Why Category Classification Comes First in Ship Cybersecurity
Not every OT system deserves the same level of protection — and IACS UR E26/E27 starts from that assumption.
As Smart Ship technology advances, the onboard system environment is changing rapidly. In the past, a vessel's control systems operated relatively independently — but today, navigation systems, engine control systems, cargo management systems, communication systems, and shore support systems are increasingly connected to one another over the network. This shift improves the efficiency of vessel operations, but it also creates new cyber risk. OT (Operational Technology) systems, in particular, require a different lens than typical IT systems: a cyberattack or system failure can translate immediately into a threat to safe navigation, human life, the environment, and property.
So the first question ship cybersecurity needs to answer is not simply, "which security solution should we install?" A different question matters more: "Among the many systems on board a ship, which ones matter most — and when an incident happens, what has to be protected and recovered first?"
The starting point for answering that question is Category Classification of OT systems. Within a ship's cybersecurity framework, system category classification is not just an asset inventory exercise — it is the core criterion that determines incident response priority and recovery time objectives. What matters most is connecting the CSDD's Zone/Conduit structure, system criticality, actual vulnerability assessment results, and IRP response procedures into a single, coherent framework.
Ⅰ. Not All OT Systems Can Be Protected the Same Way
A ship carries a very wide range of OT systems — propulsion control, steering systems, generator control, cargo management, ballast control, navigation equipment, and alarm and monitoring systems, to name the main ones.
But not all of these systems carry the same level of importance. If the onboard office system goes down temporarily, for example, it may hurt administrative efficiency, but it won't necessarily turn into a safety incident right away. If a cyberattack disables the propulsion control system or the steering system, on the other hand, the situation is entirely different — these are systems that can directly threaten the ship's safety from the very moment they fail.
The Category I, II, and III concept from IACS UR E22 offers one way to distinguish systems by their safety impact. What matters most is not the name of the system, but how quickly the risk actually materializes once it fails — in other words, the immediacy of the risk.
Ⅱ. "Immediate Risk" and "Risk Over Time" Demand Different Responses
One of the most important concepts in OT system category classification is the time-based nature of an incident's impact.
If a system's failure immediately endangers human life, ship safety, or the environment, that system needs to carry a very high level of criticality. Conversely, if a system can be run on an alternative for a period of time after failing, with the risk only building up gradually, a different response strategy can apply. This can be broken down as follows.
Systems where failure can immediately create a safety risk.
Systems that are not immediately dangerous, but can lead to a hazardous situation if the failure persists over an extended period.
Systems that have no direct impact on ship safety.
Propulsion control or steering systems, for example, are likely to be classified as Category III — there may be no time to spend on lengthy root-cause analysis after an incident with a system like this. Alarm and monitoring systems, or some voyage-support systems, may instead be classified as Category II — even though a failure won't turn into an incident immediately, it still cannot be left unaddressed for long.
This distinction is not just a classification on paper. A different category changes the incident response time, the recovery objective, the backup policy, the responsible organization, and the response procedure — all of it.
Ⅲ. Category Classification Is the Starting Point for Setting RTO and RPO
One of the most practical reasons for classifying the criticality of a ship's OT systems is to set RTO and RPO on a rational basis. RTO (Recovery Time Objective) is how quickly a system must be restored, and RPO (Recovery Point Objective) is how much data loss, up to which point in time, can be tolerated.
Would it make sense, for example, to apply the same "restore within four hours" standard to both the propulsion control system and the onboard office system? Of course not. A safety-critical system like propulsion control cannot tolerate hours of downtime. Some administrative systems, on the other hand, can run on manual work or a substitute system for a while.
Category classification, then, becomes the basis for answering questions like these:
- "How many minutes can this system be down and still be safe?"
- "How much data loss is acceptable?"
- "How often does the backup need to run?"
- "Does this need a redundant system or a manual-operation fallback?"
A Category III system may demand an RTO of minutes or less and an RPO close to zero data loss, while a Category I system can tolerate a comparatively long recovery time.
Setting RTO and RPO before classifying systems into categories is the same as making up numbers with nothing to back them.
