Digital

Cyber Is a Superintendent Topic

By Joshua Kantner · April 2026 · OceanSphere Consulting

Why Superintendents Are Directly Affected

An increasing number of onboard systems are digitally networked and software-dependent.

What Tasks Arise from This

Understanding which systems are networked, where remote access is in use and how updates are managed.

Free Initial Consultation Independent marine engineering consulting. We find a solution.
Contact

Why Assigning Cyber Purely to IT Is Insufficient

A failure caused by faulty software has different consequences than an office IT incident.

How Superintendents Should Position Themselves

Pragmatically: system knowledge, critical dependencies and coordination with IT.

Technical Deep-Dive: Which Onboard Systems Are Cyber-Relevant

The common distinction between IT (information technology) and OT (operational technology) is the key to understanding for superintendents. IT systems on board include email, internet, administrative software – systems whose failure is inconvenient but not safety-critical. OT systems, by contrast, control or monitor physical processes: main engine control, alarm systems, navigation, ballast water management, power management systems.

The problem: the boundaries between IT and OT are increasingly blurred. Modern vessels have networked systems in which a compromised office network can potentially open access to OT systems. USB sticks used for software updates on control systems are a further attack vector. Remote monitoring connections that manufacturers use for diagnostics and maintenance create additional entry points.

For a superintendent, the following systems are particularly relevant: ECDIS (Electronic Chart Display and Information System), which when tampered with can lead to navigation errors. AIS (Automatic Identification System), which serves as input for collision avoidance. GMDSS (Global Maritime Distress and Safety System), whose failure impairs rescue capability. And the power management system, whose misoperation can lead to a blackout.

IACS Unified Requirements E26 and E27 address these risks for newbuilds from 2024. E26 defines requirements for the cyber resilience of the vessel, E27 for system suppliers. For existing vessels, these requirements do not apply directly – but the underlying risks are identical. Superintendents who manage existing fleets must therefore conduct their own risk assessments.

Practical Implications: What a Superintendent Can Concretely Do

The first step requires no IT expertise: a stocktake of networked systems on board. Which systems are connected to the network? Which have remote access capabilities? Which are updated via USB or external media? This stocktake can be conducted by the superintendent together with the chief engineer during a regular vessel visit.

The second step concerns access control. Who has remote access to onboard systems? Are the accesses documented, time-limited and assigned with clear responsibilities? In practice, remote access connections that were not deactivated after a manufacturer's service visit are frequently found – open doors that nobody monitors.

The third step is integrating cyber into existing processes. Cyber risks belong in the risk assessment of the ISM system. For every change to networked systems – software update, new hardware, new remote access – a brief cyber check should take place. This need not be a comprehensive analysis but a structured three-question check: what is being changed? Who has access? What happens in the event of a failure?

A fourth point concerns the crew. Crew awareness training for cyber topics has been an IMO requirement since 2021 under the ISM Code. But quality varies enormously. A superintendent can ensure that the training includes concrete onboard scenarios – not merely general advice on phishing and passwords.

Case Context: Regulation and Real Incidents

The regulatory landscape has tightened considerably in recent years. IMO Resolution MSC.428(98) has required all operators to integrate cyber risks into their ISM system since 2021. IACS UR E26/E27 apply to newbuilds from 2024. The EU NIS2 Directive captures maritime operators in member states from 2025.

Real incidents underscore the relevance: Maersk was hit by the NotPetya attack in 2017 – estimated cost of USD 300 million. Less spectacular but more frequent are targeted phishing attacks on shipping companies, falsified payment instructions and ransomware attacks on shore-side systems that indirectly affect vessel operations as well.

For superintendents, it is important to understand that PSC inspectors are increasingly paying attention to cyber aspects. The question "How is cyber addressed in your ISM system?" is now part of the standard repertoire. Those without a cogent answer risk deficiencies.

Decision Framework: Structuring Cyber Responsibility for Superintendents

Cyber is not the sole responsibility of the superintendent – but they must shoulder their part. The structure operates on three levels: 1) Knowledge: which onboard systems are networked and critical? 2) Process: are cyber risks documented in the ISM, and is there a review process for system changes? 3) Communication: is coordination with the IT department and manufacturers established?

The most common mistake is complete delegation to IT. IT can secure networks and patch software. But IT typically does not understand which onboard systems are safety-critical and which failures have operational consequences. This assessment can only be made by someone who knows the technical side of vessel operations – the superintendent.

Key Takeaways

Related Articles

FAQ

Working with Class and Flag State on Cyber

Superintendents increasingly need to treat cyber resilience as part of the normal survey and certification conversation rather than a separate IT matter handled elsewhere. Class societies now ask targeted questions during audits about how software changes on networked systems are documented and approved, and a superintendent who cannot describe this process puts the vessel's certification at risk regardless of how well the actual systems are secured.

Flag state expectations vary, but the general direction is the same: written evidence that cyber risk is considered within the ISM framework, not a verbal assurance that IT handles it. A simple one-page summary per vessel, covering which systems are networked, who has remote access, and when the last review took place, gives the superintendent something concrete to show an auditor.

Practical Steps for the Next Vessel Visit

A superintendent does not need a cybersecurity background to make real progress during a routine vessel visit. Walking the engine control room and bridge with the chief engineer and asking which systems have ever been connected to a laptop, a USB stick or a manufacturer's remote link produces a surprisingly complete picture in under an hour.

Checking whether default passwords have been changed on networked equipment and whether a list exists of who is authorised to make software changes closes two of the most common gaps found during incident investigations. Confirming that the most recent crew cyber training actually covered onboard scenarios, rather than generic office advice, is a quick way to judge whether the requirement was met in substance or only on paper.

Do superintendents need to become cyber specialists?
No. But they need sufficient understanding of the digital risks affecting technical systems.
Why is IT support alone not enough?
Because cyber impacts onboard technology, availability and safety.
Most important first step?
Make critical networked systems and access paths visible.

Ready for a solution?

Free initial consultation – we analyze your situation and find the best path forward.

Request Consulting