IACS UR E26 · Cyber Resilience of Ships
IACS E26 Compliance for Superyachts, Starting with Remote Access
IACS E26 makes cyber resilience a class requirement for new-build yachts — and remote access is where most vessels fall short, usually a TeamViewer or AnyDesk install on a control-system PC that nobody has audited. Negu designs, deploys, and documents secure remote access that's segmented, authenticated, crew-controlled, and logged, built on SpeedFusion.
The Regulation
What is IACS E26?
IACS Unified Requirement E26, Cyber Resilience of Ships, sets minimum cyber-security requirements for a vessel's onboard computer-based systems and the networks that connect them. It applies to new ships contracted for construction on or after 1 July 2024, and it's enforced through classification — your class society verifies it at plan approval and survey, the same way it verifies stability or fire safety.
Its sister requirement, UR E27, covers the individual systems and equipment installed on board. Together they make cyber resilience part of getting — and keeping — class.
Why it matters for superyachts
For yachts, E26 typically lands on new builds of 500 GT and above classed with an IACS member — Lloyd's Register, DNV, Bureau Veritas, ABS, RINA and others. Existing yachts aren't retroactively in scope, but flag states, insurers, and owners increasingly expect the same standard, and a major refit is the natural point to meet it.
The five functional elements of E26
1.Identify
Inventory every computer-based system on board and how they connect.
2.Protect
Segment networks, control access, and secure every remote and wireless path.
Remote access lives here
3.Detect
Monitor networks and systems so a cyber incident is noticed, not discovered later.
4.Respond
Have a plan — and the onboard controls — to contain an incident quickly.
5.Recover
Restore systems from known-good backups and get the vessel back to normal operation.
Remote Access Under E26
What E26 expects from remote access
Shore-side engineers, integrators, and equipment vendors all need to reach systems on board. E26 doesn't prohibit that — it requires that every remote connection is deliberate, controlled, and accountable.
Inventoried & authorized
Every remote-access path is documented: which system, who connects, from where, and why. No undocumented vendor backdoors.
Crew-controlled
Remote sessions can be enabled, disabled, and terminated from on board. The vessel — not the vendor — holds the switch.
Authenticated & encrypted
Connections use secure, encrypted protocols with strong multi-factor authentication — never shared or default credentials.
Segmented
Remote access lands in a defined security zone, not a flat network where a vendor's laptop can see navigation, automation, and guest Wi-Fi alike.
Logged & monitored
Sessions are logged and retained, and unusual activity is detectable — so you can always answer "who was on that system, and when?"
Survey-ready evidence
Policies, zone diagrams, and test records that show class the controls exist and work — not just that they were intended.
Summarised from UR E26's requirements on remote access and communication with untrusted networks. Your class society's plan-approval checklist is the authoritative source.
How Negu Helps
E26 requirement → what Negu delivers
We handle the remote-access piece of E26 end to end — the design, the hardware, and the paperwork — on infrastructure we already run for yachts every day.
| E26 expects | Negu delivers |
|---|---|
| A documented inventory of every remote-access path | A full audit of existing remote paths — vendor VPNs, screen-sharing tools, cellular backdoors — and a single documented gateway to replace them. |
| Remote sessions the crew can enable, disable, and terminate | Onboard control of remote access with per-session approval, so the ETO or captain — not the vendor — decides when the door is open. |
| Strong authentication and encrypted connections | Encrypted SpeedFusion tunnels through Negu's managed FusionHub service, with multi-factor authentication on every remote login and no shared vendor credentials. |
| Network segmentation into security zones | Zones and conduits designed into your Peplink SDX or EPX — navigation, automation, crew, and guest networks separated, with remote access confined to its own zone. |
| Remote users kept away from the vessel's network edge | An optional shore-side jump: a private Layer 2 VLAN between yacht and shore, stood up on the fly, with a dedicated private server on Negu's global infrastructure at the far end in the region you choose — so vendors never connect to the vessel directly, and you can add more private servers to the same VLAN as needs grow. |
| Session logging, retention, and monitoring | Centralised session logging with retention and alerting, plus proactive monitoring from Negu's team so unusual activity is flagged, not filed. |
| Evidence the controls exist and work | Remote-access policy, zone diagrams, and test records packaged for plan approval and survey. |
Negu isn't a classification society and doesn't issue class approval — we build and document the remote-access controls your class surveyor verifies.
