- Prompt injection attacks manipulate AI guardrails using natural language, exploiting the semantic gap to get models to ignore developer instructions.
- AI social engineering scales faster and lowers attacker skill barriers, enabling automated, targeted campaigns like deepfakes and credential theft.
- Primary harms include data exfiltration, unauthorized transactions, and malicious or biased outputs that damage reputation and operations.
- Defenses are immature; require layered controls: human in the loop, prompt firewalls, input sanitization, least privilege, fuzz testing, patching, and user training.
Last Updated on October 7, 2026
The Maritime Transportation Security Act (MTSA) now defines mandatory cybersecurity requirements for a range of US-flagged ships, US port and cargo facilities, and Outer Continental Shelf (OCS) structures like oil and gas platforms. Its phased implementation clock is already running, with deadlines for core requirements either past or approaching.
This article explores the new MTSA cybersecurity rules and their impacts on covered firms.
Key takeaways
- The MTSA now defines obligatory cybersecurity requirements for covered entities, including vessels and facilities.
- Important new requirements include developing a formal cybersecurity plan for US Coast Guard approval, appointing a cybersecurity officer to oversee the plan, annual security awareness training for employees, periodic vulnerability assessments, and immediately reporting cyber incidents.
- The MTSA has a phased implementation timeline with several critical dates already past. The new cyber requirements take full effect on July 16, 2027.
What is the MTSA and why does it need cybersecurity requirements?
The MTSA has evolved to include cybersecurity requirements because US ports, cargo systems, and ships now depend on digital technology that is subject to increasingly widespread and dangerous cyberattacks. Digital security threats can damage critical shipping infrastructure and operations just as much as a physical security breach.
The MTSA originated in 2002 in the wake of the September 11 terrorist attacks. Initially it focused only on physical security infrastructure like fences, guards, and ID badges. Some of the changes that brought digital security concerns to the forefront include:
- Hackers’ growing focus on operational technology (OT) systems like industrial control systems, machinery, sensors and other Internet of Things (IoT) devices, and embedded software.
- Increased use of digital connections between ships and facilities to help with navigation, tracking, and cargo handling—all of which increase the digital attack surface.
- Shipping systems’ real-world vulnerability to ransomware and other malware that can disable port operations or exfiltrate sensitive data, such as the 2017 NotPetya attack on Maersk.
- Major incident prevention. A highly successful cyberattack on critical shipping infrastructure can trigger a Transportation Security Incident (TSI), a legal term for a major security event that results in significant harm or disruption to a transportation system, such as widespread loss of life, environmental destruction, or local/regional economic impacts.
Covered port facilities and vessels must now comply with strict rules for cybersecurity as they have with physical security. The new MTSA final rule, published in January 2025, is a wakeup call for maritime operators that may have seen digital security as just a routine IT issue.
“Real-world attacks have demonstrated the need for robust cybersecurity measures that can no longer be overlooked,” said Jeremy Price, Managing Director and National Cybersecurity Practice Leader at CBIZ Technology. “The US Coast Guard is really treating the threats to port security as serious issues that need addressing.”
What entities does the MTSA affect?
The MTSA applies to a wide range of entities that are at higher risk for security incidents, including:
- Maritime infrastructure like ports, cargo handling sites, cruise ship terminals, ferry operations, or LNG loading terminals.
- Outer Continental Shelf (OCS) facilities like oil and gas extraction platforms and mobile offshore drilling units (MODUs).
- US-flagged commercial vessels on international voyages, non-US vessels calling at US ports, or US-flagged ships and barges over 100 gross tons, carrying over 150 passengers, or transporting dangerous cargoes or hazardous materials.
Smaller recreational craft or fishing vessels are not subject to MTSA requirements.
The MTSA does not apply directly to non-US flagged commercial vessels. However, these entities must comply with harmonized international standards and hold a valid International Ship Security Certificate (ISSC) when visiting US ports or operating in US waters. The US Coast Guard enforces these rules through Port State Control (PSC) inspections. Non-US ships that cannot demonstrate adequate security may be denied entry, detained, or financially penalized.
What are the core MTSA cybersecurity requirements?
Maritime operators covered by the MTSA must not only implement cybersecurity controls but also document and periodically validate them. The scope of a MTSA compliant cybersecurity program includes daily operations as well as cyber incident response. All applicable controls must be active and accessible for US Coast Guard verification.
Key MTSA cybersecurity requirements include:
- A formal cybersecurity plan that documents cybersecurity safeguards across account management, device management, information security, supply chain risk management, network segmentation, and physical security controls.
- Appointing a cybersecurity officer (CySO) responsible for overseeing and implementing the cybersecurity plan.
- Providing baseline security awareness training to all staff at least annually.
- Conducting periodic physical and digital security vulnerability assessments and risk assessments.
- Reporting covered cyber incidents immediately to the National Response Center.
- Using Transportation Worker Identification Credential (TWIC) cards and conducting background checks on workers.
Each covered vessel or facility must have its own complete cybersecurity plan. Likewise, each tenant or operator within a facility may now need its own cybersecurity plan even if the facility owner handles all the physical security. This “shared responsibility” model for security will bring many new organizations under the MTSA.
What is the MTSA phased implementation timeline?
The MTSA has a phased implementation timeline with these critical dates:
- July 16, 2025—As of this date all reportable cyber incidents (see below) must be reported immediately to the National Response Center.
- January 12, 2026—As of this date, and annually going forward, all employees must have completed the cybersecurity awareness training specified under Part D, “Cybersecurity training for personnel” in the regulation 33 CFR 101.650.
- July 16, 2027—As of this date, operators must designate a Cybersecurity Officer (CySO), conduct an initial cybersecurity assessment, and submit a cybersecurity plan for US Coast Guard approval.
What classes of cyber incidents are reportable under the MTSA?
The MTSA defines a reportable cyber incident as any unauthorized activity, compromise, or targeted attack that disrupts, endangers, or impacts operations, safety, or security-plan functions in the Marine Transportation System.
This includes any attack or data breach that creates safety issues, disrupts cargo operations, or results in unauthorized access to sensitive information technology (IT) system or operational technology (OT) systems or exfiltration/loss of confidential data.
Examples of MTSA reportable cyber incidents include:
- Ransomware or other malware attacks
- Targeted phishing or social engineering attacks aimed at maritime staff or networks (as opposed to everyday spam)
- Unauthorized network access attempts
- Credential theft, including malicious privilege use by insiders
- Cyber-physical security disruptions where a digital intrusion crosses over into physical security operations (e.g., manipulating terminal gates or a ship’s steering system)
- Supply chain attacks against an operator’s vendors or service providers
- Global Positioning System (GPS) or Global Navigation Satellite System (GNSS) attacks, such as GPS spoofing causing ships to move off course
What are the benefits of MTSA cyber compliance?
MTSA compliance is mandated for covered entities and therefore essential to avoid regulatory penalties, as well as to avoid operational disruptions from preventable cyber incidents leading to financial losses and reputational damage.
By complying with MTSA cybersecurity requirements, MTSA covered entities gain benefits like:
- Reduced risk of reportable cyber incidents
- Reduced financial, reputation, safety, and other impacts from cyber incidents
- Improved safety for crews, employees, and passengers
- Enhanced trust and peace of mind for stakeholders by demonstrating a commitment to cybersecurity
- An improved compliance posture to help meet evolving industry and government standards
What’s next?
For more guidance on this topic, listen to Episode 162 of The Virtual CISO Podcast with
Jeremy Price, Managing Director and National Cybersecurity Practice Leader at CBIZ Technology.