link rel="stylesheet" href="https://unpkg.com/@phosphor-icons/web@2.1.1/src/regular/style.css"

The Coast Guard Made Cyber a Rule: What Maritime Operators Must Do Now

Anthony Mondelli
Alaska OT/ICS Cybersecurity Lead
min. read
August 13, 2026
View on Original Source
min. read

"For thirty years, MTSA meant fences, badges, and drills. Now it means firewalls, accounts, and incident reporting."

Maritime cybersecurity compliance crossed a significant line in 2025. The U.S. Coast Guard's Cybersecurity in the Marine Transportation System rule, published in January 2025 and effective in July 2025, moved cybersecurity from a best practice to an enforceable requirement for covered maritime operators. For MTSA-regulated vessels, facilities, and Outer Continental Shelf facilities, cyber is now part of the security program. It is not optional, not aspirational, and not delegable to IT.

This article is for maritime operators who need to understand what the rule requires, why waiting is the expensive option, and what the practical path forward looks like starting now.

Who Is Covered

The rule applies to MTSA-regulated maritime entities, and some operators may find themselves more squarely in scope than they expected.

Covered entities include MTSA-regulated U.S.-flagged vessels, facilities, and Outer Continental Shelf facilities. The operators who sometimes discover unexpected coverage include seafood processors with MTSA-regulated docks, fuel terminals, cargo handling operations, and port facilities where the primary business is not "maritime" but the regulated dock is.

The practical test: if you already have a Facility Security Plan under MTSA, you should evaluate whether the cybersecurity requirements now apply to your operation. That evaluation should happen with someone who understands both MTSA security requirements and OT cybersecurity, and no, these are not the same discipline.

What the Rule Actually Requires

The rule takes cybersecurity fundamentals and makes them formal, enforceable components of the maritime security program. The major requirements include:

  • Designate a Cybersecurity Officer with defined responsibilities — this is a named role with authority, not an additional duty.
  • Conduct a cybersecurity assessment that covers IT and OT systems associated with covered operations.
  • Develop and maintain a Cybersecurity Plan that addresses identified risks and defines response procedures.
  • Implement account security measures: MFA, account management, privileged access controls, for IT and OT systems.
  • Implement network segmentation between business and operational systems.
  • Conduct cybersecurity drills and exercises on a defined schedule.
  • Report qualifying cyber incidents to the National Response Center.

None of these are novel cybersecurity concepts. What the rule does is make them mandatory for covered operators and tie them to the MTSA enforcement framework.

The Clock: Effective Dates Versus Real Deadlines

The rule became effective in July 2025. Cybersecurity Plan submission requirements create deadlines for covered operators that vary by entity type. The critical message for any maritime operator reading this is: the deadline is not the start date.

Writing a credible Cybersecurity Plan requires that you have actually assessed your environment and made real improvements, not that you have filled in a template. A plan that describes controls you have not implemented and risks you have not validated will not survive a Coast Guard review, and more importantly, will not protect your operation.

Related: Industrial Router Breaches and the Shaking of OT Security — on why maritime OT exposure is real and current

Why Waiting Is the Expensive Option

The organizations that will struggle most with this rule are the ones that start late. Assessment, gap analysis, remediation, and plan writing each take time, and they must happen in sequence, because the plan documents what you assessed and fixed.

At maritime facilities, OT scoping is not straightforward. Vessels, terminal control systems, loading equipment, power distribution, communications, and navigation systems all need to be evaluated. Doing that work at an operating terminal or aboard a working vessel requires coordination with operations, with vendors, and with the MTSA security officer.

Budget cycles add another layer. Significant remediation, including network segmentation, MFA deployment, and access control changes, requires capital and operating budget. If that funding decision does not get made until the deadline is close, the work cannot get done in time.

Assessor and integrator capacity will also tighten as more operators move toward the same deadlines. Experienced OT security practitioners who understand maritime operations are not abundant.

Related: The Five Most Common Attack Paths in Operational Technology — the attack vectors your Cybersecurity Plan needs to address

The Advantage Maritime Operators Already Have

Maritime operators are not starting from zero. MTSA created organizational muscle memory that directly maps to what the cyber rule requires.

MTSA already established the Facility Security Officer role, the security plan discipline, the drill and exercise cadence, and the inspection and documentation culture. The Cybersecurity Officer function mirrors the FSO function in important ways. A Cybersecurity Plan follows the same structural logic as a Facility Security Plan. Cyber exercises fit naturally into the existing drill schedule.

Operators who align the Cybersecurity Officer and Facility Security Officer functions, or who create clear handoffs between them, will move faster than operators who treat the cyber requirement as a disconnected side project.

The advantage is real, but it requires deliberately using it. Folding cyber into the existing security program means the people who already understand MTSA compliance also understand the new requirement. That is a meaningful head start.

Related: Exposing Invisible Links — the IT-OT bridges that a cybersecurity assessment will find at your maritime facility

A Practical Sequence to Start Now

The sequence matters. Assessment before plan. Remediation before documentation. Fundamentals before advanced controls.

  1. Scope every MTSA-regulated asset and the IT and OT systems that touch it. This includes vessel systems, terminal control systems, physical access systems, and communications infrastructure.
  2. Designate the Cybersecurity Officer in writing and give them actual authority including budget authority, change authority, and access to the Facility Security Plan.
  3. Conduct the baseline cybersecurity assessment. Passive, non-intrusive assessment methods work well in operating maritime environments. This is not the time for aggressive scanning.
  4. Rank findings by operational consequence, not just technical severity. A credential management gap in a vessel control system ranks higher than the same gap in an administrative system.
  5. Fix fundamentals first: account security, vendor remote access governance, network segmentation between business and operational systems, and boundaries between IT and OT.
  6. Draft the Cybersecurity Plan from what you actually assessed and improved, not from a template that describes aspirational controls.

30-Day 'Do This Now' Checklist

  1. Confirm which facilities, vessels, docks, and operations are MTSA-regulated and covered by the cybersecurity rule.
  2. Designate the Cybersecurity Officer in writing, a named person with defined responsibilities.
  3. Verify that personnel know how to identify and report a qualifying cyber incident to the National Response Center.
  4. Schedule the baseline cybersecurity assessment for this fiscal year. Not next year.
  5. Identify the first three remediation areas: account security, vendor access, and IT/OT segmentation are almost always the right starting point.

Compliance is on the Clock

The Coast Guard did not invent new cybersecurity requirements. It made the fundamentals enforceable on a clock. The operators who treat that clock as the starting gun and use the next budget cycle to fund real assessment and remediation will end up with a Cybersecurity Plan that reflects genuine risk reduction, not just compliance paperwork.

That is worth doing regardless of the deadline.

If you're preparing for the USCG cybersecurity rule and want to understand where to start, the Koniag Cyber OT/ICS assessment practice works specifically with maritime and port operators navigating this requirement.

Find the content useful? Subscribe to The Catch, our exclusive weekly LinkedIn newsletter focused on real-life experiences doing cyber right in the most highly regulated industries.

About the resource
What you'll learn
Who is this resource for?
Download The Coast Guard Made Cyber a Rule: What Maritime Operators Must Do Now
Download Resource
Thank you and enjoy the resource
View Resource
Oops! Something went wrong while submitting the form.