海仕德数据服务
Solutions

Cybersecurity incident response & exercises

The moment the network drops or data is wiped, the crew knows what to do — turning the compliance plan into muscle memory.

2021.1.1MSC.428(98) mandatory
From the first annual DOC verification after this date, cyber risk management must be reflected in the Safety Management System (SMS).
4BIMCO response phases
Identify → define & contain → forensics & analysis → recover — plans and exercises are organized around this loop.
SMSEmbedded in the SMS
The cyber plan is not a standalone document but a component of the SMS, complementing existing ISM / ISPS procedures.

What it is

Helping ships/shipping companies build and rehearse the capability to respond to cyber incidents: incorporating cyber risk into the Safety Management System (SMS), preparing contingency/response plans, response playbooks and recovery plans, running tabletop and scenario exercises, and establishing forensic readiness. This maps directly to IMO resolution MSC.428(98) — from 1 January 2021, companies must address cyber risk management in the SMS (tied to the Document of Compliance).

Who it's for

Owners and ship managers who must meet IMO / flag-state / PSC cyber-risk-management requirements and want plans that actually work.

Our method · made visible

How we do it

Our response isn't one-off firefighting but a closed loop aligned with the four stages of the BIMCO Guidelines on Cyber Security Onboard Ships: Identify → Define & Contain → Forensics & Analysis → Recover, then back to Identify for continuous improvement.

In one table

The ship's critical scenarios: response focus and what the plan holds ready

The ship's critical scenarios: response focus and what the plan holds ready
ScenarioResponse focusWhat the plan holds ready
Navigation equipment / propulsion ICS disabled or tampered withSwitch to manual and backup means to keep navigating safely; scope the affected systemsOffline operating procedures · backup-means list · reporting path
RansomwareContain the infected area, preserve evidence, verify the backups are usableContainment steps · forensic-readiness checklist · recovery order
Shore-side data loss / business interruptionBring up alternate communication channels; run critical business in degraded modeIn-port assistance arrangements · critical backups · recovery plan

Scenarios follow the critical-scenario framework of the BIMCO Guidelines on Cyber Security Onboard Ships, tailored item by item to your ship type and configuration.

What we do / deliverables

  • Incident-response and contingency plans (per BIMCO's four phases: identify → scope/contain → forensics/analysis → recover)
  • Playbooks for the ship's critical scenarios: navigation equipment / propulsion ICS disabled or tampered with, ransomware, shore-side data loss
  • Recovery plan: on-board offline versions, critical backups, in-port assistance arrangements
  • Forensic readiness and post-incident review
  • Tabletop and scenario exercises (including management); embedded in the SMS, complementary to ISM/ISPS

Why choose us

  1. Turning compliance into muscle memory — starting from offline plans plus realistic exercises, going beyond the regulator's 'have a plan' to 'it actually works'.

  2. Tailored to BIMCO's critical scenarios — designed around ship-specific situations such as navigation-equipment/ICS paralysis, not a generic template.

From first call to close-out

How the engagement runs

  1. Current-state review & SMS alignment

    Take stock of the existing emergency system and where cyber risk sits and connects within the SMS.

  2. Plans & playbooks

    Draft response and recovery documents along BIMCO's four phases, with an offline playbook for each critical scenario.

  3. Tabletop / scenario exercises

    Realistic exercises with management involved, testing that the plans actually work with the network down.

  4. Review & revision

    Fold what the exercise exposed back into the plans, returning to 'Identify' for continuous improvement.

Standards & basis

IMO MSC.428(98)MSC-FAL.1/Circ.3BIMCO GuidelinesISM / ISPSNIST CSF

FAQ

We already have a company-level emergency plan — do we still need a separate cyber incident response?
Yes. MSC.428(98) requires cyber risk management to be reflected in the SMS, and the handling logic for cyber incidents (e.g. ICS paralysis, ransomware) differs from traditional maritime emergencies, needing dedicated offline plans and scenario-based exercises to fill the gap.
Do PSC or flag-state inspections look at the cyber contingency plan?
Yes. Since MSC.428(98) took effect, cyber risk management has been part of the SMS, and DOC/SMC audits and PSC inspections can ask to see the procedures and exercise records. A plan with no exercise register is the most common way to lose marks.
Will exercises disturb the ship's normal operation?
Tabletop exercises touch no real systems and only need the relevant people in the room; the scope and timing of scenario exercises are agreed with you in advance, steering clear of critical operational moments. The point of an exercise is to expose gaps in the plan, not to cause an incident.
Start an inquiry

Tell us what you need

The message below is pre-filled with the solution you're viewing (you can still edit it). Haishide's compliance engineering team will get back to you within 1–2 business days.

Cybersecurity incident response & exercises

Provide at least a phone or an email so we can reach you.