What the IMO, BIMCO and IACS actually say about training yacht crew on cybersecurity, the difference between guidance and regulation, and how it applies aboard, by role.
A superyacht is not an office that happens to float.
Modern yachts combine bridge systems, satellite and cellular connectivity, AV, CCTV, access control, crew and guest networks, personal devices, remote vendors, operational technology and increasingly cloud-connected systems. Some of those systems hold sensitive information. Others can affect how the vessel operates.
That matters because effective superyacht cybersecurity training should involve far more than teaching crew how to recognize a suspicious email.
The current IMO Guidelines on Maritime Cyber Risk Management specifically recognize both information technology (IT) and operational technology (OT) as part of maritime cyber risk. They address systems ranging from bridge and propulsion systems to passenger-facing networks, remote connections and third-party access.
For yachts, that is the right place to begin. Cybersecurity is not simply an IT issue. It is an operational one.
What actually governs cybersecurity on a yacht?
There is no single universal document called the Superyacht Cybersecurity Standard. Instead, a yacht may sit within several overlapping layers of regulation and guidance, including:
- the International Safety Management Code;
- IMO maritime cyber-risk guidance;
- flag-state requirements;
- yacht codes;
- classification requirements; and
- industry guidance such as The Guidelines on Cyber Security Onboard Ships.
And not every instrument applies equally to every yacht. Private or commercial status, flag, tonnage, passenger capacity, class and whether the yacht operates within an ISM/Document of Compliance structure can all matter.
That nuance is important because phrases such as "IMO requires this training for every yacht" can oversimplify a much more specific regulatory picture. Cybersecurity deserves greater precision than that.
What does the IMO actually say?
One of the foundations is IMO Resolution MSC.428(98), adopted in 2017. The resolution makes clear that cyber-risk management should be taken into account within an approved Safety Management System under the ISM Code. IMO subsequently encouraged administrations to ensure cyber risks were appropriately addressed in those systems by the first annual verification of the company's Document of Compliance after 1 January 2021.
For organizations operating within the ISM framework, the direction is clear: cyber risk is part of operational risk.
The IMO expanded substantially on this in its revised Guidelines on Maritime Cyber Risk Management, MSC-FAL.1/Circ.3/Rev.3, issued 4 April 2025. The guidance organizes maritime cybersecurity around six functional elements:
Govern. Identify. Protect. Detect. Respond. Recover.
That is a useful framework not only for compliance, but for thinking about what cyber readiness aboard a yacht should actually look like.
Cyber training means more than phishing awareness
The 2025 IMO guidance is particularly relevant to training. Among the minimum controls described under the Protect function are annual basic cybersecurity training, cybersecurity familiarization for crew when they join, and role-appropriate training for people interacting with operational technology. The guidance also emphasizes testing awareness and preparedness through mechanisms such as drills and exercises.
That is quite different from "have everyone watch a phishing video once a year."
Effective training should help people understand not only how an incident might begin, but what they should do when something unusual actually happens aboard. That principle influenced how we built YMS360 Cybersecurity.
Not everyone aboard needs the same training
A deckhand, captain, chief engineer, ETO and yacht manager do not have the same cybersecurity responsibilities. Their training should not be identical either. YMS360 therefore separates training into three levels.
Cyber Ready — Essential
Our Essential program is designed for general crew and covers:
- Phishing & Social Engineering at Sea
- Passwords & Multi-Factor Authentication
- Device & Wi-Fi Security Afloat
- Data Handling & Guest Privacy
- Incident Response & Reporting
- Physical Security & OPSEC for Yachts
- Crew-Specific Threats
The complete program takes approximately 93 minutes.
The objective is not to turn every crew member into a cybersecurity professional. It is to give them enough yacht-specific knowledge to recognize risks, make better decisions and know when and how to escalate something.
