Sea Current Tech
Connectivity, gadgets and digital life for people who work at sea

ClassNK Cyber Resilience Guide: What Crew Must Do

Updated 6 September 2026 · cyber security, ship systems, regulations, crew life

ClassNK Cyber Resilience Guide: What Crew Must Do

Here is the short answer. ClassNK published the Guidelines for Cyber Resilience of Ships (1st Edition) in July 2024 to interpret IACS Unified Requirement E26, which applies to ships contracted for construction on or after 1 July 2024. The document is guidance for shipbuilders, shipowners and management companies, and it explains ClassNK's approval process, required documents and surveys. It creates no new job title onboard. It creates paperwork and habits that fall on the engineers and the ETO.

What ClassNK actually published, and when

ClassNK issued the Guidelines for Cyber Resilience of Ships as a 1st Edition in July 2024. ClassNK's own Technical Research Report for 2024 (document reference 10_e06, item 18 in that report) lists the document by that exact name and date, so July 2024 is the reference point for the first edition.

The guidelines exist to interpret IACS UR E26, titled "Cyber resilience of ships." UR E26 aims to ensure the secure integration of both operational technology and information technology equipment into the vessel's network across design, construction, commissioning and the operational life of the ship. That last phrase is the one that matters here. Design and construction happen without the crew. Operational life is the crew.

ClassNK also states, in its rule amendment 24-1-31e (dated 27 June 2024), that UR E26 and UR E27 have been incorporated into Part X, Computer Based Systems, and into the Guidance for the Approval of Materials and Equipment for Marine Use, applying to ships contracted for construction on or after 1 July 2024. That amendment carries a separate chapter titled "Cyber Resilience" covering requirements for onboard systems and equipment.

Two related documents sit next to it and get confused with it constantly:

  • Guidelines for Designing Cyber Security Onboard Ships (Second Edition) covers newbuilding design and is aimed at shipyards and shipbuilding owners, according to ClassNK's press release announcing the second edition. That edition folds in the IEC 62443 industrial control system standards and IACS Recommendation No. 166 on cyber resilience for new ships, published May 2020.
  • Guidelines related to UR E27 target manufacturers and suppliers of marine systems and equipment. E27 is the equipment level requirement. E26 is the ship level requirement. When a vendor states their unit is "E27 approved," that says nothing about whether the ship it is fitted to passes E26.

For a fuller picture of the rule's scope, ClassNK maintains a dedicated UR E26/E27 activities page in its cybersecurity section, separate from the press releases and the rule text itself.

The definition ClassNK uses, and why it excludes crew WiFi

ClassNK defines cyber resilience in its rules as the capability to reduce the occurrence and mitigate the effects of cyber incidents arising from disruption or impairment of operational technology used for the safe operation of a ship, which potentially lead to dangerous situations for human safety, safety of the vessel, or threat to the environment.

Read that definition twice, because it draws a hard line. The scope is OT used for the safe operation of the ship. A cabin router, the crew WiFi voucher system and the mess room streaming box are not in it, unless they touch a network segment that reaches OT. That is exactly why the physical separation between crew and ship networks has become the single most examined thing onboard. If crew internet lives on its own segment with no path into the bridge or engine systems, it stays outside the scope and outside the survey. If somebody has bridged the two with a cheap switch to get a better signal in the accommodation, the crew network just became part of a classification requirement. A companion article covers the practical side of that split: how crew WiFi is separated from the ship network.

The five aspects UR E26 is built on

UR E26 covers five key aspects for ship level cyber resilience, according to ClassNK's press release on the guidelines (press release No. 11802): equipment identification, protection, attack detection, response, and recovery. ClassNK's guidelines explain how each of those is implemented in ClassNK rules and approval processes, including the surveys and documentation.

Here is what each aspect turns into as a real job on a working ship. The right column translates each requirement into what it typically becomes as an onboard task; it is a plain-language reading, not a quotation from the guidelines.

UR E26 aspect What it means onboard in practice
Equipment identification Somebody maintains an accurate inventory of computer based systems, including firmware versions and every network connection. This is the item that rots fastest, because a service engineer swaps a card in Singapore and nobody updates the list.
Protection Network segmentation stays as designed, unused ports stay disabled, and default passwords are gone. Every workaround from a busy port call erodes this one.
Attack detection Logging is enabled and the logs are actually retained. A system whose log storage filled up months ago and stopped writing new entries fails this without anybody noticing.
Response There is a written procedure people have practised, and a named person who decides when to isolate a system.
Recovery Backups exist, and somebody has restored one at least once. An untested backup is a theory.

