Cyber Risk Management in the SMS (MSC.428(98))
The ISM Code has never had a dedicated cyber risk chapter: Resolution MSC.428(98) affirms that an approved SMS should take it into account under the objectives and functional requirements of the Code, and encourages Administrations to check it from 2021.
Operational Explanation
Resolution MSC.428(98) (adopted in June 2017) does not introduce a new chapter into the ISM Code, but establishes that cyber risks must be appropriately addressed within the existing Safety Management System, under the Code's general risk management framework (in particular paragraphs 1.2.2.2 and 1.4 on risk assessment and operational procedures and operational procedures). Administrations were encouraged to ensure cyber risks were appropriately addressed in the SMS no later than the first annual verification of the Document of Compliance (DOC) after 1 January 2021: a requirement that is by now mature and well-established, no longer a recent novelty.
Technical support for this requirement is provided by the Guidelines on Maritime Cyber Risk Management (MSC-FAL.1/Circ.3/Rev.4). The current IMO Guidelines on maritime cyber risk management are MSC-FAL.1/Circ.3/Rev.4, issued on 28 May 2026 following approval by FAL 50 and MSC 111. The circular has been revised several times, which shows the topic remains under active development years after the requirement was first introduced. The Guidelines structure cyber risk management around the six functional elements of 3.5: govern, identify, protect, detect, respond and recover.
Regulatory Reference
Resolution MSC.428(98) (June 2017) does not amend the ISM Code: it affirms that an approved SMS should take cyber risk management into account in accordance with the objectives and functional requirements of the Code (par. 1.2.2.2, 1.4), and encourages Administrations to ensure that cyber risks are appropriately addressed in the SMS no later than the first annual DOC verification after 1 January 2021. What is verified in an audit remains the Code requirement, as implemented by the Administration or recognized organization. Supported by the MSC-FAL.1/Circ.3/Rev.4 Guidelines, current revision Rev.4, issued on 28 May 2026 following approval by FAL 50 and MSC 111.
Scope of Application
Every Company holding an ISM DOC, covering all IT (information technology) and OT (operational technology, e.g. machinery automation, ECDIS, GMDSS) systems on board and ashore that are relevant to operational safety.
Procedure / How to Complete It
- Integrate cyber risk into the SMS's general risk assessment, not as a separate document isolated from the rest of the safety management system.
- Apply the six functional elements of 3.5 of the MSC-FAL.1/Circ.3/Rev.4 Guidelines: govern the activity, identify critical systems, protect them, detect anomalies, respond to incidents and recover operability. Govern — establish and monitor the cyber-risk-management strategy, expectations and policies; define responsibilities and ensure accountability, authority, expertise, business continuity and crisis management.
- Distinguish and map IT systems (management, communication) and OT systems (machinery automation, navigation, cargo) separately, as they require different countermeasures.
- Integrate cyber incidents into the existing NC/Near Miss register, applying the same root cause analysis and CAPA cycle already used for other non-conformities.
- Train crew and shore-based personnel on the most common cyber risks (phishing, uncontrolled USB devices, unauthorised remote access to onboard systems).
- Maintain evidence that cyber risks are identified, controlled and reviewed as part of the SMS, available at the applicable DOC and SMC verifications: the 2021 transition is over, the requirement is not.
Practical Example
Example: a Company maps ECDIS, GMDSS and machinery automation systems as critical OT systems, establishes a control procedure for the use of external USB devices on board, and logs a malware incident detected on a shipboard laptop into the existing NC register, with a corresponding CAPA and effectiveness check.
What Typically Goes Wrong
Common Mistakes Mistake Library
| Mistake | Consequence | How to avoid it |
|---|---|---|
| Cyber risk managed as a separate IT matter, not integrated into the SMS's general risk assessment | Lack of integrated documentary evidence in the event of an audit, despite the existence of technical IT measures | Explicitly integrate cyber risk into the SMS's risk assessment and procedures, not only into the company's IT policy |
| No distinction between IT and OT systems in the cyber risk assessment | Countermeasures designed for management systems improperly applied to critical automation/navigation systems | Map IT and OT systems separately, with specific countermeasures for each category |
| Cyber incidents not logged in the existing NC/CAPA cycle | Loss of the root cause analysis and continuous improvement opportunity already provided for other non-conformities under the ISM Code | Record and assess every cyber incident under the SMS incident process, and open an NC with CAPA when a specified requirement was not met or the Company procedure requires it — not automatically for every event |
What the PSCO Checks
Operational Tips
- Don't treat cyber risk as a stand-alone document: integrate it into the SMS's general risk assessment, with the same verification and continuous improvement mechanisms.
- Apply the six functional elements of the MSC-FAL.1/Circ.3/Rev.4 Guidelines (govern, identify, protect, detect, respond, recover) as a reference structure, not just as a list of technical controls.
- Periodically review the MSC-FAL.1/Circ.3 Guidelines, current revision Rev.4 (28 May 2026, FAL 50 and MSC 111): the topic remains under active development even years after the original requirement.
Preparation checklist
Educational checklist. This summary supports learning and preparation only. It does not replace the vessel’s approved procedures, manuals, statutory documents, company SMS, or applicable official requirements. Completing it demonstrates neither compliance nor readiness for an inspection: it shows that a list has been read, not that the ship is in order. Always verify the current documents carried on board.
- Cyber risk integrated into the SMS's general risk assessment
- Critical IT and OT systems mapped separately, with specific countermeasures
- Identification, protection, detection, response and recovery procedures documented
- Cyber incidents logged in the existing NC/CAPA cycle
- Crew and shore-based personnel trained on the most common cyber risks
FAQ
Related Topics
Last substantive revision of this page: 30 August 2026 · page fingerprint 2e7a505da7f4