Breaking
SecurityDeveloping Story

Coast Guard Creates Central Maritime Cyber Policy Office

New CG-MCP office centralizes maritime cybersecurity policy as ports face rising operational technology risks.

··2 hours ago·4 min read
a golden padlock sitting on top of a keyboard
Photo by Towfiqu barbhuiya on Unsplash

The US Coast Guard's new Office of Maritime Cybersecurity Policy (CG-MCP) arrives at a moment when the maritime industry's growing reliance on digital systems is forcing regulators to rethink how they protect critical infrastructure. As ports, vessels, and the broader Marine Transportation System (MTS) adopt more advanced information and operational technology, the Coast Guard is establishing a dedicated central authority to develop and enforce cybersecurity policy.

The new office, created under the Director of Inspections and Compliance, will serve as the Coast Guard's primary liaison with industry partners and other government agencies on maritime cybersecurity matters. Its mandate covers domestic policy development, contribution to international standards, and a coordinated cybersecurity compliance and enforcement strategy.

A Central Authority for Maritime Cyber Policy

The Office of Maritime Cybersecurity Policy will function as the Coast Guard's central authority for developing and implementing policies governing the cyber safety and security of the Marine Transportation System. The MTS encompasses roughly 360 commercial sea and river ports, making it a vast and critical piece of national infrastructure.

According to the Coast Guard, the office's responsibilities will include developing domestic policy, contributing to international standards, directing a coordinated cybersecurity compliance and enforcement strategy, and engaging with maritime organizations, academia, and national laboratories. It will also monitor emerging technologies and techniques that could help the maritime sector proactively manage cyber risk.

This centralization is intended to address a long-standing fragmentation in how maritime cybersecurity policy was handled across the service.

Why the Shift Matters for Critical Infrastructure

The Coast Guard's announcement highlights the growing convergence of information technology and operational technology in the maritime sector. As ships and ports become more interconnected, the risk surface expands, and the consequences of a cyber incident can be severe.

The service said in a statement: “Advanced systems and equipment, including the increased use of information and operational technology, accelerate and transform the maritime industry. While these advancements provide operational efficiencies and improvements throughout the Marine Transportation System, they also introduce increased risks to a critical infrastructure sector.”

This framing underscores that the office is not just about compliance but about proactively managing a risk that could disrupt trade, safety, and national security.

The GAO's Critical Findings

The creation of the office comes roughly 18 months after the Government Accountability Office (GAO) identified multiple shortcomings in the Coast Guard's approach to securing the MTS. In a February 2025 report, the watchdog called on the Coast Guard to improve the accuracy of cybersecurity incident information and provide easier access to data on cyber deficiencies.

The GAO also urged the service to align its cyber plans with the national strategy, establish competency requirements for personnel with MTS cybersecurity responsibilities, and address gaps in those competencies. The report found that the Coast Guard's system of record did not provide ready access to complete information about cybersecurity issues uncovered during inspections of vessels and facilities.

The watchdog's findings painted a picture of a service struggling to keep pace with the threat landscape, with data silos and skill shortages hampering its ability to secure a critical sector.

Alignment with National Strategy

The GAO also found that the Coast Guard's cyber strategy did not fully address several characteristics of an effective national strategy, including risk assessment, performance measures, required resources and investments, and the division of roles and responsibilities.

This suggests that the new office will need to tackle not just policy development but also strategic planning, resource allocation, and interagency coordination. The Coast Guard did not say whether the creation of the new office was directly related to the GAO findings, but the timing is notable.

The office's engagement with academia and national laboratories is also meant to bring in outside expertise to help the sector anticipate and mitigate emerging cyber threats.

Industry and Government Collaboration

By serving as the primary liaison with industry partners and other government agencies, the office is designed to foster collaboration across the maritime ecosystem. This includes working with port authorities, vessel operators, and technology providers.

The office will also engage with international partners to contribute to global maritime cybersecurity standards, a key aspect given the international nature of shipping.

A Leader with Clear Priorities

Rear Adm. Robert C. Compher, assistant commandant for prevention policy, emphasized the need for the Coast Guard to keep pace with the maritime industry's technological advancement.

“The creation of the Office of Maritime Cybersecurity Policy establishes a central authority to develop clear policy, direct a unified compliance strategy, and collaborate with our partners,” Compher said.

He added that the new office is intended to address current threats and vulnerabilities while preparing the maritime sector for emerging cybersecurity challenges.

What This Means for the Maritime Sector

The establishment of the CG-MCP is a significant step for the Coast Guard's cyber posture, but its real-world impact will depend on execution. The GAO's findings highlight that policy alone is not enough—data accuracy, personnel competencies, and strategic alignment are all critical.

For maritime companies, this could mean more rigorous inspections, clearer compliance expectations, and potentially more coordinated enforcement across the sector. The office's focus on monitoring emerging technologies suggests that the Coast Guard is looking ahead to threats that may not yet be widespread.

While the Coast Guard did not explicitly link the office to the GAO report, the creation of a central authority appears to be a direct response to the identified gaps. Whether it will be enough to close them remains to be seen, but the move signals a more deliberate, centralized approach to maritime cybersecurity that could set a precedent for other critical infrastructure sectors.

#maritime cybersecurity#coast guard#critical infrastructure#cyber policy#mts

Sources

Iliyas

Founder & Editor, Xploitwire

This article was compiled from the sources listed above and checked against them for accuracy, under editorial policies set by Iliyas. Read our Editorial Policy →

← Back to all stories