Cyber Incident Response and Crisis Management: How Seaports are Rewriting the Playbook
Ports have to rethink how cyber incident response and crisis management can work together
By Lori Musser

hen digital nuisances become operational nightmares, seaports can no longer separate cyber response from crisis management; they must fuse the two to stay resilient.
Ever since digital systems became integral to cargo handling, freight mobility, gate operations, communications, and virtually every other seaport activity, ports have had to rethink how cyber incident response and crisis management can work together.
Interviews with leaders from the Port of Los Angeles, the Port Authority of New York and New Jersey, and Port Saint John reveal a shared trajectory: They are each moving from siloed cyber response toward integrated, all-hazards crisis frameworks that treat cyber disruptions with the same seriousness as hurricanes, fires, or major marine incidents. The result is a more resilient, better coordinated port ecosystem — one that recognizes cyber as a supply-chain risk, not just an IT problem.
Front and Center
Throughout the Americas, ports are embedding cyber response directly into their crisis-management structures. The Port Authority of New York and New Jersey (PANYNJ) embraced this shift with its “all hazards” approach rooted in FEMA’s Incident Command System (ICS).
“ICS allows all stakeholders to communicate clearly and coordinate rapidly,” the agency explains. Cybersecurity Operations Center (CSOC) personnel are trained in ICS procedures, ensuring that when a cyber incident occurs, roles and responsibilities are understood from the outset. If the event is confirmed to be cyber-related, technical teams can split off to focus on containment and recovery while nontechnical teams concentrate on continuity of operations.
This dual-track structure prevents the common pitfall of cyber incidents overwhelming operational staff or, conversely, technical teams being forced to manage communications and continuity decisions outside their lane.
Atlantic Canada’s Port Saint John has taken a similar approach, strengthening its emergency management program by engaging maritime community stakeholders, as well as the broader emergency response community. “Our team has spearheaded a coordinated approach,” said Becky Knox, Manager of Public Affairs & Executive Communications. The goal is to streamline protocols, clarify roles, and integrate response practices so that cyber incidents are treated with the same rigor as any other emergency.
President & CEO Craig Bell Estabrooks underscores the philosophy driving this work:
“At Port Saint John, our unwavering commitment to continuous improvement drives everything we do. We are dedicated to enhancing our emergency management program to address all risks, including cybersecurity threats, so that our port community remains resilient, safe, and ready to respond to any challenge.”
The Port of Los Angeles has long been at the forefront of cyber security innovation. Cyber is now embedded within the city and port’s broader crisis management framework, with emergency management personnel increasingly trained to understand cyber impacts. “Think of it as a strategy within the main crisis management plan,” said Chief Information Security Officer Tony Zhong.
Across all three ports, the message is unmistakable: Cyber response must be part of the core crisis management architecture, not an isolated technical function.
Building Frameworks
The systems that govern how a port functions today play a critical role in its cyber response effectiveness.
PANYNJ’s use of its Incident Command System, for example, provides a shared operational language across agencies, departments, and external partners. This ensures that when a cyber incident scales up or down, roles can be adjusted without confusion. ICS also supports the separation of technical and nontechnical response streams, which may prove critical when communications systems are degraded during an incident.
At the Port of Los Angeles, dual cyber operations have been developed, each designed to address a different layer of port and supply-chain security. The first is the Cyber Security Operations Center (CSOC), a port authority-focused operation protecting internal digital systems and assets. The second is the Cyber Resilience Center (CRC), a port community cyber defense solution supporting terminal operators, shipping lines, logistics providers, and other supply-chain partners.
This dual-track model acknowledges that cyber risk extends far beyond the port authority’s network. “Anything that moves,” Zhong noted, from marine operations to warehousing to trucking, is part of the ecosystem they aim to protect.
Port Saint John is investing in major incident response teams that are aligned with its five core enterprise risks, including cyber. They’re being developed to grow with changing threat landscapes and to align closely with partner agencies such as Transport Canada.
Structures and systems like these reflect a broader trend: Ports are designing cyber response systems that mirror the complexity of the supply chain itself.
Escalation: From Technical Event to Operational Crisis
Cyber incidents escalate quickly and unpredictably. Ports are developing clearer triggers to determine when a technical anomaly becomes a multi-department or multi-agency crisis.
At Los Angeles, analysts categorize threats based on type, severity, impact, and type of attack. More than 99% of threats are blocked automatically, but the remaining 1%, the unknowns, compel human investigation. When an incident crosses a defined threshold, it triggers broader notification across operations, communications, and executive leadership.
PANYNJ’s ICS structure is similarly ready for escalations. Because roles are predefined, the transition from technical response to full-crisis activation is carefully controlled. And because ICS is scalable, the response can expand or contract as the situation evolves.
