Maritime cybersecurity on paper vs the USB in the bridge PC
Ships now carry layers of cyber policy — but much of it lives on paper while, under pressure, a USB stick still ends up in an onboard PC. The real problem isn't writing the framework; it's whether it can be enforced in daily operation.
In this article
Maritime cybersecurity has come a long way on paper. Newbuildings are increasingly specified with security designed in; the IACS Unified Requirements E26 and E27 push cyber resilience into ship systems; most companies now hold cyber policies and produce them on demand. The written standard has genuinely risen. The question worth asking — and the one that decides whether any of it matters — is how much of that standard is actually enforced on a working ship.
Because in practice, a great deal of maritime cybersecurity still lives on paper. The framework exists, the audit passes, the policy is filed. And then, on an ordinary day under ordinary pressure, a USB stick goes into a bridge or engine-room PC to move a file, load an update or share a report — and the paper protection is simply bypassed. That gap, between the policy written and the practice enforced, is where the real risk sits.
The written standard is rising — for new ships first
It is worth being fair to the progress. Cyber-by-design is a real shift: building security into a vessel from the earliest design stages, rather than bolting it on after delivery, is the right direction, and the class requirements now pushing it into newbuildings will raise the baseline over time. None of this piece argues against that.
But two things follow. First, the strongest version of this standard arrives with new ships, while most of the fleet is already at sea and was built before it existed. Second, a requirement specified at delivery is only as good as its enforcement in service — and enforcement is exactly what a document cannot guarantee.
Where paper meets the working ship
The removable-media problem is the clearest illustration. The industry’s own Guidelines on Cyber Security Onboard Ships explicitly flag the risk of malware introduced through removable media and call for procedures to manage it. The risk is not unknown; it is well documented. And yet the USB stick endures, because it is convenient and because, when a crew is under time pressure with a job to finish, convenience wins over a policy no one is actively enforcing at that moment.
The consequences are not hypothetical either. Credential and data exposures keep landing on the industry: the FortiBleed leak alone was reported to have exposed more than 250 maritime companies, putting shipowners’ defences at risk through compromised credentials. Attackers do not need to defeat a sophisticated architecture when a leaked password or an unmanaged USB port offers an easier way in. The weakest link is rarely the framework on paper; it is the everyday practice the framework assumes but cannot compel.
What this means day-to-day
The takeaway is not that policy is pointless — it is that policy without enforcement is a false sense of security. For an owner or manager, the useful questions are about what holds when no one is watching:
- Can your removable-media rule be enforced technically, not just written? A policy that says “don’t use unauthorised USBs” is weaker than a control that limits what an unknown device can do when it is plugged in.
- Are credentials and access actually managed? Leaked or shared passwords are a recurring way in. Disciplined access control is unglamorous and it is where a lot of real risk is closed.
- Is cyber hygiene treated as seamanship, not paperwork? Crews follow procedures they understand and own. Training that makes cyber part of routine practice outperforms a policy read once and signed.
- Does the protection fit the ship you have? For the existing fleet, controls that assume new hardware or an onboard IT specialist will not be run. Protection has to be usable by the people already aboard.
In our view
The honest picture is that shipping’s cybersecurity is strong on paper and uneven in practice. The frameworks are improving and the newbuild standard is rising, and that is welcome — but resilience is not won by the document specified at delivery. It is won by whether the rule holds on a busy day, when the auditor has gone and the USB stick is the quickest way to finish the job. In our view, the industry’s next real gain in cyber resilience is not another layer of policy; it is closing the distance between what is written and what is enforced — with technical controls that do not depend on constant vigilance, and with the existing fleet given protection it can actually run. Paper raises the standard. Enforcement is what keeps the ship safe.
What to watch
Watch whether cyber requirements move from documented to genuinely enforceable onboard — real controls on removable media, access and updates — rather than audited once and quietly ignored. Watch how far IACS E26/E27 reshape newbuild practice, and whether that discipline reaches the ships already trading. And watch whether the industry treats credential and removable-media hygiene as the front line it plainly is, rather than the footnote it too often becomes.
Spot an error? Request a correction
Frequently asked questions
Isn't shipping's cybersecurity improving?
On paper, clearly yes — newbuild cyber-by-design and the IACS E26/E27 requirements are raising the standard, and most companies now hold cyber policies. The question this piece asks is different: how much of that written standard is actually enforced on a working ship, day to day, rather than produced for an audit and then left on the shelf.
Why single out removable media / USB?
Because it is a long-standing, well-recognised infection route that persists precisely because it is convenient. Industry guidance explicitly calls out the risk of malware introduced through removable media, yet under operational pressure a USB stick still gets plugged into an onboard PC to move a file, update software or share a report. It is the clearest example of the gap between policy and practice.
What does enforceable cyber protection look like?
Controls that hold even when no one is watching: technical restrictions on what removable media can do, managed software updates, disciplined access and credentials, and network segregation — backed by training that treats cyber hygiene as routine seamanship. The aim is protection that survives a busy day at sea, not a binder that survives an audit.
Written by Apeks Tech Editorial Desk
Maritime review by
İbrahim Halil Ceylan
Chief Engineer · Founder, Apeks Tech
Engineer with hands-on experience in vessel operations, survey and technical management — working on software and applied AI for shipping. About → · LinkedIn →