Cydome Targets Compliance Burden With New Vendor Risk Management Solution
Maritime Cybersecurity pioneer Cydome has extended its cybersecurity platform with a Third-Party Vendor Compliance and Risk Management solution. The new platform is designed to help shipowners, fleet managers, shipyards and third-party vendors manage the complexity around mandatory vendor cybersecurity regulatory compliance, certifications and approvals. Maritime operators need to manage their…
Cydome, a maritime cybersecurity pioneer, has introduced a new vendor risk management solution to address the compliance burden faced by shipowners, fleet managers, shipyards, and third-party vendors. This cloud-based software automates and streamlines the process of managing mandatory vendor cybersecurity regulatory compliance, certifications, and approvals.
The new platform aims to simplify the complex task of ensuring that all computer-based systems on board comply with cyber resilience requirements, as specified in IACS Unified Requirement E27. This regulation stipulates that shipowners must ensure all computer-based systems on board meet cyber resilience standards. Managing this compliance can be quite challenging, as it involves coordinating multiple internal and external stakeholders using manual processes, emails, and generic spreadsheets.
Cydome's solution provides a centralized repository for vendor certifications, approvals, and compliance status, accessible through a web-based SaaS tool. This dashboard presents a clear picture of compliance posture for all user types, including shipping companies and vendors. Additionally, the platform facilitates easy documentation sharing among users and enables the generation of reports for regulators and auditors.
Alon Ayalon, Cydome's VP of R&D and co-founder, highlights the operational complexity introduced by E27, which requires shipowners to rely on dozens or hundreds of vendors across a fleet, each with its own devices, certificates, and sub-suppliers. The new solution eliminates manual tracking of this compliance process, using a single structured system that automates the process and reduces overhead for all stakeholders.
The platform allows users to view E27 compliance status, including overall status, for specific vessels and sites or specific vendors and systems. It provides details on the vendor, equipment, certification status, and overall compliance score, as well as items that are missing, unverified, or nearing expiry. Automated reminders help ensure timely updates when documentation approaches expiry.
Ayalon notes that the implementation of this solution could significantly reduce the time spent on chasing and tracking third-party certifications, which currently consumes the work of two full-time employees in some cases. By digitizing the process and integrating automation, the solution aims to free up significant time and reduce the risk of gaps or expired certificates slipping through the cracks.
While the initial focus is on IACS UR E27, the platform will be extended to support additional frameworks, such as ISO and national standards, in the future.
Written by urgent.news from Hellenic Shipping News's reporting — not their text. Machine-written — may contain errors; check the original before relying on it.