Digital

OT and IT as a Classification Topic

By Joshua Kantner · April 2026 · OceanSphere Consulting

Why the Traditional Separation No Longer Holds

For decades, OT (Operational Technology) and IT (Information Technology) onboard existed in separate worlds. Automation ran on proprietary bus systems, navigation on dedicated networks, and IT was limited to a few PCs in the master's office. This separation was never planned — it was a side effect of the systems being technologically incompatible.

This has fundamentally changed. Modern automation systems communicate via Ethernet. ECDIS, radar and AIS share network infrastructure. Power management systems send data to shore-based analysis platforms. Alarm management systems aggregate information from dozens of sources over a shared network. The technological convergence of OT and IT is already reality on modern vessels.

For classification, this has far-reaching consequences. Previously, automation systems were assessed by their function — does the system do what it should? Now the question is added: is the system also cyber-resilient? Can an attack on the IT network affect OT systems? Are the transition points between IT and OT controlled?

IACS responded with UR E26 and E27, establishing cyber resilience as a classification requirement. But implementation meets an industry where the organisational separation of IT and OT is often more deeply rooted than the technical one. The superintendent looks after the machinery, the IT department handles email and SAP. Who looks after the VSAT system that connects both?

Which Systems Are Being Reassessed

The reassessment affects all systems sitting at the interface between OT and IT or bridging both domains. Specifically these are:

Automation systems: modern alarm and monitoring systems (AMS) communicate via Ethernet and often have web interfaces for configuration. They are functionally OT but technologically IT. A compromised AMS server can suppress alarms or display false states — with direct safety consequences.

Bridge systems: ECDIS, radar, AIS and autopilot are increasingly networked. Integration through INS (Integrated Navigation Systems) creates dependencies: if the central network fails, potentially all navigation systems are affected simultaneously. Class therefore no longer assesses only the individual function but also the resilience of the overall architecture.

Power electronics: power management systems on vessels with electric propulsion or DP systems are safety-critical. If a PMS is compromised and incorrectly connects or disconnects generators, this can cause a blackout — on a DP vessel with potentially catastrophic consequences.

Remote access architecture: VSAT systems, OEM VPN tunnels and shore-to-ship connections are the bridge between the internet and onboard systems. They fall into no classic domain — neither IT nor OT — and are therefore often systematically managed by nobody. This is precisely what makes them the most critical point in the overall architecture.

Free Initial Consultation Independent marine engineering consulting. We find a solution.
Contact

Why This Matters for Project Teams

In newbuilding projects and major retrofits, IT and OT decisions are traditionally made in separate project tracks. The automation supplier defines their network, the navigation supplier theirs, and the IT department handles VSAT and crew internet. At the end, three uncoordinated networks meet, and integration becomes improvisation.

UR E26 requires that the network topology be planned as an overall system. This requires an integrator — someone who understands how OT and IT systems interact, which data flows exist between domains and where controlled transitions are needed. In practice this is often neither the automation engineer nor the IT manager but a role that must be newly created.

For project teams this has concrete implications for the schedule. Cyber aspects must be considered during the specification phase, not only during commissioning. The network topology must be established before subsystems are ordered so that suppliers can configure their systems accordingly. FAT and SAT must be extended with cyber tests.

This means more coordination effort but prevents the expensive remediation phase before delivery. Projects that treat IT and OT as one networked domain from the outset have fewer surprises in the final phase than those that ignore the topic until the end.

What Operators Should Derive Organisationally

The technological convergence of OT and IT demands an organisational response. Operators must define responsibilities more clearly and actively manage the interfaces between departments. The question "Who is responsible for cyber security onboard?" must have a clear answer — and this answer must be embedded in the SMS.

In practice, various models have emerged. Some shipping companies have placed responsibility with the superintendent because they know the onboard systems best. Others have created a dedicated cyber responsible party who mediates between IT and technical management. Still others have anchored the topic with the DPA (Designated Person Ashore) because they are already responsible for the SMS as a whole.

None of these models is inherently better than the others. What matters is that the role is clearly defined, that the responsible person has or receives the necessary competencies, and that the interfaces between IT department, technical management and onboard operations function. A superintendent who is responsible for cyber but has no access to network diagnostic tools and has received no training will not be able to fill the role.

Technical Deep-Dive: OT/IT Convergence in Practice

The convergence of OT and IT onboard can be illustrated with concrete examples. A modern vessel typically has the following network domains: the automation network (Kongsberg, Wärtsilä, ABB or others — proprietary protocol over Ethernet), the navigation network (ECDIS, radar, AIS — increasingly over standardised Ethernet), the administrative network (email, ERP access, document management), the crew welfare network (internet for crew) and the shore-to-ship network (VSAT, 4G/5G, Fleetbroadband).

In theory these domains are separate. In practice there are numerous transitions: the automation server sends operational data to a cloud platform ashore — via the VSAT network. The ECDIS computer receives chart updates via the internet. The superintendent accesses the automation network via VPN to review logs. Each of these transitions is a point where the OT/IT boundary is breached.

The IEC 62443 standard, considered the benchmark in industrial automation, provides a useful framework for segmentation. It defines zones (groups of systems with the same protection level) and conduits (controlled transitions between zones). Applied to the maritime context this means: automation is one zone, navigation another, crew internet a third. Every data flow between these zones must pass through a controlled conduit — a firewall, application gateway or data diode.

The challenge lies in implementation. Many maritime OEMs have not developed their systems according to IEC 62443. Hardening guidelines are missing, network requirements are not documented, and the systems assume access patterns that conflict with strict segmentation. Here, operators and integrators must find pragmatic compromises — without undermining security integrity.

Case Context: When Class Asks for Network Plans

An operator brings an 8-year-old container feeder to an intermediate survey. The class surveyor asks for the current network plan. The superintendent shows the plan from build time — but since delivery a new VSAT system was installed, the ballast water treatment system was retrofitted and the automation server was replaced with a newer model. None of these changes is documented in the network plan.

The surveyor finds that the VSAT system is connected to the automation network via an uncontrolled switch — a configuration set up during VSAT installation as a "temporary solution" that was never cleaned up. The result is a finding that must be closed by the next survey.

This scenario is not an exception but the rule. Most existing vessels have network topologies that have grown over the years and no longer match documentation. For operators this is a clear signal: updating network documentation should be part of every major system change — not an afterthought that surfaces during a survey.

Decision Framework: Organisational Realignment

Operators wanting to address OT/IT convergence organisationally should prioritise three steps. First: appoint someone responsible for the network integrity of the vessel — not for IT or OT individually but for the overall topology. Second: document every network intervention — every new installation, every reconfiguration, every remote access point. Third: formalise the interface between IT department and technical management — joint reviews, aligned decision processes, shared responsibility for cyber topics.

The effort is manageable. The benefit — fewer findings at surveys, better oversight during incidents, clearer decision paths — is substantial.

Key Takeaways

Related Articles

FAQ

Why is this a classification topic?
Because digital failures can affect safety-critical vessel functions.
Which areas are affected?
Automation, bridge, power supply and systems with remote access.
Most common organisational mistake?
Keeping IT and engineering separate despite interconnected systems.

Ready for a solution?

Free initial consultation – we analyze your situation and find the best path forward.

Request Consulting