BIMCO Cyber Security
Evidence request list. 26 controls, 26 carrying auditor artefact guidance. Generated from the compliance knowledge graph on 11 September 2026. Published by The Art of Service.
BIMCO Ch10: Respond and Recover
Incident response. The company should respond to cyber incidents following the four phases (preparation, detection and analysis, containment/eradication/recovery, and post-incident activity), with onboard and shore coordination.
- Incident response plan following the four phases
- Ship-shore coordination and escalation procedures
- Incident records and post-incident reviews
- No incident response plan
- No ship-shore coordination
- Post-incident review not performed
Recovery plan. The company should maintain a recovery plan to restore affected shipboard systems and safe operation following a cyber incident.
- Recovery plan for affected shipboard systems
- Recovery priorities aligned to safety and operations
- Recovery testing/exercise records
- No recovery plan
- Recovery priorities undefined
- Recovery untested
Data recovery capability. The company should maintain backups and a data recovery capability for critical shipboard data and system configurations.
- Backup regime for critical data and OT configurations
- Tested restoration of backups
- Offline/immutable backup protection against ransomware
- No backups of critical data/config
- Restoration untested
- Backups not protected from compromise
Investigating cyber incidents. The company should investigate cyber incidents to determine root cause and inform improvements, preserving evidence where appropriate.
- Incident investigation/root-cause records
- Evidence preservation procedures
- Feedback of lessons learned into the risk assessment and plans
- Incidents not investigated
- No root-cause analysis
- Lessons not fed back
BIMCO Ch1: Cyber Security and Risk Management
Senior management involvement. The company's senior management should be involved in and own cyber risk management, integrating it with the safety management system and the company's overall risk management.
- Evidence of senior-management ownership of the cyber risk programme
- Integration of cyber risk into the Safety Management System (SMS)
- Management review records of cyber risk
- Cyber risk not owned by senior management
- Not integrated with the SMS
- No management review
Roles, responsibilities and tasks. Clear roles, responsibilities and tasks for cyber risk management should be defined across the company and onboard, including ship and shore personnel.
- Documented cyber roles and responsibilities (ship and shore)
- Assignment of a responsible person/function
- Task allocation for cyber risk activities
- Roles undefined or unassigned
- No ship/shore split of responsibility
- Accountability unclear
Differences between IT and OT systems. The Guidelines require recognising the differences between information technology (IT) and operational technology (OT) systems onboard and managing the distinct risks of OT (navigation, propulsion, cargo and other shipboard systems).
- Inventory distinguishing IT and OT systems onboard
- Risk treatment that accounts for OT availability/safety constraints
- Segregation/interface controls between IT and OT
- IT and OT not distinguished
- OT safety constraints ignored in controls
- No IT/OT interface management
Plans and procedures. The company should develop cyber security plans and procedures, embedded in the SMS, covering protection, detection, response and recovery for ship and shore.
- Cyber security plans and procedures embedded in the SMS
- Onboard procedures for protection/detection/response/recovery
- Document control and review of the plans
- No documented cyber plans/procedures
- Plans not embedded in the SMS
- Plans not reviewed/updated
Relationship with vendors and external parties. The company should manage cyber risk arising from vendors, service providers and other external parties that connect to or service ship systems.
- Cyber requirements in vendor/service contracts
- Control of vendor remote access and onboard service visits
- Assessment of vendor cyber risk
- Vendor access uncontrolled
- No cyber terms in contracts
- Vendor risk not assessed
BIMCO Ch2: Identify Threats
Threat actors. The Guidelines require identifying the threat actors relevant to the maritime context (e.g. opportunists, activists, criminals, state-sponsored actors and insiders).
- Documented assessment of relevant maritime threat actors
- Use of maritime threat intelligence sources
- Periodic update of the threat picture
- Threat actors not identified
- No maritime threat intelligence
- Threat picture not updated
Types of cyber threats. The company should identify the types of cyber threats (untargeted and targeted, including malware, phishing, social engineering and OT-specific threats) that could affect ship systems.
- Catalogue of relevant cyber threat types (targeted and untargeted)
- Mapping of threats to vulnerable shipboard systems
- Awareness material reflecting current threat types
- Threat types not catalogued
- OT-specific threats omitted
- Threats not linked to systems
BIMCO Ch3: Identify Vulnerabilities
Common vulnerabilities. The company should identify common vulnerabilities in shipboard IT and OT (e.g. obsolete systems, unpatched software, weak access controls, lack of segregation).
- Vulnerability assessment of shipboard IT/OT
- Register of identified vulnerabilities and remediation
- Review of obsolete/unsupported systems
- Vulnerabilities not assessed
- No remediation tracking
- Obsolete systems unmanaged
Typical vulnerable systems. The Guidelines identify typical vulnerable shipboard systems (navigation/ECDIS, propulsion and machinery, cargo management, communication, access control and administrative systems) to be assessed.
