What Is Maritime Security?
The framework and practices that protect vessels, ports, cargo, and crew — from the ISPS Code and MTSA to today's piracy, cyber, and geopolitical threats.
Protecting the vessel, the port, and the cargo between.
By CPE Faculty · Reviewed by Capt. Jeff Monroe, Program Director · Published August 12, 2026
Maritime security is the framework of laws, standards, and operational practices that protect vessels, ports, cargo, and crew from unlawful acts and threats — piracy, terrorism, cyberattacks, cargo theft, and the broader geopolitical risk that can shut down a trade route overnight. It spans four overlapping dimensions: physical security at the ship and the berth, cyber security across navigation and terminal systems, cargo security through the custody chain, and the geopolitical risk that shows up when a chokepoint turns contested. For a port executive, it isn’t a side function — it’s one of the core disciplines the job is built around.
The term is often used loosely alongside “maritime safety,” but the two aren’t the same. Safety covers accidents — collisions, groundings, fires, equipment failure. Security covers deliberate, unlawful acts against a vessel, a facility, or the cargo moving through it. The distinction matters because it drives different regulation, different officers, and different plans: a Safety Management System addresses one set of risks, a Ship or Facility Security Plan addresses the other, and a port executive has to be fluent in both.
It also sits alongside, but distinct from, the commercial and operational side of the industry. A vessel engaged in marine transportation has to satisfy security regulation before it satisfies a charter party — the two frameworks run in parallel, and a port that gets one right while neglecting the other still fails an ISPS Code audit or a Coast Guard inspection.
SOLAS, the ISPS Code, and MTSA.
Modern maritime security law traces to a single event. After September 11, 2001, the IMO added Chapter XI-2 to the SOLAS Convention in 2002, making the International Ship and Port Facility Security (ISPS) Code mandatory for every contracting government. The Code applies to passenger ships, cargo ships of 500 gross tons or more on international voyages, and the port facilities that serve them — Part A sets binding requirements, Part B offers non-mandatory guidance on how to meet them.
The United States implemented the same mandate domestically through the Maritime Transportation Security Act of 2002, enforced by the Coast Guard under 33 CFR Parts 101–106. MARAD supports the commercial and strategic side of the same system. In practice, a U.S. port executive has to satisfy both regimes at once — ISPS Code obligations that apply because the port serves international vessels, and MTSA obligations that apply because the facility sits on U.S. soil.
SOLAS Chapter XI-2
Added to the Safety of Life at Sea Convention in 2002; makes the ISPS Code mandatory for SOLAS contracting governments
ISPS Code
The IMO's detailed security code — mandatory Part A, recommendatory Part B — covering ships, companies, and port facilities
MTSA (2002)
The U.S. domestic implementing statute, enforced by the Coast Guard under 33 CFR Parts 101–106; requires vessel and facility security plans
Company, ship, and facility — one chain of command.
The ISPS Code builds security responsibility into three linked roles rather than one. Ashore, a Company Security Officer oversees the fleet-wide security assessment and plan. Aboard each vessel, a mariner serving as Ship Security Officer — typically the master or a senior officer already holding officer-level credentials through the MMC process — implements that plan day to day. At the terminal, a Facility Security Officer holds the equivalent role ashore, under a name that shifts with jurisdiction:
Company Security Officer (CSO)
Shore-based, appointed by the vessel operator; owns the fleet-wide Ship Security Assessment and Ship Security Plan
Ship Security Officer (SSO)
Aboard the vessel, typically the master or a senior officer; implements and maintains the Ship Security Plan day to day
Facility / Port Facility Security Officer (FSO / PFSO)
Ashore at the terminal; implements the Facility Security Plan — PFSO is the ISPS Code term, FSO the MTSA term for the same role
Five threats, one watch.
The ISPS Code was written around one threat — terrorism — but the security function it created now has to watch a wider field. Piracy and armed robbery remain concentrated in specific chokepoints and coastal waters, closely enough tracked that the ICC runs a dedicated reporting centre for it. Cargo theft and insider threats are quieter but constant, and increasingly treated as a materials-custody problem as much as a security one — the same discipline covered in our materials management guide. Cyber risk is the newest addition, spanning both a vessel’s navigation systems and a terminal’s operating systems:
Piracy & armed robbery
Concentrated in specific chokepoints and coastal waters; tracked globally by the ICC's IMB Piracy Reporting Centre
Terrorism & sabotage
The original driver behind SOLAS XI-2 and the ISPS Code after September 11
Cyberattacks
Vessel navigation systems and port terminal operating systems alike — from ransomware to nation-state intrusion attempts
Cargo theft
Theft, diversion, or tampering in transit or in the yard — a custody problem that overlaps with materials management
Insider threats
Credentialed crew, port, or terminal personnel exploiting legitimate access — one reason background screening is built into ISPS/MTSA credentialing
What’s testing the system right now.
