Security built for ships and ports
Keep a signed log of every remote session, even over a weak satellite link.
Rules
| Rule | Clause | ARRTECH |
|---|---|---|
| 33 CFR 101.650(c) | Logs protected; privileged access only. | Role-based rights; signed, chained logs. → |
| 33 CFR 101.650(h) | IT-to-OT connections logged and monitored. | Firewall, flow and jump host collection. → |
| 33 CFR 101.650(i) | No unauthorized media. | DLP device control with manager approval. → |
| IACS UR E26 | Remote access events logged for review. | Remote access logs kept per source. → |
| IMO MSC-FAL.1/Circ.3/Rev.4 | Collect and securely store logs. | Signed storage with a verifier. → |
33 CFR 101.650
Log every remote session to your ships
The Coast Guard’s cyber rule in 33 CFR 101 subpart F requires protected logs that only privileged users can access. ARRTECH logs and signs remote access and office-to-ship connections.
IACS E26
Meet class cyber rules for new ships
IACS UR E26 applies to ships contracted from July 1, 2024 and requires network monitoring and logged remote access. ARRTECH keeps remote access events for your surveyor to review.
Vessel connectivity
Collect logs over weak satellite links
Satellite links are slow and drop often. The ARRTECH agent keeps collecting offline and sends logs, encrypted, when the link returns.
By rule
IMO MSC-FAL.1/Circ.3/Rev.4
Collect and securely store logs. ARRTECH: Signed storage with a verifier.
Questions
What happens at sea?
The agent holds logs while the ship is offline and sends them, encrypted, when the link returns. DLP rule updates reach ships as small downloads that work on slow links.
Can visitors plug in a laptop or USB drive?
ARRTECH DLP allows or blocks each device by make or serial number, for a set time, with a manager approving every exception, on Windows computers.
Who acts?
A person on board or ashore. ARRTECH SOAR emails the approver up to five options and waits.
What stays with you?
Bridge and engine systems, and the cyber plan the Coast Guard approves.
Sources
Guide
What is the USCG cyber rule?
33 CFR 101 subpart F requires a Cybersecurity Officer, a cyber plan and logs protected so only privileged users can access them.
What is IACS UR E26?
A class rule for ships contracted from July 2024, requiring network monitoring and logged remote access.
How do ships log over satellite links?
Use an agent that buffers logs while offline and sends them when the connection returns.
Next steps

Spot unusual behavior early. Learns what normal looks like for every user, computer and application from your SIEM, and flags what changes.

Get the evidence fast. Investigates each finding with read-only queries and hands a person the evidence. It never approves its own work.

Keep sensitive data in. Checks email, uploads, USB drives and AI prompts before sensitive data leaves the computer.

Respond with a person in charge. Runs incident response steps through your existing tools, with a person approving each decision.

See every system. Collects and signs logs from more than 500 source types and links related events, with a verification tool for every export.