An engineering team that makes maritime cybersecurity submission-ready
Haishide Data Service (Shanghai) Co., Ltd. is based in Shanghai and focused on maritime cyber and data security. Around IACS UR E26/E27 and IEC 62443, we serve shipyards, shipboard equipment makers and owners across gap assessment, remediation and submission evidence: mapping each clause to specific devices and interfaces, and producing executable test items and submission-ready evidence packages.
Who does this
Senior compliance & submission engineer
Years of front-line experience with class cyber-resilience review and E27 submission; deeply familiar with each clause's submission practice and evidence requirements, having led compliance submission for multiple shipboard systems — and knows what assessors really look for and where projects stall.
Shipboard OT security engineer
Years of hands-on operations experience with shipboard control systems and industrial (OT) networks; familiar with how engine-room automation, navigation and monitoring systems actually run aboard, having served both in-service and newbuild projects — and knows which fixes are truly workable at sea.
Test & evidence engineer
Long focused on E27 testing and evidence engineering; turns abstract clauses into executable test items and submission-ready evidence packages, having run gap assessment and remediation across multiple equipment models — so conclusions are grounded and remediation verifiable.
The typical problems we solve
From “no idea how big the gap is” to “submission-ready evidence”
Shipboard monitoring-class system
- Problem
- The yard required E27 documentation before the maker could join the project, yet the maker had no clear view of its product gap or how to remediate.
- Remediation
- Mapped E27 clauses to the model line by line, produced a gap list and remediation roadmap, and closed the test-and-fix loop before submission.
- Outcome
- Built a reusable submission evidence set, so the same model reuses one compliance package across later projects instead of starting from scratch each time.
Even an older system can tell a clear cyber-resilience story
Engine-room automation / control system
- Problem
- The system had run aboard for years with scattered docs; when the owner asked for cyber-resilience proof under the new rules, the vendor couldn't produce a complete package in time.
- Remediation
- First mapped the system's current state and interface boundaries, then found the key gaps against E27, and worked “high-risk first, evidence next” — without a blanket shutdown.
- Outcome
- Without disrupting operations, turned a scattered status quo into a clear cyber-resilience account that holds up to both the owner and the class society.
Turning a shipful of vendor statuses into one page you can escalate
Whole-ship multi-vendor systems
- Problem
- With many vendors on one ship, E27 progress was chased over Excel — leaving no clear picture of who was ready and who wasn't.
- Remediation
- Collected each vendor's device-level status on one consistent rubric, sorted into ready / needs-work / high-risk, with gaps mapped to specific devices and clauses.
- Outcome
- Replaced the stubborn Excel with a one-page whole-ship compliance view, so the yard and owner can see at a glance what's still missing.
What our clients say
“E27 used to be a tangle for us — we didn't know where to start. Haishide laid out what to do step by step; we just followed it, and submission went a lot smoother than we expected.”
“What stood out is that they actually understand ships. Many consultants just recite the standard; they could tell us straight whether a fix would really work on our vessel.”
What our engineers say
“A lot of makers assume E27 is just handing over a few documents — then they sit down and find that even getting the “system boundary” right takes several rounds of rework. We get those rounds done with the client before submission.”
“Shipboard equipment isn't lab equipment. A “restart the service” fix that looks fine onshore may simply not be allowed on a sailing vessel — someone has to walk those traps for the client first.”
How we do it
From standard clauses to submission-ready evidence, our work runs in three stages.
Clauses broken down to executable items
We break E27 clauses into concrete test items and evidence items, turning “compliance” from an abstract requirement into work that can be done and verified.
Grounded assessment, verifiable remediation
Gap assessment maps to specific clauses and devices, and remediation comes with a verifiable loop — no conclusions drawn from subjective judgement.
Submission-ready, reusable evidence
What we produce can go straight into the submission process, and materials for a model are built once and reused across projects.
To go further, start here
Whether you want to talk through a specific compliance need or first see what we can do, the two entry points below will get you there.

