Don’t do SECURITY. Do business SECURELY.

IMO deadline for maritime cyber risk management

Ship operators must now address cyber risks in their safety management systems under IMO Resolution MSC.428(98).

From today, shipping companies are expected to address cyber risks in their safety management systems no later than the first annual verification of their Document of Compliance, under the International Maritime Organization’s Resolution MSC.428(98).

Key points

  • Applies under the International Safety Management (ISM) Code.
  • Cyber risks must be treated alongside other operational and safety risks.
  • Supported by IMO guidelines on maritime cyber risk management.
  • Flag states and port state control may check compliance during audits and inspections.
  • Industry guidance, such as the BIMCO guidelines, helps operators implement controls.

UK shipowners, operators and their technology suppliers should be able to show that cyber risks to onboard IT and operational technology are identified, protected, detected, responded to and recovered from.

Source: Maritime cyber risk and Resolution MSC.428(98) (IMO)

Need help understanding what this change means for your organisation? Get in touch for a pragmatic, no-obligation conversation.

Get our weekly insights by emailA free weekly threat and vulnerability round-up with our threat log spreadsheet, plus legal, regulatory, standards, and AI updates.
Subscribe free

More insights