Maritime Cyber Security Compliance — Gold Award 2025
Cybersecurity Awards 2025 Maritime Cyber Security Compliance Framework
Maritime Cyber & Compliance

Cyber risk management for fleet and shore operations.

STORM GRC is a maritime cyber security compliance platform that gives DPAs, Company Security Officers and IT Superintendents one workspace to manage cyber risk across fleet and shore — built around IMO Resolution MSC.428(98), IACS UR E26/E27, BIMCO guidelines and the NIS2 maritime scope.

IMO MSC.428(98) IACS UR E26 / E27 BIMCO Guidelines v4 NIS2
VSAT SHORE ECDIS
Fleet · Cyber Risk Snapshot Live
VLCC · 318,080 DWT · ECDIS update overdue Action
SUEZMAX · 157,000 DWT · IACS UR E26 readiness Compliant
Shore · MFA missing on crewing system High
Recognitions Independent awards for the STORM GRC platform and its industry-specific implementations
Cyber Security Awards 2025 Gold
GoldMaritime cyber framework
Cyber Security Awards 2025 Silver – Integrated cyber services
SilverIntegrated cyber services
Cyber Security Awards 2025 Silver – GRC automation
SilverGRC automation
Cyber Security Awards 2025 Silver – Integrated cyber services
Silver 2026Best Project – New Product (Risk Analysis)
Cyber Security Awards 2025 Silver – Integrated cyber services
Silver 2026Best Use of Risk Technology & Platform
Cyber Security Awards 2025 Silver – Integrated cyber services
Silver 2026Best Cybersecurity Risk Management
Compliance Awards 2025 Bronze – Best compliance platform
BronzeBest compliance platform
Why this matters now

Maritime cyber security stopped being an IT topic in 2021. It’s been an SMS topic ever since.

Maritime cyber requirements continue to expand through IMO resolutions, class requirements and EU regulation. Each new requirement builds on controls and processes that operators are already expected to have in place.

WAVE 01

IMO 2021

From the first annual DOC verification after 1 Jan 2021, cyber risk must be addressed in the Safety Management System under the ISM Code.

IMO Res. MSC.428(98)
WAVE 02

IACS UR E26 / E27

For vessels contracted from 1 July 2024, class societies require demonstrable cyber resilience for vessels and the systems onboard them.

IACS UR E26 · E27
WAVE 03

NIS2 reaches the port

Port operators, terminal handlers and many maritime service providers now fall under NIS2’s essential-entity obligations.

EU Directive 2022/2555
WAVE 04

Port State Control

Port State Control regimes are increasingly checking cyber documentation as part of ISM-related inspections — a deficiency here is a hold.

PORT STATE CONTROL
How STORM GRC helps

One platform. Shore and fleet.

Most cyber tools were built for an office. STORM GRC is built for an operator that has an office, a fleet, and a regulator that doesn’t separate the two.

Shore

Run your office ISMS the way auditors expect: asset register, risk treatment plan, policies and procedures, internal audits, awareness — all unified in STORM GRC.

  • ISO 27001-aligned ISMS for head office
  • GDPR & DPIA workspace for crewing & HR data
  • Vendor & agency security assessments with BitSight ratings
  • Awareness training and phishing simulations for shore staff
  • Incident, non-conformity and corrective-action registers

Fleet

Manage cyber risk at vessel level the way the Safety Management System manages every other risk: documented, attributable, auditable.

  • Per-vessel asset register (IT, OT, comms, navigation)
  • Cyber risk assessment per vessel type & trade
  • Cyber procedures aligned to ISM Code structure
  • Cyber incident reporting via your existing SMS
  • Pre-PSC inspection self-check, runnable before each call
Regulatory coverage

Every framework a DPA, MTM or auditor will name.

STORM GRC’s maritime configuration is pre-mapped to the regulations and guidelines that apply to commercial shipping. You don’t translate generic ISO 27001 controls into the language of the ISM Code — STORM GRC does that for you.

01 / IMO
Res. MSC.428(98)
Cyber risk management integrated into the Safety Management System under the ISM Code. STORM GRC produces the cyber risk register and procedures auditors expect to see in the SMS.
Covered
02 / IACS
UR E26 & E27
Cyber resilience for the vessel (E26) and for onboard systems and equipment (E27) for new builds from 1 July 2024. Mapped to STORM GRC’s asset and risk model.
Covered
03 / BIMCO
Cyber Security Onboard Ships, v4
The industry’s de facto guidance document. STORM GRC’s vessel-level procedures and onboard awareness material follow the BIMCO control structure.
Covered
04 / EU
NIS2 Directive (2022/2555)
For operators classed as essential or important entities — including port operators and many maritime service providers. STORM GRC covers risk-management, reporting and governance obligations.
Covered
05 / EU
GDPR & UK GDPR
Crewing data, agency processing, passenger data and seafarer health information. STORM GRC provides Article 30 ROPA and DPIA workflow.
Covered
06 / ISO
ISO/IEC 27001 & 27002
Shore-side ISMS baseline. STORM GRC produces policies, SoA, internal audit reports and management reviews aligned to the 2022 control set.
Covered
The maritime workspace

What your DPA actually opens on Monday.

