Securing the operational technology that keeps a vessel underway. Where an alert nobody can answer at sea is not an option.
Pelorus is CSI's maritime OT security program. A ship is a moving industrial site with intermittent connectivity, legacy control systems, and no analyst on the bridge. This blueprint is exactly how a Pelorus engagement deploys, hull by hull. The program is in active deployment with Synergist Mobility — outcome data publishes on completion.
A vessel is the hardest place to run a security program — and the worst place to be wrong.
IT security assumes connectivity, patch windows, and someone to respond. At sea, all three are unreliable. The systems that steer, power, and navigate the ship cannot be taken offline for a maintenance window in the middle of the ocean.
Three constraints that break conventional security at sea.
Detection that phones home is useless mid-ocean.
Cloud-dependent security assumes a link that a vessel may not have for days. Protection has to work fully offline, on the hull.
The control systems predate modern security by decades.
Navigation, propulsion, and cargo systems weren't built to be patched. You protect them by containing what can reach them, not by updating them.
There is no SOC on the bridge.
The crew are mariners, not analysts. Security has to prevent and contain autonomously — an alert that needs an expert to interpret will simply go unanswered.
Contain on the hull. Verify at the boundary. Report when connected.
Segment IT from OT
Establish hard boundaries so a compromised laptop cannot reach navigation or propulsion.
Contain the unknown
Unknown code runs isolated with no write access to real systems — offline, no signature needed.
Fail closed
When in doubt, the safe default is deny — the ship keeps operating, the threat does not.
Sync when able
Logs and evidence reconcile to shore the moment connectivity returns — nothing is lost at sea.
Every Pelorus engagement reports on the same six metrics.
No vanity numbers. These are the measures a fleet operator, an inspector, and an underwriter actually ask about — and what the published outcome data will cover.
Containment events on the hull
Untrusted executions isolated at the endpoint kernel — counted, logged, and blocked offline.
IT/OT boundary attempts
Crossings attempted vs. stopped at the segmentation boundary between crew systems and vessel OT.
USCG provision status
Provision-by-provision compliance state, maintained inspection-ready at all times.
Crew drill readiness
Cyber casualty drill completion and time-to-response, folded into the existing drill schedule.
Evidence sync integrity
Tamper-evident logs reconciled sea-to-shore with zero loss across connectivity gaps.
Security-attributable downtime
Vessel operational time lost to security controls. Target and expectation: zero. Do no harm.
At sea, security that waits for a connection, a patch, or an analyst is security that isn't there. It has to hold on the hull — or it doesn't hold at all.
Secure the vessel before it leaves the pier.
Three ways in for fleet operators and maritime programs.
Maritime OT brief
The Pelorus method for securing OT at sea. Download and share with the fleet.
Get the brief →Fleet posture review
We assess IT/OT segmentation and offline containment across representative vessels.
Book a review →Pelorus deployment
Scoped rollout of the maritime OT program across your fleet, hull by hull.
Scope deployment →