IMO MSC.428(98)Critical InfrastructureGlobalMaritime

IMO Maritime Cyber Risk Management

International Maritime Organization resolution requiring cyber risk management in safety management systems. Applies to all ships subject to ISM Code.

Get a Gap Assessment
The Mapping

What your auditor cites,
and what produces the evidence

The regulator's text is quoted below in italic, exactly as written. What follows each one is what the platform records, detects, or proves — not a claim about your compliance status, which no tool can confer.

IMO MSC.428(98)Resolution §2A record of accessAttribution to an individual

Cyber Risk Management

Maritime operators MUST address cyber risks in their Safety Management Systems.

A record of processing is only as good as the layer producing it. Real-time SQL auditing captures every statement against the data — the identity, the session, the client, the objects touched, the outcome — with no nightly batch window where activity goes unrecorded. Classification is what makes that a record of *regulated* data rather than a log of everything: it tells you which tables are in scope, so the register describes the processing you actually have to declare. Policy templates then produce it in the shape the framework asks for, instead of leaving you to assemble it from raw logs the week before an inspection.

IMO MSC.428(98)ISM Code 12.1A record of access

SMS Audit

Safety Management System including cyber controls MUST be verified annually by auditors.

A record of processing is only as good as the layer producing it. Real-time SQL auditing captures every statement against the data — the identity, the session, the client, the objects touched, the outcome — with no nightly batch window where activity goes unrecorded. Classification is what makes that a record of *regulated* data rather than a log of everything: it tells you which tables are in scope, so the register describes the processing you actually have to declare. Policy templates then produce it in the shape the framework asks for, instead of leaving you to assemble it from raw logs the week before an inspection.

IMO MSC.428(98)Resolution §4A record of access

Bridge System Logging

REQUIRES logging of bridge navigation, ballast control, and engine room data access.

A record of processing is only as good as the layer producing it. Real-time SQL auditing captures every statement against the data — the identity, the session, the client, the objects touched, the outcome — with no nightly batch window where activity goes unrecorded. Classification is what makes that a record of *regulated* data rather than a log of everything: it tells you which tables are in scope, so the register describes the processing you actually have to declare. Policy templates then produce it in the shape the framework asks for, instead of leaving you to assemble it from raw logs the week before an inspection.

IMO MSC.428(98)Resolution §5Routing and evidencing the response

Incident Response

Organizations MUST have procedures for responding to and recovering from cyber incidents.

Findings route by severity to Slack, Teams, email, PagerDuty, or your SIEM, and escalate automatically when nobody acknowledges them and again when nobody resolves them. Every alert arrives with the query, the identity, and the data classification already attached, so the response starts with context rather than with an investigation. The acknowledge-to-resolve history is retained, which is what evidences that the procedure was followed. Your ticketing system stays where it is — what this produces is a finding worth opening a ticket for.

What IMO MSC.428(98) covers

This instrument defines no data category of its own. Requires cyber risk to be addressed within the safety management SYSTEM. It names no data category, which is why implementations differ so widely between operators.

How IMO MSC.428(98) is enforced

Every figure below is the ceiling the instrument publishes about itself, not a prediction of what anything would cost. Enforced by Flag administrations and classification societies at audit; port state control at inspection.

MSC.428(98) requires cyber risk to be addressed in the safety management system. It carries no penalty of its own, because it does not need one: a weak SMS produces non-conformities at Document of Compliance and Safety Management Certificate audits, and ISM non-conformities lead to port state control detention, insurance consequences, and charterer rejection.

Inspectors increasingly ask for vessel-specific evidence rather than a fleet-level policy document.

Uncapped exposure that sits outside this instrument

These come from company law rather than from IMO MSC.428(98), and they are not penalties — they are liability for a loss, which is why nothing caps them at a published maximum.

Duty of oversight

Delaware, and followed in most US corporate jurisdictions. It is a rule of company law, not of any privacy or security statute.

Triggered by. A sustained or systematic failure by the board to establish a reporting system for a mission-critical risk — or, having one, consciously disregarding what it reported. The second limb is what a documented, unremediated finding goes to.

Who. Directors, in their personal capacity, in a derivative action brought on behalf of the company.

This is liability for the loss the company suffered, not a statutory penalty, so nothing caps it at a published maximum. A bad-faith finding also takes the conduct outside the exculpation and indemnification the charter would otherwise provide.

In re Caremark Int’l Deriv. Litig. (Del. Ch. 1996); Marchand v. Barnhill (Del. 2019); In re Boeing Co. Deriv. Litig. (Del. Ch. 2021).

Enforcement data reviewed August 2026. Several figures are indexed annually and move.

Ships With It

Built for IMO MSC.428(98),
not configured for it afterwards

Policy Template

Maritime OT Monitoring

Log access to navigation, ECDIS, and vessel control databases

Report

IMO Cyber Compliance Report

Annual SMS verification evidence for cyber controls

Classification

Maritime System Data

Identify AIS, ECDIS, and vessel operational data

Alert

Bridge System Access Alert

Alert on unauthorized access to navigation systems

Walk into the IMO MSC.428(98) audit knowing the answer

228 cited requirements across 57 frameworks are mapped to the controls that evidence them. A fixed-fee gap assessment tells you which of them you can already prove today.

Get a Gap Assessment