What we do
The rule creates a substantial amount of work, and almost none of it ends. A facility must designate a Cybersecurity Officer who is reachable by the Coast Guard at any hour of any day. It must complete a Cybersecurity Assessment and file a Cybersecurity Plan covering fourteen required sections §101.630(c) by 16 July 2027. Then, every year after that, it must repeat the Assessment, have the Plan audited by someone independent of the work, deliver cybersecurity training to everyone with system access, run two drills and one full exercise, and keep records of all of it available for inspection. Throughout, someone must track known exploited vulnerabilities against the facility’s systems and decide what to do about each one, report cyber incidents on a deadline, and amend the Plan whenever the facility, its ownership or its officer changes.
We do all of it. We provide the officer, conduct the Assessment, write the Plan, file it, perform the annual audit, build and deliver the training, run the drills and the exercise, monitor the vulnerability catalogue, handle the reporting, and keep the records.
Some of this work has to happen at the facility, and our officers travel to do it. The site walkdown the Assessment depends on, the drills, the exercise — we are there in person, not on a call. How many site visits your facility needs is agreed with you before the engagement starts.
The technical measures on your own systems stay with you — network segmentation, multifactor authentication, device and account controls. We tell you exactly what the rule requires and when. You decide what to buy.
What we built
We built our own software for this rule.
Every facility we take on runs through the same system: an assessment protocol that maps each requirement to the evidence it needs, a plan system covering all fourteen required sections, a monitoring service that cross-references every update to the CISA Known Exploited Vulnerabilities catalogue against your equipment automatically, and a compliance calendar carrying every recurring obligation with its deadline and its owner.
The catalogue changes constantly. Every time it does, we match the new entries against the equipment inventory we hold for your facility, and if something you run is affected you hear from us the same day, with what it is and what the rule requires you to do about it.
Filing is 25 weeks from signature. We track every deadline and make every filing. We come to you for three things: the training and the drills, which we run for you; anything in the catalogue that affects your equipment; and anything we need from your site. Everything else happens without you.
Who holds your designation
Your Cybersecurity Officer is a named individual, and we are careful about who that is.
We recruit from the Coast Guard and the military. Our officers have run security and IT operations in industrial and operational technology environments, and they understand both the equipment on a waterfront facility and the threats against it. They have worked inside regulated operations where a mistake has consequences beyond a network.
The rule sets a knowledge bar across twelve areas §101.625(e). Our officers exceed it, and we screen against a higher standard than the rule requires before anyone is designated.
You will know who your officer is, by name, before the designation is made. Your name and theirs go on the same filing.
Where to go from here
Ten questions, about two minutes. It runs in your browser and your answers are not sent to us unless you choose to send them.