On-Prem

Public Sector

Probe finds US Coast Guard has left maritime cybersecurity adrift

Numerous systemic vulnerabilities could scuttle $5.4T industry


Despite the escalating cyber threats targeting America's maritime transportation system, the US Coast Guard still lacks a comprehensive strategy to secure this critical infrastructure - nor does it have reliable access to data on cybersecurity vulnerabilities and past attacks, the Government Accountability Office (GAO) warns.

A newly released audit from the GAO, succinctly titled "Coast Guard: Additional Efforts Needed to Address Cybersecurity Risks to the Maritime Transportation System," highlights these shortcomings. The probe was conducted between December 2023 and December 2024.

Foreign governments, transnational criminals, and hacktivists alike are all looking to disrupt US ports and waterways, which support $5.4 trillion in annual economic activity and over 30 million jobs.

As thelead agency tasked with managing these risks, the US Coast Guard provides maritime transportation system (MTS) owners and operators technical assistance, threat intelligence, and other help to implement cybersecurity best practices.

The Coast Guard also provides facility and vessel inspections during which its officers document any security flaws they find.

"However, Coast Guard cannot readily access complete information on inspection results specific to cybersecurity from its system of record (Marine Information for Safety and Law Enforcement)," the GAO audit found.

The Coast Guard did develop a strategy to address MTS cybersecurity risks in 2021, but that document did not fully define the national security risks and vulnerabilities affecting critical operations or set measurable targets that can be used to gauge success.

This strategy also omitted an implementation budget, did not define the types of resources and investments needed, and skipped over who will implement it, according to the GAO.

Meanwhile, more nation-state intruders and criminal groups are attacking US transportation systems either for financial gain or to prepare for future disruptive or destructive cyberattacks.

In February 2024, the Feds warned that China's Volt Typhoon had compromised multiple critical infrastructure sectors including transportation.

And a year earlier, the Coast Guard warned [PDF] the BlackBasta ransomware group was conducting campaigns targeting maritime transportation operators. One of the group’s attacks focused on "an automation technology provider known in the MTS for its role supporting critical infrastructure sectors, including maintenance services offered for ship-to-shore cranes," the audit states.

Many of the IT and operational tech (OT) networks and systems supporting this sector are also increasingly "vulnerable to cyberattacks for a number of reasons, including their complexity and interconnections with other systems and the internet," the GAO report noted.

Additionally, Coast Guard officials and others interviewed for the audit admitted that a successful cyberattack on OT systems could have devastating effects:

Coast Guard officials and one nonfederal organization we met with told us that a cyberattack on OT used by a large vessel could cause that vessel to crash into a large bridge. This could result in an impact similar to the March 2024 non-cyber incident in which a major bridge in Baltimore, Maryland collapsed…Researchers from Rutgers University also raised the possibility of a cyberattack causing an explosion on a vessel carrying hazardous materials while docked in a facility… One nonfederal organization we met with told us that vessels could be lucrative targets for threat actors.

The Coast Guard also hasn't filled "vacancy gaps for key cyber personnel" that the GAO found in 2022, despite the Department of Homeland Security's urging. Specifically: of the 55 authorized MTSS-C cybersecurity specialists, eight positions remain vacant, as do 23 of the 156 authorized Coast Guard Cyber Protection Teams.

Until the service fills these posts, it won't be "optimally positioned" to recruit more difficult-to-fill jobs and retain skilled infosec personnel, the audit says.

To address these shortcomings, the GAO recommends that the Coast Guard undertake several actions including:

The Department of Homeland Security agreed with all of these recommendations. "The safe operation of the MTS is critical to our national and economic security," according to the GAO. ®

Send us news
13 Comments

Healthcare outfit that served military personnel settles allegations it faked infosec compliance for $11M

If this makes you feel sick, knowing this happened before ransomware actors started targeting medical info may help

How nice that state-of-the-art LLMs reveal their reasoning ... for miscreants to exploit

Blueprints shared for jail-breaking models that expose their chain-of-thought process

US Cyber Command reportedly pauses cyberattacks on Russia

PLUS: Phishing suspects used fishing gear as alibi; Apple's 'Find My' can track PCs and Androids; and more

Trump’s DoD CISO pick previously faced security clearance suspension

Hey, at least Katie Arrington brings a solid resume

Microsoft expands Copilot bug bounty targets, adds payouts for even moderate messes

Said bugs 'can have significant implications' – glad to hear that from Redmond

Qualcomm pledges 8 years of security updates for Android kit using its chips (YMMV)

Starting with Snapdragon 8 Elite and 'droid 15

Check out this free automated tool that hunts for exposed AWS secrets in public repos

You can find out if your GitHub codebase is leaking keys ... but so can miscreants

Drug-screening biz DISA took a year to disclose security breach affecting millions

If there's something nasty on your employment record, extortion scum could come calling

Ivanti endpoint manager can become endpoint ravager, thanks to quartet of critical flaws

PoC exploit code shows why this is a patch priority

C++ creator calls for help to defend programming language from 'serious attacks'

Bjarne Stroustrup wants standards body to respond to memory-safety push as Rust monsters lurk at the door

Incoming deputy boss of Homeland Security says America's top cyber-agency needs to be reined in

Plus: New figurehead of DOGE emerges and they aren't called Elon

Malware variants that target operational tech systems are very rare – but 2 were found last year

Fuxnet and FrostyGoop were both used in the Russia-Ukraine war