What Does a Company Security Officer (CSO) Do, and Why Does Location Matter?
If your vessel needs a Designated Person Ashore under the ISM Code, it almost certainly needs a Company Security Officer under the ISPS Code too. Most operators know they need one. Fewer have thought through what the role actually does, or why a CSO sitting in the wrong time zone can leave a genuine gap in a vessel's security coverage exactly when it matters.
What the ISPS Code actually requires
Section 11.1 of the ISPS Code is direct: the Company shall designate a Company Security Officer. A single CSO can cover multiple vessels, provided it's clearly documented which vessels they're responsible for.
The CSO's core duties are to ensure a Ship Security Assessment is carried out for each vessel, develop and submit the Ship Security Plan for approval, ensure the plan is properly implemented on board, and act as the liaison point between the ship, the Port Facility Security Officer, and the Ship Security Officer. Security incident reports from the vessel go to the CSO, and any amendment to an approved Ship Security Plan has to be submitted through them.
What "24-hour contact details" actually means
Part A/9.4.14 of the ISPS Code requires every Ship Security Plan to identify the Company Security Officer, including 24-hour contact details. Not office hours. Not "best endeavours." Twenty-four hours.
Security incidents don't wait for business hours any more than safety emergencies do. A suspicious approach in port, a stowaway discovery, a pirate attack, a security level change from the local authority, and an activated Ship Security Alert System all need the CSO reachable at the moment they happen, not the next morning. A CSO based in Europe or the US is, for practical purposes, unreachable during exactly the hours a vessel operating in the South Pacific, New Zealand, or Australia is most active.
Who can be a CSO?
The Code doesn't prescribe a single qualification, but it does require the CSO to have the knowledge and training to be genuinely competent, covering security administration, risk assessment, ship and port operations, and the security equipment and systems involved. We hold that training and certification directly through Lloyd's Maritime Institute, and it translates into practical coverage across four areas:
- Security assessment methodology and risk analysis, carried out in person or remotely across New Zealand, Australia, Papua New Guinea, and the wider South Pacific, with working knowledge of the specific ports, anchorages, and conditions in this region rather than a generic template.
- The ISPS Code and the company's Ship Security Plan: we work from inside your existing SSP and your management company's compliance arrangements with the vessel owner, adding coverage rather than asking anyone to restructure what's already in place.
- Liaison procedures with Port Facility Security Officers and flag state authorities: being based in the region means direct, same-timezone contact with the PFSOs at the ports you're actually calling at, not a message relayed through a shore office that's asleep.
- Security levels and the operational response each one requires, positioned to respond as conditions change in real time, across the South Pacific, New Zealand, Australian, and PNG time zones, rather than picking up the situation the next morning.
Not fully ISPS-bound? Security oversight still matters
In yacht industry practice, ISPS bites once a vessel is operating commercially, trading internationally, and crosses 500GT, the same line that pulls in full ISM compliance, and no coincidence: it's why an entire generation of yachts is deliberately designed to sit at 499GT, just under the threshold. Carrying more than 12 fare-paying guests reclassifies a yacht as a passenger vessel, which can bring ISPS into play depending on how the flag state applies it, but 500GT remains the threshold that does most of the real work. Smaller private vessels and mini-ISM operations often sit outside the mandatory requirement altogether, in the same way they can sit outside ISM.
The same logic applies here as it does to safety management: a lack of legal obligation isn't a lack of risk. This region also isn't quite the same proposition as coastal cruising in the Mediterranean: ports across the South Pacific and PNG are more remote, further from immediate outside assistance, and more variable in local infrastructure. A voluntary, properly resourced security point of contact ashore is one of the more straightforward pieces of risk management to put in place for that kind of cruising ground, and for an owner planning a move toward commercial certification later, it's a head start rather than a cost.
Domestic commercial vessels in Australia and New Zealand carry their own security obligations distinct from ISPS, a topic detailed enough that we'll cover it properly in a future article. Get in touch if you'd like to know how these requirements apply to your operation in the meantime.
