Introduction
The maritime industry is undergoing rapid digital transformation. Modern new-build vessels increasingly depend on interconnected Information Technology (IT), Operational Technology (OT), navigation systems, communication networks, automation systems, monitoring platforms, and computer-based onboard equipment.
This connectivity improves operational efficiency and enables advanced vessel management. However, it also creates a broader cyber attack surface. A vulnerability in an onboard system, network device, remote-access interface, or connected piece of equipment could potentially affect operational availability, data integrity, system reliability, or safety-related functions.
To address these evolving risks, the International Association of Classification Societies (IACS) introduced Unified Requirements (UR) E26 and E27 for cyber resilience.
UR E26 addresses the cyber resilience of ships, including the secure integration of IT and OT equipment throughout the vessel lifecycle. UR E27 focuses on the cyber resilience of onboard systems and equipment, including system integrity, hardening, interfaces, and product development considerations.
Vulnerability Assessment (VA) and Penetration Testing (PT) can form important technical security activities within a broader cybersecurity programme for new-build vessels. When planned according to the applicable vessel scope and project requirements, these assessments can help identify and validate security weaknesses before a vessel enters operational service.
Understanding IACS UR E26 and E27
IACS Unified Requirements establish minimum requirements that are incorporated into the rules and practices of IACS Member Societies, subject to their respective processes. Individual Member Societies can establish more stringent requirements.
UR E26 and E27 address different layers of vessel cyber resilience.
1. IACS UR E26 – Cyber Resilience of Ships
UR E26 considers the ship as a collective cyber-physical environment. It aims to address the secure integration of IT and OT equipment into the vessel’s network across design, construction, commissioning, and operational stages.
IACS identifies five key areas within E26:
- Equipment identification
- Protection
- Attack detection
- Response
- Recovery
These areas reflect the need for a vessel to do more than simply prevent cyberattacks. A resilient vessel should also have appropriate capabilities to identify incidents, respond to them, and recover affected systems.
2. IACS UR E27 – Cyber Resilience of Onboard Systems and Equipment
UR E27 focuses more closely on the systems and equipment installed onboard.
The requirement addresses cyber resilience considerations such as system integrity, security hardening, interfaces between users and computer-based systems, and aspects of product design and development.
This makes cybersecurity an important consideration before equipment is integrated into a vessel’s operational environment.
Why Vulnerability Assessment and Penetration Testing Matter
Vulnerability Assessment and Penetration Testing serve different purposes, and using both approaches can provide a more comprehensive understanding of technical security weaknesses.
1. Vulnerability Assessment Identifies Security Weaknesses
Vulnerability Assessment systematically examines systems and infrastructure for known vulnerabilities, insecure configurations, outdated software, exposed services, weak authentication mechanisms, and other weaknesses.
For a new-build vessel, assessment can help identify vulnerabilities before systems become deeply embedded into the operational environment.
2. Penetration Testing Validates Exploitability
Penetration Testing takes the assessment further by safely attempting to validate whether selected security weaknesses can actually be exploited.
This can help distinguish theoretical vulnerabilities from weaknesses that may create a realistic attack path within the agreed testing scope.
3. Testing Helps Identify Weaknesses Before Operational Deployment
Addressing cybersecurity weaknesses during the design, construction, integration, or commissioning stages can be more efficient than attempting to correct them after the vessel is operational.
Testing can provide project stakeholders with technical evidence that supports remediation decisions.
4. IT and OT Security Require Careful Consideration
A new-build vessel may contain several interconnected environments. These can include:
- Navigation systems
- Engine and machinery control systems
- Monitoring systems
- Communication systems
- Vessel management systems
- Servers and workstations
- Network infrastructure
- Remote-access systems
- Vendor-connected equipment
The interaction between these environments makes network architecture and segmentation particularly important.
Our Methodology for Vulnerability Assessment and Penetration Testing Based on IACS UR E26 and E27
Our methodology begins by defining the authorised testing scope and understanding the vessel’s architecture, onboard systems, network connectivity, critical assets, interfaces, and applicable project requirements before conducting controlled technical assessments.
1. Scope and Requirements Review
The first stage establishes what systems, networks, applications, devices, and interfaces are within the approved assessment scope.
Available architecture diagrams, asset inventories, system documentation, security requirements, and relevant technical information are reviewed.
This helps ensure that testing is appropriately planned for the vessel environment.
2. Asset and Attack Surface Identification
Relevant assets are identified and categorised according to their function and connectivity.
The review can include:
- Network devices
- Servers
- Workstations
- Applications
- Onboard equipment
- Communication interfaces
- Remote-access services
- Open ports and network services
- External connectivity
The objective is to understand where potential attack paths could exist.
3. Vulnerability Assessment
A structured vulnerability assessment is performed across the agreed scope.
Activities may include:
- Vulnerability scanning
- Service identification
- Software and version analysis
- Configuration assessment
- Patch-level review
- Authentication testing
- Identification of insecure protocols
- Detection of exposed services
Findings are analysed to distinguish meaningful security risks from lower-impact observations.
