The U.S. Coast Guard operates at a uniquely exposed tactical edge. Cutters, aircraft, small boats, deployable teams, unmanned systems, sensors, and shore units routinely operate far from traditional data centers and secure facilities, often carrying sensitive information needed for maritime security, law enforcement, intelligence, and national defense missions.
As Coast Guard operations become more data-intensive, connected, AI-enabled, and distributed, more valuable information is being stored directly on those endpoints. That creates a basic security question: If this device, vessel, aircraft, sensor, or unmanned platform is lost, abandoned, damaged but recoverable, or captured, what happens to the information stored inside it? That is the problem Data-at-Rest (DAR) protection is designed to address.
Data at Rest is simply information stored on a device rather than actively moving across a network. Information transmitted from a cutter to a shore command is data in transit. Once that same information is saved to an SSD, laptop, mission computer, server, or other storage device, it becomes data at rest.
Across Coast Guard missions, DAR can reside on:
If a device retains information after power is removed, it potentially contains DAR. And that information can be extremely valuable.
A lost device doesn’t need thousands of classified documents to create a serious operational or intelligence compromise. Depending on the mission, stored information may include:
In national-defense missions, Coast Guard systems may also process or retain classified information associated with Department of War, Intelligence Community, or other national-security operations. Collectively, this information can reveal what the Coast Guard knows, what it is watching, how it communicates, where it operates, and potentially what it intends to do next.
The Coast Guard has always operated in physically challenging environments. What’s changing is the quantity and value of information being pushed to those environments.
Operational decisions frequently need to be made aboard cutters, aircraft, small boats, and deployable systems without depending upon continuous access to centralized infrastructure. Edge computing makes those operations faster and more resilient. But local processing means local storage. More computing at the edge means more DAR at the edge.
AI and advanced analytics can improve maritime surveillance, object and vessel recognition, anomaly detection, sensor processing, and decision support. But AI-enabled systems can also retain valuable models, algorithms, and datasets. The endpoint may therefore contain not only operational information, but technology revealing how that information is analyzed.
The Coast Guard is increasingly evaluating and using unmanned aircraft and maritime systems to extend surveillance and operational reach. Whether remotely controlled, semi-autonomous, or autonomous, these platforms can store mission and sensor information locally. If the platform can be lost or recovered, its data may be recoverable too.
The Coast Guard operates across enormous geographic areas, from ports and coastal waters to the Arctic, Pacific, Caribbean, and other remote maritime environments. Those missions place computing systems well outside continuously protected facilities. Physical loss has to be considered a realistic operational possibility.
A system lost at sea isn’t necessarily destroyed. A small unmanned vessel may be recovered. A UAS can come down on land or in shallow water. Equipment can wash ashore. A damaged cutter or boat system may remain physically accessible. Storage components may survive damage that makes the larger platform unusable.
For security planning:
This becomes particularly important when operating near sophisticated nation-state competitors or supporting national-defense missions. A capable adversary may devote substantial resources to recovering equipment specifically because of the information inside it.
Most cybersecurity focuses on keeping attackers out of computers and networks. Physical possession creates a different problem.
Imagine a mission computer, laptop, unmanned platform, sensor, or storage device falls into unauthorized hands. An advanced adversary can:
The question is no longer: “Can they penetrate our network?” It becomes: “With our equipment sitting on their laboratory bench, can they recover what’s stored inside it?” That is a DAR problem.
Commercial encryption can provide excellent protection for enterprise information. But classified National Security Systems (NSS) face a more demanding threat model.
A common misconception is that a device is adequately protected because it uses AES-256, commercial full-disk encryption, or a “FIPS-certified” drive. Those can be important security attributes. They don’t, by themselves, constitute a classified DAR architecture.
A sophisticated adversary doesn’t necessarily need to break AES mathematically. They can search for easier paths:
The better question isn’t: “How strong is the encryption?” It is: “What must an adversary defeat before the classified data becomes accessible?”
FIPS cryptographic validation is important. It provides assurance that specified cryptographic functionality has been tested against defined requirements. But a product containing FIPS-validated cryptography isn’t automatically a complete solution for protecting classified DAR.
Consider securing a cutter. A highly secure lock on one compartment is valuable. But that lock doesn’t make the entire vessel secure. Protection depends on boundaries, access controls, credentials, procedures, and multiple defenses working together.
DAR is similar. Cryptography is a critical component of security. It isn’t the entire security architecture. For classified National Security Systems, NSA provides important direction on how those protections should work together.
