Essex Junction, VT802-335-2662dkoran@davidkoran.com
DK
David Koran& Associates
White Paper · Maritime Cybersecurity

The Cybersecurity Officer Problem

Subpart F’s Hardest Requirement for Small Maritime Operators

David W. Koran · CyberAB Registered Practitioner Advanced · ISO/IEC 27001 Auditor and Implementer · July 2026 · 8 Pages

The requirement that cannot be bought

The compliance conversation around 33 CFR Part 101, Subpart F is organized around documents. The Cybersecurity Plan is due to the Coast Guard by July 16, 2027. The Cybersecurity Assessment must precede it. Training came due in January 2026 and recurs annually. Each of these obligations has a deadline, a deliverable, and a market of providers ready to help produce it.

One requirement does not fit the pattern. Each covered owner or operator must designate a Cybersecurity Officer, in writing, by name and title, accessible to the Coast Guard 24 hours a day, 7 days a week. The duties assigned to that person under § 101.625 amount to the standing management of the entire cybersecurity program: the annual assessment, the annual audit, the training cycle, drills twice each year, the annual exercise, incident recording and reporting, and the prompt correction of everything the exercises, audits, and inspections find. The CySO also makes the single most consequential judgment in the rule, the determination of which systems are Critical IT and OT, and must be able to defend it on review.

The Coast Guard estimated the covered population at 3,447 owners and operators, and determined that roughly 91 percent of them are small entities. For that majority, every requirement in the rule can be purchased except this one. The CySO is a person, not a deliverable, and in most covered organizations that person does not currently exist.

What the paper covers

The paper reviews the requirement as written and converts the duties into calendar terms, showing why the role is smaller than a full-time position in most small operations and much larger than a collateral duty performed in spare hours. It then examines why the burden falls disproportionately on the small majority of the covered population, where no employee spans cybersecurity, maritime operations, and regulatory administration, and where the available internal candidates each involve a compromise the Coast Guard’s review is structured to find.

The heart of the paper is an even-handed evaluation of the three staffing structures available to an owner or operator: internal designation with external support, one CySO shared across multiple vessels or facilities as the rule expressly permits, and an outside designee under contract. Each structure is examined with its price stated plainly, including the real drawbacks of outsourcing the role, and the paper closes with the questions a management team should be able to answer before putting anyone’s name in the plan.

Download

The Cybersecurity Officer Problem, 8 pages, with references to the controlling regulatory text.

Download the PDF →

The designation decision has a longer horizon than the submission deadline. The plan will be reviewed once. The name in it will answer for the program every year afterward, through every audit, drill, inspection, and renewal the rule schedules. Operators who treat the designation as a staffing decision made deliberately among the three available structures will carry the program. Operators who treat it as a blank on a form will discover the difference at their first inspection.

About the Author

David W. Koran advises covered vessel and facility operators on cybersecurity readiness under 33 CFR Part 101, Subpart F, work he conducts onsite in the operating environment. He holds the CyberAB Registered Practitioner Advanced (RPA) credential and ISO/IEC 27001 certifications as an auditor and implementer, and is the founder of a consulting practice serving Defense Industrial Base contractors and their legal counsel, including maritime operators in shipbuilding, repair, and logistics, with a focus on readiness, enablement, and implementation. He is the author of Cybersecurity in the Marine Transportation System. He can be reached at dkoran@davidkoran.com or 802-335-2662.