Ports, terminals and facility operators

Maritime OT Cybersecurity Assessment and Plan Readiness

Prepare the assessment evidence, remediation priorities and recovery records your facility needs. GDF scopes maritime IT and OT work with security, engineering and operations before any testing begins.

Water treatment and electrical utility infrastructure.

Start with the facility and the systems it depends on

A terminal can depend on corporate identity, vendor connections, cargo applications, access-control systems and operational equipment. An assessment needs to explain those connections and the consequence of losing or compromising them. We establish the facility boundary, system ownership and operating constraints with the people responsible for the process.

The engagement produces a documented technical record for the facility owner and Cybersecurity Officer: the systems examined, methods used, findings supported by evidence, gaps requiring further work and corrective actions. Assessment, plan-support work and recurring assurance are separately scoped so the owner can see each responsibility and deliverable.

Facility and responsibility map

Identify the owner, operator, tenants, vendors, relevant IT/OT systems and the people who can authorize each part of the assessment. A port-authority engagement does not authorize access to a tenant's equipment.

Access and operational dependencies

Examine identity, engineering access, vendor gateways, segmentation and supporting services. Compare the intended access restrictions with configuration records and approved validation.

Recovery and incident evidence

Review configuration baselines, backup dependencies, restoration records, logging, time synchronization and escalation. Agree on a representative restore exercise where it is safe and useful.

Plan support and corrective actions

Provide technical findings, remediation owners, priorities, evidence gaps and plan-support material. The facility owner retains accountability for the plan and regulatory submissions.

July 16, 2027: assessment, officer and plan submission

The Coast Guard's implementation schedule requires covered entities to complete an initial cybersecurity assessment, designate a Cybersecurity Officer and submit a cybersecurity plan by July 16, 2027. Coverage follows the applicable vessel, facility or Outer Continental Shelf security regime. Being located at a port does not automatically establish coverage.

Under 33 CFR 101.650, cybersecurity assessments recur annually. Penetration testing is tied to cybersecurity-plan renewal, rather than a blanket annual penetration-test requirement. Annual plan audits are a separate activity. The plan generally has a five-year approval period; submission by the deadline does not mean approval is guaranteed.

The Coast Guard also states that an existing physical-security-plan waiver does not automatically exempt an entity from cybersecurity requirements. Resolve applicability, waivers and plan obligations with the owner's compliance adviser. GDF supplies technical analysis and evidence, not legal advice, a regulatory certification or a guarantee of acceptance.

Official sources: Coast Guard implementation timeline (opens in a new tab); 33 CFR Part 101, Subpart F (opens in a new tab); Coast Guard guidance on existing waivers (opens in a new tab).

Methodology

An assessment method built around operations

  1. Confirm authority

    Define facility boundaries, permitted systems, access permissions, operating windows and the person who can stop the work.

  2. Review before testing

    Start with architecture, interviews, existing records, configurations and approved passive evidence. Identify fragile equipment and essential dependencies.

  3. Approve validation

    Engineering and operations agree on active methods, exclusions, stop conditions and recovery arrangements. Laboratory or representative assets can be used where production testing is unsuitable.

  4. Document consequences

    Connect each supported finding to the affected process, access path and operating consequence. Separate observed facts, inferences and untested assumptions.

  5. Assign corrective work

    Deliver priorities, evidence, ownership and retest criteria. Keep implementation and independent audit responsibilities distinct where required.

  6. Maintain assurance

    Separately schedule annual reassessment, corrective-action verification, exercises and evidence maintenance. Ongoing work has a defined allocation and scope.

Evidence commonly examined

Evidence reviewed

  • Facility boundaries, architecture and responsibility records
  • Vendor access, identity and segmentation configurations
  • Relevant session, authentication and change records
  • Backup, restoration, incident and exercise records

What you can expect

What you receive

  • Facility-specific assessment and documented limitations
  • Operational risk register and corrective-action roadmap
  • Technical evidence and material for plan preparation
  • Executive and engineering readouts with retest criteria

Frequently asked

Common questions

Does every port business have to meet the Coast Guard deadline?

No. Applicability depends on the regulatory category and operating arrangement. Confirm which legal entities, vessels and facilities are covered before scoping compliance-related work.

Is an annual assessment the same as an annual penetration test?

No. The rule calls for annual cybersecurity assessments. Penetration testing is associated with plan renewal, while plan audits are separate. Any active testing needs its own approved operational scope.

Will the assessment interfere with equipment?

The method begins with records, architecture and passive evidence. Active validation requires engineering approval, appropriate conditions and recovery arrangements. Production disruption cannot be ruled out by a marketing promise; unsuitable methods are excluded.

Can GDF write and approve our complete compliance plan?

GDF can provide technical findings and plan-support material under an agreed scope. The owner and its qualified compliance advisers establish regulatory obligations and submissions. GDF does not approve a Coast Guard plan or certify complete compliance.

Talk with an examiner

Discuss your maritime facility

Tell us the facility type, owner or operator, assessment deadline and systems involved. Identify the security, engineering and operations contacts who can authorize the work. Keep sensitive architecture and security-plan details out of this form.

Since 1992 · 24/7 dispatch · Court-tested experts

Or call 1-800-868-8189

Email or phone is required. A submission does not create an engagement. For an active incident, please call. Read what we send with the request.

Privacy center

Choose your site settings

Optional technology stays off until you choose otherwise. You can change these browser settings at any time. Access to the core site does not depend on optional technologies.

Technology preferences
Sale or cross-context sharing: not used GDF does not sell or share website personal information for cross-context behavioral advertising.