The US Coast Guard's new Office of Maritime Cybersecurity Policy aims to ensure 'the Service maintains its leadership role in the maritime domain'.
Cybersecurity for the USCG and maritime facilities has been a national concern for the past couple of years. In February 2024, President Biden issued an executive order to amend regulations related to the safeguarding of vessels, harbors, ports, and waterfront facilities. Shortly after that executive order - which also required the establishment of reasonable precautions against cyber attacks, alongside immediate reporting of cyber incidents of those areas to the Federal Bureau of Investigation (FBI), the Cybersecurity and Infrastructure Security Agency (CISA), and the Captain of the Port, or to respective representatives. Shortly after that, the USCG also issued a Notice of Proposed Rulemaking (NPRM) to update cybersecurity requirements for vessels and facilities in the Marine Transportation System. Since then, the final rule for the marine transportation system cybersecurity requirements was published in 2025, and that documentation continued to be clarified in early 2026 in light of common questions.
More recently, cybersecurity for the coast guard has been in the headlines due to a cyberattack on North Carolina Ports. On August 4th, 2026, a cybersecurity incident stopped digital operations at all three facilities, which process over four million tons of cargo annually. The work to restore systems after the attack was done through the IT department and support from an external forensics team. While no group claimed responsibility for the attack, the event aimed more scrutiny at critical water-based infrastructure, especially following the hacks on Minnesotan water systems by Iran-linked hackers and the legislation that emerged in the aftermath. In light of the North Carolina attacks, Republican Senator Tom Cotton asked Scott Bessent, the Treasury Secretary, to invest in OT, calling current hardware and software “underfunded and outdated, leaving vital infrastructure like water systems, power facilities, and industrial plants, particularly in rural states like Arkansas, vulnerable to cyberattacks by our adversaries.”
The press release for the CG-MCP doesn’t directly address the present-day attacks on water facilities, only stating that the USCG "proactively adapts to a rapidly changing world. Advanced systems and equipment, including the increased use of information and operational technology, accelerate and transform the maritime industry. While these advancements provide operational efficiencies and improvements… they also introduce increased risks to a critical infrastructure sector.” This may be in part because the CG-MCP has been in the works for a while; the original bulletin was published on August 28, 2026 and already lists the leaders of the new department, namely Mr. Nick Parham, the Office Chief; and Commander Brandon Link, the Deputy Office Chief of the CG-MCP. Parham’s title as the Chief of the CG-MCP seems to have been effective as early as January 9th, 2026, where he signed off on a Cyber Training Verification Job Aid for Coast Guard Vessel and Facility inspectors. Brandon Link has also been named as a leader in the office as far back as April. Still, the most recent release is the first to publicly state the aims of the agency.
According to the August 31st announcement, the Office of Maritime Cybersecurity Policy will 1) create domestic policy and work with international standards to harmonize with US maritime cybersecurity goals, 2) organize a plan for cybersecurity compliance and enforcement, 3) regularly connect with stakeholders, academia, and national laboratories in the maritime space to stay updated on relevant innovation and 4) oversee and support the advancements of new technologies and methods to take care of risks alongside other critical functions. The bulletin adds more context for these goals, placing it as a descendant of Executive Order 14269 - Restoring America's Maritime Dominance.
Security officers in the Coast Guard seem to agree with this characterization. The Assistant Commandant for Prevention Policy, Rear Admiral Robert C Compher commended the creation of the new office: “The Coast Guard must maintain pace with the maritime industry’s continued technological advancements. The creation of the Office of Maritime Cybersecurity Policy establishes a central authority to develop clear policy, direct a unified compliance strategy, and collaborate with our partners. This office will ensure we are not only addressing current cyber threats and vulnerabilities, but are also preparing for the challenges ahead, safeguarding the Marine Transportation System for the future.” Considering the recent hacks in North Carolina, the next challenge may be sooner than anticipated. Hopefully, the head start the leaders of the new office have will prove to be useful advantages in their fight against maritime cybercrime.