Editor’s Note

A number on paper rarely tells you what is happening on the ship.

The industry has been building frameworks and defaults so that everyone could report something. That was the easy part. The harder work is now underway: replacing the assumed figure with the measured one and finding out whether the system you signed off on behaves the way the specification promised.

That shift favours owners willing to look closely at their own vessels and providers willing to show what the data actually says.

Today’s Headline Story

Every cyber assessment produces a number. The trouble starts when that number is treated as the answer.

CYTUR's threat brief lands on that point with unusual precision. Two integrated automation systems: one carrying more than 200 known vulnerabilities and the other about 20. On paper they belong in different worlds. On the vessel they scored within four points of each other and both required treatment. The count told the owner almost nothing about what an intruder could reach or what would happen to propulsion once they got there.

That distinction has stopped being academic. Maersk's NotPetya outage in 2017 remains the reference case for what a compromise costs a shipping business. Since then ransomware has taken down a classification society's fleet-management software and shut a major US port's systems for days. GNSS interference now disrupts navigation in the Baltic and around the Middle East as a matter of routine. In each case the damage came from how far the intrusion could travel once inside rather than from the flaw that let it in.

CYTUR's sample points at the same challenge. A serial-connected system with eight Ethernet services left active. A core controller with a clean record sitting beside a network device carrying thirteen flaws. Regulation has caught up in form: IACS UR E26 and E27 have applied to newbuild contracts since July 2024 and Recommendation 171 sets out how treatment should be weighed. What lags is the habit of asking how a piece of equipment is wired into the ship before deciding whether its vulnerability list matters at all.

The difficulty for owners is structural. Fleets run on equipment from dozens of vendors with layers of third-party components inside each cabinet and no single party holding the full connectivity picture. Scanning for vulnerabilities is cheap and easy to compare. Understanding exposure and impact requires people who know the vessel.

The report's own remediation case shows the payoff. A system moved from mandatory treatment to acceptable through updates and the removal of services that had no business running. Nothing exotic. Just knowing what was there.

Digital Ship Summit 2026

Digital Ship Summit 2026 — one month out

One room. One day. The people shaping how your fleet runs for the next decade.

IT leaders from leading shipowners and ship managers take the stage in the Athenian Riviera for three keynotes and three structured debates on data infrastructure, cyber resilience and AI.

One track. No parallel sessions. Nothing to miss.

Built for CIOs, CTOs and heads of IT who want candid conversations with peers. And with lunch and the drinks reception included, there’s plenty of time for the conversation to continue off stage.

We’re limiting attendance to 200 delegates, with remaining seats going quickly.

News in Brief

Two years after mandatory Maritime Single Windows, IMO seeks shipowner feedback

The IMO is surveying shipowners and port stakeholders on Maritime Single Windows two years after their mandatory introduction, with responses open until 31 October 2026.

Cadeler and Vattenfall target scalable offshore wind O&M platform solutions

Cadeler and Vattenfall are exploring new Major Component Exchange and maintenance solutions through Nexra, aiming to make offshore wind O&M more efficient and scalable.

ONE cuts vessel emissions intensity as digital fleet management expands

ONE has cut Scope 1 emissions intensity to 35.68 gCO₂e/TEU-km while expanding digital fleet management across more than 270 vessels through ZeroNorth.

BetterSea and GTT Marine integrate FuelEU trading into Vesper Insights

BetterSea and GTT Marine are integrating FuelEU trading, pooling and reporting into Vesper Insights, bringing compliance analysis and transactions into one platform.

MSC Cruises cuts reported methane slip with verified 1.67% and 1.48% data

MSC Cruises has verified methane slip of 1.67% and 1.48% on two LNG-fuelled vessels, replacing FuelEU Maritime default figures with ship-specific operational data.

How More Extreme Weather is Reshaping Maritime Operations, in partnership with OneOcean | 29th September

Digital Ship Summit | 15th October
Vessel Performance Summit | 10th March 2027

Yesterday's Top Story

Emmanuel Schalit, CEO of OceanWings, says wider wind propulsion adoption will depend on proven performance, independent verification and smarter software that can optimise vessel operations.

Keep Reading