Understanding Subpart F Cybersecurity Assessments
Protect the Mission, Not Just the Machines
July 28, 2026 | By Ron Frechette | Founder & Managing Director

In our previous Maritime Cyber Insights article, How NERC CIP Can Support Maritime Compliance, we explored how organizations with mature cybersecurity programs may already have many of the controls needed to support compliance with 33 CFR Part 101, Subpart F. The key takeaway was that cybersecurity compliance isn’t about starting over. It’s about understanding what you already have and where additional safeguards may be needed.
A Maritime Cybersecurity Assessment is one of the most important requirements under 33 CFR Part 101, Subpart F, yet many organizations still ask the same question:
“Where do we actually begin?”
It’s an important question, and one we’ve discussed extensively with maritime organizations across the country.
Working alongside our strategic maritime security partner, Seebald & Associates, we’ve found that the most effective Cybersecurity Assessments don’t begin with computers, firewalls, or network diagrams.
They begin with understanding the mission.
Seebald & Associates is comprised primarily of retired U.S. Coast Guard officers with decades of experience developing Facility Security Plans (FSPs), supporting Coast Guard inspections, and helping maritime organizations strengthen operational security. Combined with CyberSurv’s cybersecurity expertise, our partnership brings together operational experience and cyber risk management in a way that reflects how today’s maritime facilities actually operate.
That perspective has led us to one simple conclusion:
The best Cybersecurity Assessments protect the mission first, and the technology second.
Mission First. Technology Second.
Every maritime organization exists to perform a mission safely, securely, and efficiently.
Whether that mission involves cargo operations, fuel transfer, vessel movements, passenger transportation, offshore support, or port operations, technology exists to support those critical functions.
That is where every Cybersecurity Assessment should begin.
Rather than asking, “What systems do we have?”, organizations should first ask:
“What critical functions keep our operation running?”
Typical examples include:
- Cargo Operations
- Fuel Transfer
- Vessel Movements
- Facility Access Control
- Video Surveillance
- Communications
- Industrial Control Systems
- Environmental Monitoring
- Emergency Response
- Business Operations Supporting Maritime Activities
Once those functions are identified, the technologies that support them naturally come into focus.
These may include Information Technology (IT), Operational Technology (OT), industrial control systems, cloud services, physical security systems, remote connectivity, third-party vendors, and increasingly, Artificial Intelligence.
By starting with the mission instead of the technology, organizations gain a much clearer understanding of where cyber risk intersects with operational risk.
Four Questions Every Assessment Should Answer
Every effective Maritime Cybersecurity Assessment should answer four fundamental questions:
- What critical maritime functions support our operation?
- What technologies enable those functions?
- What would happen if those technologies were compromised, manipulated, or became unavailable?
- What safeguards should be implemented to reduce operational risk?
The answers become the foundation of your Cybersecurity Plan and provide leadership with a practical roadmap for reducing operational risk while improving cybersecurity over time.
Compliance Is Only the Beginning
One of the biggest misconceptions about Subpart F is that the Cybersecurity Assessment is the goal.
It isn’t.
The assessment is the foundation of an ongoing cybersecurity program.
The Coast Guard’s intent is to help maritime organizations establish a continuous process of identifying cyber risk, implementing safeguards, documenting cybersecurity activities, conducting annual reviews, and improving their cybersecurity posture as operations and technology evolve.
Viewed through that lens, Subpart F is more than a compliance requirement.
It is an operational resilience framework.
Figure 1. Maritime Cybersecurity Continuous Improvement Lifecycle

Understanding What the Regulation Really Requires
Subpart F requires organizations to:
- Designate a Cybersecurity Officer
- Develop and maintain a Cybersecurity Plan
- Conduct a Cybersecurity Assessment
- Maintain cybersecurity documentation
- Continuously improve their cybersecurity program
What it does not require is equally important.
Organizations are not required to:
- Hire a third-party cybersecurity firm
- Use a certified cybersecurity assessor
- Purchase specialized cybersecurity software
- Obtain a cybersecurity certification
Organizations with qualified personnel may perform their own assessments.
However, many organizations choose to engage an independent cybersecurity partner because an objective assessment often identifies operational dependencies, technology relationships, and cyber risks that internal teams may overlook. Independent assessments also provide structured documentation that supports Coast Guard inspections, executive decision making, insurance discussions, and long-term planning.
Regardless of who performs the assessment, responsibility for compliance always remains with the facility owner or operator.
Artificial Intelligence Is Changing Maritime Operations
Artificial Intelligence is rapidly becoming part of modern maritime operations.
From intelligent video analytics and predictive maintenance to document automation and operational decision support, AI is already influencing how facilities operate.
Although Subpart F does not establish AI-specific requirements, organizations should evaluate any AI capability that supports critical maritime functions or processes sensitive operational information.
The question should not be:
“Do we use AI?”
Instead, ask:
“Could this technology impact our mission if it failed, produced inaccurate information, or was compromised?”
If the answer is yes, it belongs within the scope of your Cybersecurity Assessment.
Looking Beyond Compliance
The organizations gaining the greatest value from Subpart F are not treating it as another regulatory checklist.
They are using the assessment process to better understand how technology supports their mission, identify operational dependencies before they become vulnerabilities, and make smarter cybersecurity investment decisions.
By bringing together Operations, Engineering, Physical Security, and IT, organizations develop a more complete understanding of how their facility operates and where cyber risk could interrupt the mission.
This collaborative approach is why CyberSurv and Seebald & Associates work so effectively together. Seebald’s maritime operational expertise complements CyberSurv’s cybersecurity expertise, providing organizations with practical, risk-based assessments grounded in both operational reality and cybersecurity best practices.
Compliance becomes the outcome of building a stronger, more resilient operation.
The Future of Maritime Cybersecurity Assessments
As maritime cybersecurity requirements continue to evolve, so should the tools used to perform assessments.
Traditional spreadsheets and manual documentation are often time consuming, difficult to maintain, and inconsistent from one assessment to the next.
To support this evolving methodology, CyberSurv and our sister company, Turbo AI Solutions, are developing the Turbo Assess – Maritime Operations Module.
Purpose-built for Maritime Cybersecurity Assessments, the platform guides assessors through a standardized, mission-based process while streamlining interviews, evidence collection, risk analysis, documentation, and report generation.
Our vision is simple: enable assessors to spend less time documenting information and more time helping maritime organizations strengthen their cybersecurity posture.
Final Thoughts
The true purpose of Subpart F is not to create another compliance checklist.
It is to help maritime organizations understand how technology supports their mission, identify cyber risks before they disrupt operations, and build a cybersecurity program that continuously improves over time.
A thoughtful Cybersecurity Assessment provides that roadmap.
Protect the mission, not just the machines.
That philosophy is at the heart of every engagement we perform.
Continue the Conversation
Every maritime facility is different, but the objective remains the same: protect the mission, understand the cyber risks that could disrupt it, and build a cybersecurity program that continuously improves.
At CyberSurv, we work alongside our strategic maritime security partner, Seebald & Associates, whose team is comprised primarily of retired U.S. Coast Guard officers with decades of experience in Facility Security Plans, MTSA compliance, Coast Guard inspections, and maritime security. Together, we combine operational expertise with modern cybersecurity practices to help maritime organizations strengthen operational resilience while supporting compliance with 33 CFR Part 101, Subpart F.
Whether you’re preparing for your first Cybersecurity Assessment, validating your current approach, or looking to mature your cybersecurity program, we’d welcome the opportunity to discuss your objectives and share what we’re seeing across the maritime industry.