Security Testing Aligned with IACS Unified Requirements E26 & E27 for New-Build Vessels

Security Testing Aligned with IACS Unified Requirements E26 & E27 for New-Build Vessels

Introduction

The maritime industry is becoming increasingly connected. Modern vessels rely on integrated operational technology (OT), information technology (IT), navigation systems, communication platforms, automation, monitoring systems, remote access capabilities, and computer-based onboard equipment. While digitalisation improves efficiency and operational visibility, it also introduces cybersecurity risks that can affect vessel safety, availability, data integrity, and critical operations.

Recognising these risks, the International Association of Classification Societies (IACS) introduced Unified Requirements (UR) E26 and E27 to strengthen cyber resilience across new ships and onboard systems.

UR E26 focuses on the cyber resilience of ships as a whole, including the secure integration of IT and OT equipment throughout the design, construction, commissioning, and operational lifecycle. UR E27 focuses on the cyber resilience of onboard systems and equipment, including security requirements for equipment suppliers, system integrity, interfaces, and product development.

Security testing aligned with these requirements helps shipbuilders, shipowners, equipment manufacturers, system integrators, and other maritime stakeholders identify weaknesses before they become operational security issues.

Understanding IACS UR E26 and E27

IACS Unified Requirements establish minimum requirements that are incorporated into the rules and practices of IACS Member Societies, subject to their applicable processes. Individual Member Societies may establish more stringent requirements.

UR E26 and E27 address different but interconnected areas of maritime cybersecurity.

1. UR E26 – Cyber Resilience of Ships

UR E26 addresses cybersecurity at the vessel level. It considers how IT and OT systems are integrated into the ship’s network and how cyber risks should be addressed throughout the vessel lifecycle.

The requirement focuses on key cyber-resilience areas including:

  • Equipment identification
  • Protection against cyber threats
  • Attack detection
  • Incident response
  • Recovery capabilities

The objective is to make the vessel more resilient against cyber incidents that could affect safety-critical and operational functions.

2. UR E27 – Cyber Resilience of Onboard Systems and Equipment

UR E27 focuses on the systems and equipment installed onboard. It places emphasis on system integrity, security hardening, user interfaces, and cybersecurity considerations during product design and development.

This means cybersecurity cannot be considered only after equipment is installed. Security requirements need to be considered earlier in the product and system lifecycle.

Why Security Testing Matters for New-Build Vessels

Cybersecurity weaknesses discovered after a vessel becomes operational can be significantly more difficult and expensive to address. New-build projects offer an opportunity to identify and remediate security weaknesses before systems are fully commissioned and deployed.

Security testing can support this process by examining whether technical controls are functioning as intended and whether vulnerabilities exist across connected systems.

1. Identifying Vulnerabilities Before Commissioning

Vulnerability assessment can identify weaknesses in network devices, servers, applications, communication interfaces, connected equipment, and other relevant components before the vessel enters service.

Early identification gives shipbuilders and system owners more time to implement corrective measures.

2. Protecting IT and OT Environments

Modern vessels contain a mixture of traditional IT systems and operational technologies. Security weaknesses in one environment may create pathways into another if appropriate segmentation and access controls are not implemented.

Testing can help assess whether network boundaries, access controls, authentication mechanisms, and segmentation measures are sufficiently robust.

3. Supporting Cyber Resilience

Security is not limited to preventing attacks. A resilient vessel should also be capable of detecting suspicious activity, responding to incidents, and recovering affected systems.

Testing provides an opportunity to assess technical controls that contribute to these capabilities.

4. Reducing Third-Party Security Risks

Many onboard systems are supplied by multiple equipment manufacturers and technology providers. Weaknesses in third-party equipment can introduce risks into the wider vessel environment.

UR E27 specifically addresses cyber resilience of onboard systems and equipment, making security considerations during product development and integration particularly important.

Our Methodology for Security Testing Aligned with IACS UR E26 and E27

Our methodology begins by understanding the vessel’s architecture, relevant systems, connectivity, security requirements, and testing boundaries before conducting controlled security assessments.

1. Scope and Architecture Review

The assessment begins with a review of available documentation, network architecture, system inventories, communication paths, interfaces, and relevant security controls.

This helps establish an accurate understanding of the systems that require assessment.

2. Asset and Attack Surface Identification

Relevant IT and OT assets, network interfaces, communication services, applications, devices, and exposed entry points are identified.

Understanding the attack surface helps determine where vulnerabilities could potentially affect vessel operations.

3. Vulnerability Assessment

Systems within the approved scope are assessed for known vulnerabilities, configuration weaknesses, outdated components, insecure services, authentication weaknesses, and other technical security issues.

