Cyber risk belongs in daily ship management
Cyber risk management connects people, systems and safe operation. It needs responsibilities and exercises as well as technical controls.
In 30 seconds
- IMO MSC.428(98) addresses cyber risk within the safety management system (SMS).
- The IMO maritime cyber guidance now links to MSC-FAL.1/Circ.3/Rev.3; always check the current source and applicable flag requirements.
- Define reporting, decision authority, response and recovery arrangements suited to the vessel.
Make it concrete
Run a tabletop drill: the office network is unavailable while the ship remains operational. Who reports, who authorises action, and which communications remain available?
- 01Assign responsibility
- 02Practise
- 03Review
Check your understanding
Is maritime cyber risk only the shore IT department’s responsibility?
- IMO MSC.428(98) addresses cyber risk within the safety management system (SMS).
- The IMO maritime cyber guidance now links to MSC-FAL.1/Circ.3/Rev.3; always check the current source and applicable flag requirements.
- Define reporting, decision authority, response and recovery arrangements suited to the vessel.
Go to the source
- Course notes · Nguyễn Văn Thư · An ninh mạng và khả năng chống chịu an ninh mạng trên tàu biển ↗
- IMO · Maritime cyber risk ↗
Sources reviewed: 13.09.2026