logo

What goes into testing a ship?

ID: 871da177-d068-5675-a990-c03fa3b9d08d

STIX ID: report--871da177-d068-5675-a990-c03fa3b9d08d

Feed Name: Pen Test Partners Blog

Date Published: 2024-11-05

Date Updated: 2026-03-26

Author: Andrew Tierney

...
...

This report provides practical guidance for assessing and improving cybersecurity on ships, emphasizing a risk-based approach aligned to industry frameworks and regulations (e.g., MSC.428(98), BIMCO, IACS UR E26/E27, ISO/NIST). It highlights corporate IT compromise as the most significant fleet-wide risk and focuses on oversight, network segmentation between IT and OT, perimeter defenses, and Windows domain security. The document outlines a typical testing engagement—including maturity assessment, network and Wi‑Fi reviews, segmentation validation, IT domain compromise attempts, proportionate OT checks, and external attack surface review—conducted with a risk-averse methodology and ideally scheduled during low-impact periods such as drydock.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.