Crew cybersecurity awareness training
The crew touch ECDIS and USB sticks every day — turning the human line of defense into a demonstrable compliance asset.
- 2021.1.1Training becomes auditable
- With MSC.428(98) in effect, evidence of crew cyber-awareness training enters the scope of DOC/SMC audits and PSC inspections.
- 3Role tiers
- Management-level crew / operational-level crew / shore-side staff — course depth is tailored per role, never one-size-fits-all.
- SIRE 2.0Aligned to vetting
- The course is designed against the cybersecurity elements of SIRE 2.0 and TMSA, ready to evidence in charterer reviews.
What it is
Cybersecurity awareness training for crew and shore-side managers, landing 'cyber risk management' as a component of the Safety Management System (SMS) — a mandatory IMO requirement under the ISM Code framework since 2021. The training enables frontline staff to recognize phishing/social engineering, use IT and OT systems safely (ECDIS, navigation, engine-room control), follow good practice on removable media and passwords, and know how to report and respond to incidents.
Who it's for
Owners and ship managers who must demonstrate, in DOC/SMC audits, PSC, and charterer/vetting reviews, that the crew have received cyber training.
How we do it
Awareness training isn't one-size-fits-all — coverage depth is tailored by role (management-level crew / operational-level crew / shore-based staff) × topic (phishing, removable media, passwords, OT & navigation, incident reporting), delivered onboard in-person, via e-learning / CBT and through tabletop exercises.
| Role \ Topic | Phishing & social eng. | USB / removable media | Passwords & access | OT / nav systems | Incident spotting & reporting |
|---|---|---|---|---|---|
| Management-level crew | In-depth | Standard | In-depth | Standard | In-depth |
| Operational-level crew | In-depth | In-depth | Standard | In-depth | Standard |
| Shore-based staff | In-depth | Standard | In-depth | Overview | Standard |
Delivery: onboard in-person · e-learning / CBT · tabletop exercise
Choosing between the three delivery formats
| Format | When it fits | What evidence it leaves |
|---|---|---|
| On-board in-person | Whole-crew training on board, taught against the ship's own ECDIS and engine-room equipment | Attendance and completion records (filed by voyage) |
| E-learning / CBT | A dispersed fleet with frequent crew changes that needs low-cost full coverage | Per-person completion records and individual certificates |
| Tabletop / emergency exercises | Management and key positions, testing that plans and reporting paths actually work | Exercise records and an improvement list (into the SMS register) |
※ The register and certificates are designed around what DOC/SMC audits, PSC and charterer vetting ask to see — what the auditor wants is what the register holds.
What we do / deliverables
- Role-based courses (management-level / operational-level crew, shore-side staff)
- Core topics: phishing and social engineering, ransomware, USB-media hygiene, passwords and access control, safe use of OT/navigation systems, incident recognition and reporting
- Multi-format delivery: on-board in-person teaching, e-learning/CBT, tabletop and emergency exercises
- Completion records, individual certificates, training register (as evidence for flag state/PSC/vetting)
- Integration with the company's SMS procedures
Why choose us
Demonstrable compliance — producing records and a register that go straight into the SMS and stand up to audits, turning the abstract MSC.428(98) into evidence you can present.
Fit to real shipboard scenarios — designed around ECDIS, USB and ship-to-shore communication, not generic office IT training; delivered as a blend of on-board and online.
How the engagement runs
Role & baseline survey
Separate management-level / operational-level / shore-side audiences and gauge the existing training base.
Course tailoring
Build the course around the ship's real scenarios — ECDIS, USB, ship-shore communication.
Blended delivery
On-board, e-learning and exercises, combined per audience.
Register filing
Completion records, certificates and the register hook into the company's SMS procedures, ready to evidence at any time.
Standards & basis
FAQ
Is a certificate issued after training, and does it have statutory force?
Shipboard connectivity is poor — how does e-learning work?
How does the training relate to SIRE 2.0 / TMSA?
Tell us what you need
The message below is pre-filled with the solution you're viewing (you can still edit it). Haishide's compliance engineering team will get back to you within 1–2 business days.
Crew cybersecurity awareness training