Network & Infrastructure as a Service
A private VLAN between yacht and shore — and remote access that never touches the vessel
Negu is a NaaS / IaaS provider: the hubs, the private network between them, and the servers on it are ours to run. That lets us stand up a private Layer 2 VLAN between the yacht and shore on the fly, with a dedicated private server on our global infrastructure at the far end — in the location you choose. Remote access lands there, not on the boat, and you can attach more private servers to the same VLAN whenever you need them.
How most yachts do it today — and why it's the weak point
Walk onto most yachts and remote access looks the same: TeamViewer or AnyDesk on the bridge PC, the AV rack, the HVAC controller, the automation workstation — one put there by the AV/IT integrator, another by the HVAC vendor, another by the comms specialist, each with unattended access switched on and a password that hasn't changed since commissioning. It works, which is exactly why nobody looks at it.
But every one of those installs is a standing, undocumented door into a control system — opened over the public internet through a third party's relay servers, with credentials the vessel doesn't hold and sessions the crew can't see. Remote-desktop tools are among the most commonly abused pieces of legitimate software in real-world intrusions, and the major products have had publicly disclosed security incidents of their own in recent years. Under E26 that setup fails on nearly every count: it isn't inventoried, it isn't segmented, it isn't crew-controlled, and it isn't centrally logged.
How vendors reach the yacht today
Shore side
Each supplier's own tool, each with its own password
AV / IT integrator
Unattended access · always on
HVAC vendor
Password set at commissioning
Comms specialist
Login shared across the team
and, using the same doors
Anyone with the password
Phished, leaked, or an ex-employee — same door, same access
TeamViewer / AnyDesk relay
Third-party cloud · public internet · not yours to audit
On board · one flat network
No inventory · no crew switch · no central log
Bridge PC
Listening for inbound sessions
AV rack
Listening for inbound sessions
HVAC controller
Listening for inbound sessions
Automation workstation
Listening for inbound sessions
reachable from any of these PCs
Navigation
Reachable from any of the PCs
Guest Wi-Fi
Reachable from any of the PCs
Diagram: the AV/IT integrator, the HVAC vendor, and the comms specialist each connect from their own laptop through TeamViewer or AnyDesk, relayed via a third party's cloud over the public internet, onto separate PCs on board — the bridge PC, the AV rack, the HVAC controller, the automation workstation — which all sit on one flat network with no inventory, no crew switch, and no central log. Anyone holding one of those passwords, whether phished, leaked, or a former employee, uses the same path. From any of those PCs, navigation and guest Wi-Fi are reachable.
Today
Screen-sharing tools on onboard PCs
- Installed separately by the AV/IT integrator, the HVAC vendor, the comms specialist — no single inventory of who can get in, or how
- Traffic relays through a third party's cloud, over the public internet
- Unattended access with static passwords — the credentials live with the vendor, not the vessel
- Usually sits on a flat network: one compromised PC can see navigation, automation, and guest Wi-Fi
- Crew can't see active sessions or terminate them; logs are per-tool, per-PC — if they exist at all
- Remote-desktop tools are among the most commonly abused legitimate software in real-world intrusions
With Negu
Private VLAN + shore-side jump host
- One documented entry point, off the vessel, that you can show a surveyor
- Traffic never touches the public internet — encrypted SpeedFusion into Negu's private network
- MFA on every login and per-session approval; no shared or standing vendor credentials
- Only the chosen zone is bridged — the rest of the vessel stays unreachable
- Crew can drop the tunnel from on board at any time; every session is logged ashore
- Nothing to install on onboard machines, nothing listening to the internet
That's why we consider this the safest option available to a classed vessel — not because the tools yachts use today are bad at their job, but because their job was never securing a ship's control systems. Keep them for the office laptop. Don't leave them holding the keys to the bridge.
