Introduction
A shipping container can cross multiple countries, companies, ports, terminals, warehouses, and transportation networks before reaching its final destination in the United States. At each stage, security depends on some combination of inspection, documentation, intelligence, technology, physical controls, and the people responsible for using them.
That does not mean America's ports are broadly unsecured. The United States operates a substantial maritime-security system. The Coast Guard oversees security requirements for covered facilities and vessels, while U.S. Customs and Border Protection (CBP) screens and targets cargo and vessels using a layered approach.
The more consequential question is different: How much assurance can a risk-based system provide across a supply chain that is global, distributed, privately operated, and increasingly dependent on networked technology?
That question matters because the maritime transportation system is economically significant. The Bureau of Transportation Statistics reported that U.S. ports accounted for 41 percent of all U.S. imports and exports in 2024, representing more than $2.1 trillion in trade. That is a different measure from the commonly cited statistic that more than 90 percent of global trade by tonnage moves by sea. The distinction is important because the security case does not require an exaggerated statistic.
The potential exposure comes instead from the architecture itself. Security is layered, selective, and distributed across organizations and jurisdictions. A weakness does not have to exist everywhere to matter. A gap at an origin port, a failure in cargo information, an improperly controlled access point, a compromised insider, or a cyber incident affecting terminal operations can create consequences beyond the location where the weakness occurred.
Background: Security After September 11
The modern U.S. port-security framework was built substantially in response to the September 11, 2001 terrorist attacks.
Congress enacted the Maritime Transportation Security Act (MTSA) in 2002, establishing a federal framework for assessing maritime-security risks and requiring covered facilities and vessels to implement security measures. The international International Ship and Port Facility Security (ISPS) Code established a parallel global framework.
The system that emerged was never designed around physically opening every container or continuously examining every activity at every port. That would be incompatible with the scale and speed of modern commerce.
Instead, the United States developed a layered, risk-based model.
The Coast Guard conducts facility and vessel security oversight. CBP uses advance information, intelligence, targeting, and examination programs to identify higher-risk cargo and shipments. Foreign-port assessments provide an additional layer before cargo reaches the United States. Private terminal operators and other maritime companies implement many of the physical and operational controls on which the system ultimately depends.
The resulting architecture is less like a single security checkpoint and more like a series of filters.
That provides efficiency. It also creates dependencies.
A risk-based system is only as effective as its ability to identify risk accurately, obtain reliable information, maintain functioning controls, and respond when weaknesses are discovered.
Compliance Is Not the Same as Continuous Assurance
One of the most revealing examinations of the Coast Guard's facility-inspection program came from the Government Accountability Office.
In GAO-08-12, published in 2008, GAO found that the Coast Guard identified deficiencies in roughly one-third of the facilities it inspected during the 2004–2006 period examined. The deficiencies included problems involving access controls and documentation. GAO also identified limitations in the Coast Guard's inspection data and examined questions involving staffing and differences in inspection practices.
That finding needs to be placed in its historical context. It does not establish that roughly one-third of facilities have deficiencies today. GAO's recommendations concerning staffing, inspection practices, and data were subsequently reported as implemented.
Its broader lesson remains relevant, however: inspection produces information about conditions observed during an inspection; it does not establish continuous assurance between inspections.
A gate can be secured when an inspector arrives and improperly controlled later. A credential can be valid while being misused. A security procedure can exist on paper without being followed consistently. Documentation can demonstrate that a process is required without proving that the process is effective in every operational circumstance.
This distinction becomes particularly important when evaluating a system whose security responsibilities are distributed among federal agencies, state and local authorities, terminal operators, contractors, vessel operators, and other private-sector participants.
The question is therefore not simply how many inspections occur.
It is whether inspections reveal meaningful weaknesses, whether those weaknesses are corrected, whether corrections remain effective, and whether the system can measure its own performance.
A more recent GAO examination points directly at that final problem.
