When the Maritime Transportation Security Act cyber rule took effect on July 16, 2025, it added more than a training requirement to the books. It created a position that every regulated facility has to fill by July 16, 2027.
That position is the Cybersecurity Officer, and the rule builds it much the way it built the Facility Security Officer years ago. Where an FSO owns the physical security side of a facility's security plan, the CySO owns the cybersecurity side, designated in writing by name and by title. The same July 2027 date carries two more obligations the CySO inherits: a completed Cybersecurity Assessment, and a Cybersecurity Plan submitted to the Coast Guard for approval. In practice the role can be a small team, a primary CySO backed by alternates who share the load, but the rule still holds one designated person accountable for maintaining the Cybersecurity Plan, running incident response, and answering to a Coast Guard inspector for all of it. Naming the role was the straightforward part. Whoever holds the title still has to know how to do the work, and that is what this course is built to teach.
What we built with ABS Group
The Cybersecurity Officer course is the next offering in ABS Group's MTSA Cybersecurity Training Series. To help operators meet the training mandate, we partnered with ABS Group's Cyber Center of Excellence to build mtsatraining.com, the platform that delivers MTSA cybersecurity training to maritime operators. This course moves past baseline awareness into the harder question a facility actually faces: what does the person accountable for the plan need to be able to do?
The course runs two days, instructor-led. ABS Group grounds the series in decades of maritime risk and regulatory work and brings it to the industry, and we bring years of instruction to the partnership along with hands-on assessment of complex IT and OT systems, much of it in the maritime domain. Students learn the role from people who have done the work.
The two days
Six modules take a new CySO from the mandate through the mechanics of running a program:
- CySO and MTS Overview. It starts with the basics of how cybersecurity fits into the Marine Transportation System, and what the person in the role is on the hook for.
- Critical System Security. From there the course gets into IT and OT environments, and why the operational side is where most maritime risk actually lives.
- The Cybersecurity Plan. Students learn to write and maintain the CSP the rule requires, and to keep it as something the facility uses day to day instead of a binder that gathers dust.
- Assessments, Audits, and Inspections. This one is about finding risk and deciding what to fix first, then holding up when an auditor or an inspector comes calling.
- Incident Response and Reporting. When something goes wrong, the CySO runs the Cyber Incident Response Plan, and knows exactly who to notify and how quickly it has to happen.
- Personnel Awareness and Training. The last module is building a security-minded workforce, which is the one part of the job that is never really finished.
The sequence follows the real life of the role, from understanding the mandate to standing up the plan, holding up under audit, responding when it is tested, and keeping the workforce sharp along the way. Each module maps to a duty the rule assigns the CySO, so the two days cover what the regulation actually holds the officer accountable for rather than a topic list we invented.
The labs, and a capstone escape room
The work is hands-on, so the course is built the same way, with four labs making up most of the two days. Students start by building a risk matrix and reasoning out how to rank what it surfaces, then move section by section through a Cybersecurity Plan, checking it against what the rule actually demands. From there the pressure picks up, with an incident response scenario that drops them into a live event and has them work the Cyber Incident Response Plan against the clock. The last lab steps back from any single crisis and asks them to design the kind of ongoing workforce training program a CySO ends up maintaining for years.
The two days close with a capstone: a virtual cyber escape room run as a team exercise, where a group of new CySOs work a single scenario together using everything they just learned. Turning serious security work into something people actually want to play is something we are good at, and our Westport Incident escape room came out of the same instinct. It sticks because it is genuinely fun, and because students leave having practiced the job instead of only hearing it described.
Assess, build, and now train
We have spent years on the maritime side of this work. We run penetration tests against ship networks, across both IT and OT, and tabletop exercises for offshore platforms. We build the platforms the industry trains on, including the learning system behind this series. Training the CySO is the newest piece, and it matters because that officer keeps the program running long after the assessors and platform builders have packed up and gone home.
Most firms only do one of these. The role the rule created leans on all three, and a facility racing to fill the seat wants someone who can do the job from day one. A certificate on its own does not get you there.
If your organization needs to stand up a Cybersecurity Officer, or you are the person stepping into the seat and want to walk in already knowing the job, let's talk. July 16, 2027 is closer than it looks, and the role matters too much to learn on the fly.


