The Cyber Retrofit Problem Hidden Inside the Existing Flee

🔔 Subscribe to ShipUniverse Weekly →

Existing Fleet OT Stress Test

Existing Ships Are Becoming Cyber/OT Liabilities

The machinery still works. The network around it has changed. Propulsion, navigation, power and auxiliary systems designed for a much less connected ship are increasingly sharing data with remote vendors, shore offices and digital platforms.

Essential-function trust
Propulsion
OT
Navigation
OT
Power management
OT
Local fallback
VERIFY
Cyber risk becomes marine-safety risk when a digital failure can move a physical process.
The important question is no longer whether the ship was hacked. It is which essential functions can still be trusted.

A twenty-year-old propulsion controller does not become insecure simply because it is old. The risk changes when equipment designed for a relatively isolated ship is connected to modern satellite communications, remote diagnostics, vendor support, fleet-performance platforms and shore networks.

That creates a difficult retrofit problem. The machinery may still have fifteen years of economic life left, while the software, network architecture and access model around it were never designed for the permanently connected operating environment now being built around the ship.

Maritime cybersecurity is therefore moving out of the office network and into the machinery space. The unit of risk is no longer only a stolen password or encrypted laptop. It is loss of confidence in propulsion, steering, navigation, electrical power or the information the crew uses to control them.

Global installed fleet
~116K
Merchant vessels of at least 100 GT at the start of 2026.
Fleet age by count
22.2 yr
UNCTAD's 2024 average, illustrating how much of the installed base predates today's cyber-by-design rules.
Existing-ship baseline
14
Cybersecurity controls in IACS Recommendation 194.
Current U.S. watch
~20
Commercial vessels reportedly being tracked over cyber threats in September 2026.

The week's most important maritime cyber detail is one word: propulsion

VL Prosperity investigation

Investigators found access beyond business IT

OT
Propulsion-system access reported

Updated October reporting says investigators found evidence that outsiders temporarily accessed the tanker's propulsion system.

Vessel 333 m VLCC Built in 2015, long before the current IACS newbuild cyber-resilience boundary.
Confirmed consequence No operational disruption Authorities reported no instability, crew danger or environmental impact.
Unknown Exact control scope Public reporting does not establish precisely what functions an intruder could command.
Investigation USCG + FBI Operational and information-technology systems were examined onboard.
Keep the claim precise
Access to a propulsion system is not the same as proof that an attacker controlled the engine or altered vessel movement. The significance is that the cyber-security boundary had reached equipment capable of influencing a physical marine function.

The ship did not become vulnerable overnight. Connectivity accumulated around it.

01

Local control

Machinery control and monitoring originally operate largely inside local shipboard networks.

02

Integrated bridge

Navigation, alarms, sensors and control systems exchange more information onboard.

03

Remote support

Vendors gain controlled pathways for troubleshooting, software support and diagnostics.

04

Ship-to-shore data

Performance, machinery and operational data begin moving continuously ashore.

05

Always connected

The old machinery now sits inside an environment with persistent broadband, cloud services and more third-party dependencies.

Age is not the variable to fix
A 20-year-old controller behind strong segmentation, controlled access and a tested local fallback may present less operational cyber exposure than a much newer system with weak network boundaries and permanently enabled remote access.

OT changes the consequence because these systems move the ship

Essential function

Propulsion

Engine governors, propulsion control, auxiliary systems and machinery alarms can influence the vessel's ability to maintain safe movement.

Essential function

Steering

Steering control and supporting electrical or hydraulic systems sit directly inside collision and grounding risk.

Essential function

Navigation

ECDIS, radar, GNSS, AIS and integrated bridge data affect the crew's picture of where the vessel is and what surrounds it.

Essential function

Electrical power

Power-management failure can remove several otherwise independent ship functions at the same time.

Connected operations

Cargo and ballast

Tank levels, valves, loading computers, ballast treatment and remote-control systems can create cargo, stability or pollution consequences.

Cyber-by-design arrived after most of today's fleet was already built

Existing ship

Contracted before 1 July 2024

No automatic E26/E27 retrofit

IACS' mandatory unified requirements were designed primarily around new ships. Recommendation 194 now gives the existing fleet a voluntary baseline.

→
Cyber-resilient newbuild

Contracted from 1 July 2024

Security enters the design

Asset inventories, network architecture, segmentation, access controls, testing, response and recovery are considered as part of the ship's cyber-resilience framework.

Retrofit gap
ClassNK's published E26/E27 Q&A states that replacing or newly installing an OT system on a pre-July-2024 existing ship does not, by itself, make E26/E27 compliance mandatory. That makes owner-led cyber governance particularly important during mid-life digital retrofits.

IACS' answer for the existing fleet is deliberately basic

Recommendation 194 contains fourteen baseline controls. The notable thing is how little exotic technology appears in the list. Most of it is disciplined engineering and operations.

