Supply chain and logistics

Keep goods moving through a cyber incident.

In logistics, a cyber incident can stop goods moving. We help logistics groups keep an incident at one site from reaching the rest of the network, meet NIS2 and customer requirements in each market they serve, and introduce AI into planning and operations under clear rules.

Situations we help with

Across contract logistics and warehousing; road, rail, air, and sea freight; parcel, postal, and courier services; and ports and terminals.

  • An incident or test has shown that an attacker inside one site, partner connection, or business unit could reach systems across the network.
  • You operate in several EU Member States and have not yet established which of your entities NIS2 applies to, or under which national law.
  • Customers are asking for evidence of your cyber controls and recovery capability as a condition of contract.
  • Warehouse, transport, and tracking systems depend on a small number of cloud and software suppliers, and nobody has mapped what happens if one fails.
  • Teams are piloting AI for route planning, forecasting, or document processing without common rules for data access or approval.

The challenges

Networks that connect everything

Sites, carriers, customers, and partners share systems and network connections, so a compromise at one depot or partner link can reach systems across the group. Where networks are flat, ransomware can move from an office system to the platforms that run operations.

Operational technology in warehouses and hubs

Automated sorting, conveyors, scanners, and yard systems depend on control systems that can be difficult to patch or isolate without stopping work. Security changes in these environments need planning around operating windows and safety.

Concentrated software and cloud dependence

Warehouse management, transport management, and tracking can run on a small number of cloud platforms and software suppliers. An outage, compromise, or contract change at one of them can affect every site that relies on it.

Different obligations in every country

NIS2 applies through national law, so a group operating in several Member States can face different scope decisions and reporting routes in each. Customers in scope of NIS2 or DORA add their own requirements for supplier security.

ENISA's analysis of 98 publicly reported cyber incidents in EU transport between January 2021 and October 2022 found ransomware behind 38% of them, with aviation, road, rail, and maritime transport all affected.

Source: ENISA Threat Landscape: Transport Sector, March 2023

AI in supply chain and logistics

Route planning and forecasting

The value
Better use of vehicles, drivers, and capacity.
What needs governing
Decisions made at scale on incomplete or poor data, with no clear owner when a forecast is wrong.

Document and customs processing

The value
Faster handling of shipping documents, invoices, and declarations.
What needs governing
Errors in regulated declarations, and commercial data sent to AI services the organisation has not approved.

Customer and partner assistants

The value
Faster answers on shipments, bookings, and exceptions.
What needs governing
Incorrect commitments to customers, and assistants that can see more data than each user should.

AI Factory Design sets common rules for data access, approval, and oversight across these uses, so pilots in different depots and countries can scale under one standard. It is part of our AI Governance and Transformation practice.

Regulation that may apply

NIS2 (EU)

Applies to
Transport entities in air, rail, water, and road transport, a sector of high criticality, and postal and courier services, among the other critical sectors, where they meet the size thresholds in each Member State's law.
What it asks
The management body approves the cybersecurity risk management measures, oversees their implementation, and undergoes training. A significant incident requires an early warning to the CSIRT or competent authority without undue delay and within 24 hours of becoming aware.
Timing
Applies through national law. The transposition deadline was 17 October 2024, and Member States have adopted their laws at different times.

UK NIS Regulations

Applies to
Operators of essential services in UK air, rail, water, and road transport that meet the designation thresholds.
What it asks
Appropriate and proportionate security measures, and notification of a NIS incident to the competent authority without undue delay and no later than 72 hours after becoming aware of it.
Timing
In force since May 2018. The Cyber Security and Resilience Bill, introduced to Parliament in November 2025, would update the regime.

Customer requirements

Applies to
Logistics providers whose customers are in scope of NIS2 or DORA.
What it asks
Those customers must manage the security of their suppliers, so contracts can carry security obligations, incident notification duties, and rights to evidence.
Timing
As customers renew contracts and review their critical suppliers.

We use analytics cookies to understand how this site is used. See our Privacy Notice for details. You can change your choice at any time.