An official website of the United States government
A .mil website belongs to an official U.S. Department of Defense organization in the United States.
A lock (lock ) or https:// means you’ve safely connected to the .mil website. Share sensitive information only on official, secure websites.

My Coast Guard

Subscribe to receive MyCG updates

Commentary | June 11, 2025

How Coast Guard cyber protection teams train for real-world port attacks

By Lt. Ievgen Stepanchuk, Office of Cyberspace Forces (CG-791)

Three automated ship-to-shore cranes grind to a halt after unusual container movements are detected on the platform below. One thing quickly becomes clear: this is not a mechanical failure—it’s a cyberattack. 

This vivid—though fictional—scenario launched a high-stakes training exercise for the U.S. Coast Guard’s 2013 Cyber Protection Team (CPT) last month at Pacific Northwest National Laboratory (PNNL) in Richland, Washington. As cyber threats to the Marine Transportation System (MTS) grow more advanced, exercises like this are helping prepare the Coast Guard’s cyber defenders for the realities of today’s threat landscape. 

The maritime platform replicates a realistic seaport environment using miniature cranes, cargo ships, and trucks to simulate the flow of port operations.

Over the past two years, the CPTs have prioritized developing the capability to detect malicious cyber activity on port technology, including Chinese manufactured cranes. This exercise used the new maritime platform to immerse CPT members in a lifelike simulation of a multi-stage cyberattack on a U.S. container terminal. One of five critical infrastructure platforms located at PNNL as part of the Control Environment Laboratory Resource (CELR) developed and operated by the Cybersecurity and Infrastructure Security Agency (CISA) and PNNL, the maritime platform is the federal government’s most advanced maritime cyber training platform, replicating the Operational Technology and Industrial Control Systems (ICS) found at real U.S. ports. 

“This realism is what makes the platform so valuable,” said Donny Mendoza, Deputy Program Manager for CISA projects at PNNL. “It took over a year to build, with the design and fabrication informed by visiting actual seaport facilities to replicate their systems and architecture.” 

The simulated attack featured a PNNL Red Team of cyber experts acting as adversaries, breaching networks, establishing persistence, and disrupting port operations—all while CPT members worked to detect, contain, and respond in real time. The scenario forced the team to respond under pressure, identifying how attackers gained access to the Terminal Operating System and developing mitigation strategies for fictional port authority staff. 

“Our goal was to replicate not just the infrastructure, but also the stress and operational impact of a real-world incident,” said Alex Reniers, CISA’s ICS Section Chief. 

2013 Cyber Protection Team members conduct live threat hunting operations during a simulated cyberattack on the maritime platform.

“It’s a live-fire drill in a safe environment,” said Ensign Harold Scott, the team’s Mission Element Lead. “We’re seeing how threat actors move, how effectively we can react, and what actions we can take to minimize operational disruptions.” 

For the 2013 CPT, the experience reinforced the critical importance of hands-on training that reflects real-world maritime operations to be ready to respond to future cyber incidents at U.S. ports. As the lead federal agency responsible for protecting and securing critical infrastructure in the MTS, the Coast Guard must remain ready and relevant to face evolving cyber threats. To that end, the maritime platform proved an invaluable tool, noted Chief David Kinnamont, crew lead for the participating team. 

 “The maritime platform delivered exactly what we needed,” he said, “It was a realistic scenario that improved team performance and sharpened our cyber response skills.” 

-USCG- 

Resources:  

In the news:  


The U.S. Department of Defense is committed to making its electronic and information technologies accessible to individuals with disabilities in accordance with Section 508 of the Rehabilitation Act (29 U.S.C. 794d), as amended in 1998. DoD websites use the WCAG 2.0 AA accessibility standard.

For persons with disabilities experiencing difficulties accessing content on a particular website, please use the form DoD Section 508 Form.  In this form, please indicate the nature of your accessibility issue/problem and your contact information so we can address your issue or question. If your issue involves log in access, password recovery, or other technical issues, contact the administrator for the website in question, or your local helpdesk.