The operating environment

The Coast Guard hunts on maritime networks

The Coast Guard’s own published reporting is the source for this page. Where a figure originates elsewhere we say so: the crane share below is one the Coast Guard relays from a House Select Committee investigation, and the vulnerability count is CISA’s, with the date we took our copy.

Cyber Protection Teams

What CGCYBER does on the water

The Coast Guard has a cyber command, and its Cyber Protection Teams deploy onto maritime networks — to assess them, to hunt for activity already present, and to respond when something is found. The counts are published each year in Cyber Trends and Insights in the Marine Environment.

CPT missions by year β€” CGCYBER, CTIME 2023 / 2024 / 2025. The 2025 edition is the most recent published as at 10 August 2026.
YearMissionsLocationsAssess / Hunt / Advisory / Incident response
2023301518 / 6 / 5 / 1
2024422024 / 11 / 2 / 5
2025422227 / 5 / 9 / 1

Forty-two missions across twenty-two locations in 2025, up from thirty across fifteen in 2023. The mission count held steady between 2024 and 2025; the number of distinct locations rose.

Equipment on the dock

What a hunt mission found on a crane

In a 2025 special edition of the same report, the Coast Guard states that approximately 80% of ship-to-shore cranes used in the United States are manufactured by Shanghai Zhenhua Heavy Industries, a Chinese state-owned enterprise.

A ship-to-shore crane is an operational technology system. The same report describes modern STS cranes as having connectivity to a wireless controller, cellular modems able to reach OT components directly, and remote maintenance arrangements — the same classes of exposure as any other industrial plant on a terminal.

Cyber Protection Teams have discovered cellular modems installed on STS cranes manufactured in China. One was found on a crane spreader and was not identified on the electrical schematics for the equipment; the report records that this finding came from a CPT hunt mission. The report records that the modems served no purpose in normal crane operation and were removed.

Published advisories

The Coast Guard names software and indicators

Through 2025 the Coast Guard published Maritime Cyber Alerts 01-25, 02-25 and 04-25, and Maritime Cyber Bulletins 01-25 and 02-25. They are public documents on uscg.mil, and they name specific software and specific indicators of compromise.

Separately, CISA maintains the Known Exploited Vulnerabilities catalogue — a public list of vulnerabilities confirmed to have been exploited in the wild. It stood at 1,651 entries when we last took a copy on 21 July 2026, and it is one of the things a Cybersecurity Officer has to track against a facility’s own equipment §101.625(d)(15).

Why the rule reads as it does

Subpart F is a response to this, not the origin of it

The rule makes more sense once you know what it is answering. §101.650(e)(1) asks for an assessment that analyses all networks and identifies the risk posed by each digital asset. §101.650(h) asks for segmentation between IT and OT, and for the connections between them to be logged and monitored. §101.635 asks for drills twice a year and a full exercise once.

Those are not filing requirements. They are what a team does before and after it finds something.

Next step

Nothing on this page is about you

This page describes an environment. It makes no claim about your facility and nothing here is a prediction.

Ten questions, about two minutes. It runs in your browser and your answers are not sent to us unless you choose to send them.

Does this apply to you Or schedule a call →