Introduction
Modern vessels are increasingly dependent on Operational Technology (OT) to control, monitor, automate, and support critical maritime operations. Propulsion systems, engine controls, navigation equipment, alarm systems, machinery monitoring, cargo systems, industrial control systems, and other computer-based technologies are now interconnected across vessel networks.
This digital transformation creates operational advantages, but it also expands the potential cyber attack surface. A weakness in an OT device, network connection, remote-access mechanism, or onboard system can potentially affect availability, integrity, safety, and vessel operations.
The International Association of Classification Societies (IACS) introduced Unified Requirements (UR) E26 and E27 to address cyber resilience in new ships and onboard systems. UR E26 focuses on the cyber resilience of ships and the secure integration of IT and OT equipment, while UR E27 addresses the cyber resilience of onboard systems and equipment.
An OT Security Assessment based on applicable IACS UR E26 and E27 requirements can help identify weaknesses within vessel OT environments, evaluate security controls, and support remediation before systems become operationally critical.
Understanding IACS UR E26 and E27 for OT Security
IACS Unified Requirements establish minimum requirements that are incorporated into the rules and practices of IACS Member Societies, subject to their respective processes. Individual Member Societies may establish more stringent requirements.
1. IACS UR E26 – Cyber Resilience of Ships
UR E26 addresses the vessel as a collective cyber environment. It aims to support the secure integration of IT and OT equipment throughout the design, construction, commissioning, and operational lifecycle of a ship.
IACS identifies five key aspects:
- Equipment identification
- Protection
- Attack detection
- Response
- Recovery
This approach recognises that vessel cybersecurity requires more than preventative controls. A resilient environment should also have the capability to detect incidents, respond appropriately, and recover affected systems.
For OT environments, this means understanding how control systems, monitoring systems, networks, interfaces, and connected equipment interact with one another.
2. IACS UR E27 – Cyber Resilience of Onboard Systems and Equipment
UR E27 focuses on the cyber resilience of onboard systems and equipment. It includes considerations around system integrity, security hardening, interfaces between users and computer-based systems, and cybersecurity aspects of product design and development.
This is particularly important where equipment supplied by different manufacturers becomes part of a larger vessel OT environment.
Why OT Security Assessment Is Important for New-Build Vessels
OT environments differ significantly from conventional enterprise IT environments. Availability, safety, deterministic operations, legacy technology, specialised protocols, and operational continuity can influence how security testing is performed.
1. Identifying OT Security Weaknesses
An assessment can identify weaknesses in:
- Industrial control systems
- PLCs and controllers
- Engineering workstations
- HMIs
- SCADA components
- Network switches and routers
- Firewalls
- Remote-access systems
- Monitoring systems
- Communication interfaces
- OT servers
Identifying these weaknesses during new-build stages provides an opportunity for remediation before operational deployment.
2. Protecting Safety-Critical Operations
OT systems can influence physical processes. A cybersecurity incident affecting an operational system may therefore have consequences beyond data loss.
For example, weaknesses in network architecture or access controls could potentially affect systems responsible for monitoring or controlling machinery and other vessel functions.
Security assessments help stakeholders understand these risks while keeping the operational context in consideration.
3. Assessing IT and OT Connectivity
Modern vessels often contain interconnected IT and OT environments.
Connections between corporate networks, vessel management systems, engineering workstations, remote-access solutions, and operational systems can create potential attack paths.
An OT security assessment can examine whether these connections are appropriately controlled and segmented.
4. Evaluating Remote Access
Remote maintenance and vendor access can be useful for vessel operations, troubleshooting, and support.
However, improperly configured remote-access mechanisms can create significant exposure.
Assessment activities can examine:
- Authentication controls
- Access permissions
- Remote-access pathways
- Network restrictions
- Session controls
- Exposed services
- Vendor connectivity
5. Supporting Cyber Resilience
Security assessments can contribute to the wider resilience lifecycle described by IACS by helping identify vulnerabilities and control weaknesses that could affect protection, detection, response, or recovery.
Our Methodology for OT Security Assessment Based on IACS UR E26 and E27
Our methodology begins with understanding the vessel’s OT architecture, critical systems, communication paths, operational requirements, and approved assessment boundaries before conducting controlled security assessment activities.
1. Scope and Architecture Review
The assessment starts with a review of available technical documentation.
This may include:
- Vessel network diagrams
- OT architecture
- Asset inventories
- System descriptions
- Communication flows
- Remote-access architecture
- Security-zone definitions
- Equipment information
- Applicable project requirements
This stage establishes the technical context required for safe and effective assessment.
2. OT Asset Identification
A structured inventory of relevant OT assets is developed or reviewed.
Assets may include:
- PLCs
- RTUs
- HMIs
- SCADA systems
- Engineering workstations
- Industrial servers
- Network devices
- Firewalls
- Control systems
- Monitoring systems
- Safety-related computer-based systems
- Communication gateways
Asset identification helps determine which components require greater security attention.
3. Network Segmentation Assessment
Network architecture is reviewed to understand how OT systems communicate with other vessel environments.
