Provides client assurance of current cybersecurity posture with the option of Safety Management System (SMS) documentation review, evidencing and next steps.
Is an annual check in with SYNC. We will call out differences from your baseline and support you on next steps.
This service uses SYNC’s virtual appliance and operates as the Vessel’s SIEM (Security Incident & Event Management) tool. This is typically used by clients who are required to go beyond the basics and have a dashboard showing live risk posture.
The Maritime Safety Committee (part of the IMO), sees an urgent need to raise awareness on cyber risk threats and vulnerabilities. It recognises that classification societies, ship owners and ship operators inter alia, should be expediting work to safeguard shipping from current cyber threats. You should consider this for your vessel.
The wording above is abridged from the IMO website (IMO Website, 2024, Maritime cyber risk)
Network cybersecurity isn’t just part of what we do, it is the only thing we do.
We know the nature of your business and therefore we don’t talk about past engagements, we won't ask you for testimonials, social media posts etc...
We understand that the maritime world is subject to near constant change, reprioritization and unexpected cancellations. We will work with you, to achieve the outcomes you need
Legal and Contractual obligations may take different forms (Insurance policies may require annual cybersecurity checks or charter customers/owners may expect cybersecurity to be evidenced). You will have first hand knowledge of these and we can help you address them.
Regulatory requirments take the form of recommendations initiated with the resolutions of the International Maritime Organisation (IMO), adopted into the International Safety Management (ISM) Code and brought to life as elements requiring evidence in the yacht’s Safety Management System (SMS)
Contact usGiven your clientele, the evolving technology landscape and the locations many vessels operate in; at the very least, you must take practical steps to annually baseline your cybersecurity posture, be able to evidence this in your SMS and clearly prioritise next steps - SYNC does this for you.
Currently guidance from the IMO, enacted in the ISM Code and recommended for evidence in the SMS are recommendations. Evidence for which should be provided on the vessel’s next class or flag inspection after 2021.
Provided you are able to connect our device to your yacht's network and power on, we can handle the rest. No extra skills or capabilities are required.
Owners and would-be-buyers, can check with the Owner's Representative or have your office enquire with the Dedicated Person Ashore (DPA) for the vessel. In either case, you are looking for evidence of a recent assessment in the Safety Management System (SMS).
If you are chartering a vessel, you can ask your Agent to check with the yacht’s Chief Security Officer (CSO) or Captain, for evidence of a recent assessment.
From start to finish, the assessment phase is 5 business days. The engagement completes on receipt of final payment, at which point the report is released. You may also request a 1-hour live debrief with the Penetration Tester (up to 30 days after the assessment completes).
As with all things, this is down to your risk appetite. If you wish to conduct Government level negotiations with World Leaders in Monaco Harbour, then we would suggest that you insist that the vessel makes clear its cybersecurity credentials. However, one thing you can never be certain of, is why the attacker wants access to the yacht's network. For that reason alone, we expect all yachts should at least baseline their risk posture annually.
A section in the yacht’s Safety Management System (SMS) dedicated to Cybersecurity.
A cyber incident response plan
A dated assessment report covering Operating Technology (OT) and Information Technology (IT), within the last 12 months
A prioritised list of findings
If you are a Captain, ETO, Fleet Manager or Charter company needing cybersecurity assurance for your vessel...