- Primary risk
- Operational shutdown
- Driver
- Retailer and OEM requirements
- Exposure
- Customer portals, EDI
- Recovery target
- Hours, not days
Downtime is the whole risk
Most sectors can absorb a day offline uncomfortably. Logistics cannot. Transport management, warehouse management, proof of delivery and customer tracking are all real-time, and a ransomware event means vehicles that cannot be routed, goods that cannot be booked in and invoices that cannot be raised.
The knock-on matters too. Your customers' production lines and store replenishment depend on you, which is why a logistics incident becomes a supply chain incident and why your customers increasingly audit you.
Where the exposure sits
- Customer portals — booking, tracking and document access, internet-facing by design, frequently built years ago and never tested.
- EDI and integration endpoints connecting you to retailers and manufacturers. These are trusted connections into your network and often authenticated weakly.
- Telematics and driver apps holding location data, vehicle data and personal data on drivers.
- Depot and yard systems — barrier control, ANPR, weighbridges — often on the same flat network as everything else.
- Remote access for owner-drivers and subcontractors, typically the weakest identity in the estate.
Who is asking you for evidence
Large retailers and manufacturers have pushed security requirements down their logistics supply chain, and these arrive as contractual conditions with deadlines rather than polite requests. Cyber Essentials is usually the minimum named. For larger contracts, evidence of independent penetration testing and a documented incident response plan is increasingly added.
Where to start
External infrastructure testing and a customer portal test, because that is the internet-facing exposure your customers are asking about. Then Cyber Essentials, which is what they will want on paper. Then — and this matters more than any test — an incident response plan and a tested backup restore, because your realistic worst case is being offline, and the question is how fast you get back.
Segmentation is worth attention. Depot operational systems, corporate IT and the customer portal should not sit on one flat network, and in most operators we look at, they do.
Common questions
A retailer is demanding Cyber Essentials by a deadline. Can you help?
Very common. We start with a free gap review so you know honestly whether the deadline is achievable. The usual blockers are unsupported software and missing multi-factor authentication, neither of which can be rushed safely.
We can't take systems offline for testing. Does that stop us?
No. External and application testing has no downtime impact. Internal testing is scoped with agreed rules of engagement and any fragile systems excluded — we do not run denial-of-service testing unless specifically asked, and we stay contactable throughout.
What about telematics and vehicle systems?
In-cab and telematics units are usually vendor-managed, so the practical scope is the data platform, the driver app and the API between them — which is where the personal data and the realistic attack surface actually are.
How quickly could you help if we were hit?
Triage and containment guidance starts on the phone immediately. For a West Midlands or Staffordshire operator we can be onsite the same day. The single best preparation is a tested backup and a written plan available offline.
Related
Solusec
Typically replies within one business day
Hi 👋 Need a hand with pen testing, Cyber Essentials, or something urgent? Pick whichever suits you:
💬 WhatsApp usQuick questions, quick answers 📞 Call us
+44 (0)1902 288763 ✉️ Email us
info@solusec.co.uk 📝 Leave a message
We'll reply within one business day