The US Coast Guard's mandatory cybersecurity framework under the Maritime Transportation Security Act (MTSA) has taken effect, ending two decades of voluntary compliance. Key requirements include designating a Cybersecurity Officer (CySO) responsible for both IT and OT infrastructure, annual assessments, mandatory incident reporting, and IT/OT network segmentation by July 2027. The CySO role differs from a traditional CISO in that it is more regulatory in nature. Network segmentation is identified as the most challenging requirement, with 94% of organizations encountering difficulties. Experts suggest the MTSA framework offers broader lessons for all regulated industries, particularly around assuming breach and building accountability into program design before regulatory deadlines force it.

6m read timeFrom darkreading.com
Post cover image
Table of contents
A New Role: CySOBiggest Challenge Dead Ahead

Sort: