The CyberSurv Maritime CSA Methodology

From Cyber and AI Risk to the Cybersecurity Plan

August 13, 2026 | By Ron Frechette | Founder & Managing Director 

In our previous Maritime Cyber Insights article, Understanding Subpart F Cybersecurity Assessments, we explained why a Cybersecurity Assessment should begin with the maritime mission, not simply a list of computers and software.

Today, we are formally introducing the CyberSurv Maritime Cybersecurity Assessment Methodology, a structured seven-step process that puts that principle into practice.

From Requirements to a Practical Process

Under 33 CFR Part 101, Subpart F, regulated maritime organizations must complete a Cybersecurity Assessment by July 16, 2027, and annually thereafter.

The Coast Guard’s CG-5PC Policy Letter 01-26 provides additional guidance for determining the scope of that assessment. It emphasizes understanding operational functions, inventorying the broader digital environment, evaluating risk, and determining which assets should be designated as Critical IT or OT.

The CyberSurv methodology turns that guidance into a logical and repeatable process.

The Seven-Step CSA Methodology

  1. Frame and plan the assessment
  2. Identify business and operational functions
  3. Inventory supporting IT, OT, and AI-enabled systems
  4. Analyze cyber and AI-related threats and risk
  5. Identify Priority Assets and Critical IT/OT
  6. Evaluate cybersecurity and AI governance controls
  7. Deliver the CSA Report, AI Security Posture Summary, and CSP inputs

The process uses NIST SP 800-30 for risk assessment and NIST Cybersecurity Framework 2.0 for cybersecurity control evaluation. It also references Policy Letter 01-26 to support a defensible assessment scope and risk-filtering process.

 Policy Letter 01-26 Includes AI in CSA Scoping

The Coast Guard’s CG-5PC Policy Letter 01-26 expressly identifies integrated AI tools and models as examples of internally controlled systems. It also identifies externally provided AI tools, models, and multimodal interfaces as potential operational dependencies.

Subpart F does not create a separate AI compliance requirement. However, when an AI tool, model, or dependency could introduce cyber risk, disrupt operations, or contribute to a Transportation Security Incident, it should be inventoried and evaluated through the normal CSA risk-assessment process.

During the CSA, CyberSurv examines:

  • Where AI tools and AI-enabled systems are being used
  • What information those tools can access
  • Whether AI systems connect to operational or business functions
  • Whether employees are entering sensitive information into public AI tools
  • How AI vendors and external platforms are managed
  • Whether inaccurate output, excessive access, unsafe automation, or system manipulation could create operational risk

 AI-enabled systems are inventoried, evaluated for threats and vulnerabilities, and assessed for potential operational impact just like other digital assets.

CyberSurv uses the NIST AI Risk Management Framework as supplemental guidance when reviewing AI governance and security. The Coast Guard does not require this specific framework. We use it to provide additional structure and rigor to the AI Security Posture Review.

A Clear Handoff From Assessment to Plan

The assessment and Cybersecurity Plan development responsibilities are clearly separated.

CyberSurv conducts the CSA and delivers:

  • Executive Assessment Report
  • Asset Inventory Packages
  • Risk Register
  • AI Security Posture Summary
  • CSP Input Package
  • Remediation Roadmap
  • Executive Threat Outbrief

Seebald & Associates uses the CSA findings and CSP inputs to write the Cybersecurity Plan. Its team of retired Coast Guard officers brings decades of maritime operational, facility security, and regulatory experience to the plan-development process.

The owner or operator and designated Cybersecurity Officer then review, approve, and implement the plan.

The result is a straightforward path: Understand the operation. Identify what supports it. Assess the risk. Prioritize what matters. Provide the evidence needed to build the plan.

The Bottom Line

Policy Letter 01-26 makes it clear that a Cybersecurity Assessment must examine the broader digital environment, including relevant AI tools and models. The CyberSurv Maritime CSA Methodology provides a structured path from operational understanding to defensible findings, prioritized actions, and the inputs Seebald & Associates needs to develop the Cybersecurity Plan.

CyberSurv is also working with its sister company, Turbo AI Solutions, to develop the Turbo Assess Maritime Operations Module. The goal is to streamline evidence collection, assessment workflows, and reporting while keeping cybersecurity expertise and maritime operational judgment at the center of every assessment.

Are You Confident Your CSA Is Properly Scoped?

Every maritime facility is different. A complimentary Maritime CSA Readiness Consultation will help you understand what may fall within your assessment scope, where potential gaps may exist, and what practical steps you should take next.

There is no obligation. We will discuss your operations, current preparation, IT, OT, vendor dependencies, and AI-enabled systems, then help you determine a logical path toward a defensible Cybersecurity Assessment and actionable Cybersecurity Plan.

Schedule My Complimentary CSA Consultation

Leave a Reply

Scroll to Top

Discover more from CyberSurv.com

Subscribe now to keep reading and get access to the full archive.

Continue reading