Every modern ship runs two entirely different network families: Operational Technology (OT — the systems that control the physical vessel) and Information Technology (IT — the systems that support crew + business). Understanding the segmentation between them is the single most important concept in maritime cyber security today, and — since IACS UR E26 + E27 became mandatory for new-build contracts from 1 July 2024 — a first-order regulatory requirement.
OT systems physically control the vessel. If OT fails or is compromised, the vessel loses navigational or mechanical control.
IT systems support the crew and business functions. Compromise is inconvenient but doesn't (typically) put the vessel physically at risk.
The core cyber-security control is physical + logical segmentationbetween OT and IT networks. A compromised crew laptop on the WiFi network should not be able to reach the ECDIS network. This is enforced via:
IACS Unified Requirement E26 (Cyber resilience of ships) + E27 (Cyber resilience of onboard systems and equipment) are mandatory for new-build contracts signed on or after 1 July 2024. Practical implications: