AI-generated analysis · Transportation Systems · 3 min read

Coast Guard: the IT/OT connection is what raises maritime cyber risk

The Coast Guard says the link between business systems and operational systems is where maritime cyber risk grows.

The post

Background briefing. On 19 May 2025, U.S. Coast Guard Cyber Command released its report on 2024 cyber trends in the Marine Transportation System, based on its engagements with maritime partners during 2024. It identified the interconnection of IT and OT as increasing cyber risk in the system. [1]

Context

Ports and terminals run on two kinds of systems. Business systems handle bookings, logistics and billing. Operational systems move cranes, gates and cargo. The Coast Guard's point is that the risk sits in how they're connected, not in either one alone. [1] This thread uses the release describing 2024 observations. It is background, not the newest annual report.

The same pattern shows up in the international OT security principles. They call for separating OT from other networks and for paying close attention to supplier and remote-support security. [2] Remote support is often the least-documented link between the two sides of a terminal.

Exposed: port authorities, terminal operators, vessel operators, and the logistics and maintenance providers that connect to them. This thread covers maritime only. It should not be read as describing rail or aviation, which are also in the Transportation Systems sector. [1]

The practical change is mapping. For one cargo workflow, list the information flows between business and operational systems, who supports each one, and who can authorize recovery when the two have different owners.

No specific deadline is attached to this source. The work is a dependency review, so it can start any week with the people who already run the workflow.

Analyst thread

Bottom line

Maritime cyber risk concentrates where business systems and operational systems connect, especially through remote support.

Whether one cargo workflow has a documented dependency map, recovery owner and tested fallback.

The source reflects 2024 Coast Guard engagements, not a sector-wide statistic, a specific attack, or a compliance finding.

Sources

  1. [1] Coast Guard Cyber Command releases 2024 CTIME report, U.S. Coast Guard. 19 May 2025: 2024 engagement scope and IT/OT interconnection
  2. [2] Principles of operational technology cyber security — Quick reference guide, ASD ACSC and international partners; hosted by FBI IC3. Page 1: six principles, including OT separation and supplier security