Ⅳ. Deciding "What Do We Respond to First?" When an Incident Happens
When a cyberattack actually happens, one of the hardest problems is deciding what to respond to first. If several systems on the ship show anomalies at the same time, which one do you check first? You cannot investigate every system at once — especially not on a vessel underway, with limited crew and limited time.
This is where system category becomes the criterion that sets incident response priority. If an abnormal control command is detected in the Engine Control Zone, for example, the typical IT approach — "collect the logs, analyze them, then respond" — may not be enough on its own.
The first thing to consider is the ship's safety status:
- Can control be switched to local mode?
- Does the remote-control path need to be blocked?
- Is the abnormal command actually affecting control right now?
- Is manual operation possible?
- Would isolating the system immediately create an even bigger operational risk?
OT system category classification, then, isn't just labeling something as "important" — it's the criterion that decides who moves first, and what gets done first, when an actual incident occurs.
Ⅴ. The Biggest Difference Between IT and OT: Safety Comes Before Recovery
In a typical IT system, the standard response to a cyberattack is to isolate the infected system from the network, shut the server down, then recover it. In an OT environment, however, simply shutting a system down can be the more dangerous move.
Unconditionally shutting down a particular control system on a vessel underway can create a bigger operational risk than the cyberattack itself.
So before isolating a system, ship OT security has to first understand that system's safety criticality and whether an alternative mode of operation is available. This is exactly why category classification is needed.
The classification process can't just look at a system's name — it has to weigh the following factors together:
- The system's function
- Its impact on safe navigation
- Dependencies on other systems
- Its network connection structure
- Whether external or remote access is possible
- Whether manual operation is possible if it fails
- Whether redundancy is built in
- How long recovery would take
Even the same type of system can end up in a different category depending on whether it has redundancy or a manual fallback. In other words, you cannot classify systems with a blanket rule like "ECDIS is always Category II" or "every engine control system is always Category III."
Each system has to be judged individually, based on the actual configuration and operating practice on that specific ship.
Ⅵ. Category Classification Is the Link Between the IRP and the Recovery Plan
The Incident Response Plan (IRP) and the recovery plan (SCARP, or Recovery Plan) are connected to each other, but they play different roles. Drawing a clear line between the IRP and the recovery procedure reduces confusion during incident response.
Detection → Isolation → Initial response
Recovery → Normalization
And the handoff between the two doesn't have to be left to an individual's judgment call — it can be set as an RTO-based time trigger instead. If a Category II system has an RTO of 30 minutes, for example, you can set the rule in advance: if the root cause is still not identified a set amount of time after isolation begins, the recovery procedure starts automatically.
A Category III system, by contrast, has such a short RTO that instead of spending time on analysis, you may need to switch immediately to a backup system or local control. With this structure in place, the incident responder has a clear set of criteria to work from:
- "What category is this system in?"
- "How long can this failure be tolerated?"
- "When do we hand off from the IRP to the recovery procedure?"
Ⅶ. Conclusion — Category Classification Is Where Security Begins and Where Decisions Are Grounded
In ship cybersecurity, classifying OT systems into categories is not just an asset management task. Category classification is the starting point for every security activity that follows:
In the Smart Ship environment especially, IT and OT systems keep getting more connected, and external remote access and data exchange are increasing along with it. In that environment, protecting every system to the same standard is neither realistic nor efficient.
What matters is understanding, first, which systems have a direct impact on ship safety, how quickly risk actually materializes once a system fails, and whether an alternative mode of operation exists.
The purpose of category classification in ship OT security is not to stick a number on a system. It's to focus limited time and resources on the systems that matter most first, and to make it possible to take the right response and recovery decisions when a real cyber incident happens.
That is, at its core, the reason category classification of OT systems matters so much in ship security.
Related Reading:
Principal maritime engineering leader driving digital ship innovation and cybersecurity across ship operations and automation. Expertise spanning naval architecture, ICS/OT security, offshore system design, vessel automation, IACS UR E26/E27, and smart ship & digital twin technologies.
⚓ Join the ShipPaulJobs Community
Join →

Comments
Post a Comment