Maritime Cyber Security · Private · Commercial · Defence

Privacy,kept at sea.

Intelligence-led security for vessels of every flag and purpose — superyachts and private fleets, commercial and offshore operators, naval and government programmes — and the people aboard them. We see your vessel the way an adversary would — your systems, your crew, your movements — and close the gaps before anyone can use them.

Our portfolio

What we surfaced.

A sample of what we find on vessels and fleets, sanitized for public view.

250+
Vessel & port camera feeds found exposed
73%
Assessed vessels running unpatched systems
<48h
Typical window to first compromise
Reconnaissance

Identity & crew data, mapped in three hours

Live management dashboards exposing vessel identifiers, crew emails, and internal records — located before testing began.

Surveillance

Live camera feeds into decks & cabins

Continuous visual access to marina berths, decks, and interiors — crew movements and guest activity, in real time.

Communications

Satellite-link access on a target vessel

VSAT consoles located and reached — exposing configuration, antenna positioning, and routing. Disruption confirmed.

Credentials

Crew passwords, still live in breach data

Reused logins from crew CVs and old accounts, found in breach databases years later — still valid, still protecting active systems.

Personnel

Full crew manifest, names to passports

Crew records exposed through a management portal — names, roles, contact details, and travel documents, all reachable from the open web.

Industrial / OT

Engine and power controls exposed

Operational technology — engine, power, and steering interfaces — found reachable, the systems a vessel cannot run without.

Supply chain

A vendor login, opening the whole fleet

A single supplier credential exposing access across every vessel a management company touches.

All imagery is sanitized. Client data is never shown, and every engagement is conducted with authorization.

As published in

The Unwitting Fleet · Center for International Maritime Security · cited by the U.S. Army War College

From the founder

Our work.

01Where we began

We began with penetration testing on naval and commercial maritime systems — whole fleets, and every attack surface that came with them: the vessels, their supply chains, and the vendors behind them. That is where we learned how these systems really fail, and what it takes to hold them together.

02The shift

Over time we added the private side. The same questions that mattered across naval and commercial fleets mattered just as much on private yachts — where the people aboard, and everything they carry with them, deserve that same standard of care. We never left the first work behind; we run all of it.

03Today

Today we work across private, commercial, and government fleets — owners, management companies, operators, and defence programmes internationally. No vessel is too small, and no fleet is too large. That trust is what we have built EPCYBER Maritime around.

— Eva Prokofiev, Founder & CEO

15+ years

Intelligence & cyber

100%

Confidential engagements

50+ countries

Served worldwide

Crew awareness training

Your crew is the perimeter.

Rotating crews, personal devices, credentials sitting in old databases — the people aboard are both the first line of defence and the first target. We train them like it matters.

Explore crew training
How it works

Our process, end to end.

STAGE 01

Reconnaissance

Before we approach a single system, we establish what is already exposed — across sources most firms never think to examine. Credentials, connections, documentation, patterns of movement: whatever can be found, we surface first, and we map precisely how it could be turned against the vessel.

STAGE 02

Assessment

We then test the vessel and everything connected to it as a capable adversary would — methodically, and without interrupting operations on board. Every point of entry is identified, verified, and recorded. Nothing is left to assumption.

STAGE 03

The brief

You receive a single, precise report: each finding rated by real-world risk, each remediation defined, and the whole prioritised so your team knows what to address first. Board-ready, insurer-ready, and delivered in complete confidence.

What we deliver

Six ways to see your vessel as an attacker does.

01

Cyber risk assessment

A full intelligence-led exposure assessment of your vessel or fleet — satellite consoles, open camera feeds, breached crew credentials, exposed systems — with a prioritized report.

Executive risk report
Insurer-compliant
Remote or on-site
02

Penetration testing

Active testing of VSAT, ECDIS, onboard networks, cloud dashboards, and connected shore-side infrastructure. We attempt what an attacker would.

Technical findings
Remediation priorities
Remote · on-site on request
03

Crew awareness training

Built for maritime crews, not generic corporate IT — phishing, social engineering, AI-driven threats, USB attacks, in plain language.

Session + simulation
Remote or aboard
04

Crew exposure check

An assessment of your crew's digital footprint — targeted data and exposure, found before someone else uses it.

Confidential report
Per member or manifest
Remote
05

Security consultation

Strategic review for owners, captains, managers, or insurers — posture, gaps, and guidance without a full engagement.

Session + recommendations
Remote or in person
06

Continuous monitoring

Ongoing dark-web and open-source watch on your vessel, crew, and principal — active alerts, plus a monthly intelligence brief.

Alerts + monthly brief
Remote

Recommended before charter season, delivery from shipyard, ownership transfer, refit completion, crew change, fleet onboarding, or contract award. Every engagement runs without touching vessel operations. team@epcyber.com

Who we serve

Partners in protecting the vessel — and those aboard it.

Private, commercial, or government — if it sails and it is connected, we assess it. We work directly with anyone responsible for a vessel, a fleet, or the people aboard, with no membership, introduction, or minimum fleet size required.

Private owners & charterers

From single-vessel owners to multi-yacht families and charter operators — anyone responsible for a vessel's privacy and the people aboard it. We work fast, remotely, and around the vessel.

Commercial fleets & operators

Cargo, tanker, offshore and support vessels, ferries and passenger operators — fleets where an hour of downtime is measured in money, cargo, and schedule. Assessed without interrupting operations.

Defence & government

Naval programmes, coast guard and government fleets, and the contractors building for them. This is where we started: penetration testing on naval and commercial maritime systems, and every attack surface behind them.

Management & brokerage

Fleet and shipyard teams, captains, and brokers who build our assessments into their own process — sharp findings, in plain language, no IT department required.

Shipyards, refit & suppliers

The yards, integrators and vendors a vessel depends on. One supplier credential can open an entire fleet — we test that path before someone else walks it.

Insurers & underwriters

Risk assessors and underwriters who need verifiable, insurer-ready documentation to price exposure and meet compliance — independently produced, and built to plug into your process.

On the water · in port

We operate where your vessels operate.

On the water and in port. Discreet, on your schedule, wherever the fleet goes.

About the founder

Eva Prokofiev

CEO & Founder · EPCYBER & RedRadar Technologies

15+ years in intelligence and cybersecurity. Oxford Business School — Executive Leadership. Chief Information Security Officer. Her work has been cited by the U.S. Army War College and defense publications across the EU and Middle East.

Founder of EPCYBER and RedRadar Technologies. EPCYBER — founded in 2022 — is a recognized global leader in cyber intelligence, trusted by EU & U.S. agencies and professionals across 50+ countries.

We deliver across defense, oil & gas, banking, and maritime — penetration testing, dark-web monitoring, threat intelligence, and security assessments.

OT / ICS security · Maritime systems (ECDIS, AIS, VSAT) · Penetration testing · Network & infrastructure · Cloud (AWS, Azure) · Dark-web intelligence · Threat intelligence & OSINT
The ocean offers no firewall

Privacy,
kept at sea.

Tell us about your vessel, fleet, or principal. Every enquiry is read and handled in confidence by our intelligence team.

Direct line maritime@epcyber.com