Introduced the Cranes of Concern at our Ports (CCP) Act , which would require the federal government to evaluate threats to U.S. ports posed by cranes manufactured in countries of concern.
Support requiring the federal government to evaluate security threats to U.S. ports posed by cranes manufactured in countries of concern.
Occurrences
Evidence
Executive Order 14116 amended maritime security regulations and expanded federal authority, through the Coast Guard and DHS, to address cyber threats affecting vessels, harbors, ports, and waterfront facilities.
The White House announced an initiative to bolster port cybersecurity, including Coast Guard action directed at cyber risk management for ship-to-shore cranes manufactured by the People's Republic of China and funding to replace foreign-built cranes with U.S.-manufactured cranes.
Axios reported that Biden's executive order would give the Coast Guard power to issue cybersecurity requirements for vessels and ports, and that the Coast Guard planned a maritime security directive establishing new cyber requirements for China-owned and manufactured cranes in U.S. ports.
The House Homeland Security Committee and Select Committee on the CCP reported that ZPMC cranes dominate U.S. port crane infrastructure, identified unauthorized cellular modems and remote-access concerns, and urged federal guidance to disconnect suspect modem or ZPMC connections.
The Wall Street Journal reported that a congressional probe found cellular modems on Chinese-built cargo cranes at U.S. ports and that U.S. officials had grown concerned about espionage and disruption risks tied to ZPMC cranes, which account for about 80% of U.S. ship-to-shore cranes.
The Wall Street Journal reported that the U.S. Coast Guard had inspected more than 92 ZPMC cranes at U.S. ports and found no vulnerabilities, citing a Maritime Administration report.
Assessments
The promised federal scrutiny of security threats from cranes made in countries of concern was substantially carried out during Cornyn's current Senate term: the Biden administration and Coast Guard targeted PRC-manufactured ship-to-shore cranes for cybersecurity requirements, and congressional/executive activity evaluated risks tied to ZPMC cranes. However, the evidence does not show that Cornyn sponsored, wrote, or materially advanced the actions that delivered the federal evaluation/requirements. Because unrelated federal actors appear to have completed the core outcome with little documented Cornyn contribution, this merits partial credit rather than full delivery.