Here is the honest situation. IMO Resolution MSC.428(98) requires cyber risk to be addressed in every ship's Safety Management System, and the BIMCO Guidelines on Cyber Security Onboard Ships are how the industry does it: identifying vulnerable bridge, navigation, propulsion, cargo and communications systems, segregating OT from IT, controlling access and removable media, training crew, planning contingency and recovery, and managing third parties through the BIMCO cyber security clause. Building that into the SMS and evidencing it for a flag state or class audit is real work, and a ship with cyber missing from the SMS or an untrained crew is exactly where ships and fleets fall short.
This Kit removes that translation. It is every maritime cyber obligation written as an adopt-ready control you personalize in a weekend, with the evidence an SMS auditor examines.
What you get, the moment you buy
Grounded in the BIMCO Guidelines on Cyber Security Onboard Ships and IMO Resolution MSC.428(98), with cyber risk in the ISM Safety Management System, onboard OT and IT systems, crew awareness, contingency planning and the BIMCO cyber security clause called out. Editable Word and Excel files.
What one control looks like
This is integrating cyber risk into the Safety Management System, where MSC.428(98) compliance begins. All 35 are built to this depth.
Why this is not another template pack
- The evidence is the point. A measure you cannot evidence does not pass an ISM audit. This tells you what an SMS auditor examines and where fleets fall short, for every control.
- OT, IT and the BIMCO clause built in. OT and IT segregation, onboard system protection, crew awareness and the BIMCO cyber security contractual clause are written into the controls, the substance the guidance requires.
- Built on a mapped compliance corpus, not one person's opinion, from a graph of thousands of controls across standards.
- It compounds. Maritime cyber maps onto ISO 27001, the NIST CSF and IACS UR E26/E27, so this work feeds your wider security and newbuild programs.
Who buys this
Ship owners, managers and operators, DPAs and cyber security officers, and the fleet IT and HSQE leads who own maritime cyber. Whether it is a first SMS integration or a fleet uplift, you save weeks and walk in with the onboard systems, crew training and evidence structured.
Common questions
Is it really editable? Yes. Word and Excel files you own and adapt. No portal, no subscription.
Does it cover MSC.428(98)? Yes. Integrating cyber risk into the Safety Management System, verified at the first annual DOC audit, is the first control group.
Does it cover OT systems? Yes. Bridge, navigation, propulsion, machinery and cargo OT, and their segregation from IT, are built as controls.
Does it include the BIMCO clause? Yes. The contractual cyber security clause obligations, each party's duties, cooperation and incident notification, are their own control group.
What if it is not for me? A 30-day money-back guarantee.
Instant digital download · 30-day money-back guarantee · The Art of Service Pty Ltd, GPO Box 2673, Brisbane QLD 4001 · support@theartofservice.com