Shipboard USB Security

Detect and Eliminate USB Malware Before It Infects Ship Systems

Shipboard operations depend on removable media, from chart updates and cargo documents to vendor service files. Any of those transfers can bring malware aboard and onto safety-critical OT systems. TYREX gives maritime operators a self-contained, fast-to-deploy solution for USB security and compliance.

+ 1000

Decontamination Stations Deployed

+ 100

Customers Worldwide

0

Signature-Based Antivirus

0

Anti-Malware Solutions

Malware Can Board Vessels With Any Routine File Transfer

Shipboard systems combine intermittent network connectivity with safety‑critical infrastructure and equipment intended to function for decades. In these conditions, USB devices become an essential component of shipboard operations. They also make routine workflows a vector for malware infection.

Chart Updates

Navigation files move from shore-side sources toward bridge and ECDIS-adjacent workflows.

Crew and Admin Tasks

Crew and office staff copy documents, forms, and records onto admin workstations as part of daily work.

Vendor Maintenance

Service providers arrive with diagnostics, patches, and firmware bound for service workstations.

Engine Diagnostics

Maintenance files pass between service laptops, removable media, and operational workstations.

Shipyard Periods

Retrofit and maintenance windows bring higher volumes of contractor and inspector media onboard.

Port and Cargo Data

Cargo and port documentation arrives at the pier, then enters cargo and administrative systems.

TYREX Identifies and Eliminates USB-Borne Malware

TYREX Decontamination Stations sit between arriving media and sensitive onboard systems: plug-and-play, zero-maintenance USB scanning kiosks that run advanced, AI-powered antivirus and threat analysis.

Insert

Users connect their USB device to the decontamination station to initiate the scanning process. Stations support all standard removable media, including USB drives, external hard drives, SD cards, and Android smart devices.

Scan

The station analyzes the device for malware, BadUSB attacks, and zero-day exploits. Advanced behavioral analysis identifies suspicious code patterns that traditional antivirus software might miss.

Clean

When threats are detected, the station deletes or quarantines malicious material. Legitimate files and functionality are preserved while the danger is eliminated.

Certify

The station can optionally issue a digital certificate confirming the device is safe for use. Organizations can install Workstation Protect Agent to prevent the use of uncertified devices on their hardware.

Recommended Deployment Architecture for Vessel and Fleet Environments

TYREX is a self-contained removable-media control system. Everything the control workflow needs is included, and the system fits alongside your existing security systems and processes to eliminate the malware threat while enforcing IMO 2021 removable media compliance.

TYREX Decontamination Stations

TYREX Decontamination Stations are the physical layer of the control model. A vessel designates a station as the single approved entry point for incoming media. TYREX provides multiple station form factors suitable for shoreside and shipboard deployment.

A compact wall-mounted or desktop station built for ships and other space-constrained installations.

A ruggedized tablet format for service, inspection, and field work.

A desktop station for bridges, control rooms, and sensitive areas.

A floor-standing kiosk for terminals, crew boarding areas, and other high-traffic entry points.

TYREX Management Server

TYREX Management Server administers every station in the deployment. Operators manage policy, distribute updates, and supervise stations across multiple vessels in a fleet program. The server compiles station activity into compliance documentation, and the Syslog API feeds scan events into SIEM tools.

Workstation Protect Agent

Workstation Protect Agent adds optional endpoint enforcement to station-based scanning. On protected workstations, the agent denies access to any device or file without valid certification. It operates in online and offline modes, so enforcement continues without reliable connectivity.

Close the USB Security Gap in Your Fleet

A TYREX specialist can scope the right deployment for your maritime operations, whether you run cruise ships, cargo vessels, or an offshore fleet.

Shipboard USB Security FAQs

How does TYREX compare to blocking USB ports entirely?

Blocking ports removes the risk on paper, but a vessel still needs chart updates, vendor patches, and engine diagnostics, and those files often arrive on removable media. In practice, a ban pushes transfers into unmanaged workarounds, whereas TYREX makes the USB workflows ships depend on safe.

Yes. A TYREX station runs its full scanning and decontamination workload locally, and air-gap deployment is supported for isolated systems. Networked stations receive threat definition updates automatically, while isolated stations update through secure physical media during scheduled maintenance.

A standard USB drive typically completes in under two minutes, but scan time scales with the amount of data on the device. Scanning fits into a normal boarding or handover routine without disrupting time-sensitive workflows.

No. The touchscreen walks each user through the process step by step, with no technical knowledge required. Crews rotate, and contractors come aboard on short notice, so the workflow is built for someone who has never seen the station before.

IMO Resolution MSC.428(98) calls for cyber risk management to be addressed in a vessel’s Safety Management System, and the IMO-endorsed guidelines behind it specifically name the inappropriate use of removable media as a vulnerability. TYREX gives the removable-media requirement a concrete control: a documented scanning process where media enters the vessel, with records of every scan to support SMS documentation and Document of Compliance audits.