Looking for software development? We've movedGrassFed.dev

Surgecraft Offshore

Vigilus performed an onboard maritime cybersecurity assessment for an offshore vessel, evaluating IT and OT environments, documenting vulnerabilities, and helping the client chart a path toward IMO 2021 compliance.

Surgecraft Offshore

Industries

Maritime,
Cybersecurity

Services

Penetration Testing,
Cybersecurity,
Vulnerability Assessments

Platforms

Vessel IT/OT Environment,
Network Infrastructure,
On-Premise Systems

About the project

An offshore vessel operator needed a clear view of the physical and digital security risks aboard one of its vessels. The assessment had to reflect the realities of a maritime environment, including operational technology, satellite connectivity, legacy systems, restricted access areas, and a limited testing window while the vessel was active and in dry dock.

This was not a standard office network assessment. Vessel environments introduce unique safety, uptime, and access considerations, so testing had to be practical, controlled, and focused on evidence the client could use without creating unnecessary operational risk.

What we did

  • Vigilus boarded the vessel and performed an on-site cybersecurity assessment across key areas of the environment. The team reviewed information technology systems, operational technology systems, network connectivity, separation between IT and OT, wireless exposure, and server room security.
  • Because the vessel was in operation, the team limited higher-risk exploit activity in the live environment. When a vulnerability could affect stability, Vigilus focused on demonstrating that the issue could be exploited rather than pushing further and increasing operational risk.
  • The project also required careful planning due to a short dry dock timeline. Vigilus prioritized the highest-value test paths, adapted to connection limits caused by vessel movement, and applied maritime-focused research to guide the assessment.
  • The final deliverable was a detailed report documenting findings, risk areas, and security concerns. The assessment identified important vulnerabilities that needed attention and helped the client evaluate the vessel’s security posture against IMO 2021 cyber compliance expectations.

Technologies Used

Wire Shark logo

Wire Shark

Kali Linux Logo

Kali Linux

Metasploit logo

Metasploit

Tenable IO

Tenable IO

Testimonials

"Vigilus understood that our vessel was not just another corporate network. Their team adapted quickly to the onboard environment, identified practical risks, and gave us a clear path toward improving our maritime cybersecurity posture."

Testimonial 1

"The assessment was thorough, well-organized, and grounded in the realities of vessel operations. The findings report helped our team prioritize remediation work without losing sight of compliance and operational continuity."

Testimonial 2

"Vigilus brought the right mix of cybersecurity expertise and maritime awareness. Their work gave us confidence in our IMO 2021 compliance efforts and helped us better understand the risks across our IT and OT systems."

Testimonial 3

Browse more projects

Solvionix Phishing Campaign

Solvionix Phishing Campaign

Valtara Parish Schools

Valtara Parish Schools

Contact Us