IMO Maritime Cyber Risk Management
International Maritime Organization resolution requiring cyber risk management in safety management systems. Applies to all ships subject to ISM Code.
What IMO MSC.428(98) draws on
This framework pulls on all three pillars — which is why running them as three separate tools means reconciling three sets of evidence at audit time.
Compliance
Security
What your auditor cites,
and what produces the evidence
The regulator's text is quoted below in italic, exactly as written. What follows each one is what the platform records, detects, or proves — not a claim about your compliance status, which no tool can confer.
Cyber Risk Management
Maritime operators MUST address cyber risks in their Safety Management Systems.
A record of processing is only as good as the layer producing it. Real-time SQL auditing captures every statement against the data — the identity, the session, the client, the objects touched, the outcome — with no nightly batch window where activity goes unrecorded. Classification is what makes that a record of *regulated* data rather than a log of everything: it tells you which tables are in scope, so the register describes the processing you actually have to declare. Policy templates then produce it in the shape the framework asks for, instead of leaving you to assemble it from raw logs the week before an inspection.
SMS Audit
Safety Management System including cyber controls MUST be verified annually by auditors.
A record of processing is only as good as the layer producing it. Real-time SQL auditing captures every statement against the data — the identity, the session, the client, the objects touched, the outcome — with no nightly batch window where activity goes unrecorded. Classification is what makes that a record of *regulated* data rather than a log of everything: it tells you which tables are in scope, so the register describes the processing you actually have to declare. Policy templates then produce it in the shape the framework asks for, instead of leaving you to assemble it from raw logs the week before an inspection.
Bridge System Logging
REQUIRES logging of bridge navigation, ballast control, and engine room data access.
A record of processing is only as good as the layer producing it. Real-time SQL auditing captures every statement against the data — the identity, the session, the client, the objects touched, the outcome — with no nightly batch window where activity goes unrecorded. Classification is what makes that a record of *regulated* data rather than a log of everything: it tells you which tables are in scope, so the register describes the processing you actually have to declare. Policy templates then produce it in the shape the framework asks for, instead of leaving you to assemble it from raw logs the week before an inspection.
Incident Response
Organizations MUST have procedures for responding to and recovering from cyber incidents.
Findings route by severity to Slack, Teams, email, PagerDuty, or your SIEM, and escalate automatically when nobody acknowledges them and again when nobody resolves them. Every alert arrives with the query, the identity, and the data classification already attached, so the response starts with context rather than with an investigation. The acknowledge-to-resolve history is retained, which is what evidences that the procedure was followed. Your ticketing system stays where it is — what this produces is a finding worth opening a ticket for.
What IMO MSC.428(98) covers
This instrument defines no data category of its own. Requires cyber risk to be addressed within the safety management SYSTEM. It names no data category, which is why implementations differ so widely between operators.
How IMO MSC.428(98) is enforced
Every figure below is the ceiling the instrument publishes about itself, not a prediction of what anything would cost. Enforced by Flag administrations and classification societies at audit; port state control at inspection.
MSC.428(98) requires cyber risk to be addressed in the safety management system. It carries no penalty of its own, because it does not need one: a weak SMS produces non-conformities at Document of Compliance and Safety Management Certificate audits, and ISM non-conformities lead to port state control detention, insurance consequences, and charterer rejection.
Inspectors increasingly ask for vessel-specific evidence rather than a fleet-level policy document.
Uncapped exposure that sits outside this instrument
These come from company law rather than from IMO MSC.428(98), and they are not penalties — they are liability for a loss, which is why nothing caps them at a published maximum.
Duty of oversight
Delaware, and followed in most US corporate jurisdictions. It is a rule of company law, not of any privacy or security statute.
Triggered by. A sustained or systematic failure by the board to establish a reporting system for a mission-critical risk — or, having one, consciously disregarding what it reported. The second limb is what a documented, unremediated finding goes to.
Who. Directors, in their personal capacity, in a derivative action brought on behalf of the company.
This is liability for the loss the company suffered, not a statutory penalty, so nothing caps it at a published maximum. A bad-faith finding also takes the conduct outside the exculpation and indemnification the charter would otherwise provide.
In re Caremark Int’l Deriv. Litig. (Del. Ch. 1996); Marchand v. Barnhill (Del. 2019); In re Boeing Co. Deriv. Litig. (Del. Ch. 2021).
Enforcement data reviewed August 2026. Several figures are indexed annually and move.
Built for IMO MSC.428(98),
not configured for it afterwards
Maritime OT Monitoring
Log access to navigation, ECDIS, and vessel control databases
IMO Cyber Compliance Report
Annual SMS verification evidence for cyber controls
Maritime System Data
Identify AIS, ECDIS, and vessel operational data
Bridge System Access Alert
Alert on unauthorized access to navigation systems
Other Critical Infrastructure frameworks
Walk into the IMO MSC.428(98) audit knowing the answer
228 cited requirements across 57 frameworks are mapped to the controls that evidence them. A fixed-fee gap assessment tells you which of them you can already prove today.