Maritime Cybersecurity Law Expiration Threatens US Port Infrastructure Vulnerability

As the Cybersecurity Information Sharing Act (CISA) is set to lapse on September 30 unless renewed by Congress, federal experts warn that US port infrastructure could become increasingly vulnerable to cyber threats. Private sector providers will be cut off from critical threat intelligence and liability protections, potentially leading to an 80-90% reduction in cyber information flows. This comes at a time when the US military relies on 17 commercial ports for critical logistics and supply chain operations, with previous congressional probes revealing Chinese-made cargo equipment that could enable espionage and sabotage.

Key Takeaways:

  • The Cybersecurity Information Sharing Act (CISA) is set to expire on September 30, potentially leaving US port infrastructure vulnerable to cyber threats.
  • Industry representatives are urging Congress to renew the law, citing the need for critical threat intelligence and liability protections.
  • Without CISA, private sector providers will be unable to share cyber threat information with government partners, potentially leading to an 80-90% reduction in cyber information flows.
  • The US military relies on 17 commercial ports for critical logistics and supply chain operations, making them a potential target for cyber attacks.
  • A congressional probe last year found that numerous seaports around the US contain technology originating from Chinese manufacturers that could enable espionage and sabotage.
  • The cybersecurity and intelligence community has assessed that the Chinese espionage unit, Volt Typhoon, is embedding into critical infrastructure systems, ready to disrupt or disable them in the event of a military conflict.
  • The Cybersecurity and Infrastructure Security Agency (CISA) supports a clean re-extension of CISA, citing the need to protect against widespread disruptions to port operations and cargo management systems.
  • A recent report from Booz Allen and the McCrary Institute recommends that maritime operators implement better zero trust controls and mature the security of operational technology systems that often get connected to the internet.
  • Policymakers are under pressure to incentivize port security improvements and promote the use of maturity benchmarks to help maritime managers determine the cybersecurity of their networks.

Statistics:

  • 80-90%: Potential reduction in cyber information flows if CISA expires (Park, cybersecurity staff member for Sen. Gary Peters, D-Mich.)
  • 17: Number of commercial ports used by the US military for critical logistics and supply chain operations
  • 2021: Year in which Volt Typhoon breached the Port of Houston
  • $16.3 billion: Estimated annual cargo worth handled by the Port of Houston alone

Sources:

  • NextGov: "Industry reps urge Congress to renew backbone of cyber information-sharing law"
  • McCrary Institute and Booz Allen Hamilton: Joint event on maritime cybersecurity
  • Kordinates: "United States Strategic Ports 2022"
  • NextGov: "Chinese-made cargo equipment enables cyber espionage risks at US ports, congressional probe finds"
  • Microsoft: "Volt Typhoon targets US critical infrastructure with Living Off The Land techniques"
  • The Wall Street Journal: "Typhoon: China hackers breach Port of Houston"
  • University of Maryland Baltimore County (UMBC): "What is Volt Typhoon? A cybersecurity expert explains the Chinese hackers targeting US critical infrastructure"