Logistics & Transport · NIS2 & KRITIS Transport

Your supply chain is only as secure
as the gate on a quiet night shift

The transport sector is explicitly listed under NIS2 in Annex 1 BSIG, postal and courier services included. Larger hubs such as ports fall under the KRITIS sector "Transport and Traffic" once they cross certain thresholds. Meanwhile, real incidents from recent years show how concretely freight forwarders and logistics providers are being targeted. Four things decide your exposure in logistics: transport management systems, warehouse management, terminal control, and the human factor at the gate.

NIS2- & KRITIS-ready documentation Experience with TMS, WMS & terminal control systems Free initial consultation
Logistics industry survey
81%

name the human factor as a central risk

Sophos/techconsult survey of 147 logistics professionals and executives, September 2025
Threat picture

The numbers

Two independent sources, one picture: transport and logistics are in the crosshairs, and the weak spot is rarely just technical.

7.5%
of all incidents hit the transport sector, making it the second most-targeted sector
ENISA Threat Landscape 2025
20.8%
of those hit logistics specifically, with 58.4% hitting aviation
ENISA Threat Landscape 2025
78.8%
of logistics companies surveyed had already been directly or indirectly affected by a cyberattack
Sophos/techconsult, Sept. 2025, 147 respondents
4,875
incidents analyzed between July 1, 2024 and June 30, 2025
ENISA Threat Landscape 2025
Attack surface: logistics

The flow of goods as an attack chain

Logistics companies run classic office IT alongside terminal, warehouse, and vehicle control systems, on top of constant foot and vehicle traffic at the gate. That combination opens up several routes at once for attackers, and every station in the flow of goods is one of them.

01
TMS
Transport management

Plans routes, freight, and orders centrally, with interfaces to customers, customs, and subcontractors.

02
WMS
Warehouse management

Receiving, picking, inventory: grown organically over years and tightly wired into handheld scanners and mobile devices.

03
Terminal
Container & crane control

Crane control, slot booking, and container logistics run on specialized systems that conventional IT security concepts rarely cover.

04
Gate
The human factor

Dozens of unfamiliar drivers, subcontractors, and delivery partners every day, and gate staff who are used to exactly that traffic.

Cutting across all of it: customer and supplier interfaces. APIs and portals for shipment tracking, EDI connections, and freight booking connect your network directly with your partners'.

The human factor

The biggest attack vector in logistics isn't your firewall

Scenario: gate access

Gates, terminals, and loading docks see dozens of unfamiliar drivers, subcontractors, and delivery partners every single day, on top of high turnover among gate security staff. Someone posing as a subcontractor's driver or a delivery partner exploits exactly that routine: they act confidently, reference a supposed delivery slot, and gate staff, used to this kind of traffic, wave them through. Once inside, warehouses, terminal areas, and often unsecured network ports are within reach.

„The biggest challenge remains the human factor.“

Three cases

What has already happened in the industry

Three incidents at logistics companies, as described in media reports. Not isolated cases, but a pattern.

Hellmann Worldwide LogisticsOsnabrück · ransomware

The Osnabrück-based logistics provider was hit by a ransomware attack.

Swiss Post Cargo Germanyapprox. 1,600 business customers

A cyberattack on the company affected roughly 1,600 business customers.

DSVOctober 2025

The freight giant disclosed an October 2025 incident attributed to a group calling itself "CoinbaseCartel".

Based on public reporting. accessgranted was not involved in these incidents.

See our own pentesting track record
Our approach

How does a pentest in logistics work?

Ongoing freight flow and delivery deadlines come first. That's why our approach is closely coordinated with dispatch and terminal operations.

Step 01

Scoping with operations in mind

Together we define which systems are tested actively and which are only analyzed passively, especially around terminal control and shipments in transit.

Step 02

Reconnaissance & attack preparation

Gathering information from public sources, network scans, and preparing realistic attack scenarios, including pretexting approaches targeting the gate and dispatch.

Step 03

Test execution

Manual testing within the agreed scope, with a defined emergency contact and an immediate stop if there's any unexpected impact on the flow of goods.

Step 04

Analysis & risk assessment

Every finding is rated by severity, exploitability, and impact on delivery capability and terminal operations.

Step 05

Final report & presentation

Full documentation with remediation guidance, a management summary, and mapping to NIS2 or KRITIS requirements.

Relevant modules

These tests bring your logistics IT up to standard

From dispatch to the gate, a single test won't get you there. These modules complement each other best in practice.

NIS2 and KRITIS Transport in detail

The transport sector falls under NIS2 per Annex 1 BSIG, with larger hubs additionally covered by the KRITIS regulation. Our compliance pages explain exactly what that means for you.

Pentesting in logistics & transport: your questions

Yes, the transport sector is explicitly listed as an NIS2 sector under Annex 1 BSIG, postal and courier services included. Whether your company is specifically in scope depends on its size and classification as an important or essential entity. Larger hubs such as ports can additionally fall under the KRITIS regulation.
A Sophos/techconsult survey from September 2025, covering 147 logistics professionals and executives, found that 81% name human error or lack of security awareness as a central risk. That tracks with how the industry works: high staff turnover, constant outside traffic at the gate, and time pressure in dispatch all wear down vigilance against phishing and pretexting.
Yes, that's part of our Physical Pentest module. We simulate realistic access attempts, for example posing as a driver or subcontractor, and check whether the gate, access controls, and warehouse areas hold up. The approach is agreed in advance with a defined group on your side.
Yes. Smaller and mid-sized forwarders often assume they're "too small" to be targeted, but they're frequently connected to larger supply chains through EDI interfaces and subcontractor relationships, making them an attractive detour for attackers. ENISA's finding that transport is the second most-targeted sector doesn't break down by company size.
That depends heavily on scope: how many locations, whether TMS/WMS systems and terminal control are included, whether physical and social engineering testing are part of it. After a free initial consultation, we know your scope and you get a transparent fixed-price quote.
Depending on scope, testing typically takes one to three weeks, followed by analysis and reporting. Critical findings that need immediate action are flagged to you right away, not held back for the final report.
NIS2 applies sector-wide to important and essential entities in transport. KRITIS ("Transport and Traffic") additionally applies only to operators that cross certain thresholds, such as large ports or hubs, and comes with its own, stricter obligations under BSIG. Both can apply in parallel.
Yes. We test transport management and warehouse management systems as well as APIs and portals for shipment tracking or freight booking, usually focusing on authentication, authorization between tenants, and securing interfaces to subcontractors and customers.