Essex Junction, VT802-335-2662dkoran@davidkoran.com
DK
David Koran& Associates
Maritime Cybersecurity · White Papers

Maritime Cybersecurity White Papers

Practitioner research on the Coast Guard's Cybersecurity in the Marine Transportation System rule, 33 CFR Part 101, Subpart F, written for the owners, operators, security officers, and counsel of covered vessels and facilities. Every paper works from the regulatory text and the Coast Guard's implementation guidance, cites its sources, and is available as a free PDF.

The CySO Requirement & Staffing Structures

The Cybersecurity Officer Problem: Subpart F’s Hardest Requirement for Small Maritime Operators

July 2026 · 8 Pages

The compliance conversation around Subpart F is organized around documents, and documents can be bought. One requirement does not fit the pattern: each covered owner or operator must designate a Cybersecurity Officer, in writing, by name and title, accessible to the Coast Guard 24 hours a day, 7 days a week, carrying duties that amount to the standing management of the entire cybersecurity program, including the single most consequential judgment in the rule, the Critical IT and OT determination. The Coast Guard estimated the covered population at 3,447 owners and operators, roughly 91 percent of them small entities, and for that majority the person the requirement describes does not currently exist inside the organization. This paper reviews the requirement as written, converts the duties into calendar terms to show why the role is smaller than a full-time position and much larger than a collateral duty, examines why the burden falls on the smallest operators, and evaluates the three available staffing structures, internal designation with external support, one CySO shared across multiple vessels or facilities, and an outside designee under contract, with the price of each stated plainly. It closes with the questions a management team should answer before putting anyone’s name in the plan.

A Growing Library

This maritime library is new and will grow as the practice develops, alongside the practitioner reference pages on assessment scoping, Critical IT and OT designation, the program lifecycle, and waivers and equivalencies. The established CMMC white paper library covers Defense Industrial Base cybersecurity, which runs in parallel with the Coast Guard requirements for maritime operators who also serve as defense contractors or suppliers.

About the Author

David W. Koran advises covered vessel and facility operators on cybersecurity readiness under 33 CFR Part 101, Subpart F, work he conducts onsite in the operating environment. He holds the CyberAB Registered Practitioner Advanced (RPA) credential and ISO/IEC 27001 certifications as an auditor and implementer, and is the founder of a consulting practice serving Defense Industrial Base contractors and their legal counsel, including maritime operators in shipbuilding, repair, and logistics, with a focus on readiness, enablement, and implementation. He is the author of Cybersecurity in the Marine Transportation System. He can be reached at dkoran@davidkoran.com or 802-335-2662.