View

Field notes · 28 August 2026

IT handover checklist for taking over a vessel

A practitioner's checklist for the IT side of a vessel purchase or management change: what to ask for, what to transfer, what to switch off.

Use this alongside the technical handover. It’s written for the person on the owner’s side who has been told “and can you sort out the IT” — usually a superintendent or owner’s rep, rarely an IT specialist. Skip what doesn’t apply. Forward it freely.

1. Before completion — ask the seller for these

The seller has to answer while the sale is open. Afterwards, they don’t.

  • Complete list of computer-based systems on board, with manufacturer, model and firmware/software version. If they don’t have one, that tells you something.
  • Network diagram, however old. Ask specifically for anything showing the OT side: engine control, alarm and monitoring, navigation, and how those connect to the crew and guest networks.
  • All administrative credentials: network switches, firewalls, wireless controllers, servers, hypervisors, NAS, PBX, CCTV, AV/entertainment, satellite terminals, bridge systems with logins.
  • List of every remote access path: vendor VPNs, integrator remote support tools, OEM remote diagnostics, management company links.
  • Software licence list: who owns each licence, whether it transfers, and the renewal date. Watch for PMS, charting, navigation, media servers, Microsoft/Google tenancy, antivirus, backup.
  • Connectivity contracts: provider, term, committed data, termination clause, hardware ownership.
  • Support and maintenance contracts for IT and OT equipment.
  • Domain names, email hosting, cloud accounts — and who the registered owner is.
  • Backup: what’s backed up, where, and when a restore was last tested.

2. Completion day — take control

  • Rotate every administrative credential. Store them in a password manager owned by the buyer, not by the integrator.
  • Disable or delete every remote access account that isn’t yours, and change the shared secrets on any VPN.
  • Change the registered owner and contact on domains, cloud tenants and licence portals.
  • Confirm you can log in to the connectivity provider’s portal as the account holder.
  • Take a full backup, and confirm it restores, before anyone touches anything else.

3. First thirty days — understand what you’ve got

  • Walk the vessel and check the inventory against reality. It will differ.
  • Photograph every equipment rack and label what isn’t labelled.
  • Identify anything running end-of-life software or firmware, particularly anything on the OT side.
  • List every recurring cost with its exit date.
  • Decide what the crew are allowed to do on which network, and write it down.

4. First ninety days — decide

  • Which contracts to exit at the first opportunity.
  • Which equipment is over-specified for how you’ll operate — usually some of it — and which is genuinely at risk.
  • Whether the network needs to be re-segmented before the next class cyber question arrives.
  • Who is responsible for IT now, by name, and who they call.

Common finds

Things that turn up on most handovers, in roughly descending order of frequency:

  • Administrator accounts belonging to people who left years ago.
  • Vendor remote access that has never been switched off.
  • A firewall with a rule base nobody can explain.
  • Licences that were never in the vessel’s name.
  • A backup that was configured once and never verified.
  • Two connectivity services running side by side, one of them forgotten.

If you’d like help running one of these, that’s what we do.

Share

Copy the address and paste it wherever it's useful. No tracking, no gate.

https://marinedatalogic.com/field-notes/vessel-it-handover-checklist/