Recovery is where most ships are weakest. Taking a backup is easy and everyone does it. Proving a bridge system can be restored from that backup, in an acceptable time, is the part that gets deferred forever. The one action worth prioritising after reading this is restoring one backup to spare hardware and recording how long it took.

Where the crew actually gets hit

The workload lands in three places, and none of them are glamorous.

The system inventory becomes a living document. Equipment identification sounds like a one-off task for the yard. It is not. Every firmware update, every replaced controller, every new remote support connection changes the picture. On ships that handle this well, the ETO or second engineer updates the list the same day the change happens, and it takes two minutes. On ships that handle it badly, somebody rebuilds the whole list from scratch the week before a survey, which takes days and produces a document nobody trusts.

Remote access gets logged and questioned. Vendor remote support is the most useful and most dangerous thing on a modern ship. A maker's engineer dialling into the main engine control system from ashore saves a port call. It also opens a path from the internet into OT. Under a resilience regime, somebody onboard has to know that connection exists, when it was open, and who authorised it. In practice that means a simple log: date, system, vendor, who approved it, when it was closed.

Evidence has to survive a crew change. This is the part that catches good ships out. The chief who set up the whole scheme goes on leave, the relief has never seen the file, and the surveyor asks a question nobody can answer. Evidence that lives in one person's head is not evidence. It has to live in a folder that the next person can find without a phone call.

The Starlink complication

Fast satellite broadband changed the risk picture faster than the paperwork could follow. A ship that had a slow, expensive, tightly controlled VSAT link in 2020 now has a fat always-on connection, and the temptation to hang more things off it is constant. The cyber resilience requirements do not ban that. They mean that anything connected has to be accounted for in the design and the documentation. A companion article details the specific ways this goes wrong: what crew get wrong about Starlink maritime cyber risk; the short version is that convenience patches made in good faith are the usual root cause.

Getting the documents

The guideline documents download through ClassNK's My Page service after registration. ClassNK's press release for the Designing Cyber Security Onboard Ships second edition states plainly that the guidelines are available to download free of charge via the ClassNK website for those registered for My Page. A later press release about the UR E27 guidelines says the same thing: download via the Guidelines section of My Page for registered users. The Cyber Resilience of Ships guideline itself is currently hosted by ClassNK under the file reference gl_CyberResilienceofShips_202508e.pdf, which readers can search for directly on the ClassNK site to confirm the edition in force.

As of September 2026, that is the access route described in ClassNK's own published releases. Whether registration itself carries any cost is not stated in the material reviewed for this article, so it should be treated as unconfirmed pending a check of the official page. Prices for classification services, surveys and the cyber resilience class notation are likewise not published in the documents reviewed here; a company's technical department will hold the applicable fee schedule.

There is a class notation involved. Ships whose computer based systems comply with the cyber resilience measures in the guidelines can carry the notation CyberResilience-Guideline, abbreviated CybR-G, affixed to the Classification Characters. If compliance is not maintained, the notation is deleted. That deletion clause is the quiet part of the enforcement mechanism made explicit, and it is why the inventory and the logs matter between surveys rather than only before them.

Honest cons, because this is not a free win

It generates real administrative load on ships that are already short-handed. The five aspects are sensible engineering. Keeping the evidence current on a vessel running a lean engine department, with port calls stacked and a survey list already full, is a genuine cost. Anybody who calls it "just good practice, no extra work" has not maintained an equipment inventory across three crew changes.

The guidance is written for the industry, not for the person doing the task. ClassNK's stated audience for these documents is shipbuilders, shipowners and management companies, and for E27 it is manufacturers and suppliers. That is appropriate for a classification society. It also means the documents specify what must be achieved and how approval works, and leave the shipboard procedure to the operating company. A fleet office that has not translated it into a two-page onboard routine leaves that translation to whoever ends up doing the work.

Newbuilding bias. The rules apply to ships contracted for construction on or after 1 July 2024. The related design guidelines are explicitly for newbuilding. On a fifteen year old bulker, none of this arrives as a clean package, and the retrofit questions have less published guidance behind them.

Compliance and security are not the same thing. A ship can hold the notation and still be badly exposed, because a well-documented network is only as safe as the discipline of the people using it. The notation certifies that a scheme exists and was verified. It does not certify that nobody plugged a personal laptop into the wrong port last Tuesday.

