Skip to main content

Maritime Cyber Risk Management

Peregrine has been conducting Maritime cybersecurity assessments since the International Maritime Organization (IMO) released a Maritime Safety Committee (MSC) resolution in 2017 that addresses Maritime Cyber Risk Management in Safety Management Systems (MSC-FAL.1/Circ. 3). To meet these requirements, our SMEs conducted an assessment for the U.S. Academic Research Fleet in 2020-2021 under challenging circumstances. Since then, we have had the opportunity to update these vessels to meet newer mandates to include American Bureau of Shipping (ABS) Guide for Cybersecurity Implementation for the Marine and Offshore Industries (ABS CyberSafety Volume 2) dated August 2023. Since 2019, as a sponsor of the Maritime Transportation System (MTS) Security Operations Center (SOC) MTS-ISAC | maritime cybersecurity, our SMEs have access to all Maritime cybersecurity threats from this DHS sponsored ISAC.

Original Guidance

  • The Maritime Transportation Security Act (MTSA)
  • International Standards Organization (ISO) series 27001 – “Specifications for Information Security Management Systems (ISMS)”
  • The IMO Guidance MSC-FAL – Cir 3; Guidelines on Maritime Cyber Risk Management
  • IMO Resolution MSC.428(98) – Maritime Cyber Risk Management in Safety Management Systems
  • The IMO Directive – “The Guidelines on Cyber Security Onboard Ships”
  • Maritime Cybersecurity Center – Importance of Cyber Security in Maritime Operations

USCG Maritime Final Rule

A single maritime cyber incident can jeopardize safety, disrupt operations and send a wave through supply chains. Recognizing the increase of these very real risks to vessels, facilities and OCS infrastructure, the U.S. Coast Guard issued its Cybersecurity in the Marine Transportation System Final Rule. Peregrine Technical Solutions can support this new USCG-issued guidance. At the core are five required actions:

  • Annual Cybersecurity Training. Each covered entity must ensure that personnel complete cybersecurity training promulgated in 33 CFR 101.650 by January 12, 2026, and annually thereafter.
  • Designated Cybersecurity Officer (DCO). Each regulated entity must designate a qualified Cybersecurity Officer (CySO) to oversee cybersecurity efforts. This individual does not need to serve as CySO full-time, but they must understand maritime systems and cyber risk management. Along with any alternate CySOs, they must be available “at all times.”
  • Annual Cybersecurity Assessment. Organizations must assess their technical controls, policies, and procedures annually to uncover vulnerabilities and drive improvement.
  • Comprehensive Cybersecurity Plan. The plan must detail how cyber threats are identified, prevented, detected, and responded to. It must include risk analysis, response protocols, and recovery steps.
  • Execution and Continuous Improvement. Cyber Plans must be tested, revised, and embedded into daily operations. Training, drills, and responsive updates are critical to maintaining readiness.

Peregrine can support multiple roles

  • As a Trusted Advisor, to assess and validate individual flagged shipping companies and vessel’s compliance requirements.
  • As a Cyber Threat Specialist, to support country flagged shipping companies and vessel owners to certify their ships and train their staff.
  • As a Third-party Assessor, to conduct compliance and risk assessments.
  • As a Maritime Cybersecurity SME, to conduct audits both virtually and physically onboard ships.
  • As a Cyber Defense Strategist, to provide continuous monitoring solutions, post certification.

Risk Assessment Process

Peregrine has developed a streamlined process to meet this USCG Maritime Final Rule deadline and ensure customer compliance. Our process meets the MSC-FAL.1/Circ. 3 guidelines and can quickly and efficiently meet the needs of our maritime clients. Peregrine has partnered with Microsoft and will use their Azure Defender for IoT to assist in asset discovery, threat detection, and vulnerability analysis.

With a deep understanding that the Maritime Environment presents unique challenges, our SMEs are equipped to support:
Vulnerability management through cybersecurity site visits to assist both civilian and contract mariners with patching and scanning of systems and networks. Afloat site, system, and operational technology Assessment and Authorization, including mission-based cybersecurity risk assessments. Inspections and performing compliance visits to measure cybersecurity readiness of individual ship or department adherence with compliance measures.

Our process consists of the following for phases:

  • Phase 1 – Pre-Assessment Activities
  • Phase 2 – Ship Assessment
  • Phase 3 – Vulnerability Review/Report
  • Phase 4 – Produce Debrief

Our process methodology incorporates the five functions included in the NIST Risk Management Framework:

  • Identify – Inventory Ship Systems/Assets/Data, Define Personnel Roles, Conduct Risk Assessment to Identify Threats and Vulnerabilities
  • Protect – Access Control, Awareness & Training, Data Security, Processes/Procedures, Maintenance Plus Drills/Exercises
  • Detect – Anomalies/Events, Continuous Monitoring
    and Detection Processes.
  • Respond – Response Planning, Communications Analysis and Mitigation
  • Recover – Backup/Restoration of Cyber Systems Necessary for Ship Operations, Capture Lessons Learned and Update Plans