A widespread misconception: cyber audits onboard are pure document checks. The surveyor arrives, looks at the folders, checks whether a cyber chapter exists in the SMS and ticks the box. This may still have been the case in 2021, when integration of cyber risks into the SMS (per MSC.428(98)) had just become mandatory. Today — and particularly for vessels under UR E26/E27 — the survey depth goes considerably further.
Modern cyber audits verify the coherence between documentation, technical reality and organisational understanding. Does the network plan match the actual installation? Does the crew know the procedures described in the SMS? Are the technical measures marked as "implemented" in the risk assessment actually in place?
This is a fundamental difference from a pure paper check. Presenting a well-written document is not enough. The auditor will ask: "Show me the network plan and then the actual network." They will ask: "Who last had remote access to the automation system, and where is that documented?" They will ask the Chief Engineer: "What do you do if ECDIS does not start tomorrow?"
Auditors increasingly come with a technical background. Whereas ISM auditors traditionally came from safety management, cyber aspects are now often assessed by surveyors with IT/OT experience. This changes the dynamic considerably.
Four areas regularly come into focus during cyber audits:
System inventory: is there a current register of all CBS onboard? Does it contain manufacturers, software versions, network connections and remote access points? Does it match the actual installation? An outdated or incomplete inventory is one of the most common findings.
Access control: how are user accounts on CBS managed? Are there individual accounts or are generic logins used? Are default passwords changed during commissioning? Is there an overview of who may access which systems? In practice, generic logins and unchanged default passwords are the rule, not the exception.
Remote access: which remote access possibilities exist? Who controls them? Is there a log showing who accessed what and when? Are permanent VPN tunnels documented? Auditors will specifically ask about OEM remote maintenance access — and expect a traceable answer.
Restart procedures: do recovery procedures exist for critical systems? Are they documented, known to the crew and tested? A recovery plan that nobody onboard knows is worthless. Auditors will ask spot-check questions such as: "What are your first three steps when the power management system fails?"
The greatest risk during cyber audits is the discrepancy between documentation and reality. When the network plan shows three separate network segments but onboard a single uncontrolled switch connects everything, that is a finding. When the risk assessment lists firewalls as a protective measure but no firewall is installed, that is a finding. When the SMS describes a remote access protocol but the Chief Engineer has never heard of it, that is a finding.
Auditors check for plausibility. They compare what is written with what they find onboard. This check is not destructive — it is not about searching for faults. It is about verifying that cyber risk management actually functions and does not merely exist on paper.
The most common plausibility gaps in practice: network plans showing the state at delivery but not subsequent changes (VSAT, new systems, computer replacements). Risk assessments created by external consultants with no connection to the actual systems onboard. SMS procedures formulated generically with no concrete instructions for the crew.
For operators this means: investing in current, accurate documentation is more important than investing in expensive technology. A well-documented vessel with a trained crew passes an audit better than a technically perfectly secured vessel whose documentation does not match.
The best preparation for a cyber audit is not audit preparation but a functioning cyber risk management in daily operations. Those who have this need not fear any auditor. Those who do not will be unable to simulate substance through short-term document preparation.
Nevertheless, there are pragmatic steps operators should review before a survey: first, update the network plan — does it match reality? Are there systems not captured? Second, check remote access — which VPN tunnels are active? Are all documented? Are there access points not deactivated since the last maintenance?
Third, brief the crew — not to memorise answers but to ensure that basic procedures are known. Who is responsible for cyber topics? What is reported and to whom? What are the first steps during a system failure?
Fourth, walk through realistic onboard scenarios: who may access which system? What happens during an ECDIS failure? How is remote access authorised and documented? These exercises are not merely audit preparation — they are the operational core of functioning cyber management.
The concrete survey practice varies between classification societies but follows a common pattern. For newbuildings under UR E26, the entire cyber documentation is surveyed: CBS inventory, network topology, risk assessment, protective measures, recovery procedures. The surveyor compares documentation with the actual installation and verifies that critical measures are implemented.
For existing vessels, the survey focuses on the SMS. Per MSC.428(98), cyber risks must be addressed in the SMS. The surveyor checks: is there a cyber chapter? Does it contain a risk assessment? Are procedures defined for remote access, software updates and incident response? Does the crew know these procedures?
Typical survey steps in detail: the surveyor asks to see the network plan and then walks through the engine room with the Chief Engineer to verify actual network connections. They ask for the ECDIS software version and compare it with the inventory. They check whether default passwords have been changed by observing a login attempt. They ask about the last remote access and check whether a log exists.
For findings, societies distinguish between observations (improvement recommendations) and non-conformities (deviations that must be corrected). A missing CBS inventory is typically a non-conformity. An outdated software version may be an observation if a mitigation measure is in place.
The five most common cyber findings during onboard audits, based on industry experience:
1. Network plan outdated or non-existent. Avoidance: update the network plan with every system change. A simple network diagram showing all CBS and their connections suffices as a basis.
2. No CBS inventory or incomplete. Avoidance: create an inventory containing at minimum system name, manufacturer, software version, operating system and network connection. Systematically complete during the next survey.
3. Default passwords not changed. Avoidance: change all default passwords at commissioning or at the latest during the next maintenance. Keep a list of changed credentials securely stored.
4. Remote access not documented. Avoidance: introduce a remote access logbook. For each access: date, system, technician, purpose, duration, authorised by. Paper-based is fine — as long as it is maintained.
5. No recovery procedure for navigation. Avoidance: create a simple, one-page document: what to do during ECDIS failure? Backup navigation? Who informs the company? Post in the bridge area and discuss once per quarter.
Free initial consultation – we analyze your situation and find the best path forward.
Request Consulting