Skip to main content
Image coming soon

IMO Maritime Cyber Risk Management Evidence & Implementation Kit

$249.00
Adding to cart… The item has been added
IMO Maritime Cyber Risk Management · MSC.428(98) · Evidence & Implementation Kit
Meet the IMO maritime cyber requirement, without decoding the guidelines yourself.
Every duty handed to you as an adopt-ready control, from integrating cyber risk into the SMS through identify, protect and detect to respond, recover and verification, with the evidence an auditor examines.
SMS-cyber-ready in a weekend, not a quarter.

Here is the honest situation. IMO Resolution MSC.428(98) requires cyber risks to be appropriately addressed in a ship's safety management system under the ISM Code, and the IMO guidelines set out the functional elements: identify, protect, detect, respond and recover. It applies across IT and operational technology and depends on both shore and crew. An operator that runs ships but cannot show cyber risk in its SMS, its protective measures or its response plans is exactly where operators fall short at an ISM audit.

This Kit removes the guesswork. It is the maritime cyber requirement written as adopt-ready controls you personalize in a weekend, with the evidence an auditor examines.

What you get, the moment you buy

18
Duties as adopt-ready controls. Every duty, from SMS integration through identify, protect, detect, respond, recover and verification, written so you personalize and apply it.
18
Evidence-they-examine checklists. For each control, exactly what an auditor examines, plus where operators fall short, so you close the gap first.
1
Maritime Cyber Control Matrix, pre-built. Every duty in a working spreadsheet, ready to record status, owner and evidence location.
1
Gap & Readiness Assessment. Score each duty and the workbook returns your readiness as a single percentage, and exactly what to fix before an ISM audit.

Grounded in IMO Resolution MSC.428(98) and the IMO guidelines on maritime cyber risk management, with SMS integration, the identify, protect, detect, respond and recover functions, IT and OT systems, crew training, third-party risk and ISM verification called out. Editable Word and Excel files.

Cyber risk is now part of your ISM audit
Since the requirement took effect, ISM auditors expect to see cyber risk addressed in the safety management system: the identified systems, the protective measures, the response plans and the ability to keep operating safely during disruption. An operator with no cyber risk in the SMS gets a finding. This Kit builds the SMS-integrated identify-protect-detect-respond-recover controls with the evidence an auditor asks for.

What one control looks like

This is integrating cyber risk into the safety management system, where the requirement begins. All 18 are built to this depth.

IMO-1 Integrate cyber risk into the safety management system SMS
Put this control in place

Ensure [your organization name] addresses maritime cyber risk within its safety management system under the ISM Code, treating it as a risk to the safe operation of its ships, with defined responsibilities, and document it, so that cyber risk is managed within the SMS and the organization can evidence its integration as IMO Resolution MSC.428(98) requires.

Guidance note.

IMO Resolution MSC.428(98) requires cyber risks to be appropriately addressed in the safety management system under the ISM Code.

Evidence an auditor examines
  • Cyber risk addressed in the SMS
  • Defined responsibilities
  • Records of the integration
Common finding they raise: Cyber risk is not addressed within the ship safety management system.

Why this is not another template pack

  • The evidence is the point. A duty you cannot evidence is an ISM audit finding. This tells you what an auditor examines and where operators fall short, for every duty.
  • Identify-to-recover built in. The SMS integration and the identify, protect, detect, respond and recover functions are written into the controls, the substance the IMO guidelines set out.
  • Built on a mapped compliance corpus, not one person's opinion, from a graph of thousands of controls across standards.
  • It compounds. The IMO functions mirror the NIST framework, so this work feeds your wider cyber and safety programs.

Who buys this

Shipowners, operators and managers and their DPA, safety, IT and OT leads. Whether it is a first SMS integration or an audit-readiness pass, you save weeks and walk in with identify, protect, detect, respond and recover structured.

By the end of the weekend you will have
✓  An adopt-ready control for all 18 duties
✓  A completed maritime cyber control matrix
✓  The evidence an auditor examines
✓  Your SMS-integrated cyber controls in place
✓  A readiness percentage and a fix list
✓  The response, recovery and OT gaps closed

Common questions

Is it really editable? Yes. Word and Excel files you own and adapt. No portal, no subscription.

Is this an ISM certificate? No. It is an implementation toolkit grounded in the IMO guidance. Certification is through your ISM audit; this gets your SMS cyber content and evidence in order fast.

Does it cover operational technology? Yes. Identifying and protecting OT and control systems is built as controls.

Does it cover response and recovery? Yes. Responding to and recovering from cyber incidents and maintaining safe operation are built as controls.

What if it is not for me? A 30-day money-back guarantee.

Do not face an ISM audit with cyber risk missing from your SMS.
Every maritime cyber duty is fast to adopt with the Kit. It is instant, and it is guaranteed.
Add it to your cart and be SMS-cyber-ready this weekend.

Instant digital download · 30-day money-back guarantee · The Art of Service Pty Ltd, GPO Box 2673, Brisbane QLD 4001 · support@theartofservice.com