Surgecraft Offshore
Vigilus performed an onboard maritime cybersecurity assessment for an offshore vessel, evaluating IT and OT environments, documenting vulnerabilities, and helping the client chart a path toward IMO 2021 compliance.
Industries
Maritime,
Cybersecurity
Services
Penetration Testing,
Cybersecurity,
Vulnerability Assessments
Platforms
Vessel IT/OT Environment,
Network Infrastructure,
On-Premise Systems
About the project
An offshore vessel operator needed a clear view of the physical and digital security risks aboard one of its vessels. The assessment had to reflect the realities of a maritime environment, including operational technology, satellite connectivity, legacy systems, restricted access areas, and a limited testing window while the vessel was active and in dry dock.
This was not a standard office network assessment. Vessel environments introduce unique safety, uptime, and access considerations, so testing had to be practical, controlled, and focused on evidence the client could use without creating unnecessary operational risk.
What we did
- Vigilus boarded the vessel and performed an on-site cybersecurity assessment across key areas of the environment. The team reviewed information technology systems, operational technology systems, network connectivity, separation between IT and OT, wireless exposure, and server room security.
- Because the vessel was in operation, the team limited higher-risk exploit activity in the live environment. When a vulnerability could affect stability, Vigilus focused on demonstrating that the issue could be exploited rather than pushing further and increasing operational risk.
- The project also required careful planning due to a short dry dock timeline. Vigilus prioritized the highest-value test paths, adapted to connection limits caused by vessel movement, and applied maritime-focused research to guide the assessment.
- The final deliverable was a detailed report documenting findings, risk areas, and security concerns. The assessment identified important vulnerabilities that needed attention and helped the client evaluate the vessel’s security posture against IMO 2021 cyber compliance expectations.
Technologies Used
Wire Shark
Kali Linux
Metasploit
Tenable IO