The case for a timezone-matched CSO
An external contracted CSO carries out the same function as an in-house one: formal designation in the Ship Security Plan, round-the-clock reachability, direct liaison with the SSO and PFSO, and ongoing oversight, without a dedicated shore-side security role on payroll. We work whichever way genuinely fits the vessel: as the sole, independent CSO where there's no existing shore-side security arrangement in place, or integrated alongside an existing management company's structure where there is. We're not in the business of taking over relationships that are already working well; our interest is filling a genuine gap, not creating a competing one.
We operate exclusively across the South Pacific, New Zealand, Australian, and Papua New Guinea time zones, the window most primary CSOs, based in Europe or the US, structurally can't cover. Where a management company is already in place, this isn't about replacing them. We work alongside your current structure, as backup CSO cover during your primary's off-hours or as the regionally based CSO for vessels operating semi-permanently in this region, integrated into your existing Ship Security Plan and reporting lines rather than duplicating them.
A vessel arriving in Auckland at 1500 local time, an ordinary working afternoon, needing an urgent liaison call with the Port Facility Security Officer is, in UTC terms, calling in at 0200: the middle of the night in the UK and Continental Europe. A CSO in the same time zone as the vessel takes that call as a normal part of the day. A CSO on the other side of the world is asleep, and the vessel is carrying the deficiency, not the CSO.
What a contracted CSO arrangement looks like
A properly structured contracted CSO arrangement is a formal agreement, not a loose understanding. It sets out which vessels are covered and which Ship Security Plan applies to each, the contact arrangements and expected response times, and the liaison procedures with PFSOs and flag state security authorities at the ports you're actually using. It also defines the scope of our involvement in security assessments, drills, and plan reviews, and, where a primary CSO is already in place, the handover procedures between us.
The CSO is named in the Ship Security Plan, with contact details on board: active participation in the vessel's security management, not a name on a document.
Summary
If your vessel is subject to the ISPS Code, a reachable, properly trained CSO is a Code requirement with an explicit 24-hour contact standard, not a discretionary extra. And if your vessel doesn't legally require one, genuine security oversight ashore is still worth having before an incident makes the case for you.
Contact us if you'd like to know more about how we can help your company operate safely, securely, and within requirements, whether as your primary CSO, or as timezone-matched backup cover alongside your existing management structure.
Frequently asked questions
Does every superyacht need a Company Security Officer?
In practice, once a superyacht is operating commercially, trading internationally, and crosses 500GT, the same line that triggers full ISM compliance. It's a threshold the industry takes seriously enough that an entire generation of yachts is deliberately designed to sit just under it, at 499GT. Carrying more than 12 fare-paying guests reclassifies a yacht as a passenger vessel, which can bring ISPS into play depending on the flag state, but 500GT is what does most of the real work. Vessels outside these thresholds aren't legally required to carry a CSO, though showing up at an ISPS-regulated port without one, when you should have one, means delays, detentions, or berth refusals, not a warning letter.
Can the DPA and CSO be the same person?
Yes. In smaller operations this is standard practice, provided the dual role is explicitly documented in both the Safety Management System and the Ship Security Plan. We hold both, and we work alongside your existing yacht management company's structure rather than displacing it, complementing the compliance arrangements already in place between the manager and the vessel owner with regional, time-zone-matched coverage. If you haven't already, it's worth reading our companion article on what a Designated Person Ashore does under the ISM Code.
Does a CSO really need to be contactable 24 hours a day?
Yes. This is a specific requirement under ISPS Code Part A/9.4.14, which requires the Ship Security Plan to list the CSO's 24-hour contact details, not just their name.
Why would a vessel use a CSO based in New Zealand or Australia instead of near its management company?
Because a CSO based in Europe or the US is asleep during the hours a vessel operating in the South Pacific, New Zealand, or Australia needs 24-hour contact most; a regionally based CSO closes that gap without replacing the existing management structure.
Does hiring a regional CSO mean replacing our existing management company?
No. Most vessels using our CSO or DPA services keep their existing management company in place, and we integrate as regional or backup cover within that structure. For vessels without an existing shore-side arrangement, we can also act as sole, independent CSO.
Have a question about this topic?
Book a free 15-minute call with Craig Hopkins — practical answers, no jargon.