Introduction
Digital technologies have become an integral part of modern vessel design and operations. New-build vessels increasingly rely on interconnected Information Technology (IT), Operational Technology (OT), navigation systems, automation, machinery control, monitoring platforms, communication systems, remote-access solutions, and computer-based onboard equipment.
This connectivity can improve efficiency, automation, monitoring, and operational decision-making. At the same time, it introduces cybersecurity risks that can affect vessel operations, safety, system integrity, and data.
For shipbuilders, shipowners, equipment manufacturers, system integrators, and other maritime stakeholders, cybersecurity therefore needs to be addressed throughout the vessel lifecycle rather than treated as a final-stage technical activity.
The International Association of Classification Societies (IACS) introduced Unified Requirements (UR) E26 and E27 to strengthen the cyber resilience of new ships and onboard systems. UR E26 focuses on cyber resilience at the ship level, including the secure integration of IT and OT equipment, while UR E27 addresses cyber resilience of onboard systems and equipment.
A structured cybersecurity assessment can help organisations identify security gaps, evaluate implemented controls, document remediation, and establish evidence that supports IACS UR E26 and E27 compliance readiness.
Understanding IACS UR E26 and E27
IACS Unified Requirements are minimum requirements that are incorporated into the rules and practices of IACS Member Societies, subject to their respective processes. Each Member Society may establish more stringent requirements.
Understanding the distinction between E26 and E27 is important when planning a cybersecurity assessment.
1. IACS UR E26 – Cyber Resilience of Ships
UR E26 addresses the vessel as a collective cyber environment. IACS describes its objective as ensuring the secure integration of IT and OT equipment into the vessel’s network during design, construction, commissioning, and the operational life of the ship.
The requirement addresses five key areas:
- Equipment identification
- Protection
- Attack detection
- Response
- Recovery
This means cyber resilience is not limited to preventing unauthorised access. A resilient vessel should also have appropriate capabilities for identifying cyber incidents, responding to them, and recovering affected systems.
2. IACS UR E27 – Cyber Resilience of Onboard Systems and Equipment
UR E27 focuses on the cybersecurity of onboard systems and equipment.
It addresses areas such as:
- System integrity
- Security hardening
- Interfaces between users and computer-based systems
- Product design and development
- Cybersecurity considerations for equipment before implementation onboard
This makes E27 particularly relevant to equipment manufacturers, system suppliers, and other parties involved in delivering technology for new-build vessels.
3. Applicability to New Ships
IACS revised the original E26 and E27 requirements following industry feedback and changes to their applicability and survey approach. The revised requirements superseded the original versions and apply to applicable new ships contracted for construction on and after 1 July 2024.
The applicability of mandatory and non-mandatory requirements can vary according to vessel type and size. Therefore, compliance readiness should be evaluated against the applicable classification-society requirements and the specific characteristics of the vessel.
Why Cybersecurity Assessment Is Important for IACS Compliance Readiness
Compliance readiness is more than checking whether cybersecurity documents exist. It involves determining whether the technical, organisational, and operational controls required by the applicable requirements have been appropriately addressed.
1. Identify Security Gaps Before Classification Review
A cybersecurity assessment can identify weaknesses before they become issues during formal review, verification, or survey activities.
Potential gaps may exist within:
- Network architecture
- OT environments
- IT infrastructure
- Onboard equipment
- Access controls
- Remote access
- System hardening
- Vulnerability management
- Security monitoring
- Incident response
- Recovery mechanisms
Identifying these gaps early provides greater opportunity for remediation.
2. Establish Visibility Across IT and OT
A new-build vessel can contain a complex combination of IT and OT technologies.
Understanding which systems are connected, how they communicate, and which systems are critical is an important part of cybersecurity readiness.
An assessment can help establish:
- Asset visibility
- Network relationships
- Communication pathways
- Trust relationships
- Security zones
- External connections
- Remote-access pathways
3. Evaluate Network Segmentation
Network segmentation can help limit the impact of a security incident.
The assessment can examine whether appropriate boundaries exist between:
- Corporate IT
- Vessel IT
- OT networks
- Navigation systems
- Machinery systems
- Engineering environments
- Remote-access infrastructure
- Third-party connections
Weak segmentation can create opportunities for lateral movement between systems.
4. Identify Vulnerabilities
Vulnerability Assessment can identify known technical weaknesses across approved systems.
Potential findings include:
- Outdated software
- Missing security patches
- Vulnerable services
- Insecure configurations
- Weak authentication
- Exposed ports
- Unsupported components
- Insecure protocols
For sensitive OT environments, testing methods should be carefully selected to minimise operational risk.
5. Validate Security Controls
Penetration Testing and controlled security validation can help determine whether selected weaknesses can actually be exploited.
This provides additional insight beyond a vulnerability scan by demonstrating realistic attack paths within the authorised scope.
6. Support Evidence-Based Remediation
A compliance-readiness assessment should produce actionable findings rather than simply identifying deficiencies.
A structured report can document:
- Security gap
- Affected system
- Risk level
- Technical evidence
- Potential impact
- Recommended corrective action
- Remediation status
- Retesting requirements
This creates a traceable path from identifying a gap to validating its resolution.
Our Methodology for IACS UR E26 and E27 Compliance Readiness Assessment
Our methodology begins by mapping the vessel’s applicable cybersecurity requirements to its architecture, systems, controls, and available evidence before performing technical assessments and documenting the gaps that may affect compliance readiness.
1. Requirement and Scope Review
The first stage establishes the assessment scope and identifies the applicable IACS requirements based on the vessel’s characteristics and project context.
