海仕德数据服务
Solutions

Crew cybersecurity awareness training

The crew touch ECDIS and USB sticks every day — turning the human line of defense into a demonstrable compliance asset.

2021.1.1Training becomes auditable
With MSC.428(98) in effect, evidence of crew cyber-awareness training enters the scope of DOC/SMC audits and PSC inspections.
3Role tiers
Management-level crew / operational-level crew / shore-side staff — course depth is tailored per role, never one-size-fits-all.
SIRE 2.0Aligned to vetting
The course is designed against the cybersecurity elements of SIRE 2.0 and TMSA, ready to evidence in charterer reviews.

What it is

Cybersecurity awareness training for crew and shore-side managers, landing 'cyber risk management' as a component of the Safety Management System (SMS) — a mandatory IMO requirement under the ISM Code framework since 2021. The training enables frontline staff to recognize phishing/social engineering, use IT and OT systems safely (ECDIS, navigation, engine-room control), follow good practice on removable media and passwords, and know how to report and respond to incidents.

Who it's for

Owners and ship managers who must demonstrate, in DOC/SMC audits, PSC, and charterer/vetting reviews, that the crew have received cyber training.

Our method · made visible

How we do it

Awareness training isn't one-size-fits-all — coverage depth is tailored by role (management-level crew / operational-level crew / shore-based staff) × topic (phishing, removable media, passwords, OT & navigation, incident reporting), delivered onboard in-person, via e-learning / CBT and through tabletop exercises.

In-depthStandardOverview

Delivery: onboard in-person · e-learning / CBT · tabletop exercise

In one table

Choosing between the three delivery formats

Choosing between the three delivery formats
FormatWhen it fitsWhat evidence it leaves
On-board in-personWhole-crew training on board, taught against the ship's own ECDIS and engine-room equipmentAttendance and completion records (filed by voyage)
E-learning / CBTA dispersed fleet with frequent crew changes that needs low-cost full coveragePer-person completion records and individual certificates
Tabletop / emergency exercisesManagement and key positions, testing that plans and reporting paths actually workExercise records and an improvement list (into the SMS register)

The register and certificates are designed around what DOC/SMC audits, PSC and charterer vetting ask to see — what the auditor wants is what the register holds.

What we do / deliverables

  • Role-based courses (management-level / operational-level crew, shore-side staff)
  • Core topics: phishing and social engineering, ransomware, USB-media hygiene, passwords and access control, safe use of OT/navigation systems, incident recognition and reporting
  • Multi-format delivery: on-board in-person teaching, e-learning/CBT, tabletop and emergency exercises
  • Completion records, individual certificates, training register (as evidence for flag state/PSC/vetting)
  • Integration with the company's SMS procedures

Why choose us

  1. Demonstrable compliance — producing records and a register that go straight into the SMS and stand up to audits, turning the abstract MSC.428(98) into evidence you can present.

  2. Fit to real shipboard scenarios — designed around ECDIS, USB and ship-to-shore communication, not generic office IT training; delivered as a blend of on-board and online.

From first call to close-out

How the engagement runs

  1. Role & baseline survey

    Separate management-level / operational-level / shore-side audiences and gauge the existing training base.

  2. Course tailoring

    Build the course around the ship's real scenarios — ECDIS, USB, ship-shore communication.

  3. Blended delivery

    On-board, e-learning and exercises, combined per audience.

  4. Register filing

    Completion records, certificates and the register hook into the company's SMS procedures, ready to evidence at any time.

Standards & basis

IMO MSC.428(98)MSC-FAL.1/Circ.3 Rev.3ISM CodeBIMCO Guidelines v5TMSA / SIRE 2.0 (aligned)

FAQ

Is a certificate issued after training, and does it have statutory force?
We provide completion records, individual certificates and a training register as evidence for flag state/PSC/vetting. But cybersecurity awareness training is a requirement within the ISM/SMS framework, not a standalone statutory certificate; its value is letting you present evidence that 'the crew have been trained' during audits.
Shipboard connectivity is poor — how does e-learning work?
Courses can ship as an offline package installed on board, with completion records syncing in port or when the link is up; or switch to on-board in-person teaching. The format serves two goals — the crew actually learn, and you can evidence it — and neither locks you to one form.
How does the training relate to SIRE 2.0 / TMSA?
Both SIRE 2.0 and TMSA contain cybersecurity-related elements, and the course is designed to align with and support them, helping you present training evidence in charterer vetting. But they are the charterers' review regimes, not qualifications we issue — we are never vague about this.
Start an inquiry

Tell us what you need

The message below is pre-filled with the solution you're viewing (you can still edit it). Haishide's compliance engineering team will get back to you within 1–2 business days.

Crew cybersecurity awareness training

Provide at least a phone or an email so we can reach you.