Cyber Ready — Professional
Technical personnel need substantially more depth. The Professional curriculum covers:
- Network Architecture & Segmentation
- Secure Remote Access
- Identity & Access Control
- Email, Domain & Web Protection
- Endpoint, OT & Bridge/IoT Hardening
- Monitoring, Incident Response & Continuity
Those subjects reflect the reality of modern yacht networks. A professional responsible for firewalls, VLANs, remote access, endpoints or onboard systems needs more than general cyber awareness.
Cyber Ready — Fleet / Manager
Management has a different responsibility again. Our Fleet / Manager program covers cyber-risk governance, the SMS, the maritime regulatory environment, roles and responsibilities, insurance and liability, data protection, and incident command and continuity.
That matters because cybersecurity culture does not begin with the youngest crew member clicking a link. It begins with management deciding what should happen before, during and after an incident.
Where BIMCO fits
IMO guidance intentionally remains relatively high level. Industry guidance helps translate those principles into more practical controls. The IMO itself points maritime organizations toward The Guidelines on Cyber Security Onboard Ships, produced by BIMCO and other industry organizations, including the Superyacht Builders Association.
BIMCO adds an important nuance. Its guidance does not present cyber-awareness training itself as a universal mandatory requirement. Instead, it treats training as a fundamental part of cyber-risk management and recommends both general awareness and more specialized training for people with greater cybersecurity responsibilities.
That distinction matters. Guidance is not the same thing as regulation. Neither is every regulation automatically applicable to every yacht. Responsible cybersecurity providers should explain that difference rather than turning every piece of maritime guidance into a blanket compliance claim.
What about classification and IACS?
Cybersecurity is also moving into vessel design and onboard equipment. The International Association of Classification Societies has developed UR E26, covering cyber resilience of ships, and UR E27, covering cyber resilience of onboard systems and equipment. IACS lists the current E26 revision as Rev.1, November 2023.
These requirements are particularly relevant in the newbuild and class environment. They should not, however, be presented as universal requirements for every yacht already operating. Again, applicability matters.
How we decide what goes into YMS360 training
This is an important distinction in how we approach cybersecurity education. We don't begin with a generic corporate cyber-awareness course and then add pictures of yachts. We begin with the maritime environment.
The YMS360 curriculum is checked against primary source material including relevant IMO instruments, IACS requirements, the Red Ensign Group Yacht Code and BIMCO industry guidance. Regulatory statements are rechecked when curriculum content changes.
Just as importantly, we document where an instrument does not apply. Our source methodology distinguishes between mandatory requirements, guidance, recommendations and material that may be useful for context without governing a yacht directly.
That distinction is deliberate. Good cybersecurity requires understanding what standards actually say. Good compliance requires understanding where they actually apply.
Training should create evidence
There is another important shift happening in maritime cybersecurity. It is increasingly not enough simply to say "yes, our crew received cyber training." Organizations increasingly need to demonstrate what they actually did.
Our Cyber Readiness Report therefore records training assignments, completion, certificates and projected renewal targets from the vessel's live training records. Certificates can also be independently verified without requiring a YMS360 login.
That distinction matters. Training should produce evidence, not merely a checkbox.
Cyber readiness is bigger than training
Training is only one part of protecting a modern yacht. Cyber readiness also includes areas such as network architecture, segmentation, identity and access control, remote support, monitoring, backups, incident response, third-party access, asset visibility and management responsibility.
The IMO's framework captures the broader goal well:
Govern. Identify. Protect. Detect. Respond. Recover.
That is a much better definition of yacht cybersecurity than "don't click suspicious links."
Cybersecurity awareness matters. But the objective should be something larger: a crew that understands cyber risk, technical professionals who can manage it, and leadership that knows what to do when something goes wrong.
That is cyber readiness.
About YMS360 Cybersecurity
YMS360 provides cybersecurity training built specifically for the superyacht environment, with separate programs for crew, technical professionals and fleet or management personnel. Training is priced per yacht rather than per user, with vessel-level readiness reporting and independently verifiable certificates.
Train your crew before the next port call
Short, role-aware cybersecurity training with a verifiable certificate.
See pricing