Basilisk
BASILISK
[setor_logistica]LOGISTICS & SUPPLY CHAIN

Offensive security for logistics and supply chain.

Logistics works because systems belonging to different companies trust one another. We test exactly that trust — and what happens when someone walks in through it.

When information becomes cargo theft

Here information has physical consequences. Knowing what sits in which vehicle, on which route and with what estimated arrival is direct input for cargo theft. And because operations depend on automated exchange with carriers, brokers and customers, a large number of doors must stay open for partners.

  • Route and cargo content data has operational value to organised crime.
  • The chain involves dozens of partners with very uneven security maturity.
  • Automated exchange interfaces were designed to work, not to distrust.
  • A dispatch system outage halts invoicing and locks the yard within hours.

What we test in a logistics operation

We walk the path of the cargo and the path of the data describing it, from order to delivery.

// partner data exchange

Integration and EDI interfaces: authentication between companies, origin validation and what a compromised partner could do inside your environment.

// tracking and telemetry

Tracking portals and position APIs: enumeration of tracking codes and exposure of route, content and delivery estimates.

// transport management

Dispatch and routing systems: role-based authorisation, destination changes and integrity of the loading order.

// customer and carrier portals

Access for shippers, drivers and carriers, including isolation between companies sharing the same platform.

// shipping documentation

Issuance and lookup flows for transport documents, where manipulation has a direct effect on the cargo and on tax obligations.

// yard and devices

Handhelds, scales, gate control and operational wireless: what a foothold obtained in the yard reaches in central systems.

Operational risk and legal duty

We translate technical findings into the two languages that drive decisions here: operational loss and contractual obligation.

GDPR
Delivery addresses, driver records and recipient history are personal data. We document data subject exposure and the route of disclosure.
Shipper requirements
Industrial customers audit their logistics operator's security. The attestation letter answers that questionnaire without exploitable detail.
Cargo insurance
Insurers assess control over sensitive information when pricing. Evidence of periodic testing is an argument in that conversation.
Document integrity
Where a transport document can be altered, the problem stops being technical and becomes fiscal. We treat that finding with elevated severity.

How we run without locking the yard

01

Window outside dispatch peak

Dispatch systems only undergo active testing in a window agreed with operations, because an outage there locks the yard and invoicing within hours.

02

Focus on the partner boundary

We prioritise integration interfaces, measuring what a compromised partner would reach — the most likely scenario and the least tested.

03

Tracking enumeration

We test how far cargo, route and content can be discovered from outside, because that exposure is the input for targeted theft.

04

Remediation and retest

We prioritise by what exposes cargo and route data first, follow the remediation and retest before the final version.

What you receive

  • Executive report in operational risk
  • Reproducible technical report
  • Partner boundary analysis
  • Tracking enumeration testing
  • Justified CVSS scoring
  • Priority by cargo exposure
  • Retest of remediated findings
  • Attestation letter for shippers

Sector FAQ

Can testing halt dispatch?

+

No, and the schedule exists to prevent it. Dispatch and yard systems only undergo active testing in a window agreed with operations, with volume limits and an open channel so activity can be stopped within seconds. Where criticality is too high we work on a replica or with non-intrusive activity.

Do you test our partners and carriers?

+

We test your boundary with them, not their infrastructure — that would require separate authorisation from each company. What we measure is what a compromised partner could do inside your environment: the reach of those credentials, what that interface accepts and whether origin is genuinely verified.

Is tracking data exposure really a security risk?

+

It is one of the most concrete in this sector. When codes can be enumerated to reveal route, content and delivery estimate, that stops being information and becomes input for targeted theft. We test that enumeration specifically and report it with the severity the physical impact justifies.

Does the report satisfy a shipper or insurer audit?

+

It does. The attestation letter confirms scope, period and conclusion without exposing exploitable detail, which is the format accepted in supplier questionnaires. For insurers, the executive report in operational risk language tends to be the more useful document in a pricing conversation.

Services applied to this sector

// contact

Ready to uncover your flaws?

First scoping call is free and covered by NDA. Within 48 hours you receive technical proposal, scope and timeline. No bureaucratic forms.