Your latest security report lists vulnerabilities across several onboard systems. One has hundreds of findings, another has only a handful.
You need to decide what to address first, but the numbers alone cannot tell you which weakness could cause the greatest disruption to your vessel.
On 21 September, CYTUR published findings from its maritime equipment assessments showing that systems with very different vulnerability counts could fall into the same risk treatment category. Active services, network connections and the potential impact on vessel operations all influenced the result.
The assessments cover a limited sample, but they raise a useful question for anyone responsible for vessel IT: are you prioritising the longest list of findings, or the risks that matter most to your operation?
A weakness in a restricted system and the same weakness in equipment reachable through a supplier connection can present very different risks. You need to understand how the equipment is connected, who can access it and which operations depend on it.
The equipment itself may also contain more than you expect. CYTUR identified unnecessary active services and vulnerabilities in supporting components. A controller may appear well protected while a connected network device introduces another access path.
This makes the actual installation important. An equipment list tells you what is onboard. Understanding its connections helps you determine what needs attention.
If you follow Maritime Pulse, you may have heard us make this point before. We promise there is a reason we keep returning to it. Understanding how systems connect is something we consider essential to managing vessel cyber risk.
There are different approaches to assessing that risk, and vulnerability counts have their place. At Sea IT, years of working with vessel IT and OT integration have taught us to look at those findings alongside access, network boundaries and operational dependencies.
BlueCORE provides a standardised onboard foundation for this approach. Combined with maintained documentation and dialogue with equipment suppliers, it helps establish a clearer picture of how systems connect and where responsibility sits.
Remediation also needs planning. Your team should understand how an update or configuration change could affect operation, how it will be verified and what happens if the change does not work as expected.
Assess
Consider each weakness alongside access, connectivity and operational impact.
Prioritise
Address the risks with the greatest potential consequences for your vessel.
Verify
Confirm that corrective actions reduce exposure and preserve required functionality.
A useful security report should help you decide what to do next, with a clear understanding of why it matters onboard.


