Solas Insights
Notes from the practice
AI governance, UAE and Gulf compliance, and maritime and OT security, written by the people who do the work, framed for the regulators who review it.
Maritime & OTLatest
Writing a Ship Cyber Security Management Plan That Satisfies the ISM Code
How to build a cyber risk management plan inside your SMS that passes ISM Code DOC and SMC verification, with the IMO and IACS sources that back it.
10 Sep 20269 min read
Read article- UAE & Gulf ComplianceUAE PDPL vs GDPR: The Differences That Change Your Compliance ProgrammeHow UAE PDPL differs from GDPR on legal basis, consent, transfers, DPO triggers and penalties — and what to change in your programme.3 Sep 20268 min
- Maritime & OTIACS UR E26/E27 for Newbuilds: What Owners Must Demand From Yards in 2026What Gulf owners must demand from shipyards and vendors to get a genuinely E26/E27-compliant newbuild — deliverables, contract clauses, and survey readiness.1 Sep 20267 min
- UAE & Gulf ComplianceUAE Information Assurance Standards: A Controls Primer for Critical-Sector OperatorsA practitioner primer on UAE IA Standard controls: scope, P1-P4 priorities, management and technical families, and what CII operators must implement first.1 Sep 20269 min
- AI GovernanceISO/IEC 42001 vs NIST AI RMF: Choosing a Framework for Your AI Management SystemISO/IEC 42001 vs NIST AI RMF: certification, scope and adoption differences, and how Gulf operators should choose or combine them.19 Aug 20269 min
- UAE & Gulf ComplianceUAE PDPL Breach Notification: What to File and WhenWhat UAE PDPL Article 9 requires when personal data is breached: who files, what the notification must contain, and why the deadline is unsettled.5 Aug 20268 min
- AI GovernanceShadow AI: How to Discover, Assess and Govern Unsanctioned AI UseA practical method to find, risk-rank and govern unsanctioned AI in Gulf enterprises, mapped to NIST AI RMF, ISO/IEC 42001 and the UAE PDPL.21 Jul 20269 min
- UAE & Gulf ComplianceUAE Cyber Security Council's New Recovery Centre: What Gulf Operators Should Read Into ItThe UAE Cyber Security Council's new Abu Dhabi recovery centre signals a shift toward recoverability. What it means for Gulf operators now.2 Jul 20265 min
- Maritime & OTDefending Bridge Navigation: ECDIS, AIS and GPS Against Spoofing and JammingHow Gulf ship operators harden ECDIS, AIS and GPS against the GNSS jamming and spoofing now routine across the Strait of Hormuz.30 Jun 20269 min
- Maritime & OTOT vs IT Security on Ships: Why an ECDIS Is Not Just Another EndpointWhy ECDIS and other shipboard OT need a different security model than IT endpoints, and what IACS, IMO and USCG rules now require of Gulf operators.22 Jun 202610 min
- Maritime & OTMaritime Cybersecurity Compliance in 2026: IMO, IACS UR E26/E27, USCG & NIS2 ExplainedWhich maritime cyber regulations apply to your fleet in 2026: IMO MSC.428(98), IACS UR E26/E27, the USCG rule, and NIS2, with deadlines and a starting plan.11 Jun 20268 min
- UAE & Gulf ComplianceUAE PDPL Readiness: A Practical Checklist for 2026What UAE Federal Decree-Law No. 45 of 2021 (PDPL) actually asks of organisations processing personal data in the Emirates, mapped to controls you can stand up before the enforcement regime tightens.11 Jun 20264 min
