Offensive security for logistics and supply chain.
Logistics works because systems belonging to different companies trust one another. We test exactly that trust — and what happens when someone walks in through it.
When information becomes cargo theft
Here information has physical consequences. Knowing what sits in which vehicle, on which route and with what estimated arrival is direct input for cargo theft. And because operations depend on automated exchange with carriers, brokers and customers, a large number of doors must stay open for partners.
- Route and cargo content data has operational value to organised crime.
- The chain involves dozens of partners with very uneven security maturity.
- Automated exchange interfaces were designed to work, not to distrust.
- A dispatch system outage halts invoicing and locks the yard within hours.
What we test in a logistics operation
We walk the path of the cargo and the path of the data describing it, from order to delivery.
Integration and EDI interfaces: authentication between companies, origin validation and what a compromised partner could do inside your environment.
Tracking portals and position APIs: enumeration of tracking codes and exposure of route, content and delivery estimates.
Dispatch and routing systems: role-based authorisation, destination changes and integrity of the loading order.
Access for shippers, drivers and carriers, including isolation between companies sharing the same platform.
Issuance and lookup flows for transport documents, where manipulation has a direct effect on the cargo and on tax obligations.
Handhelds, scales, gate control and operational wireless: what a foothold obtained in the yard reaches in central systems.
Operational risk and legal duty
We translate technical findings into the two languages that drive decisions here: operational loss and contractual obligation.
- GDPR
- Delivery addresses, driver records and recipient history are personal data. We document data subject exposure and the route of disclosure.
- Shipper requirements
- Industrial customers audit their logistics operator's security. The attestation letter answers that questionnaire without exploitable detail.
- Cargo insurance
- Insurers assess control over sensitive information when pricing. Evidence of periodic testing is an argument in that conversation.
- Document integrity
- Where a transport document can be altered, the problem stops being technical and becomes fiscal. We treat that finding with elevated severity.
How we run without locking the yard
Window outside dispatch peak
Dispatch systems only undergo active testing in a window agreed with operations, because an outage there locks the yard and invoicing within hours.
Focus on the partner boundary
We prioritise integration interfaces, measuring what a compromised partner would reach — the most likely scenario and the least tested.
Tracking enumeration
We test how far cargo, route and content can be discovered from outside, because that exposure is the input for targeted theft.
Remediation and retest
We prioritise by what exposes cargo and route data first, follow the remediation and retest before the final version.
What you receive
- Executive report in operational risk
- Reproducible technical report
- Partner boundary analysis
- Tracking enumeration testing
- Justified CVSS scoring
- Priority by cargo exposure
- Retest of remediated findings
- Attestation letter for shippers
Sector FAQ
Can testing halt dispatch?
+
No, and the schedule exists to prevent it. Dispatch and yard systems only undergo active testing in a window agreed with operations, with volume limits and an open channel so activity can be stopped within seconds. Where criticality is too high we work on a replica or with non-intrusive activity.
Do you test our partners and carriers?
+
We test your boundary with them, not their infrastructure — that would require separate authorisation from each company. What we measure is what a compromised partner could do inside your environment: the reach of those credentials, what that interface accepts and whether origin is genuinely verified.
Is tracking data exposure really a security risk?
+
It is one of the most concrete in this sector. When codes can be enumerated to reveal route, content and delivery estimate, that stops being information and becomes input for targeted theft. We test that enumeration specifically and report it with the severity the physical impact justifies.
Does the report satisfy a shipper or insurer audit?
+
It does. The attestation letter confirms scope, period and conclusion without exposing exploitable detail, which is the format accepted in supplier questionnaires. For insurers, the executive report in operational risk language tends to be the more useful document in a pricing conversation.
Services applied to this sector
Ready to uncover your flaws?
First scoping call is free and covered by NDA. Within 48 hours you receive technical proposal, scope and timeline. No bureaucratic forms.