Home / Resources / Fleet cyber governance checklist

Cruise lines and maritime · Governance checklist

Fleet cyber governance checklist

Fifteen questions to ask the fleet's IT, marine, and technical teams and the vendors who support the ships. Answer them for two ships of the same class. Where the answers differ, that gap is usually the first governance finding.

Fifteen questions to ask the teams and vendors

They tell a governance leader quickly where a fleet stands: who owns OT on board, what can reach it from shore, and what the board actually sees.

Inventory and ownership

  • Is there an OT asset inventory for each ship, and who keeps it current?
  • Who owns OT security on board: IT, the chief engineer, or the OEM?
  • Which systems are safety critical, and are they on separate networks?

Connectivity and remote access

  • How many satcom and LEO links does each ship have, and what can reach OT through them?
  • Which vendors have remote access, how is it approved, and is it logged and time-limited?
  • Is guest and crew traffic kept off the bridge and machinery networks?

Vendors, OEMs and shipyards

  • Do contracts require IACS E27 or IEC 62443 security from suppliers?
  • How do OEMs deliver and test patches, and who signs off on board?
  • Do new builds and refits go through a cyber review before delivery?

Detection and response

  • Can the team see OT network traffic at sea, or only IT?
  • Does the incident response plan cover a ship at sea with limited bandwidth?
  • When did the bridge, engine room, and shore teams last run a cyber tabletop together?

Compliance and reporting

  • Which vessels and U.S. terminals fall under the USCG rule, and are they on track for July 16, 2027?
  • Is cyber risk in each ship's Safety Management System, as IMO expects?
  • What does the board see each quarter, and does it show OT as well as IT?
Download

Fleet cyber governance checklist

The fifteen questions as a one-page PDF with space for answers by ship. Red Tiger can turn it into a fleet baseline survey and score every ship the same way.

Download the checklist (PDF)

Not legal advice. Rule status as of Oct. 4, 2026.

Where Red Tiger fits

Red Tiger assesses shipboard OT the same way it assesses a plant: passive on the live systems, with the chief engineer and the bridge team, from the satcom links down to propulsion, power, and navigation. The findings and remediation options go to fleet leadership, and the team fixes the immediate need.

U.S.-flagged vessels and U.S. terminals also fall under the Coast Guard cyber rule. See the USCG cyber rule readiness checklist and the USCG Regulated Sector page.

Thank you! Your submission has been received!
Oops! Something went wrong while submitting the form.