海仕德数据服务
Solutions

Shipboard penetration testing & red teaming

Test the bridge and engine room through an attacker's eyes — safety first, never gambling with live systems under way.

4Test-window tiers
Under way / alongside·in port / dry dock·off-hire / FAT rig·digital twin — testing depth is strictly tiered to the ship's state.
0Destructive tests under way
Generally no destructive testing on live systems under way — the safety constraint is written into the Rules of Engagement.
IT/OTThe gateway as the boundary
A core verification goal: confirming an IT-side compromise cannot cross the gateway into OT and navigation systems.

What it is

Assessing the security of a ship's IT and OT systems from a real attacker's perspective: covering the bridge/navigation systems (ECDIS, radar, GPS/GNSS, AIS), engine room/OT (propulsion, power, alarms), IT (Windows domain, email, cargo management), satcom, and the IT/OT gateways and network segmentation. The core constraint — high-risk testing is done in a safe state (alongside, at the yard, in dry dock / off-hire, or on a FAT rig, in port, or against a digital twin), and generally no destructive testing is done on live systems under way.

Who it's for

Owners, equipment makers and yards who want to know 'what would happen if someone really attacked' yet worry most that the test itself could affect ship safety.

Our method · made visible

How we do it

First map the ship's attack surface — the bridge, engine-room OT, IT, satcom VSAT and the IT-OT gateway are each a class of risk; high-risk testing runs only in safe states (alongside / dry-dock·off-hire / FAT bench / digital twin), never gambling with systems underway.

In one table

Which tests in which state — the safety boundary spelled out first

Which tests in which state — the safety boundary spelled out first
Ship's stateWhat we doWhat we don't
Under wayInterviews, configuration and document review, passive observationAny injection or destructive testing that could disturb systems under way
Alongside / in portControlled IT and network testing in an agreed window, stoppable at any momentDeep exploitation of in-use OT beyond the 'block initial access' objective
Dry dock / off-hireThe deep-testing window: segmentation verification, IT/OT gateway penetration, measured OT checksAny target outside the written authorization
FAT rig / digital twinOffensive verification opens up: exploitation, fault injection— an isolated environment that never touches the real ship

Rules of Engagement are signed before every test: scope, window, contacts and the stop mechanism in black and white.

What we do / deliverables

  • Maturity assessment (against the Identify/Protect/Detect/Respond/Recover framework)
  • Network-segmentation and IT/OT gateway testing (verifying IT cannot affect OT)
  • Core-network (satcom, firewalls, switches) and wireless/Wi-Fi assessment
  • IT-infrastructure penetration (focus: the Windows domain, which can affect a whole fleet)
  • Measured inspection of OT systems (aimed at 'blocking initial access', avoiding disturbance)
  • Severity-ranked vulnerability report (impact + actionable fixes) and debrief

Why choose us

  1. A safety-first testing philosophy — dry dock/FAT/digital-twin first, never breaking live systems under way, addressing owners' biggest concern head-on.

  2. Fleet thinking, prioritized like an attacker — using one representative ship to find high-impact issues reproducible across the fleet, spending budget on the risks that truly shake the whole fleet.

From first call to close-out

How the engagement runs

  1. Scope & Rules of Engagement

    Confirm targets, windows and the stop mechanism in writing with the owner / maker.

  2. Window scheduling

    Match testing depth to the ship's state — high-risk items go only into dry-dock / FAT / digital-twin windows.

  3. Execution

    Proceed in attacker-priority order, stopping on any anomaly; in-use OT gets measured checks only.

  4. Report & debrief

    A severity-ranked vulnerability report, each finding with its impact and an actionable fix.

  5. Fix verification

    Targeted retesting after remediation to confirm the holes are actually closed.

Standards & basis

IEC 62443IACS UR E26 / E27IMO MSC.428(98)BIMCO Guidelines

FAQ

Could penetration testing break on-board systems and affect sailing?
We schedule high-risk testing for a safe state (alongside, at the yard, in dry dock / off-hire, or on a FAT rig, in port, or against a digital twin) and generally do no destructive testing on live systems under way; for in-use OT systems we only do measured checks aimed at 'blocking initial access', avoiding disturbance.
What do we need to prepare before the test?
A network topology, an asset inventory and past assessment reports (if any) speed things up considerably; without them we start from interviews and configuration review — 'no topology diagram available' is itself a gap-assessment finding.
How are the results and vulnerability details kept confidential?
Testing runs inside a mutually signed NDA and Rules of Engagement; the report goes only to the agreed recipients and vulnerability details are not disclosed to third parties. After remediation, a retest can confirm closure.
Start an inquiry

Tell us what you need

The message below is pre-filled with the solution you're viewing (you can still edit it). Haishide's compliance engineering team will get back to you within 1–2 business days.

Shipboard penetration testing & red teaming

Provide at least a phone or an email so we can reach you.