The assessment may examine:
- Network zones
- Firewall rules
- VLAN configuration
- Trust relationships
- IT/OT connectivity
- Unnecessary communication paths
- Remote-access connections
- External interfaces
The objective is to identify whether inappropriate connectivity could create opportunities for unauthorised access or lateral movement.
4. Vulnerability Assessment
Where technically appropriate, OT assets and supporting infrastructure can undergo vulnerability assessment.
Testing can identify:
- Known vulnerabilities
- Unsupported software
- Missing security updates
- Weak configurations
- Insecure protocols
- Exposed services
- Default credentials
- Authentication weaknesses
- Unnecessary services
Because OT systems can be sensitive to active scanning, assessment methods should be selected according to the operational characteristics of the environment.
5. Security Configuration Review
Security configurations can be reviewed across relevant OT infrastructure.
This can include:
- Firewall configuration
- Network-device configuration
- User privileges
- Password policies
- Remote-access settings
- Security logging
- System hardening
- Access-control mechanisms
Configuration review can identify weaknesses that automated vulnerability scanning may not detect.
6. Controlled Penetration Testing
Where explicitly authorised and technically safe, controlled penetration testing can be used to validate selected weaknesses.
Testing may assess whether an attacker could potentially:
- Obtain unauthorised access
- Bypass authentication
- Escalate privileges
- Access restricted network segments
- Exploit exposed services
- Move between connected systems
- Reach sensitive OT components
The testing approach should account for the potential operational impact of interacting with industrial systems.
7. Remote Access and Interface Assessment
Remote-access pathways, engineering interfaces, vendor connections, APIs, gateways, and other communication mechanisms can be assessed.
This helps determine whether externally accessible pathways are adequately protected.
8. Risk Analysis and Reporting
Security findings are documented according to their technical significance and potential operational impact.
Reports can include:
- Finding description
- Affected asset
- Risk rating
- Technical evidence
- Potential impact
- Attack scenario
- Remediation recommendation
- Retesting requirements
This provides technical teams and project stakeholders with actionable information for remediation.
9. Remediation Validation and Retesting
Once identified weaknesses have been addressed, retesting can confirm whether remediation was successful.
This provides evidence that previously identified vulnerabilities have been resolved or appropriately mitigated.
Cyberintelsys OT Security Services
Cyberintelsys is a CREST-accredited cybersecurity company for Vulnerability Assessment (VA) and Penetration Testing (PT), delivering industry-recognized security testing services for organizations across multiple sectors.
For maritime OT environments, assessments can be structured around the vessel architecture, technology, operational sensitivity, and applicable requirements.
1. OT Security Testing
OT Security Testing can help identify vulnerabilities and security weaknesses across operational technology environments.
Assessment areas can include:
- OT network architecture
- Industrial devices
- Control systems
- Engineering workstations
- OT servers
- Communication interfaces
- Remote-access pathways
- Security configurations
2. ICS / SCADA Security Assessment
ICS / SCADA Security Assessment focuses on the security of industrial control and supervisory systems.
This can help organisations identify weaknesses affecting system integrity, access control, network security, and operational resilience.
3. Network Penetration Testing
Network Penetration Testing can assess network infrastructure, exposed services, segmentation, authentication, and potential attack paths.
For vessel environments, testing can be carefully scoped to avoid unnecessary disruption to operational systems.
3. Infrastructure Vulnerability Assessment and Penetration Testing
Infrastructure VAPT can complement OT-focused assessments by evaluating supporting infrastructure within the approved scope.
4. Network Architecture Security Review
Network Architecture Security Review can help examine the overall security design and connectivity of vessel networks.
Why Choose Cyberintelsys?
Maritime OT security requires an assessment approach that considers both cybersecurity and operational consequences.
Cyberintelsys combines technical security testing capabilities with a risk-focused approach to help organisations identify and address weaknesses across interconnected technology environments.
Key considerations include:
- CREST accreditation: Cyberintelsys is CREST-accredited for Vulnerability Assessment and Penetration Testing.
- OT-focused assessment: Testing can be structured around operational technology and industrial environments.
- Controlled testing: Assessment methods can be selected according to the sensitivity of the systems involved.
- Technical reporting: Findings can include evidence, risk context, and remediation recommendations.
- Network-focused analysis: IT/OT connectivity and segmentation can be assessed within the agreed scope.
- Requirement alignment: Assessments can be structured based on applicable IACS UR E26 and E27 requirements.
Contact Cyberintelsys
As maritime systems become more interconnected, OT security needs to be considered from the earliest stages of vessel design and construction.
An OT Security Assessment based on applicable IACS UR E26 and E27 requirements can help identify weaknesses across onboard systems, industrial networks, control environments, communication interfaces, and connected infrastructure.
Early assessment allows shipbuilders, shipowners, equipment manufacturers, system integrators, and other maritime stakeholders to address security weaknesses before they become more difficult to remediate.
Contact Cyberintelsys to discuss your OT security requirements and strengthen the cyber resilience of your new-build vessel and onboard systems.