Agree the task and the boundary
Define the system to be reviewed, the responsible officer, the planned duration, and what would trigger a stop. State whether the requested work is observation, diagnosis, configuration, or a document review. Some work requires onboard attendance or a separately approved delivery route.
Arrange access securely
Do not put passwords, remote-desktop codes, network diagrams, or administrator credentials in a public inquiry. Use only the operator-approved access method, with appropriate authorization, limited duration, and a record of who connected. The initial inquiry should ask for a controlled handoff.
Document the outcome
Request a summary of observations, authorized changes, unresolved items, and any next steps. Confirm that temporary access has been closed in accordance with the operator’s procedures. A remote session is not automatically a survey, test certificate, or acceptance of operational readiness.
IMO’s maritime cyber guidance treats cyber risk management as part of a vessel’s wider safety and security practices. The remote-access checklist here is an operational planning aid, not a cybersecurity certification.
IMO · Maritime cyber risk ↗Information to prepare
- Responsible onboard and shoreside contacts
- System, symptom, and approved session window
- Operator-approved remote-access process
- Expected report and acceptance criteria