Maritime ICT Cybersecurity Drills

Maritime ICT Cybersecurity Drills

Training crews to identify, protect, respond to, and recover from real onboard cyber incidents including phishing emails, infected USB devices, and compromised mobile equipment.

From Compliance to Crew Readiness

Cyber incidents are no longer an IT issue. They are an operational and safety risk. Marpoint’s ICT Cybersecurity Drill is a practical, scenario-based service that helps shipping companies meet regulatory requirements while ensuring crews know how to respond correctly when incidents occur.

Cyber Incident Lifecycle Training

identify-protect-respond-recover

The drill is structured around the complete cyber incident lifecycle expected by regulators and auditors.

Cybersecurity Drill Use Cases

The Marpoint ICT Cybersecurity Drill is based on real-life onboard situations frequently observed during inspections, audits, and incident investigations.

spam mail phishing

Phishing & Spam Email Onboard

Crew members receive a suspicious email and must:

  • Identify warning signs
  • Avoid unsafe interaction
  • Report and escalate correctly

Infected USB or Removable Media

A USB device introduces suspicious behavior. The drill trains crews to:

  • Stop usage immediately
  • Isolate affected equipment
  • Prevent further spread

Mobile Device–Related Incidents

Risks are introduced through personal or shared mobile devices connected onboard.

Missing or Corrupted Operational Files

Crew response when critical files are unavailable or damaged, focusing on:

  • Correct reporting
  • Preventing escalation
  • Supporting recovery

How the Drill Is Executed

The drill is typically completed within a single scheduled session per vessel.

Each scenario is executed in a controlled environment, focusing on behavior, awareness, and procedural compliance.

Compliance & Audit Alignment

Crew actions during the drill align with internationally recognized principles of identification, protection, response, and recovery, providing defensible audit evidence.

Deliverables

Benefits for Shipping Companies

  • Improved crew cyber awareness onboard
  • Faster, structured response to incidents
  • Reduced risk of escalation and downtime
  • Stronger ship–shore coordination
  • Clear, defensible evidence of cyber preparedness during audits

Who This Service Is For

  • Shipowners and Ship Managers
  • HSQE and Compliance Teams
  • Maritime IT & Cybersecurity Managers
  • Vessels preparing for DOC verification or audits

Get it started

Stop treating cyber-drills as a checkbox. Start treating them as a shield.
Marpoint’s ICT Cybersecurity Drills turn mandatory requirements into a streamlined, high-performance process.

From compliance to confidence in four clicks:

Frequently Asked Questions

Why Cybersecurity Drills Are Mandatory

Cyber incidents are no longer limited to shore-side IT systems. They increasingly originate onboard, through everyday crew interaction with email, removable media, and mobile devices.

Under the ISM Code, companies are required to ensure that cyber risks are appropriately addressed within the Safety Management System (SMS). Since 1 January 2021, this requirement has been reinforced through guidance issued by the International Maritime Organization.

Auditors and inspectors now expect practical evidence that: Crews can recognize cyber risks Correct procedures are understood Cyber incidents are included in emergency preparedness Policies alone are no longer sufficient.

What Is the Marpoint ICT Cybersecurity Drill

The Marpoint ICT Cybersecurity Drill is a unique, crew-centric training service designed to prepare shipboard personnel for the full lifecycle of a cyber incident.

Unlike traditional cybersecurity training or tabletop exercises, the drill focuses on real crew actions onboard, not theoretical responses or IT troubleshooting.

The drill trains crews to:

  • Identify suspicious cyber activity
  • Protect vessel systems through correct first actions
  • Respond using structured communication and escalation
  • Recover operations in coordination with shore-based IT teams
  • No real malware is used. No operational, navigational, or safety-critical systems are affected.

Which regulations does this drill support?

The Marpoint ICT Cybersecurity Drill supports alignment with:

  • IMO MSC-FAL.1/Circ.3
  • ISM Code – Emergency Preparedness (Element 8)
  • SMS training and awareness requirements
  • Company cyber risk management procedures

Does the drill train the full cyber incident lifecycle?

Yes.
The drill is specifically designed to train crews to identify, protect, respond to, and recover from cyber incidents commonly encountered onboard, including phishing emails and infected removable media.

Is this drill acceptable evidence during audits and inspections?

Yes.
Each drill includes official documentation and a confirmation letter that may be presented to auditors, Flag State, Class, or Port State Control as evidence of crew training and cyber emergency preparedness.

Does the drill involve real malware or system disruption?

No.
The drill is conducted in a controlled environment using simulated scenarios. No real malware is deployed, and no operational, navigational, or safety-critical systems are affected.

Are safety-critical OT systems involved in the drill?

No direct interaction with safety-critical OT systems occurs.
The drill focuses on crew awareness, communication, escalation, and initial containment actions related to ICT systems, in line with SMS and cyber risk management principles.

Who participates in the drill onboard?

Participation typically includes:

  • Shipboard crew members
  • Officer in Charge
  • Shore-based IT or support teams (as applicable)

The focus is on demonstrating correct roles, responsibilities, and communication pathways.

Is the drill conducted onboard or remotely?

The drill can be conducted:

  • Onboard the vessel
  • Remotely, with live guidance from Marpoint engineers
  • In a hybrid format, depending on operational constraints

How often should cybersecurity drills be conducted?

The frequency should align with company SMS procedures and audit cycles.
Many companies conduct cybersecurity drills annually or prior to DOC verification to demonstrate continuous compliance and crew awareness.

Does the drill replace cybersecurity policies or technical controls?

No.
The drill complements existing policies and technical measures by validating that crews understand procedures and can apply them correctly during an incident.

What documentation is provided after the drill?

Deliverables include:

  • Official ICT Cybersecurity Drill Report
  • Scenario-based drill documentation
  • Cybersecurity Drill Confirmation Letter

These documents are designed to be audit-ready.

Is the drill vessel-specific?

Yes.
Each drill is executed and documented per vessel, ensuring traceability and relevance for audits and inspections.

Request a Cybersecurity Drill Proposal

No obligation. No operational disruption.