Maritime Cybersecurity Has Plenty of Guidance. The Hard Part Is Knowing What to Do Next.

Cyber Readiness in A9X CyberDetective turns IMO, NIS2, BIMCO and IAPH guidance into practical vessel-by-vessel checks, supported by existing audit data.

IMO. NIS2. BIMCO. IAPH.

There is no shortage of cybersecurity guidance for the maritime industry.

The harder question for the person actually responsible for a fleet is much simpler:

What should I be checking on each vessel today?

That is the problem we wanted to address with the new Cyber Readiness feature in A9X CyberDetective.

From guidance to practical checks

Cyber Readiness brings together related requirements and recommendations from IMO, NIS2, BIMCO and IAPH and turns them into a practical vessel-by-vessel checklist.

Instead of simply presenting another document to read, the system gives teams specific checks and actions to work through.

These include areas such as:

  • Antivirus protection
  • Windows security and pending restarts
  • User and access reviews
  • Crew cyber awareness and training
  • Incident response preparedness
  • Backup and recovery
  • Other operational cyber controls

Each item includes references back to the relevant source guidance, so teams can see why the check matters and where it came from.

It isn't just another compliance checklist

This was important to us.

A checklist that exists separately from what is actually happening on the vessel only tells half the story.

Cyber Readiness therefore works alongside existing CyberDetective audit data.

If an audit has already identified an issue — for example, a machine without suitable antivirus protection or a Windows PC waiting for a restart — that issue remains visible alongside the readiness checks.

That creates a much more useful question:

Are we doing what the guidance recommends, and does the technical evidence support it?

Built for ongoing use

Cyber readiness isn't something that should be assessed once and forgotten.

Teams can switch between checklist and table views, filter checks by guidance or standard, and mark individual checks as completed.

CyberDetective records the completion date and the user who performed the check, creating a simple record of the work being carried out across the fleet.

Reported technical issues remain visible rather than disappearing simply because a checklist item has been completed.

A starting point, not a magic "compliant" button

We have deliberately avoided presenting Cyber Readiness as an automatic compliance certificate.

Maritime cyber requirements depend on the vessel, company, operation and applicable regulatory environment. Specific flag-state and port requirements are not included in this initial release.

Instead, Cyber Readiness is designed to do something more practical:

Help maritime teams understand what they should be checking, identify where attention is needed, and decide what to do next.

Because having another 50-page cybersecurity document isn't necessarily the problem.

Turning it into action is.

Cyber Readiness will be available in CyberDetective in early October 2026.

Interactive demo

Try USB Manager Local Edition in the browser.

Walk through USB blocking, temporary unblock, Secure Copy, ECDIS media, Defender update USB creation, settings, license, and updates.