The safer design: remote access that lands ashore
How the shore-side jump is wired
On board
Peplink SDX / EPX · zoned network · crew holds the switch
Negu hub
Managed FusionHub · Negu private backbone
Your private VLAN
Provisioned on the fly · region you choose · grows as you need
Your private server
Dedicated jump host · same internal IP range as the yacht
+ Log collector / monitoring
Add to the VLAN · E26 Detect
+ Backup & recovery target
Add to the VLAN · E26 Recover
+ Second jump host
Another region · e.g. near the management office
Engineers & vendors
Reach the jump host only — never a direct path to the vessel
✕ No direct path from engineers to the vessel — the jump host is the only door
Diagram: the yacht's Peplink SDX or EPX connects over an encrypted Layer 2 SpeedFusion tunnel to a Negu hub on Negu's private backbone, which extends a private VLAN, provisioned on the fly, to a dedicated private server (the jump host) in the region the customer chooses. That server carries the yacht's internal IP range, and additional private servers — a log collector for E26 Detect, a backup and recovery target for E26 Recover, or a second jump host in another region — can be added to the same VLAN. Engineers and vendors connect only to the jump host, with MFA, per-session approval, and logging; there is no direct path from them to the vessel.
One front door — and it isn't on the vessel
Engineers and vendors connect to the shore-side private server, never directly to the yacht. There's a single, documented entry point to inventory, harden, and show your surveyor — not a dozen vendor VPNs pointed at the boat.
A Layer 2 VLAN, on the fly, same internal IP range
The chosen onboard zone is bridged at Layer 2 over an encrypted SpeedFusion tunnel into a private VLAN that spans yacht and shore. Onboard systems are reachable ashore by their own internal addresses — no NAT gymnastics, no re-addressing — and only the zone you choose is extended. Provisioned on demand, not on a yard schedule.
Your servers, your regions — grow the VLAN as you need
Start with one dedicated jump host on Negu's global infrastructure, placed wherever you choose — near the yard, near the management office, or in a jurisdiction the owner prefers. Then attach more private servers to the same VLAN whenever you need them: an off-vessel log collector or monitoring node (E26 Detect), a backup and recovery target (E26 Recover), or a second jump host in another region.
Crew-controlled, logged ashore
The tunnel can be dropped from on board at any time, and every remote session is authenticated with MFA and logged on the shore side — so the audit trail survives even if something happens to the vessel's own systems.
The shore-side jump is optional — remote access can also terminate on board behind the same controls. Many owners choose the private server precisely because it keeps vendors, and their credentials, off the vessel's network edge altogether. Pair it with Negu colocation if you'd rather run your own hardware in the same place.
How It Works
From gap assessment to survey-ready remote access
Assess: map every remote-access path
We inventory the computer-based systems on board and every way a shore-side party can reach them — vendor VPNs, screen-sharing tools, the cellular modem nobody remembers installing.
Design: zones, conduits, and one controlled gateway
We design the security zones and a single remote-access gateway — on board, or on a shore-side private server — with multi-factor authentication, encryption, and crew-side control built in from the start.
Implement: deploy on Peplink and SpeedFusion
Remote access runs over encrypted SpeedFusion tunnels through Negu's managed FusionHub, terminating on a Peplink SDX or EPX that enforces the zones on board.
Evidence: documentation for plan approval and survey
You get the remote-access policy, zone diagrams, test records, and session logs your class surveyor asks for — and monitoring that keeps them current after delivery.
Already running Peplink on board? Most of the hardware you need is probably already there — E26 is about how it's configured, controlled, and documented.
Why Negu
Built on infrastructure yachts already trust
Our Network, End to End
Hubs, backbone & private servers
Remote sessions ride encrypted SpeedFusion tunnels on Negu's managed FusionHub, across our own private backbone, to a private server on our global infrastructure — no third-party cloud VM bolted on, and nothing shared with other customers.
Survey-Ready Documentation
Policy, diagrams, test records
Every engagement ends with the documentation pack your class surveyor expects, written in the language of E26's functional elements rather than generic IT policy.
Monitored After Delivery
Logging, alerting, support
Compliance isn't a one-off survey. Session logs, alerts, and Negu's support team keep remote access controlled for the life of the vessel.
FAQ
Frequently asked questions
Need the connectivity side too? See Negu's managed FusionHub service, our recommended Peplink Starlink routers, or talk to our sales team.
Book a Review
Get an IACS E26 remote-access review
Tell us about the vessel — new build or in service, class society, and how remote access works today — and we'll come back with a gap assessment and a scoped plan.