Pelorus Deployment Blueprint Reference Architecture Maritime OT
Ship bridge operations console at sea — maritime operational technology environment secured under the Pelorus program
◉ Pelorus · Maritime

Securing the operational technology that keeps a vessel underway. Where an alert nobody can answer at sea is not an option.

Pelorus is CSI's maritime OT security program. A ship is a moving industrial site with intermittent connectivity, legacy control systems, and no analyst on the bridge. This blueprint is exactly how a Pelorus engagement deploys, hull by hull. The program is in active deployment with Synergist Mobility — outcome data publishes on completion.

The Environment

A vessel is the hardest place to run a security program — and the worst place to be wrong.

IT security assumes connectivity, patch windows, and someone to respond. At sea, all three are unreliable. The systems that steer, power, and navigate the ship cannot be taken offline for a maintenance window in the middle of the ocean.

What Makes It Hard

Three constraints that break conventional security at sea.

01 / CONNECTIVITY

Detection that phones home is useless mid-ocean.

Cloud-dependent security assumes a link that a vessel may not have for days. Protection has to work fully offline, on the hull.

02 / LEGACY OT

The control systems predate modern security by decades.

Navigation, propulsion, and cargo systems weren't built to be patched. You protect them by containing what can reach them, not by updating them.

03 / NO ANALYST

There is no SOC on the bridge.

The crew are mariners, not analysts. Security has to prevent and contain autonomously — an alert that needs an expert to interpret will simply go unanswered.

The Pelorus Method

Contain on the hull. Verify at the boundary. Report when connected.

01

Segment IT from OT

Establish hard boundaries so a compromised laptop cannot reach navigation or propulsion.

02

Contain the unknown

Unknown code runs isolated with no write access to real systems — offline, no signature needed.

03

Fail closed

When in doubt, the safe default is deny — the ship keeps operating, the threat does not.

04

Sync when able

Logs and evidence reconcile to shore the moment connectivity returns — nothing is lost at sea.

What We Measure

Every Pelorus engagement reports on the same six metrics.

No vanity numbers. These are the measures a fleet operator, an inspector, and an underwriter actually ask about — and what the published outcome data will cover.

M1

Containment events on the hull

Untrusted executions isolated at the endpoint kernel — counted, logged, and blocked offline.

M2

IT/OT boundary attempts

Crossings attempted vs. stopped at the segmentation boundary between crew systems and vessel OT.

M3

USCG provision status

Provision-by-provision compliance state, maintained inspection-ready at all times.

M4

Crew drill readiness

Cyber casualty drill completion and time-to-response, folded into the existing drill schedule.

M5

Evidence sync integrity

Tamper-evident logs reconciled sea-to-shore with zero loss across connectivity gaps.

M6

Security-attributable downtime

Vessel operational time lost to security controls. Target and expectation: zero. Do no harm.

Program status: in active deployment with Synergist Mobility. Outcome data across these six metrics publishes here on completion of the engagement.
The Implication
At sea, security that waits for a connection, a patch, or an analyst is security that isn't there. It has to hold on the hull — or it doesn't hold at all.

Stop Threats Before They Execute

Your free Kernel-Level Defense Buyer’s Guide is ready to download.

By providing my email address, I consent to receive emails and text messages—including newsletters and marketing communications—from creators of Warden Secure, Cyber Strategy Institute, our flagship zero-trust platform for ransomware prevention, and agree to the Terms and Privacy Policy. You may unsubscribe at any time.