Back to Industries
INDUSTRIES · TRANSPORT & LOGISTICS

Whoever has you, has your clients.

The attack does not take the route through sender or recipient, but through the party both of them trust. That makes the task more than defence: it is evidence — being able to show that nothing left the building. We build interfaces with an identity, access that expires, and the logs that answer that question.
NIS2 · transport BSI-KritisV annex 7 Evidence, not assurance

In this sector, time decides

Consignment, window, contractual penalty — whatever slows the flow loses. In that calculation security is almost always the item that comes last and is dropped first: the certificate to be replaced next week, the interface to be secured later, the driver's account left open after they moved on. None of these decisions was made wrongly. They were made under time pressure, and they accumulate.

What we find

Database and logistics systems whose interfaces have run unchanged for years and hand over data in the clear. Encryption is the exception, and where it is missing it is replaced by other constructions — an additional network, a restriction to address ranges, a hop across a server everyone knows. Virtual desktops are in use, but who opens which session there, and what it is allowed to reach, is rarely something anyone can survey. Where an EDR does exist, it delivers alerts to a place where nobody works through them.

At mid-sized and smaller forwarders, even that is unlikely. There is a firewall and antivirus, and that is where it ends.

This matches what ENISA describes in its threat landscape for the transport sector: attacks overwhelmingly hit IT and administration — booking, billing, customer data — rather than control technology. Ransomware leads by a wide margin, followed by data theft.

The provider is the route to the client

This sector's greatest exposure is not its own house but its position. Whoever has the logistics provider has effectively everything: what a client orders, what it ships, to whom, in what quantity, at what price and on what date. The attack does not take the route through the sender or the recipient — it takes the route through the party both of them trust, and then keeps using that trust.

That shifts the actual task. It is not only to fend off an attack, but to be able to demonstrate to clients that no access took place and no data left. A company that cannot do this loses the contract even when nothing happened.

That the target is not always the data itself is shown by the port of Antwerp: between 2011 and 2013, attackers acting for a smuggling ring gained access to the systems of two container terminals in order to change the collection times and locations of prepared containers and pick them up ahead of the legitimate carrier. The attack was aimed at the IT; the haul stood in the yard.

How far the outage reaches when the systems themselves are hit is documented too. In 2017 NotPetya brought down the global IT of one of the largest shipping lines, with terminals in more than a hundred countries out at once. An Australian logistics group was hit twice within months in 2020 by different groups, the second time with contracts and employee data exfiltrated. A globally active freight forwarder shut down most of its worldwide operations in February 2022 and was constrained for around three weeks — by its own statement without the ability to arrange shipments or handle customs.

The existing estate cannot carry this

Structures that were common on networks twenty years ago do not answer the question the client is asking. A firewall and antivirus say nothing about who accessed what, and when.

How to get out of it

Interfaces get an identity. Every data handover to clients, carriers and platforms runs authenticated and encrypted, with named counterparts instead of permitted address ranges.

Access gets an end. Subcontractors, drivers and external dispatchers get access for a period, not in perpetuity. The most common finding is the account left open after someone moved on.

The virtual desktop becomes a controlled zone. What a session may reach and what may leave it is defined and recorded, rather than assumed.

One source of truth. Identities, rights and states live in one place and under version control. Without it, the assurance given to a client stays an assertion.

Evidence instead of assurance. Access to consignment and customer data is logged and summarised, so that the question "did anything leave your systems" can be answered with a document.

Where it pays to start

A survey of the interfaces and of external access, before anything is procured. In this order: which systems exchange data in the clear today and with whom; who has access from outside and since when; what a session in the virtual desktop is allowed to reach; and whether it could be shown, for the last twelve months, who accessed which client data.

Sources: ENISA Transport Threat Landscape, March 2023; the BSI Act, Annex 1, as amended by the German NIS2 implementation act; BSI-KritisV § 9 with annex 7. Incidents per contemporaneous reporting and, in the freight forwarder's case, the company's own statement.

Concrete offerings

What you can hand off

  • Survey of interfaces

    Which systems exchange data with whom, in what form, and with what protection.

