Skip to main content
All news

Press release··3 min read

NEGU launches IACS E26-ready secure remote access for superyachts — and takes vendor screen-sharing tools off the bridge

A private yacht-to-shore network means engineers reach a jump host ashore, never the vessel — with the crew holding the switch.

Diagram of NEGU's private VLAN: the yacht connects over SpeedFusion to a NEGU hub and on to a dedicated private server; engineers reach only that server.

NEGU, the network- and infrastructure-as-a-service provider for superyachts and private aviation, has launched a secure remote-access service designed around IACS Unified Requirement E26, the cyber-resilience rule that class societies now verify on new-build vessels.

Remote access is where most yachts fall short of E26 — and the reason is familiar to any ETO. Walk onto most yachts and the bridge PC, the AV rack, the HVAC controller and the automation workstation each carry a screen-sharing tool such as TeamViewer or AnyDesk, installed separately by the AV/IT integrator, the HVAC vendor and the comms specialist, usually with unattended access switched on and a password unchanged since commissioning. Each one is a standing, undocumented door into a control system, opened over the public internet through a third party's relay servers, with credentials the vessel doesn't hold and sessions the crew can't see.

How vendors reach the yacht today: separate screen-sharing installs relayed over the public internet onto PCs on one flat network

"Those tools are fine for what they were built for — supporting an office PC," NEGU said. "They were never designed to secure a ship's control systems, and under E26 that setup fails on nearly every count: it isn't inventoried, it isn't segmented, it isn't crew-controlled and it isn't centrally logged. We wanted to give owners the safest option available to a classed vessel, and that meant taking remote access off the boat entirely."

A private VLAN between yacht and shore

NEGU's approach uses its own hubs, private backbone and servers to stand up a private Layer 2 VLAN between the yacht and shore, on demand, over an encrypted SpeedFusion tunnel. At the far end sits a dedicated private server on NEGU's global infrastructure, in whatever region the owner chooses, carrying the yacht's own internal IP range.

Engineers and vendors connect to that server — with multi-factor authentication, per-session approval and full session logging held ashore — and never to the vessel directly. The crew can drop the tunnel from on board at any time, and additional private servers, such as a log collector or a backup target, can be attached to the same VLAN later.

Delivered end to end

The service covers a gap assessment of every existing remote-access path, a zone-and-gateway design, deployment on the Peplink SDX and EPX hardware most vessels already carry, and a documentation pack — remote-access policy, zone diagrams and test records — prepared for plan approval and survey. NEGU is not a classification society and does not issue class approval; it builds and documents the controls the surveyor verifies.

UR E26 applies to new ships contracted for construction on or after 1 July 2024 and is enforced through classification rather than as a separate audit. Existing yachts are not retroactively in scope, but owners, managers, insurers and flag states increasingly expect the same controls, and a major refit is the natural point to meet them.

The service is available now for new builds and vessels in service. The full explainer — including a plain-language account of what E26 expects from remote access — is at negu.com/iacs-e26.

About NEGU

NEGU is a network- and infrastructure-as-a-service provider for superyachts and private aviation. It runs its own hubs, private backbone and servers, delivering bonded connectivity at sea, a managed Peplink FusionHub service with unlimited data, colocation, and secure remote-access designs aligned with IACS E26.

Press enquiries: get in touch