The assessment is performed with consideration for the operational sensitivity of maritime environments.

4. Network and Segmentation Assessment

Network architecture and segmentation controls are reviewed to determine whether critical systems are appropriately isolated and whether unnecessary communication paths exist.

Particular attention can be given to connections between IT and OT environments, remote access mechanisms, and externally accessible services.

5. Controlled Penetration Testing

Where authorised and technically appropriate, penetration testing can be conducted to validate whether identified weaknesses can be exploited.

Testing is carefully planned to minimise disruption to safety-critical or operational systems.

6. Security Configuration Review

Relevant security configurations can be examined across network devices, operating systems, applications, security appliances, and other in-scope components.

The objective is to identify security gaps that may not necessarily appear through automated vulnerability scanning alone.

7. Reporting and Remediation Guidance

Findings are documented according to their security significance and potential operational impact.

The resulting report can include:

  • Identified vulnerabilities
  • Risk ratings
  • Affected assets
  • Technical evidence
  • Potential impact
  • Recommended remediation
  • Prioritisation guidance
8. Retesting

After remediation, identified issues can be reassessed to verify whether corrective measures have addressed the previously identified weaknesses.

This creates a structured security-testing cycle rather than treating the assessment as a one-time activity.

Cyberintelsys Services for Maritime Security Testing

Cyberintelsys is a CREST-accredited cybersecurity company for Vulnerability Assessment (VA) and Penetration Testing (PT), delivering industry-recognized security testing services for organizations across multiple sectors.

Security assessments can be tailored to the technology and risk profile of new-build vessel environments.

1. Vulnerability Assessment

Vulnerability Assessment identifies known security weaknesses across in-scope systems and infrastructure.

It can help identify:

  • Missing security patches
  • Vulnerable software and services
  • Weak configurations
  • Exposed ports and services
  • Authentication weaknesses
  • Outdated components
  • Network security gaps

The findings provide a prioritised view of vulnerabilities that require remediation.

2. Penetration Testing

Penetration Testing goes beyond vulnerability identification by safely validating whether selected vulnerabilities can be exploited under an agreed scope.

Testing may assess:

For maritime environments, testing boundaries and methods should be carefully defined to protect operational and safety-critical systems.

3. Network Security Testing

Network security testing examines communication pathways, exposed services, segmentation, access controls, and network configurations.

This can be particularly relevant where multiple IT, OT, communication, and onboard systems interact.

4. Web Application and API Security Testing

Modern vessels and supporting maritime operations may use web applications, dashboards, APIs, portals, and remote management interfaces.

Testing can identify vulnerabilities that could expose operational information, authentication mechanisms, or connected systems.

5. Configuration and Security Review

Configuration reviews help identify security weaknesses that may arise from improper settings, unnecessary services, weak access controls, or insufficient hardening.

These assessments can complement automated vulnerability scanning and penetration testing.

Why Choose Cyberintelsys?

Cybersecurity in the maritime sector requires more than identifying generic IT vulnerabilities. Testing needs to consider system interdependencies, operational availability, network architecture, and the potential consequences of security weaknesses.

Cyberintelsys brings a security-testing approach focused on identifying vulnerabilities and providing actionable remediation guidance.

Key advantages include:

  • CREST accreditation: Cyberintelsys is CREST-accredited for Vulnerability Assessment and Penetration Testing.
  • Risk-focused testing: Assessments are structured around the potential security and operational impact of identified weaknesses.
  • Technical depth: Testing can combine vulnerability assessment, penetration testing, network analysis, and security configuration review.
  • Structured reporting: Findings are documented with evidence, risk context, and remediation recommendations.
  • Lifecycle perspective: Security testing can be incorporated into relevant stages of a new-build vessel project rather than being treated only as a final-stage activity.
  • Industry-aligned approach: Assessments can be structured with reference to applicable cybersecurity requirements, including IACS UR E26 and E27 where relevant.

Contact Cyberintelsys

As vessels become more connected, cybersecurity must become an integral part of new-build design, integration, commissioning, and security assurance.

Security testing aligned with IACS UR E26 and E27 can help identify weaknesses across vessel networks, onboard systems, equipment, and connected technologies before they create greater operational or security risks.

Whether the objective is to assess vulnerabilities, validate security controls, strengthen network resilience, or support applicable cybersecurity requirements, early testing can provide valuable visibility into the security posture of a new-build vessel.

Contact Cyberintelsys to discuss your maritime cybersecurity testing requirements and strengthen the security and resilience of your new-build vessel environment.

Reach out to our professionals