Skip to main content

INSIGHTS

Does IMO Require Cybersecurity Training for Yacht Crew?

Share
IMO cyber guidance: is crew cybersecurity training a requirement? Relevant, role-based, verifiable.

The IMO's guidance calls for crew cyber training, but whether it is mandatory depends on the yacht. What MSC.428(98) and the 2025 IMO guidelines actually say.

A deceptively simple question comes up often in maritime cybersecurity: does the IMO require yacht crew to receive cybersecurity training?

The most accurate answer is this. The IMO's current cyber-risk-management guidance explicitly calls for annual basic cybersecurity training for employees and cybersecurity familiarization for crew joining a vessel. But whether that guidance translates into a regulatory obligation for a particular yacht depends on the regulatory framework that applies to that yacht.

That distinction matters. It is easy to turn a piece of maritime guidance into a sweeping statement such as "IMO requires every yacht crew member to complete annual cybersecurity training." The reality is more nuanced. And in cybersecurity, nuance matters.

Start with MSC.428(98)

The IMO's approach to cyber risk did not begin with crew training. A foundational step was Resolution MSC.428(98), adopted in 2017.

The resolution affirmed that an approved Safety Management System should take cyber-risk management into account in accordance with the objectives and functional requirements of the International Safety Management Code — the ISM Code.

For companies operating under the ISM framework, the IMO encouraged administrations to ensure that cyber risk was appropriately addressed in the Safety Management System by the first annual verification of the company's Document of Compliance after 1 January 2021.

The significance of MSC.428(98) is straightforward: cyber risk became something that should be managed as part of the vessel's broader safety-management process, not treated as a separate IT problem.

But MSC.428(98) does not mean that every vessel in the world automatically falls under the same cybersecurity requirements. Applicability still matters.

Then came the revised IMO cyber guidelines

The IMO significantly expanded its cybersecurity guidance in MSC-FAL.1/Circ.3/Rev.3, issued 4 April 2025. The guidelines describe cyber-risk management around six functional elements:

Govern. Identify. Protect. Detect. Respond. Recover.

That framework covers considerably more than phishing or password security. It addresses areas including authentication, network segmentation, firewalls, logging, third-party connectivity, backups, software updates, incident response and supply-chain security.

And importantly for crew training, the IMO becomes quite specific.

What does the IMO actually say about cybersecurity training?

Under the Protect function, the current IMO guidelines call for:

  • annual basic cybersecurity training for employees;
  • OT-specific cybersecurity training for people who use operational technology;
  • cybersecurity familiarization for crew when they join a vessel;
  • training that covers cyber hygiene, recognizing and detecting incidents, response and recovery; and
  • periodic testing of cybersecurity knowledge through methods such as drills and exercises.

That is meaningful language. It tells us that the IMO does not view cybersecurity education as a one-time presentation or simply an annual phishing exercise.

Crew should understand how cyber incidents happen, how they may recognize one, what they should do next, and how their actions affect the vessel's ability to recover. For yachts, that is a much more useful way to think about cybersecurity awareness.

So is it mandatory?

This is where the answer requires precision. The IMO document above is titled Guidelines on Maritime Cyber Risk Management. Guidelines are not automatically the same thing as a universally applicable statutory training requirement.

The regulatory picture depends on the yacht. Factors can include:

  • private versus commercial operation;
  • flag;
  • tonnage;
  • passenger capacity;
  • class;
  • whether the vessel operates under the ISM Code; and
  • whether the company holds a Document of Compliance.

The YMS360 curriculum specifically distinguishes vessels operating under an ISM/Document of Compliance structure from yachts to which that framework may not apply. Our own training documentation therefore does not claim that the same regulatory instrument governs every yacht. That is deliberate.

The correct question is not simply "does the IMO mention cybersecurity training?" It unquestionably does. The better question is "which IMO, flag, class and safety-management requirements apply to this particular yacht?"

Why the distinction matters for yacht managers

There are two poor ways to approach cybersecurity training. The first is to ignore it because someone determines that a particular IMO provision is not directly mandatory for their yacht. The second is to claim that every piece of maritime cybersecurity guidance is mandatory regardless of vessel type or operating regime. Neither approach is particularly useful.

Regulatory applicability and sensible risk management are related, but they are not identical. A yacht may still face meaningful cyber risks even when a specific statutory requirement does not apply.

The crew still uses email. People still connect phones and laptops. Contractors still require access. Remote support still occurs. The yacht still operates connected networks, communications systems, AV, CCTV and increasingly interconnected operational systems. The cyber risk does not disappear because a compliance box is absent.

Why cybersecurity familiarization matters on a yacht

One aspect of the IMO guidance is especially relevant to yachting: cybersecurity familiarization when joining the vessel.

