IMCSO launches cybersecurity methodology

Importer
Ship coming into port with crane on the right

The methodology provides a standardised framework for accredited cyber consultants and maritime personnel, outlining test scope to ensure consistent, effective cybersecurity assessments.

It is mandatory for cybersecurity practitioners to comply with these standards to maintain their status in the IMCSO’s Certified Supplier Registry, yet there is currently no way in the maritime sector for governing the quality of assessments, explained Campbell Murray, chief executive at the IMCSO.

“This methodology will set a precedent by providing a set of criteria that assessors must observe when on engagement and against which maritime security can be measured,” said Murray.

The tests will evaluate security across ten categories of operational technology (OT), including navigation, propulsion, safety systems, cargo handling and compliance.

These assessments may take place at sea, on shore, or a combination of both. Unlike other sectors, the maritime industry lacks comprehensive OT standards, making this methodology a crucial step forward in addressing security gaps.

Additionally, the captain and crew of assessed vessels will undergo pre-assessment training to become cyber-ready, ensuring they understand the process and its findings.

The IMCSO methodology includes key components like rules of engagement, risk management, and reporting protocols. It offers standardised outputs, providing clear recommendations to address security vulnerabilities.

The results of these assessments will be added to the Cyber Risk Registry, offering insights to stakeholders such as port authorities, insurance companies and industry partners, while supporting broader efforts to enhance cyber resilience across the maritime sector.