From Compliance to Resilience: A Practitioner-Led Cyber Security Management Framework for LNG and Tanker Fleet Operations Aligned with USCG and IMO Regulatory Requirements
Main Article Content
Abstract
The rapid digitalization of LNG carrier and petroleum tanker operations has substantially expanded the cyber-attack surface of some of the world’s most consequential maritime assets, yet a persistent gap remains between the intent of international regulatory instruments and their operational implementation at fleet management level. Drawing on thirteen years of HSEQ/Tanker Operation management experience within LNG and tanker fleets, active participation in SIRE 2.0 development, and direct involvement in Cyber Security Management Plan (CSMP) drafting at Vice President level within a major LNG shipping group, this paper presents a practitioner-developed CSMP framework derived from a three-layer qualitative analysis: systematic regulatory mapping across IMO, USCG, and NIST instruments; operational framework construction; and a structured gap analysis comparing regulatory requirements against operational practice. The framework identifies five critical implementation gaps, including the OT/IT convergence challenge, entirely unaddressed in all current regulatory instruments, and proposes a five-component, scalable CSMP architecture embedded within the existing ISM Code Safety Management System. To the authors’ knowledge, this is the first practitioner-led, vessel-type-specific CSMP integrating IMO, USCG, and NIST requirements into a single executable operational architecture for LNG and tanker fleet environments. Given the centrality of US LNG export terminals, Cameron LNG, Sabine Pass, and Freeport LNG, to US energy security and foreign policy, the framework carries direct significance for USCG regulatory development, domestic LNG terminal operators, and national critical infrastructure protection.