Port Saint John’s emphasis on enterprise risk alignment ensures that cyber incidents are evaluated not only for their technical characteristics but also for their potential operational, reputational, and safety impacts.
Across all three ports, escalation is no longer ad hoc — it is procedural, rehearsed, and grounded in shared criteria.
Stepping Up to the Plate
One of the most persistent challenges in cyber crisis management is ensuring that nontechnical staff understand their responsibilities when the disruption is digital.
Los Angeles addresses this through its Cyber Resilience Center (CRC), which shares intelligence with terminal operators and many other stakeholders. Because some partners have large IT teams and others have none, the CRC provides scalable support without inserting itself into the partners’ internal response processes or operations.
One way that PANYNJ tackles the challenge is through ICS training and quarterly cyber tabletop exercises that include external partners. These exercises ensure that operational staff, from marine operations to airport personnel, understand how cyber disruptions affect their functions.
Port Saint John emphasizes employee awareness and training programs, recognizing that frontline staff are often the first to notice anomalies. Their training initiatives aim to build a culture where cyber vigilance is part of everyday operations.
Across ports, the trend is clear: operational staff must be cyber-aware, even if they are not cyber experts.
Communication Under Stress: Redundancy Rules
Cyber incidents often degrade or disable traditional communication channels. Ports are responding by building redundancy into their communication plans.
PANYNJ has developed a PACE (Primary, Alternate, Contingency, Emergency) communication plan so stakeholders know exactly which communication methods to use if primary systems fail. This prevents confusion during high-stress moments and ensures continuity of command.
Los Angeles emphasizes the “three foundational pillars” — people, process, and technology — as the basis for effective cyber programs. If one pillar becomes unbalanced, Zhong notes, the entire response suffers, so there are important checks and balances in place.
Port Saint John’s interagency collaboration ensures that communication protocols are aligned across organizations, reducing friction during joint responses.
The common thread is preparation: ports are not waiting for a crisis to test their communication systems. They are rehearsing regularly, with partners at the table.
Before the Crisis
Cyber incidents rarely stay within one organization’s boundaries. Ports are strengthening relationships with federal agencies, terminal operators, utilities, and other partners long before an incident occurs.
PANYNJ invites external partners to its quarterly cyber tabletop exercises, ensuring that “we are not meeting our federal partners and other stakeholders for the first time” during a crisis.
Port Saint John maintains close collaboration with other ports, Transport Canada, and response partners across North America. These relationships allow them to share best practices, understand emerging threats, and learn from major maritime incidents that have occurred elsewhere.
Los Angeles’ CRC and CSOC models have become globally recognized, demonstrating how ports can build community wide cyber defense capabilities.
Collaboration is no longer optional; it is the backbone of modern cyber resilience.
The Human Factor
Technology alone cannot secure a port. All three ports emphasize the human factor as the most important and most challenging element of cyber resilience.
Los Angeles runs continuous cybersecurity awareness training to shift employee perceptions of risk. “Cybersecurity is a shared responsibility,” Zhong stresses. “Every employee has a stake in it.”
Port Saint John echoes this philosophy, investing heavily in employee awareness initiatives and IT infrastructure hardening.
PANYNJ’s ICS training ensures that personnel across the organization understand how to function within a coordinated response structure.
Together, these efforts reflect a cultural shift: cyber resilience is becoming part of the organizational identity, not just a technical requirement.
Looking Ahead
Ports are also preparing for the next wave of challenges, especially the security implications of artificial intelligence. Los Angeles is evaluating AI through a security lens focused on safeguards while meeting the needs of business functions.
Port Saint John and PANYNJ are monitoring emerging threats through regional partnerships and national working groups. As Knox noted, the Association of Canadian Port Authorities maintains working groups for both emergency preparedness and cybersecurity. Like the AAPA’s IT and cyber security committees, these are valuable forums for ports seeking shared solutions.
Across all interviews, one theme emerges: ports must be pragmatic, not perfectionist. Zhong recommended that seaports work with what they have, don’t try to tackle everything at once, address one problem at a time, and build on the foundation of people, process, and technology.
A New Era of Cyber Operational Resilience
North American ports are entering a new era, one where cyber incident response and crisis management are inseparable. Through ICS-based structures, dual cyber operations, major incident response teams, PACE communication plans, and continentwide collaboration, ports can and will continue to enhance the resiliency of their maritime ecosystem.
The work is ongoing, but the direction is clear: Cyber resilience is now a core operational competency, essential to protecting the supply chain, safeguarding communities, and ensuring that ports remain engines of economic vitality in an increasingly digital world.
