Issue 5
By   / 30 Sep 2026
Compliance proves you wrote the access policy. It doesn’t prove you would catch it being used against you. In maritime cybersecurity, that gap is where fleets are breached.
By Simon Fotakis │ Maritime CISO, Insight │ Maritime Hub, Issue 5
By 2026, the maritime cybersecurity rulebook has put identity firmly in scope. IMO Resolution MSC.428(98) folds cyber risk into the ship's safety management system¹. BIMCO's Guidelines on Cyber Security Onboard Ships, Version 5, name access control and user privilege management as core controls². Your next ISM audit and your SIRE 2.0 assessment will both require that an access control policy is present. And yet, in the same year, more than 250 maritime, port and energy firms leaked credentials, 63% of them default admin accounts³. Every one of those firms could have probably passed a policy audit the week before. The rules had put identity in scope. The audits confirmed the paperwork existed. But the credential still leaked.
A certificate is a snapshot of your paperwork. It is not a control that catches a stolen login at 03:00.
That gap is not a technology problem but a fundamentally structural one. A clean audit proves the access policy exists and was evidenced on the day. It proves nothing about whether a departed superintendent's login still works, or that a shared bridge credential is not present in a crew WhatsApp group. At Insight, we view maritime identity risk through a three-layered lens that must line up: the Certificate you hold, the Credential the attacker uses, and the Catch that truly defends you. Get the first right but miss the third, and you can be compliant and compromised all at once.
Ask a maritime CISO what their last cyber audit proved, and the honest answer is: the policy existed on audit day. That is not negligible. But BIMCO v5 is explicit that a cyber risk assessment must be revisited whenever networks, connections, hardware and accounts change², which, on a live fleet, implies continuously.
A point-in-time certificate cannot satisfy a continuous requirement. It samples the estate, then moves on. Malicious actors do not.
This is where continuous identity management earns its keep. Insight builds a live identity store across ship and shore, capturing every user and machine identity, its owner, its privileges and usage. The result is an auditable evidence trail that an ISM auditor or SIRE 2.0 assessor can recognise. The outcome the client buys is not another static record; it is a defensible view of identity risk, accessible whenever they need it any time, any day.
2026 threat reporting is blunt: maritime incidents are increasingly identity-centric and persistence-driven, not purely technical⁴. The modern attacker rarely bothers with a clever exploit; a valid credential is often enough. In November 2025, the Black Sea logistics agency Stark Shipping had roughly 226 GB of manifests and financial files exfiltrated, through what looks like exposed remote access and admin-account phishing⁵. On another occasion, a widely deployed maritime VSAT terminal was found exposing its private satellite-network authentication key, through an unauthenticated management interface⁶.
The credential, not the exploit, is the way in.
Thus, the fix is not another certificate; it is true access control, that works in the operating environment. Shared and default accounts need to be eliminated. Multi-factor authentication and conditional access need to be enforced ashore and, as connectivity improves, extended shipside wherever practical. Privileged-access management should govern fleet platforms, while; OEMs, satellite providers and remote-support teams, should use time-bound (Just in Time), brokered access.
The supply chain reaches your fleet through logins, so it sits inside your identity perimeter whether your audit scope reaches it or not.
IMO's six functions include “Detect” for a reason¹. Resilience is not proven by holding a certificate; it is proven by detecting a login being used against you in real time and shutting it down. That requires a 24/7 AI-powered maritime SOC watching identity signals and anomalous behaviour; impossible-travel logins, privilege escalation, dormant accounts reactivating, or a machinery account authenticating, from a continent away. And when an alert fires, an approved playbook kicks in; identification to isolation, containment and reporting, not a shrug and a password reset. The evidence trail should answer the questions a charterer or SIRE 2.0 assessor will ask; which account was affected, what was the operational and safety impact, what containment was applied, and how was the incident closed?
The fair objection? “We already run detection. Our compliance programme drives real monitoring.” If that is true, you are ahead of much of the market, and this article is not arguing against well-run detection programmes. But for many vessel operators, the gap remains. The frameworks ask for the Catch, yet certification too often rewards the Certificate and never tests for it.
1. Baseline the Certificate. Honestly
List every account, human and machine, with its owner, privileges, last use and authentication method, then keep that view current across ship and shore. Most vessel operators cannot answer “who can log in to this vessel, and with what rights” in under a day. When kept live, that answer is more valuable than any certificate on the wall.
2. Close the Credential Gap
Eliminate shared and default accounts where found. Enforce MFA and conditional access wherever possible. Time-box and log OEM and remote-support access. Revoke a leaver’s access across ship and shore the same day. The process must work 24/7 with a vessel mid-ocean not just in a shore workshop the week before an inspection.
3. Build the Catch, and Measure It
Stand up 24/7 identity monitoring and tested ‘suspicious login’ playbooks. Measure identity exposure at board-level using; Key Risk Indicators, Key Performance Indicators, privileged and shared account counts, share protected by MFA, mean time to revoke a leaver, and the time to detect and contain a misused login. Those identity metrics indicate whether you would survive an actual attack. A certificate only proves you survived audit day.
A fleet does not become resilient the day it passes. It becomes resilient when it watches its own keys.
The sector is past debating whether identity is the front door. The real question is whether vessel operators can align the Certificate, the Credential and the Catch into one continuous operating model. Those who stop at the certification may prove compliance, but it does not prove resilience. Leaders go further, treating identity as a live operational discipline across fleet, shore, OEMs and security teams. Insight helps orchestrate that model end-to-end, from identity governance and privileged-access control through to a maritime SOC that catches trusted access, turned hostile.
You passed the audit. Would you catch the login?
Next in Issue 6: How Identity, Operational Technology segmentation and the incident playbook come together when a vessel is mid-voyage.

Simon Fotakis is a Maritime CISO at Insight, where he advises fleet operators on cyber risk across ship and shore. He has structured and led security programmes protecting assets across organisations generating up to $10 billion in revenue, with significant maritime experience gained at some of the world's largest ship managers. He is CISSP certified, and his focus spans maritime cyber architecture, ship-to-shore security, identity and access governance, and turning regulatory frameworks into working operational resilience
From strategic workshops to scalable solutions, we're ready to help you accelerate transformation and realise the full value of your data and Al investments.