Available documentation may include:
- Vessel architecture
- System inventories
- Network diagrams
- Equipment lists
- Security policies
- System specifications
- Communication diagrams
- Remote-access architecture
- Supplier documentation
- Classification requirements
The objective is to create a clear assessment baseline.
2. Asset and System Inventory Review
Relevant IT, OT, and onboard computer-based systems are identified and reviewed.
The inventory may include:
- Servers
- Workstations
- PLCs
- HMIs
- SCADA systems
- Navigation systems
- Machinery systems
- Network devices
- Firewalls
- Communication gateways
- Engineering workstations
- Remote-access infrastructure
Accurate asset identification supports both security assessment and compliance documentation.
3. Cybersecurity Architecture Assessment
The vessel’s cybersecurity architecture is assessed to determine whether security controls are appropriately designed.
This can include reviewing:
- Network segmentation
- Security zones
- Firewall placement
- Access-control architecture
- IT/OT connectivity
- External interfaces
- Remote connections
- Communication pathways
The objective is to identify architectural weaknesses that could undermine cyber resilience.
4. Vulnerability Assessment
Approved systems are assessed for known technical vulnerabilities.
Activities may include:
- Vulnerability scanning
- Service enumeration
- Software-version review
- Patch assessment
- Configuration analysis
- Authentication checks
- Identification of exposed services
The testing approach is adjusted according to the sensitivity of the vessel environment.
5. Security Configuration Review
Security configurations are reviewed to identify weaknesses that may not be identified through automated vulnerability scanning.
Potential areas include:
- Firewall rules
- Network-device configurations
- User privileges
- Password policies
- Remote-access settings
- System hardening
- Logging
- Security controls
6. Penetration Testing
Where authorised and technically appropriate, penetration testing can validate selected vulnerabilities and security controls.
Depending on the approved scope, testing may assess:
- Network security
- External attack surfaces
- Internal environments
- Web applications
- APIs
- Authentication
- Access control
- Remote-access mechanisms
- Network segmentation
For OT environments, testing is planned carefully to minimise disruption to safety-critical and operational systems.
7. Detection, Response, and Recovery Review
Because E26 addresses detection, response, and recovery as part of the vessel’s cyber resilience, these capabilities should also be considered during readiness assessment.
The review can examine:
- Security monitoring
- Logging
- Alerting
- Incident-response procedures
- Recovery procedures
- Backup mechanisms
- System restoration processes
- Contingency arrangements
8. Gap Analysis and Risk Prioritisation
Identified weaknesses are mapped against the relevant assessment requirements and categorised according to risk and remediation priority.
This allows project teams to distinguish between:
- Critical gaps
- High-priority weaknesses
- Configuration issues
- Documentation gaps
- Process deficiencies
- Lower-risk observations
9. Remediation Validation and Retesting
After corrective actions are implemented, retesting can verify whether identified technical weaknesses have been successfully addressed.
This provides evidence of progress toward cybersecurity readiness.
Cyberintelsys Services for IACS Compliance Readiness
Cyberintelsys is a CREST-accredited cybersecurity company for Vulnerability Assessment (VA) and Penetration Testing (PT), delivering industry-recognized security testing services for organizations across multiple sectors.
For new-build vessels, relevant security services can be combined according to the vessel architecture and assessment scope.
1. OT Security Testing
OT Security Testing can assess operational technology environments for vulnerabilities, insecure configurations, access-control weaknesses, and network-security gaps.
This can be particularly relevant to systems that control or monitor physical vessel operations.
2. ICS / SCADA Security Assessment
ICS / SCADA Security Assessment can examine industrial control and supervisory environments for weaknesses affecting system integrity, access control, network security, and resilience.
Network Penetration Testing
Network Penetration Testing can assess network infrastructure, exposed services, segmentation, authentication, and potential attack paths.
Infrastructure VAPT
Infrastructure VAPT can provide additional assessment of supporting infrastructure within the approved vessel environment.
Network Architecture Security Review
Network Architecture Security Review can evaluate network design, communication pathways, security zones, and connectivity between relevant systems.
Security Devices Configuration Review
Security Devices Configuration Review can help identify configuration weaknesses in security appliances and network protection mechanisms.
Why Choose Cyberintelsys?
Cybersecurity compliance readiness requires a combination of technical assessment, documentation, risk analysis, and remediation validation.
Cyberintelsys brings together security-testing capabilities that can help organisations understand their technical security posture and address weaknesses before formal compliance or classification activities.
Key strengths include:
- CREST accreditation: Cyberintelsys is CREST-accredited for Vulnerability Assessment and Penetration Testing.
- Technical security testing: VA and PT can be used to identify and validate security weaknesses.
- OT and infrastructure assessment: Testing can extend across relevant operational and supporting environments.
- Risk-focused reporting: Findings can include technical evidence, impact, severity, and remediation guidance.
- Architecture-focused assessment: Network segmentation and communication pathways can be reviewed.
- Readiness-oriented approach: Assessment findings can support organisations in identifying and addressing gaps before applicable classification or compliance activities.
Contact Cyberintelsys
Preparing a new-build vessel for IACS UR E26 and E27 requirements requires cybersecurity to be considered throughout design, integration, commissioning, and testing.
A structured cybersecurity assessment can help identify vulnerabilities, architectural weaknesses, configuration issues, documentation gaps, and deficiencies in security controls before they become more difficult to address.
The goal is not simply to identify problems, but to create a practical roadmap toward stronger cyber resilience and IACS UR E26 & E27 compliance readiness.
Contact Cyberintelsys to assess your new-build vessel’s cybersecurity posture, identify readiness gaps, and strengthen your approach to applicable IACS UR E26 and E27 requirements.