Start from the response plan but supplement it with scenario playbooks (malware, data leaks, denial of service, system unavailability), drilled regularly and updated with lessons; for ships the contingency must already sit in the ISM Code 1.4.5 emergency procedures. Prepare and practise an incident response plan with roles, communication paths and core activities (starting a backup ECDIS after malware may spread the infection). Have external expert help available for complex incidents or where insurers require it, covering network activity, anomalous or uninventoried devices, uncoordinated vendor access, forensics and clean-up, and use knowledge of past incidents across the fleet.
The graph holds this control, the 0 it maps to, and the evidence behind each claim, over MCP and REST.