US Coast Guard Opens Dedicated Cybersecurity Office for America's Ports and Waterways

A new federal office will write the rules on digital security for the network of ports, ships, and waterways that keeps American trade moving. It arrives after a government watchdog said the Coast Guard's cyber approach had serious gaps.

ThreatVectr Newsdesk· 3 min read
AI analyzing network data
Share

Key points

  • The US Coast Guard formally created the Office of Maritime Cybersecurity Policy (CG-MCP) to set and enforce digital security rules across America's Marine Transportation System.
  • The new office covers roughly 360 commercial sea and river ports that together form the backbone of US maritime trade.
  • A February 2025 Government Accountability Office report found the Coast Guard's existing cyber strategy lacked proper risk assessments, performance measures, and clear staff responsibilities.
  • CG-MCP will act as the Coast Guard's main point of contact with shipping companies, other government agencies, and international standards bodies.
  • The Coast Guard has not confirmed whether the GAO's criticism directly triggered the new office's creation.

America's ports do not run on ropes and radar alone. Every major facility now depends on software-controlled cranes, automated cargo tracking, and networked navigation systems. That connectivity is efficient. It is also a door that criminals can try to open.

The US Coast Guard has created a new unit specifically to lock that door: the Office of Maritime Cybersecurity Policy, known as CG-MCP. It will be the single central authority for writing, implementing, and enforcing cybersecurity rules across the Marine Transportation System, the collective name for the ports, vessels, and waterways that move goods around the country.

What will this office actually do?

CG-MCP will set policy, run compliance checks, and act as the Coast Guard's official voice on maritime cyber issues with industry and foreign governments. It sits inside the Directorate of Inspections and Compliance, which means it has enforcement teeth, not just advisory status.

The office will also track new technologies and attack techniques so the sector can respond before a problem becomes a crisis, rather than after.

Rear Admiral Robert C. Compher, who oversees prevention policy, framed it plainly: the Coast Guard needs a single body that can write clear rules, unify enforcement, and coordinate with partners. Until now, that function was scattered.

Why now, and what went wrong before?

The timing matters. In February 2025, the Government Accountability Office, the independent watchdog that audits federal agencies, published a report identifying significant weaknesses in how the Coast Guard was handling cybersecurity across those 360 commercial ports.

The GAO found four specific problems worth noting:

Problem identified What it meant in practice
Inaccurate incident records Cyber attacks were not always logged correctly
Hard-to-access deficiency data Inspectors could not easily see known weaknesses
Strategy misaligned with national plans Coast Guard cyber goals did not match federal priorities
Staff competency gaps Personnel with cyber duties lacked defined skill requirements

The GAO called on the Coast Guard to fix all of these. The Coast Guard has not said publicly whether the new office is a direct response to that report, first covered by SecurityWeek.

For ordinary people, the stakes are concrete. A disrupted port does not just inconvenience shipping companies. It delays the goods on shop shelves, the fuel at petrol stations, and the raw materials factories need.

Should ordinary people do anything?

Not immediately. This is a structural government reform aimed at operators of ships and port facilities, not individual consumers. If you work in maritime logistics, your employer may face new compliance requirements in the coming months. Watch for updated Coast Guard guidance on cybersecurity standards, particularly around reporting digital incidents and staff training expectations.

For everyone else, the practical takeaway is that the federal government is trying to harden a part of critical infrastructure that had been running without a clear set of cyber rules. That is overdue, and it is a good thing.

© 2026 Threat Vectr