Disruptive By Design: MTSA Cybersecurity Requirements: A Culture Shift for Maritime Security
As cyber incidents increase, the U.S. Coast Guard’s (USCG’s) Maritime Transportation Security Act (MTSA) cyber rule is pushing maritime organizations to treat cybersecurity as an operational discipline, anchored in training, governance and visibility across information technology (IT) and operational technology (OT).
Cyber risk is increasingly intersecting with safety in the maritime domain. As vessels and port operations become more connected, incidents are rising. Cyber Trust & Resilience for Maritime reported that maritime cyber incidents increased by 103% in 2025 compared with 2024.
Cyber incidents can also cause significant operational disruption, affecting productivity, revenue and recovery costs. Depending on the nature of the attack, organizations may face substantial expenses to restore operations. According to the U.S. Coast Guard’s 2024 Cyber Trends and Insights in the Maritime Environment report, 70% of breached organizations reported that the incident caused significant or very significant disruption. The same year, the average cost of a data breach across industries reached approximately $4.88 million.
Regulators have responded by translating long-standing security expectations into concrete cybersecurity requirements intended to reduce risk and limit the operational impact of future attacks.
In January 2025, the USCG published a final rule that updates requirements for U.S.-flagged vessels, Outer Continental Shelf facilities and MTSA-regulated facilities. The rule became effective July 16, 2025, and it establishes baseline expectations that include role-based training:
All personnel: Foundational cybersecurity awareness (e.g., recognizing phishing and social engineering, maintaining account and device security and security reporting guidelines.
Key personnel: Expanded, role-specific training that emphasizes responsibilities during a cyber incident, escalation paths and maintaining awareness of evolving threats and countermeasures.
OT users: Additional specialized training on protecting operational technology and managing cyber-physical risk in safety-critical environments.
Cybersecurity Officer (CySO): Advanced training focused on program governance, oversight and managing and responding to cyber threats.
Beyond training, the rule requires a cybersecurity assessment and the development of a Cybersecurity Plan and a Cyber Incident Response Plan, along with measures such as penetration testing. The rule also introduced immediate reporting expectations for certain cyber incidents as the effective date. Training was required to be completed by January 12, 2026, and the remaining major requirements, including designating the CySO and submitting the Cybersecurity Plan for approval, are due by July 16, 2027.
Taken together, these requirements push organizations to map both IT and OT environments, identify critical assets and understand how systems and data flows are interconnected. That visibility sets the foundation for a practical cybersecurity plan and an incident response capability that works under operational pressure.
The rule also signals a change in regulatory posture: cybersecurity is being treated less as a checklist item and more as an operational culture. By making baseline training universal, the Coast Guard is reinforcing that cyber hygiene is not confined to IT teams, especially when phishing and credential theft remain common across access vectors.
Similar approaches are emerging internationally. In December 2025, Italy’s Ministry of Infrastructure and Transport issued an updated circular on navigation safety that strengthens cyber risk management expectations for national vessels, information security management companies and port facility operators. Requirements will go into force in November 2026. The circular reflects many of the same themes found in the USCG’s MTSA cyber rule, reinforcing a broader regulatory trend toward more formalized cybersecurity requirements across the maritime sector.
Cyber attacks are now a persistent feature of the operating environment, and maritime regulators are responding accordingly. The Coast Guard’s cyber rule elevates cybersecurity to a shared responsibility across the workforce while pressing organizations to build a clear picture of their IT and OT dependencies, so they can anticipate operational impacts, reduce avoidable exposure and respond effectively when incidents occur.
Comments