- Inventory of typical vulnerable shipboard systems
- Per-system vulnerability assessment
- Prioritisation by criticality to safety and operations
- Critical shipboard systems not assessed
- Navigation/propulsion OT omitted
- No criticality prioritisation
Ship to shore interface. The company should address vulnerabilities at the ship-to-shore interface (data exchange, remote connections, shore-based management of ship systems).
- Mapping of ship-to-shore data flows and connections
- Controls securing the ship-to-shore interface
- Monitoring of shore-initiated connections
- Ship-to-shore connections unmapped
- Interface not secured
- Shore connections unmonitored
Remote access. The company should manage the cyber risks of remote access to shipboard systems (by shore staff, vendors and service providers), including authentication and monitoring.
- Remote access policy for shipboard systems
- Strong authentication and logging of remote sessions
- Approval and time-bounding of vendor remote access
- Remote access uncontrolled
- No authentication/logging
- Vendor remote access not approved
System and software maintenance. The company should manage vulnerabilities arising from system and software maintenance, including patching, updates and maintenance by third parties.
- Patch/update procedures for IT and OT (with OT change-control constraints)
- Control of maintenance media and third-party maintenance
- Records of maintenance activities
- No patch/update process
- Maintenance media uncontrolled
- Third-party maintenance unlogged
BIMCO Ch4-6: Likelihood, Impact and Risk Assessment
Assessing the likelihood. The likelihood of a cyber incident is assessed as the product of threat and vulnerability, and quantified to inform the risk assessment.
- Likelihood assessment combining threat and vulnerability
- Documented likelihood ratings per scenario
- Basis/assumptions for likelihood quantification
- Likelihood not assessed
- No threat x vulnerability basis
- Ratings undocumented
Impact assessment. The impact of a cyber incident is assessed against the confidentiality, integrity and availability (CIA) of affected systems, with particular weight on availability and integrity for OT and safety-critical systems.
- Impact assessment using the CIA model per system
- Consideration of safety, environmental and operational impact for OT
- Impact ratings feeding the risk assessment
- Impact not assessed against CIA
- Safety/operational impact of OT ignored
- Impact not linked to risk
Risk assessment. The company should conduct a cyber risk assessment following the four phases (identify, assess likelihood and impact, evaluate and prioritise risk, and decide treatment), documented and periodically reviewed.
- Documented cyber risk assessment following the four phases
- Risk register with prioritised risks and treatment decisions
- Periodic review/update of the assessment
- No structured risk assessment
- Risks not prioritised or treated
- Assessment not reviewed
Third party risk assessments. The company should assess cyber risks introduced by third parties (vendors, ports, agents) and reflect them in the risk assessment and contracts.
- Assessment of third-party cyber risk
- Reflection of third-party risk in contracts and the risk register
- Monitoring of significant third parties
- Third-party risk not assessed
- Not reflected in contracts
- No monitoring of third parties
BIMCO Ch7: Develop Protection Measures
Defence in depth and in breadth. Protection should apply layered (defence in depth) and broad (defence in breadth) measures across people, processes and technology for both IT and OT.
- Layered protection architecture for IT and OT
- Coverage of people, process and technology controls
- Network segmentation between IT, OT and external networks
- Single-layer protection only
- People/process controls missing
- No segmentation
Technical protection measures. The company should implement technical protections including network segmentation, access control, wireless access control, system hardening, malware protection and secure configuration of shipboard systems.
- Network segmentation and boundary controls onboard
- Access control and wireless access control configurations
- System hardening and secure-configuration baselines
- No segmentation between IT/OT
- Default/weak configurations
- Wireless access uncontrolled
Procedural protection measures. The company should implement procedural protections including crew training and awareness, physical and removable media controls, upgrade/patch procedures and access management.
- Crew cyber awareness and training programme and records
- Physical and removable-media control procedures
- Access management procedures (joiner/mover/leaver, visitors)
- No crew training
- Removable media uncontrolled
- Access not managed
BIMCO Ch8: Develop Detection Measures
Detection measures. The company should implement detection, logging, blocking and alerting to identify cyber incidents affecting shipboard systems in a timely manner.
- Logging and monitoring of shipboard IT/OT where feasible
- Alerting and blocking mechanisms
- Review of logs and alerts
- No logging/monitoring onboard
- No alerting
- Logs not reviewed
Malware detection. The company should deploy malware detection and prevention appropriate to IT and OT, recognising constraints on OT systems.
- Malware detection/prevention on IT systems
- Compensating controls where OT cannot run anti-malware
- Update process for detection signatures
- No malware detection
- OT compensating controls absent
- Signatures not updated
BIMCO Ch9: Establish Contingency Plans
Establish contingency plans. The company should establish contingency plans to maintain or restore safe operation of the ship in the event of a cyber incident affecting critical systems, including manual/fallback procedures.
- Contingency plans for loss of critical IT/OT systems
- Manual or fallback operating procedures
- Testing of contingency arrangements
- No contingency plans for critical systems
- No manual fallback
- Contingency not tested
Assembled from the framework’s own control set, so this list is regenerated rather than written and stays current as the graph does.