Useful links
Contents
A selection of reference websites and documents on maritime and port cybersecurity. This is a long-term effort, so the list is certainly still incomplete. A French version of this page is also available, with the addition of the French national framework.
Regulation, standards and good practice
- IMO: the International Maritime Organization page on maritime cyber risk
- IMO: Resolution MSC.428(98) on maritime cyber risk management in safety management systems
- IMO: MSC-FAL.1/Circ.3/Rev.4, Guidelines on maritime cyber risk management, 28 May 2026
- The Guidelines on Cyber Security Onboard Ships (v5), produced by BIMCO, CLIA, ICS, INTERCARGO, INTERTANKO and others, also presented on the BIMCO website
- DCSA: implementation guides and templates for cybersecurity on board ships
- IACS: Recommendation on cyber resilience, Rec 166
- ISO/IEC: ISO/IEC 27001, information security management systems
- NIST: the Cybersecurity Framework, referenced by the IMO guidelines
- ENISA: Good practices for cybersecurity in the maritime sector, port security
- EMSA: MARSEC 9209 publication
- IAPH: Cybersecurity Guidelines for Ports and Port Facilities (v2.0)
- IAPH: Cyber Resilience Guidelines for Emerging Technologies in the Maritime Supply Chain, added as a reference by MSC-FAL.1/Circ.3/Rev.4
- EU: Directive (EU) 2022/2555 (NIS2)
- EU: Regulation (EC) No 725/2004 on enhancing ship and port facility security
- UK Department for Transport: Code of Practice, Cyber Security for Ships
- UK Department for Transport: Good Practice Guide, Cyber Security for Ports and Port Systems
- United States: Cybersecurity in the Marine Transportation System, the US Coast Guard final rule published in the Federal Register
- United States: USCG Office of Commercial Vessel Compliance, Vessel Cyber Risk Management Work Instruction
Ecosystem
- NORMA Cyber, the Norwegian Maritime Cyber Resilience Centre
- MTS-ISAC, the Maritime Transportation System Information Sharing and Analysis Center
- IAPH, the International Association of Ports and Harbors
Classification and certification
- IACS: Unified Requirements E26 and E27 on the cyber resilience of ships and of onboard systems and equipment
- Bureau Veritas: NR 659, Rules on Cybersecurity for the Classification of Marine Units
- Bureau Veritas: NR 642, Cybersecurity Requirements for Products to be Installed On-Board Naval Ships
- ClassNK: cyber security services and guidelines
- DNV: RP-0496, Cyber security resilience management for ships and mobile offshore units in operation, and the DNV maritime cyber security pages
Research
- Maritime Cyber Threats Research Group (University of Plymouth, United Kingdom): the group works on decision support, supply chain vulnerabilities, the cybersecurity of autonomous ships and the human factor.
- In the summer of 2013, researchers from the University of Texas ran the first GPS spoofing experiments against a luxury yacht at sea.
Reports and vulnerability research
- IOActive report on the vulnerabilities of satellite terminals
- Pentest Partners on vulnerabilities in container ship load planning software
- Pentest Partners on OSINT and social engineering risks around ship satellite communications
- A US Department of Homeland Security document on the cyber risks of port operations
Awareness videos
Most of the awareness videos I collect are gathered in a dedicated YouTube playlist:
Olivier JACQ, President and founder of CYBERMOOV Consulting.