Who should not spend time on this

A junior engineer or a cadet on a ship built before 2024 gains little from reading the full ClassNK guideline document cover to cover. It is written for approval processes they will never run. The principles matter more than the text: keep crew traffic off ship systems, never plug personal devices into OT networks, and report anything strange rather than fixing it without telling anyone.

For advice on protecting a personal phone, laptop and bank accounts while travelling, this is the wrong document entirely. Classification rules cover the ship. Personal security is a different problem with different tools, and port WiFi security is a far more useful read for that.

If a ship is not classed with ClassNK, the ClassNK-specific approval process and notation do not apply to it. The underlying IACS unified requirements still do, through whichever society the ship is classed with, so the five aspects still describe that world. The paperwork route will be different.

What a good ship actually does

The ships that handle this well share a few habits, and none of them require a budget.

  • The network diagram lives on the bridge and in the ECR, printed, with a revision date. A diagram in an email nobody can find is worth nothing at 0300.
  • One person owns the inventory. Usually the ETO, sometimes the second engineer. Ownership by committee means ownership by nobody.
  • Remote support sessions get a line in a logbook. Date, system, vendor, approver, closed at. Thirty seconds each.
  • Backups get restored on a schedule, not just taken on a schedule. Once a quarter is enough to catch media that has already failed.
  • New joiners get a five minute brief on what they must not plug in. This prevents more incidents than any piece of software.

FAQ

Does the ClassNK cyber resilience guide apply to my existing ship?

The IACS UR E26 and E27 requirements were incorporated into ClassNK's rules for ships contracted for construction on or after 1 July 2024. That means the requirements land on newbuildings first. Older vessels are governed by their existing class arrangements and by company and flag state cyber policies, so ask your technical superintendent what applies to your specific hull.

Is the ClassNK guideline free to download?

ClassNK's own press release for the Designing Cyber Security Onboard Ships second edition states the guidelines are available to download free of charge via the ClassNK website for those registered for the My Page service, and a later release about the UR E27 guidelines describes the same route. Whether My Page registration itself is free is not stated in ClassNK's published material reviewed for this article. Check the official ClassNK page before assuming either way.

What is the difference between UR E26 and UR E27?

UR E26 is the ship level requirement and covers secure integration of OT and IT equipment into the vessel's network. UR E27 is the equipment level requirement and targets manufacturers and suppliers of marine systems and equipment. A vendor can hold E27 approval for a unit while the ship it is installed on still fails E26, because E26 is about how everything fits together.

Does crew WiFi fall under these cyber resilience rules?

Not by itself. The ClassNK definition of cyber resilience is built around operational technology used for the safe operation of the ship. Crew internet on a properly separated network sits outside that scope. The moment somebody bridges crew and ship networks, the crew side becomes part of a classification concern, which is why the separation is worth protecting.

What is the CybR-G notation?

CyberResilience-Guideline, abbreviated CybR-G, is a class notation affixed to the Classification Characters for ships whose computer based systems comply with the cyber resilience measures in the ClassNK guidelines. If compliance is not maintained, the notation is deleted. That is the mechanism that makes the requirements continuous rather than a one-time inspection.

Who onboard is responsible for cyber resilience?

The guidelines describe requirements for the ship and its approval, and leave the onboard assignment to the company. In practice the work concentrates on the ETO where one is carried, and on the second or chief engineer where one is not, with the master accountable overall. If your ship has not named a person, that is the first gap to close.

Verdict

The guide is worth the download for an ETO, a chief engineer, or anybody whose signature ends up on a survey document. It is clear about what must be achieved, and it explains the approval route properly. It will not hand over an onboard procedure, and the administrative load is real on a short-handed vessel. The five aspects are the useful part, and equipment identification and recovery are where nearly every ship is weaker than it looks on paper.

A note on sourcing

The claims about ClassNK's documents in this article are drawn from ClassNK's own published guidelines, press releases and rule amendments, cited above by title, date and reference number where one exists: the 1st Edition Guidelines for Cyber Resilience of Ships (July 2024, listed as item 18 in ClassNK's 2024 Technical Research Report, document 10_e06); press release No. 11802 on the UR E26 guidelines; rule amendment 24-1-31e (27 June 2024); the Designing Cyber Security Onboard Ships Second Edition press release; and the current guideline PDF filed under gl_CyberResilienceofShips_202508e.pdf. Where a figure could not be verified against those sources — particularly fees and My Page registration costs — this article says so directly rather than filling the gap.

Related reading