At a Glance
- Engagement type: Specialist cyber incident response for vessels at sea, in port or at anchor
- Incident types: Ransomware, ECDIS / RADAR compromise, OT disruption, USB-borne malware, AIS / GNSS spoofing, BEC, supply-chain compromise
- Response model: Remote initial triage + on-board response within 48-72h where required, named maritime cyber consultants
- Engagement model: Retainer-based readiness + on-demand response, or one-off incident response
- Response time: instant, no delay. Initial triage starts within an hour of call
What is Vessel Cyber Incident Response?
Cyber incident response for vessels is a specialist discipline. Unlike land-based IR, vessel IR must contend with limited satellite bandwidth, hours-to-days transit time to reach the ship, the master's overriding authority on safety and navigation, OT systems that cannot be aggressively touched, and the operational reality that you cannot just "shut everything off" on a vessel underway.
Codesecure provides vessel IR as a hybrid remote + on-board service. Initial triage and containment guidance starts within an hour via secure shore-link. Forensic evidence collection and deep-dive analysis are coordinated remotely with the master, chief engineer and ETO. Where on-board presence is required (deep forensics, evidence chain of custody, full system rebuild), our maritime IR consultant boards the vessel at the next port call or via launch where time-critical.
Why It Matters
Vessel incidents are not theoretical. Public reports include ransomware shutting down shipping company operations, ECDIS rendered unusable mid-voyage by malware, port operations paralysed by attacks, AIS and GNSS spoofing campaigns, and BEC scams diverting bunker payments. Each of these has direct safety, environmental and commercial impact, and each is responded to differently from a typical IT-only incident.
Maritime IR is also increasingly required by SMS and class-society programmes. IMO MSC.428(98) expects response procedures in vessel SMS. IACS UR E26 / E27 expect documented incident response capability. P&I clubs and cyber insurance policies typically require a named IR provider relationship before claim coverage applies. A pre-arranged maritime IR retainer satisfies all of these.
What's Included
Codesecure's vessel IR programme covers initial response, deep IR and post-incident recovery:
1-Hour Initial TriageRemote triage call within an hour of incident notification, containment guidance for master / ETO
Pre-Approved Containment PlaybooksDocumented playbooks for ransomware, ECDIS compromise, OT disruption, AIS spoofing, BEC
Remote Forensic CollectionGuidance for master / ETO to capture forensic evidence with shore-side analysis
On-Board IR Within 48-72hNamed maritime cyber consultant boards vessel for deep IR where required
OT Incident CoordinationCoordination with engine OEM, ECDIS vendor, class society for OT-related incidents
Supply-Chain Compromise ResponseIR for compromise via vendor technician, USB media, software update, surveyor visit
AIS / GNSS Spoofing InvestigationInvestigation of suspected AIS or GNSS spoofing incidents with evidence preservation
BEC InvestigationBusiness email compromise investigation for shipping operations, bunker fraud, charter fraud
Post-Incident ReportClass-society-aligned incident report with root cause, timeline and lessons learned
Retainer ReadinessPre-arranged retainer with documented contact paths, tabletop exercises and quarterly drills
Get a Free IR Readiness Review
45-minute call with our maritime IR lead. Bring your current IR capability, fleet exposure and insurance policy requirements, leave with a phased readiness plan. Instant response, no delay.
Book Free Strategy Call
Methodology
Every Vessel IR engagement follows a 5-phase methodology aligned with IMO and IACS guidance:
1
Retainer Setup & Readiness
Scoping call, NDA, IR retainer agreement, contact path documentation, fleet risk profile, tabletop exercise.
2
1-Hour Triage on Activation
Incident notification triggers triage call within one hour. Master / ETO contacted. Initial containment guidance issued.
3
Remote Forensic Collection
Forensic guidance for master / ETO to capture evidence under shore-side direction. OT vendor coordination as needed.
4
On-Board IR Phase
Named consultant boards vessel at next port call or via launch for deep IR, evidence chain of custody, system rebuild.
5
Post-Incident Report & Recovery
Class-society-aligned incident report, lessons learned, control gap remediation, SMS update.
