Compliance

Crew Awareness vs. Technical Measures

By Joshua Kantner · April 2026 · OceanSphere Consulting

Why the Comparison Is Misleading

The debate "crew awareness or technical measures?" is regularly conducted in the maritime industry — and it regularly leads astray. The question suggests that one must choose one side. In reality both are indispensable and only effective in combination.

Technical measures without a trained crew are like a fire suppression system without anyone who recognises the alarm. A firewall protects the network — but when a crew member plugs an infected USB stick directly into an automation PC because they do not know the instruction, they bypass every network protection measure. Conversely, the best awareness programme is of little use when the network is configured so that a single compromised computer can reach all systems.

IACS addressed this clearly in UR E26: cyber resilience requires both technical and organisational measures. The IMO Guidelines MSC-FAL.1/Circ.3 likewise emphasise that training and technology must go hand in hand. The approach must be holistic — defence in depth, as security terminology calls it. Multiple protective layers that complement each other.

The practical challenge lies in aligning both levels. Awareness training must reflect the actual technical circumstances onboard. And technical measures must account for the fact that crew must work with the systems — under time pressure, during watch handovers, under adverse conditions.

Where Technical Measures Reach Their Limits

Technical measures reach their limits where people interact with systems, suppliers and external interfaces. Four areas are particularly critical:

First: OEM remote maintenance. When an automation technician connects to the automation server via VPN, this is technically an authorised access. Whether the technician actually is who they claim to be, whether they perform only the agreed work and whether the session is properly terminated afterwards — technology alone cannot ensure this. A trained person onboard is needed to monitor and document the access.

Second: software updates. OEMs deliver updates via USB stick or remote session. A technical system can scan the USB stick for malware — but whether the stick actually comes from the OEM and not from an unknown source can only be verified by a person who knows the process and checks the origin.

Third: alarms and anomalies. A monitoring system can detect unusual network activity and generate an alarm. But the decision whether this is a regular operation (e.g. a planned update) or an incident requires human judgement. Without trained personnel who can correctly assess alarms, they are either ignored or trigger unjustified alarm.

Fourth: physical access. A crew member or yard worker who connects a device to a network port during a port call bypasses every network-side protection measure. Awareness must convey why unknown devices must not be connected and which ports should be physically secured.

Free Initial Consultation Independent marine engineering consulting. We find a solution.
Contact

What Crew Awareness Should Actually Achieve

Crew awareness in the cyber context is not the annual PowerPoint presentation about phishing emails. It is about establishing safe routines embedded in daily onboard operations. Four areas are central:

Access control: who may access which systems? Crew members must know that default passwords must be changed, that credentials must not be shared and that every access to safety-critical systems must be traceable. This is not IT training — it is part of onboard organisation.

Handling removable media: USB sticks are the most common physical infection vector onboard. The crew must understand why unknown USB sticks must not be connected to networked systems. This affects not only the master but everyone with access to a PC — from the engineer to the cadet.

Reporting: when something unusual happens — a system responds slowly, an unknown window opens, a network device shows unexpected activity — the crew must know whom to report it to and that reporting will not result in punishment. Many incidents go unreported because the crew fears having done something wrong.

Remote access: when an OEM technician requests remote access, the crew must know what to check and document. Who authorised the access? To which system? For what duration? What was done? This information must be recorded — not as bureaucracy but as the basis for traceability.

How Both Levels Are Meaningfully Connected

Connecting technical measures and crew awareness succeeds when both build on the same risk basis. Concretely this means: the risk analysis identifies the critical CBS and their vulnerabilities. From this, technical measures are derived (segmentation, access control, monitoring) and organisational procedures (instructions, reporting protocols, training content).

The SMS is the natural place for this integration. Cyber procedures should not stand as a separate chapter there but be embedded in existing sections — navigation, machinery operation, emergency procedures. This way cyber becomes part of normal onboard organisation and is not perceived as a foreign element.

A practical example: the procedure for OEM remote maintenance. Technically, VPN access is routed through a controlled conduit and automatically disconnected after the session ends. Organisationally, the Chief Engineer documents the access in the logbook, verifies the technician's identity and confirms completion. Both interlock — the technical system limits access, the organisational measure ensures oversight.

Technical Deep-Dive: Defence in Depth Onboard

Defence in depth is not a marketing term but a proven security concept. It is based on the assumption that no single protective measure is perfect. Instead, multiple protective layers are stacked so that the failure of one layer is caught by the next.

Applied to a vessel this looks as follows: Layer 1 is network perimeter control — the firewall between VSAT and the onboard network. Layer 2 is network segmentation — separating OT, navigation and crew internet. Layer 3 is system hardening — deactivating unnecessary services, changing default passwords, applying patches. Layer 4 is access control — who may access which systems. Layer 5 is monitoring — detecting anomalies. Layer 6 is crew awareness — the human element that closes the gaps between technical layers.

Each layer on its own is incomplete. The firewall can be bypassed (USB stick). Segmentation can be breached (uncontrolled switch). Hardening can become outdated (missing patches). Access control can fail (shared passwords). Monitoring can be overwhelmed (too many alarms). But in combination, the multi-layered concept creates a resilience far exceeding the sum of individual measures.

For operators this means: do not invest in a single technology and hope it covers everything. Instead build a balanced portfolio of measures — technical and organisational — that is internally consistent and regularly reviewed.

Case Context: Awareness Programmes That Work

The most effective awareness programmes in shipping are those that are concrete and close to onboard reality. Generic online courses about phishing emails ashore are of limited use for a crew working with automation systems and navigation equipment.

What works: training based on the actual systems onboard. Which systems are networked? Where are the remote access points? What do we do when a system behaves unusually? These questions should be covered in every induction of new crew members and in regular refreshers.

Tabletop exercises have proven particularly effective. A scenario is walked through: "ECDIS shows a blue screen. What are the next steps?" The crew discusses the options, identifies gaps in the procedure and develops a more sustainable understanding of the relationships. Such exercises require no equipment, only one hour of time — and they produce a more lasting understanding than any presentation.

Key Takeaways

Related Articles

FAQ

Is crew awareness sufficient?
No. It is only effective in combination with system architecture.
Are technical measures more important?
Both are indispensable. Only together do they create robust security.
What should awareness cover?
Real routines: access, removable media, alarms and unusual system behaviour.

Ready for a solution?

Free initial consultation – we analyze your situation and find the best path forward.

Request Consulting