  • Authenticated data handover

    Named counterparts, encryption in transit, an end to permitting whole address ranges.

  • Access for a period

    Subcontractors, drivers and external dispatchers with time-bound access instead of a standing account.

  • Controlled virtual desktops

    Defined what a session may reach and what may leave it — recorded rather than assumed.

  • Evidence for clients

    Logs and reporting that answer questions about access and data leaving your systems with something provable.

  • Detection that connects

    Alerts run into a process with named ownership — manual, automated or by playbook.

Regulatory framework

The four that actually bite

Four bodies of rules decide what actually has to be done in transport and logistics. Also relevant, depending on the business: ISO 27001, customs law and AEO status, and clients' own supplier requirements, which in practice often bite faster than any regulator.

  • NIS2 · transport
    NIS2 implementation · transport sector, all four modes

    Air, rail and water transport appear in annex 1 of the BSI Act with entity types of their own. For road transport, annex 1 names only operators of traffic control installations and intelligent transport systems; a pure road forwarder does not appear there and is reached by NIS2 only where it operates a critical installation under annex 7 of the BSI-KritisV. An entity is essential under section 28(1) no. 4 where it falls under an entity type in annex 1 and has at least 250 employees, or more than 50 million euro turnover and additionally more than 43 million euro balance sheet total. Check that against your own number before someone sells it to you.

  • BSI-KritisV § 9
    BSI-KritisV · annex 7, thresholds for transport

    A logistics centre counts as a critical installation above 17.55 million tonnes or 53.2 million consignments a year. The more telling part is the structure: the regulation lists the IT system for logistics control and administration as an installation category of its own. The software is what is critical, not the warehouse — which makes securing it something other than a property matter.

  • IMO MSC-FAL.1/Circ.3
    IMO · Guidelines on Maritime Cyber Risk Management, rev. 3 of 04.04.2025

    Ties cyber risk management through the ISM Code to the ship's safety management system and therefore to its certification. For shipping lines and charterers this is no longer a paper but a condition of operating — with effect on every service provider connected to those systems.

  • EDPB 01/2020
    EDPB · Guidelines on processing personal data in the context of connected vehicles

    Telematics data from company vehicles is personal data about the drivers and needs a legal basis. In practice this is overlooked, because the systems are procured as a fleet tool. We separate analysis for operations from analysis that leads back to a person, and document who may access what.

Sector facts

As of 2026-09 · Source: dynexo Operations
Typical engagementsForwarders and logistics providers · several sites · subcontractors in daily operation
Most common triggersA client's supplier requirement, NIS2 applicability, an incident at a partner, a tender with a security annex
Core regulationNIS2 · BSI-KritisV annex 7 · IMO where maritime · GDPR for telematics
What we touch firstInterfaces in the clear, external access, virtual desktops
Largest exposureThe position in the supply chain — access to every client's data
What clients ask forEvidence that nothing left · not an assurance
Timing constraintNo standstill in operations · changes run around the peaks
Operating levelsManual, automated or by playbook — selectable per area
Asked often

Asked before the briefing

  • We have a firewall and antivirus. Is that not enough?
    Not for the question your clients ask. Neither says anything about who accessed which consignment and customer data, and when. That is what has to be shown when it matters — and it is what a tender with a security annex asks for.
  • Our interfaces have run for years. Do we have to touch them?
    If they hand over data in the clear, yes — but not all at once. We survey them, sort by data type and counterpart, and convert them in sequence, starting where customer data flows. A replacement during normal operations can be planned; an outage at peak cannot.
  • How do we handle subcontractors who change constantly?
    Access for a period rather than in perpetuity, bound to the assignment and not to the person. The most common finding in this sector is the account left open after someone moved on, and that is a question of procedure, not of technology.
  • May we analyse our drivers' telematics data?
    For operations yes, with a legal basis and to the extent needed for it. The EDPB guidelines treat this data as personal data about the drivers. We separate operational analysis from analysis that leads back to a person, and record who may access what.
Next step

Could you show that nothing left your systems?

The industry briefing surveys your interfaces and external access, checks what a session in the virtual desktop can reach, and shows what can actually be evidenced about access over the past months.