Superba Knowledge — Bridging Regulations and Operations Beta
IT/EN
Download
Operational Guide · Registers & Logbooks

Cyber Risk Management of Automation Systems

From 1 July 2024, new ships must demonstrate cyber resilience from the design stage onward: what changes for the OT systems controlling engines, pumps and engine room automation.

cyber riskIACS UR E26IACS UR E27OTautomation

Operational Explanation

Engine room automation and control systems (Operational Technology, OT) are increasingly interconnected with onboard IT networks, increasing exposure to cyber risks that can have direct physical consequences: an attack on, or malfunction of, the control system of a critical engine or pump is not just an IT problem, but an operational and safety risk.

Since 1 July 2024 the new Unified Requirements IACS UR E26 (Cyber Resilience of Ships) and UR E27 (Cyber Resilience of On-Board Systems and Equipment) have entered into force, applicable to new ships contracted from that date. UR E26 treats the ship as a collective entity, covering identification, protection, detection, response and recovery; UR E27 imposes robustness and design requirements on suppliers of onboard systems and equipment.

2026 revision: following experience gained in compliance verification and industry feedback, IACS has revised both URs, introducing a standardized approach to survey requirements and a categorization of compliance into mandatory and non-mandatory depending on ship type and size. Compliance is verified annually: at the first applicable Annual Survey, the owner must present to the surveying body logs or other documented evidence of the implementation of the ship's cyber security and resilience programme. It is also foreseeable that existing ships, not originally subject to UR E26, will be progressively brought within scope through Renewal Surveys in the coming years.

Regulatory Reference

IACS UR E26 (Cyber Resilience of Ships) and UR E27 (Cyber Resilience of On-Board Systems and Equipment), in force since 1 July 2024 for new ships contracted from that date, with a 2026 revision introducing a mandatory/non-mandatory categorization by ship type and size and a standardized approach to annual survey requirements; these add to Res. MSC.428(98) (incorporation of cyber risk management into the SMS under the ISM Code, in force since 1 January 2021) and the MSC-FAL.1/Circ.3 Guidelines (updated with a revision approved by MSC 108, May 2024).

Scope of Application

UR E26/E27 apply mandatorily to new ships according to type/size thresholds contracted from 1 July 2024; cyber risk management principles in the SMS (MSC.428(98)) instead apply to all existing ships via the ISM Code.

Procedure / How to Complete It

  1. Map all onboard OT/IT systems (engine automation, pump control systems, integrated navigation systems) and their interconnections.
  2. Segment OT networks from IT/internet networks where possible, limiting external access points to critical control systems.
  3. Apply access control procedures (physical and logical) to critical automation systems, including management of USB drives and external devices.
  4. For new ships built from 2024, verify supplier compliance of systems/equipment with UR E27 requirements.
  5. Include cyber incident scenarios in the SMS emergency response procedures, with defined roles and responsibilities.
  6. Train engine room personnel on cyber risks specific to automation systems, not only IT/office staff.
  7. Prepare, ahead of the first applicable Annual Survey, logs or documented evidence of the implementation of the ship's cyber security and resilience programme.
  8. Verify whether your ship falls within the mandatory or non-mandatory scope of the 2026 revision of UR E26/E27, according to type and size.

Practical Example

Example procedure: remote access to the main engine automation system permitted only via a segmented, authenticated connection, with every access logged and periodically reviewed by the Chief Engineer.

Real Cases

Cyber security incidents in the maritime sector, including cases affecting navigation or automation systems, have driven IACS to develop UR E26/E27 as a structural requirement from the design stage of new ships, recognizing that OT cyber security cannot be added effectively after the fact with the same efficacy as a natively resilient design.

Common Mistakes Mistake Library

MistakeConsequenceHow to avoid it
OT and IT networks not segmented, with shared access pointsA compromise of the IT network (e.g. via email) can propagate to critical control systemsSegment OT networks from IT networks, limiting and monitoring interconnection points
Uncontrolled use of USB drives or external devices on automation systemsCommon vector for introducing malware into control systemsApply rigorous control procedures for external devices connected to OT systems
Cyber risk training limited to IT/office personnel, excluding engine officersPersonnel who interact daily with OT systems fail to recognize the signs of a possible cyber incidentExtend cyber risk training specifically to engine room personnel
Cyber security programme implementation logs not prepared ahead of the first applicable Annual Survey after the 2026 revisionInability to demonstrate the required compliance during the surveyPrepare in good time the documentation required by the 2026 revision of UR E26/E27

PSC Observations

Verification of the integration of cyber risk management into the SMS (under MSC.428(98)) can be subject to PSC control as part of the general ISM Code verification; UR E26/E27 are instead verified mainly at the Class survey/certification stage for new construction.

Operational Tips

Checklist

FAQ

Do UR E26/E27 also apply to existing ships?
UR E26/E27 apply mandatorily to new ships contracted from 1 July 2024; existing ships remain subject to the cyber risk management principles in the SMS under Resolution MSC.428(98), in force since 2021, which has a different and more general scope. It is nonetheless foreseeable that existing ships will progressively be brought within UR E26 scope through Renewal Surveys in the coming years.
What changes with the 2026 revision of UR E26/E27?
A categorization of compliance into mandatory and non-mandatory is introduced depending on ship type and size, along with a standardized approach to survey requirements: at the first applicable Annual Survey, the owner must present documented evidence of the implementation of the cyber security and resilience programme.
What is the difference between UR E26 and UR E27?
UR E26 addresses the ship as a collective entity for cyber resilience (identification, protection, detection, response, recovery); UR E27 imposes specific robustness and design requirements on individual systems and equipment supplied by third parties prior to installation on board.
Should a cyber incident on OT systems be managed as an ISM Non-Conformity?
Yes: since cyber risk management is incorporated into the SMS under MSC.428(98), a significant incident or vulnerability on OT/IT systems should be treated with the same rigour as any other Non-Conformity, including root cause analysis and CAPA.
🎬 Additional photos, videos and interactive diagrams for this topic will be available in a future version of the platform.

Related Topics