EVERY LINK
IS A WEAK POINT.
Freight moves on connections nobody has inspected in years: EDI links, carrier APIs, vendor remote access, and portals that serve every customer from one database. We test those.
THE SUPPLY CHAIN THREAT MODEL
Downtime is measured in hours, not records
A freight forwarder that loses its transport management system does not degrade gracefully, it reverts to phone calls and handwritten bills of lading. Extortion operators price against that, which is why this sector sees availability attacks.
Trading partner connections predate modern authentication
EDI over AS2 and SFTP, X12 and EDIFACT translators, value added networks, and certificates that expire on nobody's calendar. These links are trusted by design and inspected by nobody, and a malformed message frequently reaches a parser that has never seen a boundary condition.
Shipment data is targeting data
Bills of lading, consignee addresses, commodity descriptions, and contract rates enable cargo theft and competitive intelligence, not just privacy harm. Cross-customer access in a tracking portal is a physical security finding as much as a data one.
WHAT DRIVES THE REQUIREMENT
For a logistics operator, testing is rarely optional. C-TPAT, customer contracts and the crossover between physical and digital systems all assume the environment has been adversarially tested.
C-TPAT cybersecurity criteria
US Customs and Border Protection's minimum security criteria include specific cybersecurity requirements for participating members across the trade chain.
Customer security schedules
Large shippers and retailers impose security requirements and audit rights on their logistics providers through contract, often including independent testing.
NIS2 and sector resilience regimes
Transport is designated an essential sector under the EU NIS2 Directive, bringing risk management and incident reporting obligations to operators in scope.
TSA surface transportation directives
Applicable to designated rail, pipeline, and other surface operators, with prescriptive requirements on segmentation, access control, and incident response.
WHAT WE TEST
TMS, WMS & customer portals
- Cross-customer shipment and document access in tracking portals
- Shipment, rate, and billing modification without authorisation
- Bill of lading and proof of delivery retrieval by identifier enumeration
- Warehouse management interfaces and handheld scanner applications
- Contract rate exposure between accounts
EDI & partner integrations
- AS2 and SFTP configuration, certificate lifecycle, and authentication strength
- X12 and EDIFACT translator boundary and malformed message handling
- Per-partner API scoping: can one partner's key reach another's data?
- Carrier integration and webhook authentication
- API key management, rotation, and over-permissioning
Identity, vendor access & IT/OT boundary
- Active Directory attack paths to TMS and WMS service accounts
- Vendor and managed service provider remote access scope and controls
- Reachability testing from corporate IT into warehouse automation networks
- Warehouse wireless and scanner network segmentation
- Passive analysis of automation protocol traffic, without active probing
HOW WE WORK
The work follows the connections, not the asset register. Portal authorisation, EDI and identity paths run in parallel.
Connection mapping
Inventory every trading partner link, vendor remote access path, and integration into the platforms that move freight. In this sector the scope document is a connection diagram.
Threat modelling
Extortion operators seeking operational shutdown, cargo theft crews seeking shipment intelligence, and partners with more access than anyone intended.
Agentic exploitation
Agent swarms work portal authorisation, EDI handling and identity paths in parallel, exploiting what they reach. Warehouse automation is observed passively; nothing that could move a conveyor is executed without operations sign-off.
Evidence and operational framing
Findings expressed in operational terms (what an attacker could reach, alter or halt) with control mapping against C-TPAT, SOC 2, and the customer schedules in scope.
WHAT YOU RECEIVE
WHEN SUPPLY CHAINS BREAK
Public disclosures worth reading closely. In each case the response was to disconnect, because segmentation could not be relied on to contain the problem.
Maersk (NotPetya)
2017Destructive malware entered through a Ukrainian tax software update and propagated across a flat global network.
Terminals worldwide reverted to manual operation; roughly $300M in losses and a near-total IT rebuild.
Expeditors International
2022Targeted ransomware led the freight forwarder to shut down most operating systems globally as a containment measure.
Weeks of manual booking and customs processing, with losses disclosed at over $60M.
DP World Australia
2023A cyber incident forced disconnection from the internet, halting container operations at several major ports.
Tens of thousands of containers stranded during peak season; national import flows disrupted for days.
COSCO Shipping
2018Ransomware severed email and network connectivity supporting US terminal and booking operations.
Customers redirected to other carriers. CMA CGM was hit by a comparable pattern two years later.
FREQUENTLY ASKED
How does this differ from a standard IT penetration test?+
A standard test covers the corporate estate. This adds the systems that actually run the business: TMS and WMS business logic, multi-customer isolation in tracking portals, EDI message handling, and the boundary between corporate IT and warehouse automation. Those are where the operational findings are, and generic testing does not reach them.
Can you test EDI without disrupting our trading partners?+
Yes. We test your translation and integration layer: configuration, authentication, certificate handling, and how it parses malformed input. No transactions are sent to production partners, and anything involving a real partner happens only with their explicit coordination.
Our TMS is a cloud product. Is that the vendor's problem?+
The vendor is responsible for their application code and hosting. You are responsible for user permissions, role configuration, API integration security, credential management, and which of your customers can see what. In practice that configuration and integration layer is where most findings sit.
Do you test warehouse automation and OT?+
Passively by default. We map segmentation, capture and analyse protocol traffic, and identify what is reachable from corporate networks. Active testing against controllers, conveyors, or autonomous equipment happens only with plant operations approval and a safety plan, because the failure mode is physical.
When should testing not happen?+
Peak season. Testing during the October to December window, quarter end, or a major customer go-live concentrates risk exactly when downtime costs the most. We would rather schedule around it than work with a scope so constrained the results are meaningless.
Find out what one partner connection can reach
Tell us which platforms you run and who connects into them. We will scope the engagement around those connections and around your peak season.