IACS Recommendation 194 control map Existing ships
Control area Purpose Why legacy ships struggle Operational effect
Asset inventory Know which OT equipment, software and interfaces actually exist onboard. Systems accumulate through refits, vendor replacements and undocumented connections. Foundation
Network protection Separate and control communication between OT, IT and other zones. The original network may never have been designed around security zones. Contains spread
Malware protection Reduce malicious-code exposure using controls compatible with the system. Old or specialized equipment may not support conventional endpoint security. Compatibility issue
Access control Limit physical and logical access to essential systems. Shared accounts and inherited vendor credentials may persist for years. Reduce exposure
Wireless control Limit wireless exposure around OT and essential services. Convenience networks can appear after delivery without redesigning the OT boundary. Boundary risk
Remote access Authenticate, restrict and control shore or vendor connections. Remote maintenance may have been added long after commissioning. High priority
Portable media Control USB and maintenance devices entering ship systems. Offline machinery often still requires portable media for updates and diagnostics. Physical path
Training Make crew familiar with OT cyber incidents and degraded operation. Cyber response may historically have been treated as a shore-IT function. Crew control
Updates and maintenance Maintain supported software and controlled configuration. Patching may depend on equipment vendors, certification and planned downtime. Lifecycle issue
Network monitoring Detect abnormal communication, access attempts and malfunction. Many old OT networks were designed to operate, not to generate security telemetry. Visibility gap
Shore responsibility Define who supports the master during an incident. Responsibility may be split among owner, manager, IT team and vendors. Governance
Incident reporting Standardize escalation and evidence capture. A machinery malfunction may not initially look like a cyber incident. Recognition
Backup and restore Restore essential systems or configurations after compromise. A backup is not useful unless the correct software, configuration and restore method still exist. Recovery critical
Response and recovery Isolate affected systems and return the ship safely to operation. Crew must know what can be disconnected without creating a second operational hazard. Safety critical

The hardest cyber question after an incident may be "is this ship safe to sail?"

Recovery test

Restarting software is not the same as restoring trust

A ship may need to demonstrate that essential controls, protective functions, alarms, local operating modes and restored configurations behave correctly before normal operation resumes.

Control Can propulsion, steering and power still be controlled safely?
Identify which functions remain dependable and which operating restrictions are necessary.
Fallback Does local or alternative control actually work?
A documented backup mode has little value if nobody has verified it under safe conditions.
Restore Are known-good software and configurations available?
Recovery depends on clean backups, vendor support and an understood restoration sequence.
Evidence Can the owner prove the affected function is trustworthy again?
Class, flag, port authorities, charterers or terminals may need confidence before normal operations resume.

Existing ships can be hardened without pretending they are newbuilds

DNV's Cyber Secure framework explicitly includes vessels already in operation. Its entry-level notation is aimed at ships where only limited onboard modifications are feasible, while its broader Essential level examines control systems in greater depth.

The default scope covers ten essential onboard functions, including propulsion, steering, navigation, power generation, watertight integrity and related supporting systems. That framing is important: a retrofit program does not have to replace every controller. It has to identify which digital dependencies can create an unacceptable physical consequence and place credible barriers around them.

Retrofit priority
For many existing ships, the first high-value investment is unlikely to be replacing the main engine control system. It is knowing every connection into that system, separating it from unnecessary networks, controlling remote access, monitoring the boundary and proving the crew can continue safely if the digital layer becomes untrustworthy.

Legacy Ship OT Exposure Stress Test

Model an existing vessel's cyber exposure based on architecture rather than age alone. The score deliberately rewards segmentation, controlled remote access, visibility and tested recovery because those factors determine whether a cyber event remains an IT problem or reaches a physical ship function.

ShipUniverse Existing Fleet Cyber Model

How much OT liability has accumulated around this ship?

This is a defensive screening model. It does not test for vulnerabilities or simulate an attack. It scores architectural exposure, containment and recovery readiness from the operating information entered below.

OT risk model
Ship and OT footprint
Screening count across propulsion, steering, power, navigation and other essential functions.
Network and access
Detection and recovery
Legacy OT exposure
High

The vessel combines several connected essential functions with weak segmentation and limited OT visibility.

Exposure score 58 / 100
Physical-consequence surface 48 / 100
Containment strength 29%
Recovery readiness 59%
Vessel age 18 yr
Primary weakness Remote access
Resilience profile
Asset visibility
65%
Containment
29%
Detection
0%
Recovery
59%
Highest-value next control Re-engineer persistent remote OT access.

Move toward explicit approval, strong authentication and narrowly scoped vendor access before replacing otherwise serviceable machinery.

ShipUniverse defensive screening model only. It does not detect vulnerabilities, predict compromise probability, certify compliance or replace a vessel-specific cyber risk assessment. Scores are analytical sensitivity weights based on concepts in IACS Recommendation 194, IACS UR E26/E27, IMO cyber-risk guidance and existing-vessel class frameworks. Ship age is deliberately given limited weighting because architecture, access control, monitoring and recovery capability are more informative than age alone.
Research basis: October 2026 reporting on the U.S. Coast Guard and FBI investigation involving VL Prosperity; Gard's October 5, 2026 guidance on Cybersecurity Controls for Existing Ships; IACS Recommendation No. 194; IACS UR E26 and E27; ClassNK E26/E27 guidance and Cyber Security Management System material; DNV Cyber Secure class notation for vessels in operation; IMO revised Guidelines on Maritime Cyber Risk Management; U.S. Coast Guard Cybersecurity in the Marine Transportation System requirements and 2025 CTIME report; France Cyber Maritime 2025 Maritime Cyber Threat Overview; and UNCTAD merchant-fleet statistics. Incident claims are limited to what authorities or cited reporting currently support.
By the ShipUniverse Editorial Team — About Us | Contact