Yacht crews change. Relief crew arrive. Seasonal personnel join. Contractors come aboard. Crew members bring personal phones, tablets and laptops. People may receive credentials for onboard Wi-Fi, shared systems, crew applications, email or management platforms within hours of arriving.

That creates a very practical question: what does somebody need to know about the yacht's digital environment before they start interacting with it? At minimum, that may include things such as:

  • how onboard networks are separated;
  • acceptable use of personal devices;
  • password and MFA expectations;
  • how guest and crew data should be handled;
  • whether removable media is permitted;
  • how suspicious activity should be reported;
  • who has authority to grant remote access; and
  • what to do when a device behaves unexpectedly.

That is what makes yacht-specific training different from generic corporate cybersecurity awareness. Context matters.

A deckhand and an ETO should not receive identical cyber training

The IMO guidance also specifically distinguishes general training from OT-specific training for OT users. That principle makes sense aboard a superyacht.

Someone using onboard email and Wi-Fi has one risk profile. Someone with administrative access to switches, firewalls, servers, bridge interfaces, AV systems or remote-support platforms has another.

That is why YMS360 separates cybersecurity training into different tracks:

  • Cyber Ready — Essential provides the foundation for crew, covering phishing and social engineering, passwords and MFA, device and Wi-Fi security, privacy, incident reporting, physical security and crew-specific threats.
  • Cyber Ready — Professional goes deeper into network architecture, segmentation, secure remote access, identity, endpoint and OT hardening, monitoring and incident response.
  • Cyber Ready — Fleet / Manager addresses governance, regulatory context, responsibility, insurance, privacy and incident command.

The principle is simple: training should reflect what somebody can access, what they are responsible for, and what decisions they may need to make during an incident.

Training also needs to be testable

There is another phrase in the IMO guidance that deserves attention: cybersecurity knowledge should occasionally be tested through measures such as drills and exercises.

That points toward a broader idea: watching content is not the same as demonstrating understanding.

YMS360 training requires a graded quiz at the end of each course, with an 80% pass mark. A program certificate is issued only after every course within that program has been passed. That still isn't the same as running a live onboard incident exercise, but it creates a measurable baseline.

A future maturity step for yachts is to combine training with realistic exercises. What happens if somebody believes a crew email account has been compromised, and who gets called? What if a vessel device suddenly begins behaving abnormally, and who has authority to disconnect it? What if the IT provider needs emergency remote access — who approves it, and how is it recorded? A cybersecurity plan becomes much more valuable when the crew has practiced what happens next.

What about BIMCO?

BIMCO's Guidelines on Cyber Security Onboard Ships provides another useful perspective. Version 5 dedicates specific sections to training and awareness, crew personal devices, remote access, administrator privileges, MFA and passwords, removable media, detection and contingency planning.

The important point is not that every recommendation creates a new legal obligation. It is that the industry's view of maritime cybersecurity is increasingly consistent: people, systems, procedures and technical controls have to work together. Training is one part of that system.

What should a yacht actually do?

Rather than beginning with the question "are we required to buy cybersecurity training?", a stronger starting point is "what does our crew need to know to operate this yacht safely in a connected environment?" Then determine the regulatory framework that applies to the particular vessel.

For many yachts, that should lead to a training structure with three basic characteristics: relevant, role-based and verifiable.

  • Relevant means the scenarios actually look like life aboard a yacht.
  • Role-based means an ETO does not receive the same depth of training as someone who simply uses the crew network.
  • Verifiable means the yacht can demonstrate who completed the training, when it happened and what was covered.

YMS360's Cyber Readiness Report, for example, records assigned programs, completion status, certificates and projected renewal targets directly from live training records. Individual certificates can also be independently verified without requiring access to the yacht's YMS360 account.

The more useful question

So, does the IMO require cybersecurity training for yacht crew? The IMO's current maritime cyber-risk guidelines clearly call for annual basic cybersecurity training, crew familiarization and more specialized training for OT users. Whether those provisions constitute a direct requirement for a particular yacht depends on the vessel's regulatory circumstances.

But there is a larger point. A yacht does not become vulnerable because a regulation says it is vulnerable. And it does not become cyber ready because somebody checked a training box. The objective should be a crew that understands the environment it is working in, recognizes when something may be wrong, and knows what to do next.

Compliance may determine what a yacht must do. Cyber readiness asks whether the yacht is actually prepared.

About YMS360 Cybersecurity

YMS360 cybersecurity training is built specifically for the superyacht environment, with separate programs for crew, technical professionals and fleet or management personnel. Training is priced per yacht rather than per user, with vessel-level Cyber Readiness reporting and independently verifiable certificates.

Explore YMS360 Cybersecurity →

Train your crew before the next port call

Short, role-aware cybersecurity training with a verifiable certificate.

See pricing
Enroll your yacht

Ready to harden your crew's
cyber posture?

Contact us +1.754.600.8735