In 2025, GAO reported that DHS had not fully assessed the effectiveness of its layered approach for securing U.S.-bound vessels and maritime cargo. GAO found that the Coast Guard and transportation-sector partners had identified a strategic goal but had not developed objective, measurable, and quantifiable performance goals and measures sufficient to fully assess progress and effectiveness on an ongoing basis.
As of the latest GAO tracking, that recommendation remained open. The Coast Guard reported that it was developing performance goals for incorporation into the next iteration of the Transportation Systems Sector Risk Management Plan, with completion anticipated by the end of 2026.
That is a different problem from a missing security plan.
It is a problem of measuring whether the security architecture actually produces the intended level of protection.
The Selective-Screening Problem
The scale of global commerce makes universal physical inspection impractical.
The United States therefore relies on targeting.
GAO's 2025 review describes DHS's maritime-security approach as layered, with the Coast Guard and CBP screening, targeting, and examining vessels and cargo before departure from foreign ports, while in transit, and after arrival at U.S. ports.
This approach is operationally necessary. But it creates a fundamental dependency: the system must identify the right risks with incomplete information.
Cargo moves through manufacturers, exporters, consolidators, freight forwarders, trucking companies, foreign terminals, shipping lines, transshipment points, U.S. terminals, rail networks, warehouses, and final destinations.
Each participant can provide useful information.
Each can also become a point where information is incomplete, manipulated, delayed, misunderstood, or simply unavailable.
That does not mean sophisticated adversaries can automatically defeat screening. It means that the security architecture must account for the possibility that a threat may be concealed within an otherwise legitimate commercial transaction.
The potential mechanisms are familiar across supply-chain security: fraudulent documentation, misrepresentation of cargo, exploitation of transshipment routes, concealment, compromised personnel, or manipulation of information used for targeting.
The strategic problem is therefore not that every container is a potential weapon.
It is that the security system must decide which shipments deserve greater scrutiny without having perfect visibility into the entire chain that produced them.
The Security Perimeter Begins Overseas
A container does not become a security concern only when a ship reaches an American harbor.
The Coast Guard's International Port Security Program exists because security conditions at foreign ports can affect the risk associated with vessels and cargo traveling to the United States.
That creates a forward layer of assurance—but one with geographic and institutional limits.
GAO's 2023 examination found that the Coast Guard's foreign-port assessment program had generally met its triennial assessment requirement before COVID-19 interrupted country assessment visits during fiscal years 2020 and 2021. The program resumed visits in May 2021. GAO also identified challenges involving access to some foreign ports and information sharing.
Those findings should not be presented as though nothing changed afterward.
GAO's current tracking shows that the Coast Guard subsequently documented procedures for alternative assessments, established procedures for distributing annual assessment reports to CBP and other agencies, and created processes for coordinating foreign-port security capacity-building efforts with the State Department. Several of the original GAO recommendations are now classified as implemented.
One recommendation remains open and partially addressed: the Coast Guard's development of performance measures that fully assess both its triennial assessment mandate and the program's effect on maritime-security risk.
The forward-security challenge is therefore better understood as a continuing assurance and measurement problem rather than a static failure.
The scale illustrates the difficulty. GAO reported that Coast Guard personnel visited 74 of 123 maritime trading partners during fiscal years 2023 and 2024, with 78 country visits conducted in total.
Physical presence abroad is valuable, but it cannot eliminate uncertainty across a global maritime system.
The United States must combine visits, intelligence, information sharing, foreign-government cooperation, alternative assessment methods, and downstream screening.
In other words, domestic port security begins before the container reaches U.S. jurisdiction.
When Cybersecurity Becomes Physical Security
The newest layer of the problem is digital.
Modern ports depend on information technology and operational technology for functions that directly affect physical operations. Cargo-management systems, terminal operating systems, gates, cameras, scheduling platforms, communications, cranes, and other systems are increasingly interconnected.
A cyber incident can therefore have physical consequences without a conventional physical intrusion.