A risk register, treatment plan and document library configured for shipping — so the DPA, CSO and Tech team aren’t translating the latest BIMCO guidance into your own format every time something changes.

STORM GRC asset model for a maritime operator

Per-vessel risk register

Each vessel has its own asset inventory and risk register, rolled up to the fleet view your management board wants to see.

Cybersecurity-ready documentation

Cyber Security Management System and Vessel Cybersecurity Manuals written in the structure and language of the Safety Management System.

Pre-PSC self-check

A short, captain-friendly checklist that mirrors what Port State Control inspectors are now asking for — runnable before each call.

Implementation

From kickoff to audit-ready in 90 days.

A typical mid-size operator (15–40 vessels, shore office) hits audit-ready cyber posture within one quarter. Larger operators or new builds with IACS UR E26 obligations run a longer programme — but the first 30 days look the same.

30
days

Shore foundation

  • STORM GRC tenant provisioned and configured for maritime
  • Shore office asset inventory complete
  • Initial cyber risk register live, mapped to ISM
  • Stakeholders (DPA, CSO, IT, Tech) onboarded
60
days

Fleet-wide assessment

  • Per-vessel cyber risk assessment delivered
  • Vessel-level treatment plan with owners
  • Cyber procedures integrated into SMS
  • Awareness rollout to seafarers begins
90
days

Audit-ready

  • Internal audit completed and reported
  • Management review pack signed off
  • Pre-PSC self-check rolled out to fleet
  • External audit / DOC verification supported
Operational outcome

STORM GRC helps maritime operators centralise cyber risk management, vessel-level procedures, audit evidence and compliance workflows into one operational workspace aligned with maritime regulations and Safety Management System requirements.

Maritime-ready compliance operations Built for DPAs, CSOs, IT and Technical teams
Operational focus
Fleet Vessel & shore coverage
90 Day implementation roadmap
24/7 Compliance visibility
Multi Framework governance
Maritime FAQ

Maritime cyber security compliance — questions from Maritime IT teams.

If your question isn’t here, the answer is a 30-minute call — usually faster than email.

Does the vessel side need bandwidth to use STORM GRC?
No. STORM GRC is a browser-based SaaS platform — your team works from any device with an internet connection. There is no software to install on vessels. Vessel-level documents (procedures, checklists, awareness materials) are produced on shore and pushed to fleet via your existing document distribution channels, so vessels need no dedicated bandwidth for the platform itself.
Will STORM GRC disrupt our existing SMS?
STORM GRC is designed to plug into your existing Safety Management System, not replace it. Cyber procedures are produced in a format and structure that maps to your existing SMS chapters. Your DPA reviews and adopts what fits — STORM GRC doesn’t issue documents on your behalf.
We have an existing ISO 27001 ISMS for the office. Do we start over?
No. STORM GRC imports an existing SoA, policy stack and risk register, and reconciles it with the maritime scope. Most operators bring a shore ISO 27001 baseline and use STORM GRC to extend it to the fleet, not replace it.
Does STORM GRC cover IACS UR E26 / E27 for new builds?
Yes. IACS UR E26 (vessel) and E27 (onboard systems) requirements are mapped into STORM GRC’s asset and risk model. STORM GRC helps you evidence cyber resilience for the class society at delivery, and maintain it through the vessel’s lifecycle.
Are we caught by NIS2?
Many maritime companies are. NIS2 explicitly includes inland, sea and coastal passenger and freight water transport companies. For maritime transport, scope applies to the company (owner, manager or operator), not the individual vessels themselves. The exact position still depends on your structure, jurisdiction and role.
How does the integration with our security stack work?
STORM GRC integrates with Microsoft Defender, CrowdStrike and other MDM/EDR tools to pre-populate risk assessments and audit evidence. BitSight and FortiRecon feed into the supplier file for third-party risk. Jira and Teams pick up remediation tasks so your IT team doesn’t switch tools. For shore IT this typically removes 100+ hours of evidence collection per audit cycle.
Certifications

ICT PROTECT holds internationally recognised certifications across quality, security and assurance.

ISO 9001 · ISO 27001 · ISO 22301 · ISO 27701 ISAE 3000 Type I Cyber Essentials Certified and Cyber Essentials Plus
Get started

Walk us through your fleet. We’ll walk you through STORM GRC.

A practical discussion with someone experienced in DOC verification and maritime cybersecurity assessments. You receive a short written summary of the main gaps identified against IMO MSC.428(98) and IACS UR E26/E27.

Book a maritime demo

EU-based team. Genuine maritime references on request.