SuperbaKnowledge Demonstration release
Platforms
ENIT
Operational guide · SMS process

Cyber Risk Management in the SMS (MSC.428(98))

The ISM Code has never had a dedicated cyber risk chapter: Resolution MSC.428(98) affirms that an approved SMS should take it into account under the objectives and functional requirements of the Code, and encourages Administrations to check it from 2021.

ISM Codecyber riskMSC.428(98)SMS

Operational Explanation

Resolution MSC.428(98) (adopted in June 2017) does not introduce a new chapter into the ISM Code, but establishes that cyber risks must be appropriately addressed within the existing Safety Management System, under the Code's general risk management framework (in particular paragraphs 1.2.2.2 and 1.4 on risk assessment and operational procedures). Administrations were encouraged to ensure cyber risks were appropriately addressed in the SMS no later than the first annual verification of the Document of Compliance (DOC) after 1 January 2021: a requirement that is by now mature and well-established, no longer a recent novelty.

Technical support for this requirement is provided by the Guidelines on Maritime Cyber Risk Management (MSC-FAL.1/Circ.3/Rev.4). The current IMO Guidelines on maritime cyber risk management are MSC-FAL.1/Circ.3/Rev.4, issued on 28 May 2026 following approval by FAL 50 and MSC 111. The circular has been revised several times, which shows the topic remains under active development years after the requirement was first introduced. The Guidelines structure cyber risk management around the six functional elements of 3.5: govern, identify, protect, detect, respond and recover.

Regulatory Reference

Resolution MSC.428(98) (June 2017) does not amend the ISM Code: it affirms that an approved SMS should take cyber risk management into account in accordance with the objectives and functional requirements of the Code (par. 1.2.2.2, 1.4), and encourages Administrations to ensure that cyber risks are appropriately addressed in the SMS no later than the first annual DOC verification after 1 January 2021. What is verified in an audit remains the Code requirement, as implemented by the Administration or recognized organization. Supported by the MSC-FAL.1/Circ.3/Rev.4 Guidelines, current revision Rev.4, issued on 28 May 2026 following approval by FAL 50 and MSC 111.

MSC-FAL.1/Circ.3/Rev.4, §3.5 · MSC.428(98).

Scope of Application

Every Company holding an ISM DOC, covering all IT (information technology) and OT (operational technology, e.g. machinery automation, ECDIS, GMDSS) systems on board and ashore that are relevant to operational safety.

Procedure / How to Complete It

  1. Integrate cyber risk into the SMS with clear responsibilities, authority, resources and competence.
  2. Use Rev.4's six elements—Govern, Identify, Protect, Detect, Respond and Recover—as concurrent and continuous activities, not a one-off sequence.
  3. Map critical IT/OT systems, dependencies and supplier access; provide authorised, controlled and risk-based remote access.
  4. Record and assess cyber events through the SMS incident process. Open an NC and CAPA when a specified requirement has not been met or the procedure requires it, not automatically for every incident.
  5. Prepare safe response, continuity and recovery: protect backups, test restoration and exercise roles and communication proportionately.
  6. Define internal and external notifications under flag and other applicable duties. For OT, coordinate isolation and recovery with competent operational functions: indiscriminate disconnection or rebooting may compromise safety.

Practical Example

Example: malware detected on a laptop is reported and its connections to critical systems assessed. Containment takes operational safety into account. If analysis identifies access contrary to procedure, an NC with CAPA is opened; the label 'cyber incident' alone does not determine classification. Recovery is verified before return to service.

What Typically Goes Wrong

The absence of a dedicated ISM chapter on cyber risk sometimes leads Companies to treat it as a purely IT matter, managed separately from the rest of the SMS: this is exactly the error Resolution MSC.428(98) is meant to correct, requiring that cyber risk be addressed with the same procedural rigour (risk assessment, procedures, verification, continuous improvement) already applied to other operational risks under the ISM Code.

Common Mistakes Mistake Library

MistakeConsequenceHow to avoid it
Cyber risk managed as a separate IT matter, not integrated into the SMS's general risk assessmentLack of integrated documentary evidence in the event of an audit, despite the existence of technical IT measuresExplicitly integrate cyber risk into the SMS's risk assessment and procedures, not only into the company's IT policy
No distinction between IT and OT systems in the cyber risk assessmentCountermeasures designed for management systems improperly applied to critical automation/navigation systemsMap IT and OT systems separately, with specific countermeasures for each category
Cyber incidents not logged in the existing NC/CAPA cycleLoss of the root cause analysis and continuous improvement opportunity already provided for other non-conformities under the ISM CodeRecord and assess every cyber incident under the SMS incident process, and open an NC with CAPA when a specified requirement was not met or the Company procedure requires it — not automatically for every event

What the PSCO Checks

MSC.428(98) identifies the first annual verification of the Company DOC after 1 January 2021 as the deadline by which Administrations were encouraged to ensure cyber risks were addressed in the SMS. This does not introduce an annual SMC verification. Audits examine procedures and implementation evidence; relevant systemic shortcomings may also emerge during PSC.

Operational Tips

Preparation checklist

Educational checklist. This summary supports learning and preparation only. It does not replace the vessel’s approved procedures, manuals, statutory documents, company SMS, or applicable official requirements. Completing it demonstrates neither compliance nor readiness for an inspection: it shows that a list has been read, not that the ship is in order. Always verify the current documents carried on board.

FAQ

Does cyber risk need a separate ISM chapter?
No. MSC.428(98) affirms that cyber risk should be addressed within the SMS in accordance with the Code's objectives and functional requirements.
What does the 2021 date mean?
The resolution encouraged Administrations to ensure integration no later than the first annual DOC verification after 1 January 2021. It is a historical implementation milestone, not a limit on the continuing duty.
Is every cyber incident an NC?
No. Record and assess the event; an NC depends on a requirement not being met or the applicable procedure.
Are the six Rev.4 elements sequential stages?
No. Govern, Identify, Protect, Detect, Respond and Recover operate concurrently and continuously.

Related Topics

Last substantive revision of this page: 15 September 2026 · page fingerprint 6db5a250e0ed