Skip to content
CISO Marketplace Services

Maritime Systems Security Assessment

Specialized security testing for maritime technology, including navigation systems, vessel communication, and port infrastructure.

In scope

  • Navigation system testing
  • AIS security assessment
  • ECDIS security review
  • Radio communication testing
  • Port system security evaluation
  • Vessel tracking security
  • Maritime IoT device testing

You receive

  • Maritime security report
  • Navigation system analysis
  • Communication security findings
  • Port infrastructure recommendations
  • Vessel tracking security guide
  • Maritime IoT security assessment
  • 90-day follow-up review

Tiers

Choose the depth.

Core Maritime Systems Assessment

$38K

Assessment of 1 vessel or port facility (1 location): navigation system testing, AIS and ECDIS configuration review, vessel communications review, basic port/shore system evaluation, report and a follow-up review.

Sites
1
  • Navigation system security testing on 1 vessel/facility
  • AIS and ECDIS configuration review
  • Vessel communication (satcom, radio) configuration review
  • Shore/port system interface review
  • Maritime security report and 90-day follow-up review
  • — Active AIS/ECDIS spoofing and manipulation testing
  • — Radio frequency testing
  • — Vessel tracking system security
  • — Maritime IoT device testing
Scope Core Maritime Systems Assessment

Advanced Maritime Security Program

$65K

Assessment of up to 3 vessels/port facilities. Adds active AIS and ECDIS testing, radio communication testing, vessel tracking security, and port system security evaluation. Includes a follow-up review.

Sites
3
  • Everything in the Core tier, for up to 3 vessels/facilities
  • Active AIS spoofing and ECDIS chart/update integrity testing
  • Radio communication testing
  • Vessel tracking security assessment
  • Port system security evaluation
  • — Maritime IoT device and sensor testing
  • — Custom test tooling
  • — Monitoring implementation
Scope Advanced Maritime Security Program

Enterprise Maritime Security Solution

$95K

Assessment of up to 5 vessels/port facilities. Adds maritime IoT device testing (up to 15 device models), custom test tooling for proprietary bridge or cargo systems, and monitoring implementation with detection use cases. Larger fleets are scoped separately.

Sites
5
devices
15
  • Everything in the Advanced tier, for up to 5 vessels/facilities
  • Maritime IoT device testing, up to 15 device models
  • Custom test tooling for proprietary systems
  • Monitoring implementation with maritime-specific detections
  • Fleet-level security recommendations
  • — Monitoring licences and onboard hardware
  • — 24/7 monitoring operations
  • — Fleets above 5 vessels/facilities (scoped separately)
Scope Enterprise Maritime Security Solution

Members: engagement coupons from the CISO Marketplace coupon book apply to services. There is no blanket discount.

What's inside this engagement

Phase by phase.

How a security assessment engagement runs, what happens in each phase and what you see. Exact scope, tier and timeline are fixed in your proposal and SOW.

  1. 01Scoping

    Systems, sites, stakeholders and the question the assessment must answer.

    You see · Your objectives and constraints.

  2. 02Discovery & evidence

    Documents, configurations and interviews, plus technical testing where the service includes it.

    You see · Access and time with key people.

  3. 03Analysis

    Findings rated by risk to your business, not by a generic score.

    You see · A prioritized view of your risk.

  4. 04Report & debrief

    Executive summary, findings and a remediation roadmap, walked through with your team.

    You see · The report and the debrief.

Commercials

From first call to final report.

  1. 01

    Scoping call

    A practitioner, not a salesperson, walks through targets, constraints and what a good outcome looks like for you.

  2. 02

    Proposal & rules of engagement

    A fixed-scope proposal with tier, price and deliverables. Rules of engagement, contacts and out-of-bounds systems are agreed in writing.

  3. 03

    Sign, then start

    MSA and SOW are signed electronically and the deposit is paid. Only then does testing begin.

  4. 04

    Execution

    Testing runs to the agreed plan. Critical findings are escalated as they are found; you don't wait for the report.

  5. 05

    Report & debrief

    An executive summary plus technical findings with evidence, reproduction steps and fixes, walked through with your team.

  6. 06

    Retest

    Where the tier includes it, we verify your fixes and reissue the report, so auditors and customers see the issues closed.

Timelines are set per engagement in the SOW.

Related

Research

Latest from the blog

All posts on cisomarketplace.com →
Talk to an advisor
Advisor