Cybersecurity incident response & exercises
The moment the network drops or data is wiped, the crew knows what to do — turning the compliance plan into muscle memory.
- 2021.1.1MSC.428(98) mandatory
- From the first annual DOC verification after this date, cyber risk management must be reflected in the Safety Management System (SMS).
- 4BIMCO response phases
- Identify → define & contain → forensics & analysis → recover — plans and exercises are organized around this loop.
- SMSEmbedded in the SMS
- The cyber plan is not a standalone document but a component of the SMS, complementing existing ISM / ISPS procedures.
What it is
Helping ships/shipping companies build and rehearse the capability to respond to cyber incidents: incorporating cyber risk into the Safety Management System (SMS), preparing contingency/response plans, response playbooks and recovery plans, running tabletop and scenario exercises, and establishing forensic readiness. This maps directly to IMO resolution MSC.428(98) — from 1 January 2021, companies must address cyber risk management in the SMS (tied to the Document of Compliance).
Who it's for
Owners and ship managers who must meet IMO / flag-state / PSC cyber-risk-management requirements and want plans that actually work.
How we do it
Our response isn't one-off firefighting but a closed loop aligned with the four stages of the BIMCO Guidelines on Cyber Security Onboard Ships: Identify → Define & Contain → Forensics & Analysis → Recover, then back to Identify for continuous improvement.
- Identify识别Detect anomaly · confirm incident
- Define & Contain界定 / 控制Scope impact · isolate & contain
- Forensics & Analysis取证 / 分析Preserve evidence · root cause
- Recover恢复Restore ops · lessons learned
Aligned with the four stages of the BIMCO Guidelines on Cyber Security Onboard Ships
The ship's critical scenarios: response focus and what the plan holds ready
| Scenario | Response focus | What the plan holds ready |
|---|---|---|
| Navigation equipment / propulsion ICS disabled or tampered with | Switch to manual and backup means to keep navigating safely; scope the affected systems | Offline operating procedures · backup-means list · reporting path |
| Ransomware | Contain the infected area, preserve evidence, verify the backups are usable | Containment steps · forensic-readiness checklist · recovery order |
| Shore-side data loss / business interruption | Bring up alternate communication channels; run critical business in degraded mode | In-port assistance arrangements · critical backups · recovery plan |
※ Scenarios follow the critical-scenario framework of the BIMCO Guidelines on Cyber Security Onboard Ships, tailored item by item to your ship type and configuration.
What we do / deliverables
- Incident-response and contingency plans (per BIMCO's four phases: identify → scope/contain → forensics/analysis → recover)
- Playbooks for the ship's critical scenarios: navigation equipment / propulsion ICS disabled or tampered with, ransomware, shore-side data loss
- Recovery plan: on-board offline versions, critical backups, in-port assistance arrangements
- Forensic readiness and post-incident review
- Tabletop and scenario exercises (including management); embedded in the SMS, complementary to ISM/ISPS
Why choose us
Turning compliance into muscle memory — starting from offline plans plus realistic exercises, going beyond the regulator's 'have a plan' to 'it actually works'.
Tailored to BIMCO's critical scenarios — designed around ship-specific situations such as navigation-equipment/ICS paralysis, not a generic template.
How the engagement runs
Current-state review & SMS alignment
Take stock of the existing emergency system and where cyber risk sits and connects within the SMS.
Plans & playbooks
Draft response and recovery documents along BIMCO's four phases, with an offline playbook for each critical scenario.
Tabletop / scenario exercises
Realistic exercises with management involved, testing that the plans actually work with the network down.
Review & revision
Fold what the exercise exposed back into the plans, returning to 'Identify' for continuous improvement.
Standards & basis
FAQ
We already have a company-level emergency plan — do we still need a separate cyber incident response?
Do PSC or flag-state inspections look at the cyber contingency plan?
Will exercises disturb the ship's normal operation?
Tell us what you need
The message below is pre-filled with the solution you're viewing (you can still edit it). Haishide's compliance engineering team will get back to you within 1–2 business days.
Cybersecurity incident response & exercises

