage and continue throughout operations.

⑧ Cyber Incident Response at Sea

A cyber incident at sea differs fundamentally from one ashore. The crew cannot call IT support, reboot the data centre, or wait for a specialist to arrive. Response must be immediate, largely autonomous, and guided by pre-defined procedures that the crew has internalised through training.

Cyber Incident Response Sequence — At Sea
DETECT
OT monitor alert, crew observation of anomalous system behaviour, or external notification triggers incident declaration
ASSESS
Master, Chief Engineer, and ETO assess which CBS are affected and classify incident severity per SCARP definitions
CONTAIN
Isolate affected systems per ZCD zone boundaries. Activate fallback/manual modes for safety-critical Category A systems. Maintain safe navigation.
NOTIFY
Report to DPA, flag state, and class society per SCARP reporting requirements. Initiate shore support if needed (CSIRT, vendor).
RECOVER
Restore systems from backup, verify integrity, return to normal operations, and document the incident for post-incident review and class reporting.

⑨ Annual Survey Readiness

IACS UR E26 compliance does not end at delivery. Classification societies conduct annual surveys to verify that cyber resilience measures remain effective as the ship operates. This transforms cyber resilience from a one-time compliance event into an ongoing operational requirement.

Annual Survey — What Class Will Check
ZCD is current and reflects actual as-installed network architecture
CBS Inventory is updated to include any new or changed systems
OT monitoring is operational and logs are available for review
SCARP is current, relevant crew have been trained, and drills are evidenced
Any cyber incidents since last survey are documented and lessons incorporated
Software patch status for all CBS is documented and justified

What Classification Societies Actually Verify at Audit — And Why Projects Fail

⑩ Regulatory Landscape — Where Ship Cyber Resilience Fits

IMO MSC-FAL.1/Circ.3
Non-mandatory guidance for maritime cyber risk management. Applies to existing ships via ISM SMS. Broader in scope but less prescriptive than IACS UR E26.
IACS UR E26 (2024)
Mandatory for newbuildings contracted from 1 July 2024. Most prescriptive and technically detailed maritime cyber regulation currently in force.
EU NIS2 / CRA
EU regulations on network security (NIS2) and cyber resilience for products (CRA). Increasingly relevant for ships operating in EU waters and EU-registered companies.
Flag State Requirements
Individual flag states are developing their own mandatory cyber requirements. Compliance landscape becoming increasingly complex for ships with multi-flag exposure.

IMO Cybersecurity Regulations — Complete Overview for Maritime Professionals

IMO Chose Code Over Mandates — What This Means for Ship Cyber Resilience

One Ship, Three Regulatory Layers — Unifying NIS2, CRA, and IACS UR E26

⑫ FAQ — Ship Cyber Resilience

Q. What is the difference between cyber security and cyber resilience for ships?

Cybersecurity focuses on preventing attacks; cyber resilience focuses on maintaining operations despite attacks. For ships at sea, where expert support is unavailable and safety cannot be paused, resilience is more operationally important than prevention alone. IACS UR E26 mandates both prevention (via zone controls and access management) and resilience (via SCARP, fallback modes, and recovery procedures).

Q. 선박 사이버 복원력이 ISM 코드와 어떻게 연결되는가?

IMO MSC-FAL.1/Circ.3는 사이버 리스크 관리를 ISM(국제안전관리) 코드의 SMS(안전관리시스템)에 통합할 것을 권고합니다. 즉, 선박의 사이버 복원력 계획(SCARP)은 기존 비상절차, 비상훈련, 사고보고 체계와 통합되어야 하며, 이는 선원들이 별도의 사이버 절차를 기억하는 것이 아니라 기존 안전문화의 일환으로 사이버 대응 역량을 갖추어야 함을 의미합니다.

Q. How often should cyber resilience drills be conducted on ships?

IACS UR E26 does not specify a minimum drill frequency, but industry best practice — aligned with fire and abandon-ship drill requirements — suggests at least annual tabletop exercises and crew awareness refreshers at crew changeover. Critical roles (ETO, Chief Engineer, Master) should participate in scenario-based drills at least annually.

Q. Does IACS UR E26 require a dedicated Cyber Security Officer on board?

IACS UR E26 does not mandate a dedicated Cyber Security Officer (CSO) role on board. However, it requires that roles and responsibilities for cyber incident response are clearly assigned in the SCARP. In practice, the Electro-Technical Officer (ETO) most commonly takes on the primary technical cyber response role, supported by the Chief Engineer and Master.

Captain Paul
Captain Paul
Maritime Cybersecurity Practitioner · IACS UR E26/E27 Specialist

This guide is based on practitioner experience implementing ship cyber resilience programmes across shipyards, owners, and classification societies. Content reflects operational realities as of August 2026. Always consult the official IACS UR E26 document and your classification society for authoritative guidance.

⚓ Join the ShipPaulJobs Community

Join →
Share

Comments

Top Ranked · All Posts

Popular Posts