The Department of Homeland Security Office of Inspector General reported in July 2024 that Coast Guard facility and vessel inspections did not always address the full scope of potential cybersecurity threats. The OIG also identified limitations involving cybersecurity expertise and private-sector adoption of Coast Guard cyber services.
The finding came before the Coast Guard's new minimum cybersecurity requirements took effect.
On July 16, 2025, the Coast Guard's final rule establishing minimum cybersecurity requirements for covered U.S.-flagged vessels, Outer Continental Shelf facilities, and MTSA-regulated facilities became effective. The rule requires measures including cybersecurity plans, designated cybersecurity officers, incident reporting, and other controls intended to detect, respond to, and recover from cyber incidents.
Implementation has been phased. The Coast Guard states that covered entities must meet specified training requirements, while owners and operators have until July 16, 2027, to designate cybersecurity officers, conduct cybersecurity assessments, and submit cybersecurity plans for approval.
The regulatory framework continued to develop during 2026. The Coast Guard issued additional policy and guidance supporting the cybersecurity regulations in June 2026 and, in August 2026, established the Office of Maritime Cybersecurity Policy under the Director of Inspections and Compliance.
That development is significant because it demonstrates that maritime cybersecurity is moving from an emerging concern toward a more formalized component of maritime-security governance.
But regulation does not automatically equal resilience.
The effectiveness of the new requirements will depend on implementation, inspection capacity, technical expertise, information sharing, compliance, and the ability to identify vulnerabilities across interconnected systems.
The distinction is the same one that applies to physical security: having a requirement is not the same as continuously proving that the requirement works.
The Insider Problem
Technology and inspection cannot eliminate the human element.
Ports depend on employees, contractors, truck drivers, vessel crews, security personnel, maintenance workers, and other people who require legitimate access to restricted environments and systems.
Credentialing can establish whether a person is authorized to enter an area. It does not establish that every authorized person will always use that access appropriately.
That creates a persistent insider-risk problem involving possibilities such as coercion, corruption, collusion, theft, unauthorized disclosure, or misuse of legitimate access.
The answer cannot simply be to treat every worker as a threat. Commercial ports require trusted personnel to function.
The more useful security question is whether access is appropriately limited, monitored, auditable, and responsive to changing risk.
This is another reason inspections, intelligence, cybersecurity, physical controls, and operational management cannot be treated as separate disciplines.
From Port Security to National Resilience
The most important strategic lesson is that maritime security is also a resilience problem.
A successful attack would not necessarily resemble a dramatic assault on a port.
A disruption could involve cargo information, a terminal operating system, a gate-control system, a compromised shipment, an insider, a security incident, or a combination of smaller failures.
The consequence could remain local.
Or it could propagate through interconnected transportation networks.
A major terminal disruption can create congestion elsewhere. Cargo can be diverted. Rail and trucking capacity can become constrained. Manufacturing inputs can be delayed. Emergency logistics can become more difficult. Defense-related supply chains can face additional pressure.
These are potential consequences, not predictions that any particular incident will produce them.
The objective of maritime security is therefore not simply to prevent every incident.
It is also to ensure that when incidents occur, they can be detected, contained, investigated, and recovered from without producing disproportionate national effects.
That changes what should be measured.
Inspection counts matter, but they are not enough.
More useful measures include whether high-risk deficiencies are repeatedly identified, whether corrective actions are verified, whether unannounced checks reveal problems that routine examinations miss, whether foreign-port information reaches the agencies that need it, whether cyber vulnerabilities are incorporated into security oversight, and how quickly critical operations can recover after disruption.
GAO's 2025 maritime-cargo-security assessment points directly toward this measurement problem by recommending objective, measurable, and quantifiable performance goals for the layered security approach.
Strategic Implications
Four conclusions emerge from the evidence.
First, security should extend outward.
The earlier a risk can be identified and addressed, the less dependent the system becomes on detection at the final U.S. port.
Second, compliance should be evaluated as an ongoing process rather than a paperwork exercise.
