Under the U.S. Coast Guard’s (USCG) Cybersecurity in the Marine Transportation System final rule (33 CFR Part 101, Subpart F), the Cybersecurity Officer is the accountable owner of a facility’s, vessel’s or Outer Continental Shelf (OCS) facility’s cyber posture: the Cybersecurity Assessment, the Cybersecurity Plan, incident response and reporting, and workforce training. By July 16, 2027, regulated owners and operators must designate a CySO, conduct a Cybersecurity Assessment and submit a Cybersecurity Plan to the USCG for approval.
This comprehensive, practitioner-focused course is designed for personnel responsible for overseeing, supporting or implementing cybersecurity measures within the Marine Transportation System (MTS). Delivered in person over two days, it combines instructor-led modules, hands-on labs and a team capstone exercise so participants leave with a working understanding of what the CySO role requires and how to execute it.
Duration:
- In-Person: 2 Days, 9:00 AM - 5:00 PM
Course Prerequisites: N/A
What You'll Learn
- Explain the CySO’s responsibilities, authorities and reporting relationships under the USCG cybersecurity rule
- Distinguish IT and OT environments and identify the critical systems that fall within scope
- Conduct or oversee a Cybersecurity Assessment and translate findings into a compliant Cybersecurity Plan (CSP)
- Lead response to a cyber incident and meet the rule's reporting obligations
- Build and sustain a personnel awareness and training program that satisfies the rule and reduces real-world risk
Who Should Attend
- Designated or prospective Cybersecurity Officers and Alternate CySOs
- Facility Security Officers, Vessel Security Officers, and Company Security Officers taking on cyber responsibilities
- IT and OT managers at MTSA-regulated facilities, vessels and OCS facilities
- Compliance, safety, and security leads supporting cybersecurity planning, preparedness and response
Core Course Modules
- CySO and MTS Overview - MTS Cybersecurity Foundations
- Critical System Security - Understanding IT and OT Environments
- Cybersecurity Plan (CSP) - Building and Maintaining the CSP
- Assessments, Audits and Inspections - Finding and Prioritizing Risk
- Incident Response and Reporting - Executing the Cyber Incident Response Plan (CIRP)
- Personnel Awareness and Training - Building a Security-Conscious Workforce
Hands-On Labs and Applied Learning
- Risk Matrix Assessment - score and prioritize real-world vulnerabilities across a sample facility or vessel
- Cybersecurity Plan Section Review - evaluate a draft CSP section against the rule’s requirements
- Incident Response Scenario - walk a cyber incident from detection through USCG reporting
- Training Program Development - design an awareness and training program for a mixed IT/OT workforce
Capstone: Virtual Cyber Escape Room
The course concludes with a team capstone built around a virtual cyber escape room. Teams apply the full CySO workflow: detect, assess, respond and report, under time pressure, using what they’ve learned across every module. It’s collaborative, competitive and designed to be the part of the course people talk about afterward.