Skip to main content
Image coming soon

BIMCO Maritime Cyber Security Evidence & Implementation Kit

$249.00
Adding to cart… The item has been added
BIMCO Cyber Security · Cyber Risk Onboard Ships · Evidence & Implementation Kit
Manage maritime cyber risk to BIMCO and IMO MSC.428(98), without turning the guidance into controls yourself.
Every maritime cyber obligation handed to you as an adopt-ready control, from cyber risk in the Safety Management System and onboard systems through protection and detection to response, recovery and the BIMCO contractual clause, with the evidence an SMS auditor examines.
Audit-ready in a weekend, not a quarter.

Here is the honest situation. IMO Resolution MSC.428(98) requires cyber risk to be addressed in every ship's Safety Management System, and the BIMCO Guidelines on Cyber Security Onboard Ships are how the industry does it: identifying vulnerable bridge, navigation, propulsion, cargo and communications systems, segregating OT from IT, controlling access and removable media, training crew, planning contingency and recovery, and managing third parties through the BIMCO cyber security clause. Building that into the SMS and evidencing it for a flag state or class audit is real work, and a ship with cyber missing from the SMS or an untrained crew is exactly where ships and fleets fall short.

This Kit removes that translation. It is every maritime cyber obligation written as an adopt-ready control you personalize in a weekend, with the evidence an SMS auditor examines.

What you get, the moment you buy

35
Obligations as adopt-ready controls. Every maritime cyber obligation, from cyber risk in the SMS and onboard system identification through protection, detection, response and recovery to the BIMCO contractual clause, written so you personalize and apply it.
35
Evidence-they-examine checklists. For each control, exactly what an SMS auditor examines, plus where ships and fleets fall short, so you close the gap first.
1
Maritime Cyber Control Matrix, pre-built. Every obligation in a working spreadsheet, ready to record status, responsible person and evidence location across the fleet.
1
Gap & Readiness Assessment. Score each obligation and the workbook returns your readiness as a single percentage, and exactly what to fix next.

Grounded in the BIMCO Guidelines on Cyber Security Onboard Ships and IMO Resolution MSC.428(98), with cyber risk in the ISM Safety Management System, onboard OT and IT systems, crew awareness, contingency planning and the BIMCO cyber security clause called out. Editable Word and Excel files.

Cyber has to live in the SMS, not a side binder
MSC.428(98) does not ask for a separate cyber document, it requires cyber risk to be managed inside the existing Safety Management System, verified at the first annual DOC audit. A side policy the crew never sees fails. This Kit builds cyber into the SMS with the roles, procedures and records an ISM auditor expects.

What one control looks like

This is integrating cyber risk into the Safety Management System, where MSC.428(98) compliance begins. All 35 are built to this depth.

BIMCO-1 Integrate cyber risk into SMS SMS INTEGRATION
Implement this control

Incorporate maritime cyber risk management into the documented Safety Management System of [your vessel or fleet name] so that cyber threats to safety and operational technology are identified, assessed, and mitigated as an integral part of ISM Code procedures, with verification completed no later than the first annual Document of Compliance audit after 1 January 2021 and maintained at every renewal thereafter.

Practitioner note.

Class and flag verify cyber integration during ISM audits, not as a separate certificate.

Evidence an SMS auditor examines
  • SMS manual section referencing cyber risk management and MSC.428(98)
  • Document of Compliance audit report noting cyber risk verification
  • Company cyber risk assessment records for the fleet
  • Management review minutes covering cyber risk objectives
Common finding they raise: Cyber policy exists as a standalone document but is never cross-referenced from the approved SMS procedures.

Why this is not another template pack

  • The evidence is the point. A measure you cannot evidence does not pass an ISM audit. This tells you what an SMS auditor examines and where fleets fall short, for every control.
  • OT, IT and the BIMCO clause built in. OT and IT segregation, onboard system protection, crew awareness and the BIMCO cyber security contractual clause are written into the controls, the substance the guidance requires.
  • Built on a mapped compliance corpus, not one person's opinion, from a graph of thousands of controls across standards.
  • It compounds. Maritime cyber maps onto ISO 27001, the NIST CSF and IACS UR E26/E27, so this work feeds your wider security and newbuild programs.

Who buys this

Ship owners, managers and operators, DPAs and cyber security officers, and the fleet IT and HSQE leads who own maritime cyber. Whether it is a first SMS integration or a fleet uplift, you save weeks and walk in with the onboard systems, crew training and evidence structured.

By the end of the weekend you will have
✓  An adopt-ready control for all 35 obligations
✓  A completed maritime cyber control matrix
✓  The evidence an SMS auditor examines
✓  Cyber risk integrated into your SMS
✓  A readiness percentage and a fix list
✓  The common onboard and crew gaps closed

Common questions

Is it really editable? Yes. Word and Excel files you own and adapt. No portal, no subscription.

Does it cover MSC.428(98)? Yes. Integrating cyber risk into the Safety Management System, verified at the first annual DOC audit, is the first control group.

Does it cover OT systems? Yes. Bridge, navigation, propulsion, machinery and cargo OT, and their segregation from IT, are built as controls.

Does it include the BIMCO clause? Yes. The contractual cyber security clause obligations, each party's duties, cooperation and incident notification, are their own control group.

What if it is not for me? A 30-day money-back guarantee.

Do not let cyber sit outside the SMS.
Every maritime cyber obligation is fast to adopt with the Kit. It is instant, and it is guaranteed.
Add it to your cart and be audit-ready this weekend.

Instant digital download · 30-day money-back guarantee · The Art of Service Pty Ltd, GPO Box 2673, Brisbane QLD 4001 · support@theartofservice.com