Two developments dominate current maritime security coverage. The first is geopolitical: since late 2023, Houthi attacks on commercial shipping transiting the Red Sea and the Bab-el-Mandeb Strait have repeatedly forced major carriers to suspend the route and reroute around the Cape of Good Hope — adding one to two weeks of transit time to Asia–Europe trade and demonstrating how a single chokepoint can reshape global shipping patterns. Trade press like gCaptain has tracked the rerouting, the insurance premiums, and the naval escort operations that followed closely enough to make the Red Sea the reference case for geopolitical trade-route risk.
The second is cyber. The 2017 NotPetya malware outbreak, which crippled Maersk’s global IT systems and cost the carrier hundreds of millions of dollars, remains the industry’s reference incident, and it hasn’t stayed isolated — U.S. officials have since disclosed attempted nation-state intrusions at American port facilities, and ransomware continues to hit terminal operators worldwide. Industry bodies have responded accordingly: BIMCO’s cyber security guidance is now a standard reference for shipowners and operators building out the cyber leg of an ISPS-compliant security program, alongside the physical and procedural requirements the Code has always covered.
From the credential to the front office.
Most people enter maritime security through one of two doors. Afloat, it’s an extension of a licensed mariner’s career — the Ship Security Officer role is an additional duty layered onto an officer who already holds a Merchant Mariner Credential, not a separate entry-level track. Ashore, it runs through port and terminal operations, compliance, or law enforcement into a Facility Security Officer or port-authority security-management role, often alongside the wider operational grounding covered in our marine transportation guide.
Both paths lead toward the same executive ceiling. A port CEO or terminal general manager doesn’t need to personally write a Facility Security Plan, but does need to govern one — understand where ISPS and MTSA obligations bind, where security budget competes against throughput, and how a Red Sea-style disruption or a ransomware incident gets escalated and managed. That governance layer, not the technical security work itself, is what CPE’s executive curriculum addresses: security governance, risk management, and ISPS/MTSA compliance make up one module of 18, sitting alongside operations, commerce, regulation, and leadership — a deliberately honest scope, since no five-day program replaces a certified security officer, but every port executive still has to be conversant in what that officer does.
Frequently asked questions.
What is maritime security?
Maritime security is the framework of laws, institutions, and operational practices that protect vessels, ports, cargo, and crew from unlawful acts and threats — spanning physical security, cyber security, cargo security, and geopolitical trade-route risk. At sea and at the berth, it is governed primarily by the IMO’s ISPS Code and, in the United States, the Maritime Transportation Security Act (MTSA).
What is the ISPS Code?
The International Ship and Port Facility Security Code is the security framework the IMO added to SOLAS Chapter XI-2 after the September 11 attacks, taking effect July 1, 2004. Part A sets mandatory requirements — security plans, security officers, security levels — for passenger ships, cargo ships of 500 gross tons or more on international voyages, and the port facilities that serve them; Part B provides non-mandatory implementation guidance.
Who is responsible for port security?
Responsibility is layered. Internationally, the IMO sets the ISPS Code baseline; in the United States, the Coast Guard enforces it domestically alongside MTSA, and MARAD supports the commercial and strategic side. At the facility level, a Facility Security Officer (PFSO internationally, FSO under MTSA) implements the security plan, while a vessel’s Company Security Officer (CSO) and Ship Security Officer (SSO) handle the same chain of command afloat.
What are current maritime security threats?
The threat picture spans piracy and armed robbery; terrorism and sabotage; cyberattacks on vessel and port systems; cargo theft; and insider threats from credentialed personnel. Geopolitical flashpoints add another layer — Houthi attacks on Red Sea shipping since late 2023 have repeatedly forced major carriers to reroute around the Cape of Good Hope, and trade bodies including BIMCO have flagged rising cyber risk to port and terminal operating systems.
How do you get into maritime security?
Most people enter through one of two doors: a maritime credential — see our MMC application guide — that leads to a CSO or SSO role afloat, or a shoreside security and compliance path into a PFSO/FSO or port-authority security-management role ashore. Both paths eventually intersect with port executive leadership, where CPE’s own curriculum covers security governance and ISPS/MTSA compliance as one of 18 modules.
Ready to lead on maritime security?
The Certified Port Executive™ Program is built for maritime and port professionals ready to move from operations into executive leadership — five days, 18 modules, and a credential recognized across the Americas and the Caribbean.