A Maritime Nerve Center: The Scale of the Port Complex
Capt. Kit Louttit runs the vessel traffic service for the ports of Los Angeles and Long Beach. LA alone is the busiest U.S. port; Long Beach is number two. Combined they rank ninth in the world. In 2024, 19.9 million TEUs moved through 55 terminals—each scheduling independently. The Marine Exchange glues them together with a unified schedule stored in the Maris database. Every ship entry carries 30 columns of data: arrivals, departures, shifts, last port, agent, berth, tug count. On July 30, the system tracked 174 upcoming arrivals, 214 departures, and 40 shifts. Nothing is a surprise.
Risk Management from the Operator’s Seat
Steve Winston walks through three NIST incident‑response preparation guidelines: establish operational capability, track and document incidents, test the plan. The Marine Exchange runs annual disaster recovery drills that always reveal a missed weakness. Winston emphasizes risk assessment based on probability and damage, not marking everything high. He recommends a combination of physical, technical, and administrative controls—badge systems without MFA are as weak as MFA without badges. He then describes a real‑world insider threat recruitment pattern: adversaries use LinkedIn to find targets, offer a job at double salary, ask for a small sample of work, then escalate demands after the target has already leaked sensitive data.
Building Incident Response Baselines: Know Normal First
“You can’t detect anomalies if you don’t know what normal looks like,” Winston says. His baselines include CPU, RAM, and network usage; registry keys; file hashes; expected PowerShell and WMIC command usage; normal outbound DNS query volumes per host. He notes that 2025 has seen more data exfiltration via DNS TXT records. Other signals: abnormal login times, PowerPoint spawning cmd sessions, remote access tools executed from ProgramData or AppData, service accounts that never log in suddenly authenticating, and a sudden jump in privilege elevation frequency. Winston also warns about lack of outbound filtering—most new clients had almost none, making it easy for attackers to phone home.
The Perimeter: Firewalls, Patches, and Zero-Day Risks
Winston dissects CVE‑2024‑3400, a Palo Alto Networks zero‑day. A simple POST request with a malicious session‑ID cookie writes a file name to the system, and the firewall then executes each command in that name—no file content needed. He criticizes Palo Alto for not allowing users to change the default SSLVPN port. At the Marine Exchange, any exposed SSLVPN on a Palo Alto is vulnerable because it reveals the HIPP report endpoint. Winston stresses the trade‑off between availability and security: rushed patches can break functionality, and zero‑day variants bypass those patches anyway. The digital attack surface starts at the edge appliance, and both inbound and outbound filtering must be tested.
Notable Quotes
An internal threat is often thought of as a state actor that gets hired under the pretense of infiltrating a company and extracting data. Based on my experience, that’s not usually how that actually works out. Steve Winston · ▶ 12:25
You can’t detect anomalies if you don’t know what normal looks like. Steve Winston · ▶ 20:54
Any attacker that has SSLVP open, SSLVPN open on Apollo Alto, is exposed because it exposes that HIPP report endpoint using a very simple post request and a malicious session ID cookie. Steve Winston · ▶ 25:44
Key Takeaways
- The LA/Long Beach port complex moves 19.9 million TEUs annually through 55 independent terminals.
- Insider threats often recruit through fake high-salary job offers, not direct infiltration.
- Without outbound filtering, attackers can exfiltrate data via DNS TXT records undetected.
About the Speaker(s)
Capt. Kit Louttit was appointed Executive Director of the Marine Exchange of Southern California in January 2013. A graduate of the United States Coast Guard Academy, he served 30 years in the Coast Guard, retiring with the rank of Captain. His experience includes 10 years at sea, six years commanding three cutters, and two years as commanding officer of USCG Integrated Support Command in San Pedro.
Steve Winston is a Senior Systems Administrator and CASP-certified cybersecurity professional with over nine years of experience supporting more than 30 organizations across finance, healthcare, manufacturing, and critical infrastructure. He specializes in securing hybrid infrastructures and threat mitigation, combining deep systems knowledge with an adversarial mindset to close security gaps.