4. Network Security Assessment
Network security is examined to understand how systems communicate with each other.
The assessment can consider:
- Network segmentation
- Access controls
- Firewall configurations
- Communication paths
- Unnecessary services
- Trust relationships
- Remote access
- IT/OT connectivity
This is particularly important in environments where compromise of one system could potentially create a pathway toward another environment.
5. Controlled Penetration Testing
Penetration testing is performed within an explicitly agreed scope and under carefully controlled conditions.
Depending on the project, testing may evaluate whether identified weaknesses can be exploited to:
- Gain unauthorised access
- Bypass authentication controls
- Escalate privileges
- Access sensitive information
- Move between network segments
- Exploit vulnerable services
- Demonstrate realistic attack paths
Testing methods are selected according to the operational sensitivity of the vessel environment.
6. Web Application and Interface Testing
Where vessel systems include web-based interfaces, portals, dashboards, APIs, or management applications, these components can be assessed for application-layer vulnerabilities.
Testing may examine authentication, authorisation, input validation, session management, access control, and other relevant security controls.
7. Risk Analysis and Reporting
Identified vulnerabilities are documented with sufficient technical evidence to support remediation.
Reports can include:
- Vulnerability description
- Affected asset
- Severity or risk rating
- Technical evidence
- Potential impact
- Attack scenario
- Recommended remediation
- Retesting requirements
This enables technical and project teams to prioritise remediation based on risk.
8. Remediation and Retesting
After corrective actions are implemented, identified vulnerabilities can be retested.
Retesting helps verify whether the remediation has successfully addressed the original security weakness and whether the vulnerability remains exploitable.
Cyberintelsys Services for New-Build Vessel Security
Cyberintelsys is a CREST-accredited cybersecurity company for Vulnerability Assessment (VA) and Penetration Testing (PT), delivering industry-recognized security testing services for organizations across multiple sectors.
Security testing can be structured around the technology, architecture, testing boundaries, and applicable requirements of a new-build vessel.
1. Vulnerability Assessment
Vulnerability Assessment provides systematic visibility into technical weaknesses across approved systems.
The assessment can identify:
- Known vulnerabilities
- Missing patches
- Insecure configurations
- Weak services
- Exposed ports
- Outdated software
- Authentication weaknesses
- Network security issues
This helps stakeholders prioritise weaknesses before they become operational security concerns.
2. Penetration Testing
Penetration Testing validates selected vulnerabilities through controlled security testing.
Depending on the scope, testing can assess:
- External attack surfaces
- Internal networks
- Network infrastructure
- Applications
- APIs
- Authentication mechanisms
- Access controls
- Segmentation
- Remote-access pathways
For vessel environments, testing is planned carefully to avoid unnecessary disruption to operational or safety-critical systems.
3. Network Penetration Testing
Network penetration testing evaluates whether network-level weaknesses could provide unauthorised access or enable movement between connected environments.
This is particularly relevant for vessels containing interconnected IT and OT systems.
4. Web Application and API Penetration Testing
Web-based interfaces and APIs can introduce application-layer vulnerabilities into maritime environments.
Testing can help identify weaknesses in authentication, authorisation, session management, input validation, business logic, and access controls.
5. Security Configuration Assessment
Configuration reviews complement VA and PT by examining whether devices and systems are securely configured.
This can help identify unnecessary services, weak security settings, excessive privileges, insecure protocols, and other configuration-related weaknesses.
6. Retesting and Remediation Validation
After vulnerabilities are remediated, retesting can confirm whether the corrective measures have effectively resolved the identified issues.
This creates measurable closure for security findings.
Why Choose Cyberintelsys?
Effective maritime cybersecurity testing requires an understanding of both technical security risks and the operational sensitivity of vessel environments.
Cyberintelsys focuses on delivering structured security assessments that generate actionable technical findings rather than simply producing vulnerability lists.
Key considerations include:
- CREST accreditation: Cyberintelsys is CREST-accredited for Vulnerability Assessment and Penetration Testing.
- Risk-based assessment: Findings can be evaluated according to their potential security and operational impact.
- Technical testing expertise: VA, PT, network security testing, application testing, and configuration assessment can be combined according to scope.
- Structured reporting: Findings include technical evidence and practical remediation recommendations.
- Controlled testing: Testing boundaries can be established to minimise risks to operational environments.
- Requirement-focused approach: Assessments can be planned based on applicable IACS UR E26 and E27 requirements and the specific vessel project.
Contact Cyberintelsys
Cybersecurity should be considered throughout the lifecycle of a new-build vessel rather than only after the vessel enters service.
Vulnerability Assessment and Penetration Testing based on applicable IACS UR E26 and E27 requirements can help identify weaknesses across onboard systems, networks, applications, interfaces, and connected infrastructure.
Early identification and remediation can strengthen cyber resilience while giving shipbuilders, owners, equipment suppliers, system integrators, and other stakeholders greater visibility into the vessel’s technical security posture.
Contact Cyberintelsys to discuss Vulnerability Assessment and Penetration Testing requirements for your new-build vessel and strengthen its cybersecurity readiness.