Ports, terminals and facility operators
Maritime OT Cybersecurity Assessment and Plan Readiness
Prepare the assessment evidence, remediation priorities and recovery records your facility needs. GDF scopes maritime IT and OT work with security, engineering and operations before any testing begins.
Start with the facility and the systems it depends on
A terminal can depend on corporate identity, vendor connections, cargo applications, access-control systems and operational equipment. An assessment needs to explain those connections and the consequence of losing or compromising them. We establish the facility boundary, system ownership and operating constraints with the people responsible for the process.
The engagement produces a documented technical record for the facility owner and Cybersecurity Officer: the systems examined, methods used, findings supported by evidence, gaps requiring further work and corrective actions. Assessment, plan-support work and recurring assurance are separately scoped so the owner can see each responsibility and deliverable.
Facility and responsibility map
Identify the owner, operator, tenants, vendors, relevant IT/OT systems and the people who can authorize each part of the assessment. A port-authority engagement does not authorize access to a tenant's equipment.
Access and operational dependencies
Examine identity, engineering access, vendor gateways, segmentation and supporting services. Compare the intended access restrictions with configuration records and approved validation.
Recovery and incident evidence
Review configuration baselines, backup dependencies, restoration records, logging, time synchronization and escalation. Agree on a representative restore exercise where it is safe and useful.
Plan support and corrective actions
Provide technical findings, remediation owners, priorities, evidence gaps and plan-support material. The facility owner retains accountability for the plan and regulatory submissions.
July 16, 2027: assessment, officer and plan submission
The Coast Guard's implementation schedule requires covered entities to complete an initial cybersecurity assessment, designate a Cybersecurity Officer and submit a cybersecurity plan by July 16, 2027. Coverage follows the applicable vessel, facility or Outer Continental Shelf security regime. Being located at a port does not automatically establish coverage.
Under 33 CFR 101.650, cybersecurity assessments recur annually. Penetration testing is tied to cybersecurity-plan renewal, rather than a blanket annual penetration-test requirement. Annual plan audits are a separate activity. The plan generally has a five-year approval period; submission by the deadline does not mean approval is guaranteed.
The Coast Guard also states that an existing physical-security-plan waiver does not automatically exempt an entity from cybersecurity requirements. Resolve applicability, waivers and plan obligations with the owner's compliance adviser. GDF supplies technical analysis and evidence, not legal advice, a regulatory certification or a guarantee of acceptance.
Official sources: Coast Guard implementation timeline (opens in a new tab); 33 CFR Part 101, Subpart F (opens in a new tab); Coast Guard guidance on existing waivers (opens in a new tab).
Methodology
An assessment method built around operations
-
Confirm authority
Define facility boundaries, permitted systems, access permissions, operating windows and the person who can stop the work.
-
Review before testing
Start with architecture, interviews, existing records, configurations and approved passive evidence. Identify fragile equipment and essential dependencies.
-
Approve validation
Engineering and operations agree on active methods, exclusions, stop conditions and recovery arrangements. Laboratory or representative assets can be used where production testing is unsuitable.
-
Document consequences
Connect each supported finding to the affected process, access path and operating consequence. Separate observed facts, inferences and untested assumptions.
-
Assign corrective work
Deliver priorities, evidence, ownership and retest criteria. Keep implementation and independent audit responsibilities distinct where required.
-
Maintain assurance
Separately schedule annual reassessment, corrective-action verification, exercises and evidence maintenance. Ongoing work has a defined allocation and scope.
Evidence commonly examined
Evidence reviewed
- Facility boundaries, architecture and responsibility records
- Vendor access, identity and segmentation configurations
- Relevant session, authentication and change records
- Backup, restoration, incident and exercise records
What you can expect
What you receive
- Facility-specific assessment and documented limitations
- Operational risk register and corrective-action roadmap
- Technical evidence and material for plan preparation
- Executive and engineering readouts with retest criteria
Frequently asked
Common questions
Does every port business have to meet the Coast Guard deadline?
No. Applicability depends on the regulatory category and operating arrangement. Confirm which legal entities, vessels and facilities are covered before scoping compliance-related work.
Is an annual assessment the same as an annual penetration test?
No. The rule calls for annual cybersecurity assessments. Penetration testing is associated with plan renewal, while plan audits are separate. Any active testing needs its own approved operational scope.
Will the assessment interfere with equipment?
The method begins with records, architecture and passive evidence. Active validation requires engineering approval, appropriate conditions and recovery arrangements. Production disruption cannot be ruled out by a marketing promise; unsuitable methods are excluded.
Can GDF write and approve our complete compliance plan?
GDF can provide technical findings and plan-support material under an agreed scope. The owner and its qualified compliance advisers establish regulatory obligations and submissions. GDF does not approve a Coast Guard plan or certify complete compliance.
Talk with an examiner
Discuss your maritime facility
Tell us the facility type, owner or operator, assessment deadline and systems involved. Identify the security, engineering and operations contacts who can authorize the work. Keep sensitive architecture and security-plan details out of this form.
Since 1992 · 24/7 dispatch · Court-tested experts
Related capabilities