What You Get
Every Vessel IR engagement ships with the same operational handoff:
IR Retainer AgreementPre-arranged retainer with documented contact paths and SLAs
Containment PlaybooksPre-approved playbooks for top maritime incident types
Tabletop Exercise ReportsMaster / ETO / shore tabletop exercise findings and action items
Incident Triage & Coordination24x7 incident triage and coordination with master, ETO, vendors, class
Post-Incident ReportClass-society-aligned incident report with root cause and lessons learned
Quarterly DrillsPre-arranged quarterly drills to keep retainer warm and team trained
Timeline
IR retainer onboarding completes in 1-2 weeks. On activation, triage within an hour, on-board phase within 48-72h. Instant response, no delay, kickoff scheduled same or next business day after scoping.
Week 1
Retainer Setup
Scoping, retainer agreement, contact path documentation, fleet risk profile.
Week 2
Tabletop & Playbooks
Tabletop exercise with master / ETO / shore team. Playbooks aligned to fleet.
On Activation
Triage & Response
1-hour triage. On-board phase within 48-72h. Post-incident report within 30 days.
// Frameworks & Standards We Cover
NIST 800-61 IR
SANS PICERL
MITRE ATT&CK
MITRE ATT&CK for ICS
IMO MSC.428(98)
IACS UR E26 / E27
BIMCO Cyber Guidelines
TMSA 3
Wazuh
TheHive
Cortex
MISP
Talk to a Maritime IR Lead
30-minute call with our maritime IR lead. Discuss your fleet, insurance requirements and current IR readiness with no sales pressure.
Schedule Free Call
Frequently Asked Questions
How quickly can you respond if a vessel is under attack?
Initial triage call within one hour of notification, any hour of day, any day of year, for retainer customers. Containment guidance for master / ETO follows immediately. Remote forensic guidance starts the same shift. On-board consultant within 48-72 hours where on-board IR is required, sometimes faster if a port call coincides.
Do we need an IR retainer or can you respond ad-hoc?
We respond to ad-hoc maritime IR incidents, but a retainer is strongly recommended for several reasons: insurance policies typically require a pre-arranged IR provider relationship for claim coverage, response is significantly faster with documented contact paths and pre-arranged playbooks, and tabletop-exercised teams perform measurably better than cold teams during real incidents.
What does maritime IR cost?
Retainer pricing varies by fleet size, vessel type, response SLA and included tabletop / drill cadence. We provide a fixed-fee scoped proposal within 24-48 hours of scoping. On-incident response is typically billed on top of retainer at agreed day-rates with capped on-board engagement scope.
Will you go to the vessel anywhere in the world?
Yes, within reason. We coordinate with the operator on visa, BTL / clearance, port logistics and travel time. For high-time-criticality incidents we deploy from the nearest available consultant region. Our consultants have travelled to Indian, South-east Asian, Middle Eastern, European and Australian ports for vessel IR engagements.
Do you handle AIS / GNSS spoofing investigation?
Yes. AIS and GNSS spoofing investigation includes evidence preservation, comparison against expected position vs reported position, review of AIS class B vs class A traffic patterns, GNSS receiver log analysis, and coordination with shipping operations and authorities where appropriate.
How do you coordinate with class society and Flag during incidents?
Our retainer setup includes documented coordination paths with your class society (IRS, DNV, BV, LR, ABS) and Flag administration. During incidents we coordinate with class on incident reporting, with Flag on safety notifications, and with P&I club on insurance and recovery aspects.
Can IR evidence satisfy IMO / IACS audits?
Yes. Post-incident reports are aligned to IMO MSC.428(98), IACS UR E26 / E27 and BIMCO Cyber Guidelines. They are accepted as audit evidence for vessel SMS verification, class-society cyber audits, and TMSA 3 vetting submissions.
Ready to Set Up Vessel IR Readiness?
Codesecure delivers vessel IR with 1-hour triage, on-board response and class-society-aligned reporting. Free 30-minute readiness review, instant response, no obligation.
Get a Free Strategy Call
See All Maritime Services