A security plan has value only if the controls it describes work under real operating conditions.
Third, cyber and physical security increasingly form one operational system.
A compromised network can affect gates, cargo movement, surveillance, communications, and other physical functions.
Fourth, resilience is part of security.
A system that prevents many incidents but cannot recover from a major disruption remains strategically exposed.
None of these conclusions requires assuming that America's ports are unprotected.
The evidence shows something more complicated: the United States has constructed a layered maritime-security system precisely because no individual inspection, agency, technology, or checkpoint can provide complete assurance.
That architecture can be strengthened by better measurement, information sharing, forward assurance, cyber oversight, insider-risk management, and recovery planning.
Conclusion
America's maritime supply chain is not a single security perimeter.
It is a chain of jurisdictions, organizations, technologies, physical facilities, commercial relationships, and human decisions extending from foreign origin points to American ports and inland distribution networks.
That is what makes the system efficient.
It is also what makes assurance difficult.
The central security challenge is not that U.S. ports are simply “uninspected.” They are inspected, regulated, monitored, and supported by multiple federal and private-sector security programs.
The challenge is determining whether those layers provide sufficient assurance across the spaces between inspections, across the boundaries between agencies, across foreign jurisdictions, and increasingly across the boundary between cyberspace and physical infrastructure.
The United States does not need to inspect every container to secure the maritime supply chain.
It does need to know where its visibility is limited, where its assumptions can fail, how quickly weaknesses are detected, and whether a local disruption can be contained before it becomes a national one.
That is the real port blindspot.
Sources and Additional Information
U.S. Government Accountability Office — GAO-08-12, Maritime Security: Coast Guard Inspections Identify and Correct Facility Deficiencies, but More Analysis Needed of Program's Staffing, Practices, and Data
U.S. Government Accountability Office — GAO-23-105385, Coast Guard: Opportunities Exist to Strengthen Foreign Port Security Assessment Program
U.S. Government Accountability Office — GAO-25-106953, Maritime Cargo Security: Additional Efforts Needed to Assess the Effectiveness of DHS's Approach
U.S. Government Accountability Office — GAO-25-107244, Coast Guard: Additional Efforts Needed to Address Cybersecurity Risks to the Maritime Transportation System
DHS Office of Inspector General — OIG-24-37, Coast Guard Should Take Additional Steps to Secure the Marine Transportation System Against Cyberattacks
U.S. Coast Guard — ISPS / MTSA Maritime Security Framework
U.S. Coast Guard — Cybersecurity in the Marine Transportation System: Final Rule
U.S. Coast Guard — Cybersecurity Regulation Implementation Timeline
U.S. Coast Guard — Office of Maritime Cybersecurity Policy, August 2026
U.S. Department of Transportation, Bureau of Transportation Statistics — Port Performance Freight Statistics: 2026 Annual Report
U.S. Congress — Maritime Transportation Security Act of 2002, Public Law 107-295
U.S. Copyright Office — Copyright and Artificial Intelligence
Call to Action
Read the full Strategic Current analysis for additional research on maritime security, national resilience, defense infrastructure, and the systems that connect global commerce to U.S. security.
Subscribe to The Strategic Current for ongoing research-driven analysis covering military history, national security, intelligence, defense technology, and preparedness.
AI Disclosure
AI-Assisted Content Disclosure: This article was prepared with the assistance of generative artificial intelligence. AI was used to help organize, draft, edit, and refine the article based on the supplied research materials and additional verification conducted for this publication. The underlying research and sources were reviewed as part of the preparation process, and the final article should be reviewed and edited before publication. AI assistance does not constitute an endorsement of the content or sources, and generative AI can introduce factual or interpretive errors. Readers are encouraged to consult the original sources provided above. If you identify a discrepancy or factual issue, please contact [email protected]. For additional information regarding AI-assisted content and copyright, see the U.S. Copyright Office report, Copyright and Artificial Intelligence: Part 2—Copyrightability.
