logo

Maritime lawyers assemble!

ID: 26274fdf-acb1-57ae-97f0-5966dece0277

STIX ID: report--26274fdf-acb1-57ae-97f0-5966dece0277

Feed Name: Pen Test Partners Blog

Date Published: 2024-11-05

Date Updated: 2026-03-26

Author: Ken Munro

...
...

This report analyzes how increasing ship connectivity and new IACS cyber requirements (UR E26/E27) are reshaping maritime cyber risk, potentially rendering non-compliant vessels out of class and uninsured. It outlines delays to implementation (to July 1) and significant enforcement challenges due to widespread technical debt and limited cyber expertise among classification assessors, illustrated by findings such as backdoors, undocumented remote access, default credentials, and NAC bypasses during installations. While major cyber incidents at sea remain rare, the report underscores strong criminal incentives (e.g., fraud and cargo theft) and urges owners and operators to contractually enforce vendor security, validate installations against secure designs, and engage experienced maritime-focused penetration testers.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.