What CGCYBER does on the water
The Coast Guard has a cyber command, and its Cyber Protection Teams deploy onto maritime networks — to assess them, to hunt for activity already present, and to respond when something is found. The counts are published each year in Cyber Trends and Insights in the Marine Environment.
| Year | Missions | Locations | Assess / Hunt / Advisory / Incident response |
|---|---|---|---|
| 2023 | 30 | 15 | 18 / 6 / 5 / 1 |
| 2024 | 42 | 20 | 24 / 11 / 2 / 5 |
| 2025 | 42 | 22 | 27 / 5 / 9 / 1 |
Forty-two missions across twenty-two locations in 2025, up from thirty across fifteen in 2023. The mission count held steady between 2024 and 2025; the number of distinct locations rose.
What a hunt mission found on a crane
In a 2025 special edition of the same report, the Coast Guard states that approximately 80% of ship-to-shore cranes used in the United States are manufactured by Shanghai Zhenhua Heavy Industries, a Chinese state-owned enterprise.
A ship-to-shore crane is an operational technology system. The same report describes modern STS cranes as having connectivity to a wireless controller, cellular modems able to reach OT components directly, and remote maintenance arrangements — the same classes of exposure as any other industrial plant on a terminal.
Cyber Protection Teams have discovered cellular modems installed on STS cranes manufactured in China. One was found on a crane spreader and was not identified on the electrical schematics for the equipment; the report records that this finding came from a CPT hunt mission. The report records that the modems served no purpose in normal crane operation and were removed.
The Coast Guard names software and indicators
Through 2025 the Coast Guard published Maritime Cyber Alerts 01-25, 02-25 and 04-25, and Maritime Cyber Bulletins 01-25 and 02-25. They are public documents on uscg.mil, and they name specific software and specific indicators of compromise.
Separately, CISA maintains the Known Exploited Vulnerabilities catalogue — a public list of vulnerabilities confirmed to have been exploited in the wild. It stood at 1,651 entries when we last took a copy on 21 July 2026, and it is one of the things a Cybersecurity Officer has to track against a facility’s own equipment §101.625(d)(15).
Subpart F is a response to this, not the origin of it
The rule makes more sense once you know what it is answering. §101.650(e)(1) asks for an assessment that analyses all networks and identifies the risk posed by each digital asset. §101.650(h) asks for segmentation between IT and OT, and for the connections between them to be logged and monitored. §101.635 asks for drills twice a year and a full exercise once.
Those are not filing requirements. They are what a team does before and after it finds something.
Nothing on this page is about you
This page describes an environment. It makes no claim about your facility and nothing here is a prediction.
Ten questions, about two minutes. It runs in your browser and your answers are not sent to us unless you choose to send them.