National Security Presidential Memorandum 12 (NSPM-12), National Policy for the Cybersecurity of National Security Systems, issued in June 2026, establishes cybersecurity governance for NSS across the federal government.
Importantly, NSPM-12 reestablishes the Director of the National Security Agency as the National Manager for National Security Systems, including responsibilities associated with minimum requirements for cryptology and cryptographic systems.
That is relevant to the Coast Guard because of its unique position. The Coast Guard is an armed force, a federal law-enforcement organization, a maritime security organization, and a component of the Department of Homeland Security. Its missions can span ordinary government information, highly sensitive law-enforcement and intelligence information, and classified national-security operations.
Not every Coast Guard endpoint therefore requires the same protection. But when a Coast Guard system is an NSS and retains classified information, protecting that information isn’t simply a matter of choosing a commercial encryption product or encrypted SSD. NSA has a defined national role in establishing appropriate cryptographic protections. One important mechanism is the Commercial Solutions for Classified program.
NSA’s Commercial Solutions for Classified (CSfC) program enables appropriately evaluated commercial technologies to be used within NSA-defined architectures to protect classified information. For stored classified information, NSA’s Data-at-Rest Capability Package defines DAR architectures.
CSfC changes the question from: “Is this device encrypted?” to: “Does the complete solution provide the layers of protection required for classified information?”
Several concepts are particularly relevant to Coast Guard NSS.
CSfC DAR applies defense in depth rather than placing all trust in one encryption mechanism. If an adversary compromises one independent protection layer, another is intended to remain between the attacker and the classified information.
CSfC architectures use commercial products evaluated for specific security functions and selected according to applicable NSA requirements. A product being commercially available, or advertised as using “military-grade encryption”, isn’t the same as being evaluated for a defined role in a classified DAR architecture.
Strong encryption is valuable only if unauthorized users cannot cause storage to unlock. Think of encrypted storage as a secure compartment aboard a cutter. Encryption provides the reinforced boundaries. Authentication controls the hatch. An exceptionally strong compartment provides limited protection if the hatch automatically opens whenever someone powers up the system. Both protections matter.
Encryption keys are critical assets. A sophisticated adversary may have little reason to attack AES directly if they can recover or exploit the mechanism protecting its keys. DAR architecture therefore considers key generation, storage, protection, and authorization, not simply the encryption algorithm.
This is particularly important for Coast Guard operations. A lost UAS, deployable computer, sensor, or maritime system may be disconnected from every trusted network. Remote wipe may be impossible. Enterprise security services may be unreachable. The protection therefore needs to remain effective on the endpoint itself. Physical possession of the equipment should not equal possession of its classified information.
The Coast Guard has always engineered missions around operating in difficult environments.
As computing and data become increasingly important to maritime operations, information survivability deserves similar attention.
Programs developing and acquiring NSS endpoints should ask:
These should be design and acquisition questions, not questions first asked after equipment is deployed.
Maritime domain awareness, edge computing, AI, unmanned systems, distributed operations, and increasingly sophisticated sensors are placing more valuable information on Coast Guard endpoints operating outside traditional physical-security boundaries.
That creates a straightforward operational reality: If we cannot guarantee possession of the device, we must ensure that possession of the device does not provide possession of its data.
Commercial encryption and FIPS-validated cryptography can be important components. For classified information on National Security Systems, however, checking an encryption box isn’t enough. NSPM-12 reinforces NSA’s central role in protecting NSS, while NSA’s CSfC DAR program provides architectures for combining evaluated commercial technologies into layered protections for classified information.
For the Coast Guard, DAR shouldn’t be viewed simply as an IT or cybersecurity requirement. It is information survivability, and for national-security missions, it can be mission survivability.
The Coast Guard may not always be able to prevent a device, sensor, unmanned system, aircraft component, or maritime endpoint from being lost, damaged, or recovered by an unauthorized party. It can, and should, design systems so losing the equipment doesn’t mean losing control of the sensitive or classified information stored inside it.
Brett Hansen, Cigent CEO, has 30 years of IT experience. Prior to joining Cigent, he held leadership positions with companies providing SaaS data solutions. He was also an executive at Dell for over a decade overseeing Client Software organization including developing and leading Dell Data Security business that provided integrated hardware and software security solutions. Brett started his career with IBM holding leadership positions with various software organizations focusing on IT management, development, and security.