• 3 min de lectura
• 3 min de lectura

Cydome, a maritime cybersecurity company, has expanded its technology platform by launching a comprehensive risk and compliance management solution for third-party providers.
The tool aims to help shipowners, fleet managers, shipyards, and external suppliers manage the complexity of mandatory cybersecurity regulations, certifications, and industry approvals.
The need for this solution arises in the face of regulations such as the IACS Unified Requirement E27, which stipulates that shipowners must ensure that all onboard computer systems comply with strict cyber resilience requirements.
Currently, tracking these standards is done through manual processes based on emails and generic spreadsheets, a method that lacks clear governance, auditable change logs, and a centralized source of information.
To solve this operational challenge, Cydome's platform uses a web-based SaaS tool that automates administrative tasks and centralizes supplier certifications in a unified control panel.
This system allows shipping companies to monitor the compliance posture of their fleet and offices, while enabling suppliers to automatically update their documentation and generate detailed reports for regulators and classification societies.
"The E27 regulation introduced important rules for mandatory cyber resilience in the supply chain. However, this also entails operational complexity in managing the compliance process. Shipowners can depend on dozens or even hundreds of suppliers in a fleet, each with their own devices, certificates, and sub-suppliers," explained the VP of R&D and co-founder of Cydome, Alon Ayalon.
"Until now, most of this has been tracked manually using spreadsheets and emails to the different stakeholders involved. Our solution replaces that administrative complexity with a unique and structured system that automates the process and reduces the workload for shipping companies, suppliers, and classification societies," he added.
The IACS Unified Requirement E27 regulation is aimed at critical operational and safety computer systems (IT and OT) to ensure their onboard cyber resilience, aligning with industrial frameworks such as the IEC 62443 standard. However, the absence of a single approval process and the existence of exemptions have created a complex scenario to manage.
"In practice, E27 has led shipowners, shipyards, and fleet managers to try to figure out if their suppliers and systems comply with the regulation, while manually collecting information and reviewing valid and expired certificates from multiple suppliers and sub-suppliers. This consumes an inordinate amount of time," Ayalon noted.
The new system addresses this problem by showing the global compliance status by vessel, installation, supplier, or equipment, issuing automatic alerts when documentation is close to expiring. "We have already seen cases where clients have two people working full-time just to chase and follow up on third-party certifications," Ayalon stated.
"The vessel manager or shipyard no longer has to chase every supplier, and the supplier doesn't have to send the same information separately to different clients. Once the information is managed in one place, it's possible to see what complies with the standard, what's missing, what requires attention, and what's close to expiring," he complemented.
Although the platform's initial scope focuses on the IACS UR E27 standard, Cydome plans to extend its functions to support other international and national regulatory frameworks such as the ISO standard.
"The goal is to offer maritime industry players a single environment from which to manage third-party regulatory compliance and associated risks under multiple regulatory regimes," Ayalon concluded.

