Cyber Risk Management of Automation Systems
From 1 July 2024, new ships must demonstrate cyber resilience from the design stage onward: what changes for the OT systems controlling engines, pumps and engine room automation.
Operational Explanation
Engine room automation and control systems (Operational Technology, OT) are increasingly interconnected with onboard IT networks, increasing exposure to cyber risks that can have direct physical consequences: an attack on, or malfunction of, the control system of a critical engine or pump is not just an IT problem, but an operational and safety risk.
Since 1 July 2024 the new Unified Requirements IACS UR E26 (Cyber Resilience of Ships) and UR E27 (Cyber Resilience of On-Board Systems and Equipment) have entered into force, applicable to new ships contracted from that date. UR E26 treats the ship as a collective entity, covering identification, protection, detection, response and recovery; UR E27 imposes robustness and design requirements on suppliers of onboard systems and equipment.
2026 revision: following experience gained in compliance verification and industry feedback, IACS has revised both URs, introducing a standardized approach to survey requirements and a categorization of compliance into mandatory and non-mandatory depending on ship type and size. Compliance is verified annually: at the first applicable Annual Survey, the owner must present to the surveying body logs or other documented evidence of the implementation of the ship's cyber security and resilience programme. It is also foreseeable that existing ships, not originally subject to UR E26, will be progressively brought within scope through Renewal Surveys in the coming years.
Regulatory Reference
IACS UR E26 (Cyber Resilience of Ships) and UR E27 (Cyber Resilience of On-Board Systems and Equipment), in force since 1 July 2024 for new ships contracted from that date, with a 2026 revision introducing a mandatory/non-mandatory categorization by ship type and size and a standardized approach to annual survey requirements; these add to Res. MSC.428(98) (incorporation of cyber risk management into the SMS under the ISM Code, in force since 1 January 2021) and the MSC-FAL.1/Circ.3 Guidelines (updated with a revision approved by MSC 108, May 2024).
Scope of Application
UR E26/E27 apply mandatorily to new ships according to type/size thresholds contracted from 1 July 2024; cyber risk management principles in the SMS (MSC.428(98)) instead apply to all existing ships via the ISM Code.
Procedure / How to Complete It
- Map all onboard OT/IT systems (engine automation, pump control systems, integrated navigation systems) and their interconnections.
- Segment OT networks from IT/internet networks where possible, limiting external access points to critical control systems.
- Apply access control procedures (physical and logical) to critical automation systems, including management of USB drives and external devices.
- For new ships built from 2024, verify supplier compliance of systems/equipment with UR E27 requirements.
- Include cyber incident scenarios in the SMS emergency response procedures, with defined roles and responsibilities.
- Train engine room personnel on cyber risks specific to automation systems, not only IT/office staff.
- Prepare, ahead of the first applicable Annual Survey, logs or documented evidence of the implementation of the ship's cyber security and resilience programme.
- Verify whether your ship falls within the mandatory or non-mandatory scope of the 2026 revision of UR E26/E27, according to type and size.
Practical Example
Example procedure: remote access to the main engine automation system permitted only via a segmented, authenticated connection, with every access logged and periodically reviewed by the Chief Engineer.
Real Cases
Common Mistakes Mistake Library
| Mistake | Consequence | How to avoid it |
|---|---|---|
| OT and IT networks not segmented, with shared access points | A compromise of the IT network (e.g. via email) can propagate to critical control systems | Segment OT networks from IT networks, limiting and monitoring interconnection points |
| Uncontrolled use of USB drives or external devices on automation systems | Common vector for introducing malware into control systems | Apply rigorous control procedures for external devices connected to OT systems |
| Cyber risk training limited to IT/office personnel, excluding engine officers | Personnel who interact daily with OT systems fail to recognize the signs of a possible cyber incident | Extend cyber risk training specifically to engine room personnel |
| Cyber security programme implementation logs not prepared ahead of the first applicable Annual Survey after the 2026 revision | Inability to demonstrate the required compliance during the survey | Prepare in good time the documentation required by the 2026 revision of UR E26/E27 |
PSC Observations
Operational Tips
- Always segment OT networks of critical automation systems from IT/internet networks, when technically possible.
- Apply rigorous procedures on the use of external devices (USB, maintenance laptops) on control systems.
- Extend cyber risk training to engine room personnel, not only those managing IT/administrative systems.
Checklist
- Onboard OT/IT systems mapped with their interconnections
- Segmentation of OT networks from IT networks applied where possible
- Physical and logical access control applied to critical automation systems
- Supplier compliance with UR E27 verified for new construction
- Engine room personnel trained on automation-specific cyber risks
- Logs/documented evidence of the cyber security programme prepared ahead of the first applicable Annual Survey