IMO 2021 and USB Security: Reducing Removable Media Risk in the Maritime Industry

Much of the operational technology (OT) at sea today was not designed for current maritime cybersecurity threats. Many systems run on software that no longer receives security patches, and replacing that equipment is rarely practical while a ship remains in service. That makes critical ship systems vulnerable to malware and zero‑day threats, among other cybersecurity risks.

The International Maritime Organization (IMO) recognized the cybersecurity gap and introduced what the industry now calls IMO 2021, which requires ship operators to manage cyber risk. In this article, we explore what IMO 2021 expects and take a closer look at its implications for maritime USB security.

What Does IMO 2021 Require?

IMO 2021 is the informal name for the deadline set by Resolution MSC.428(98). The resolution was adopted in 2017, and it requires cyber risk to be addressed within a ship’s safety management system (SMS), the system that already governs safety under the ISM Code. Compliance was tied to the first annual verification of a company’s Document of Compliance after 1 January 2021, which is where the name comes from.

The resolution is supported by a set of guidelines, MSC-FAL.1/Circ. 3, which explain how cybersecurity risks should be managed. The guidelines, which align with the NIST Cybersecurity Framework, mention six elements:

  • Govern: Set the cyber risk strategy, policies, and responsibilities.
  • Identify: Determine the systems, assets, and risks that matter.
  • Protect: Put safeguards in place to defend the systems on board.
  • Detect: Recognize a cyber incident quickly enough to act.
  • Respond: Contain a cyber incident and limit its effect.
  • Recover: Restore the systems needed to keep operating.

Among other controls, the Protect element calls for safeguards to protect systems from unauthorized removable media. A deficiency can be recorded by a Flag State or by Port State Control, and vessels can be detained in serious cases.

Maritime cybersecurity standards have been further strengthened since 2021. The European Maritime Safety Agency issued guidance in 2023 on how cybersecurity should be examined during inspections, and the International Association of Classification Societies (IACS) unified requirements known as E26 and E27 to set a higher technical standard for ships contracted from 2024 onward.

Who Has to Comply with Resolution MSC.428(98)?

The guidance applies to any company that holds a Document of Compliance under the ISM Code, which covers most vessels engaged on international voyages. Passenger ships fall within scope, as do cargo ships of 500 gross tonnage (GT) and above.

Responsibility doesn’t stop at the operator. The obligation is part of the SMS, so it applies to the shoreside managers who maintain that system and to the crew who follow its procedures. The SMS should also address third-party technician and vendor USB use during maintenance and survey work.

How USB Carries Malware Onto Ships

A USB drive is one of the few practical ways to move data onto maritime OT systems that aren’t connected to the network. USB devices are often part of routine vessel workflows for chart updates, data transfer to air-gapped bridge systems, engine diagnostics, and maintenance. Malware designed to spread by USB can cross the air gap without any network connection, carried by malicious or unsuspecting technicians and crew members.

One 2024 example shows the risk: the security firm ESET reported that loaders for the Korplug malware, also known as PlugX, had been found on the systems of European cargo shipping companies based in Norway, Greece, and the Netherlands. ESET found that the initial infection had, in some cases, been launched from a USB drive.

Decontamination Stations Provide the USB Security Vessels Need

IMO 2021 expects USB risk to be managed, but it doesn’t say how. A USB decontamination station, sometimes called a sheep dip station or a USB scanning kiosk, gives vessel operators an easy-to-use, easy-to-deploy solution for USB cybersecurity risk.

TYREX decontamination stations provide a physical checkpoint that scans USB devices for malware, zero-day threats, and other risks before they are connected to vessel OT systems. The stations work in both networked and air-gapped settings, so they suit ships and shore facilities where the network is unreliable or isolated.

Decontamination stations are available in multiple form factors. The floor-standing TYREX Totem suits an entryway at a shore facility or larger vessel, while the smaller TYREX Satellite and TYREX Console can be mounted on a wall or placed on a workstation where vessel space is limited. The TYREX Mobile is a ruggedized portable decontamination station that personnel can carry to scan devices anywhere on board or ashore.

TYREX provides a complete USB decontamination solution that works alongside the security systems a vessel already runs. Scan events can be exported to a SIEM platform through a Syslog API, and reports can be produced in PDF or CSV for compliance records. The TYREX Management Server adds centralized control for a larger deployment, so an operator can manage every station across a fleet from one console.

A Practical Way to Meet IMO 2021 on USB Security

Decontamination stations give maritime businesses a straightforward way to implement removable media cybersecurity controls that align with IMO 2021 recommendations. Our stations are deployed in more than 5,000 locations worldwide.

Talk to a TYREX specialist to see how the stations would fit your vessels and shore facilities.

Sign up for the TYREX newsletter for expert analysis and guidance from TYREX USB security experts Gerard Varjacques and Christophe Bourel.