Keep goods moving through a cyber incident.
In logistics, a cyber incident can stop goods moving. We help logistics groups keep an incident at one site from reaching the rest of the network, meet NIS2 and customer requirements in each market they serve, and introduce AI into planning and operations under clear rules.
Situations we help with
Across contract logistics and warehousing; road, rail, air, and sea freight; parcel, postal, and courier services; and ports and terminals.
- An incident or test has shown that an attacker inside one site, partner connection, or business unit could reach systems across the network.
- You operate in several EU Member States and have not yet established which of your entities NIS2 applies to, or under which national law.
- Customers are asking for evidence of your cyber controls and recovery capability as a condition of contract.
- Warehouse, transport, and tracking systems depend on a small number of cloud and software suppliers, and nobody has mapped what happens if one fails.
- Teams are piloting AI for route planning, forecasting, or document processing without common rules for data access or approval.
The challenges
Networks that connect everything
Sites, carriers, customers, and partners share systems and network connections, so a compromise at one depot or partner link can reach systems across the group. Where networks are flat, ransomware can move from an office system to the platforms that run operations.
Operational technology in warehouses and hubs
Automated sorting, conveyors, scanners, and yard systems depend on control systems that can be difficult to patch or isolate without stopping work. Security changes in these environments need planning around operating windows and safety.
Concentrated software and cloud dependence
Warehouse management, transport management, and tracking can run on a small number of cloud platforms and software suppliers. An outage, compromise, or contract change at one of them can affect every site that relies on it.
Different obligations in every country
NIS2 applies through national law, so a group operating in several Member States can face different scope decisions and reporting routes in each. Customers in scope of NIS2 or DORA add their own requirements for supplier security.
ENISA's analysis of 98 publicly reported cyber incidents in EU transport between January 2021 and October 2022 found ransomware behind 38% of them, with aviation, road, rail, and maritime transport all affected.
AI in supply chain and logistics
Route planning and forecasting
- The value
- Better use of vehicles, drivers, and capacity.
- What needs governing
- Decisions made at scale on incomplete or poor data, with no clear owner when a forecast is wrong.
Document and customs processing
- The value
- Faster handling of shipping documents, invoices, and declarations.
- What needs governing
- Errors in regulated declarations, and commercial data sent to AI services the organisation has not approved.
Customer and partner assistants
- The value
- Faster answers on shipments, bookings, and exceptions.
- What needs governing
- Incorrect commitments to customers, and assistants that can see more data than each user should.
AI Factory Design sets common rules for data access, approval, and oversight across these uses, so pilots in different depots and countries can scale under one standard. It is part of our AI Governance and Transformation practice.
Regulation that may apply
NIS2 (EU)
- Applies to
- Transport entities in air, rail, water, and road transport, a sector of high criticality, and postal and courier services, among the other critical sectors, where they meet the size thresholds in each Member State's law.
- What it asks
- The management body approves the cybersecurity risk management measures, oversees their implementation, and undergoes training. A significant incident requires an early warning to the CSIRT or competent authority without undue delay and within 24 hours of becoming aware.
- Timing
- Applies through national law. The transposition deadline was 17 October 2024, and Member States have adopted their laws at different times.
UK NIS Regulations
- Applies to
- Operators of essential services in UK air, rail, water, and road transport that meet the designation thresholds.
- What it asks
- Appropriate and proportionate security measures, and notification of a NIS incident to the competent authority without undue delay and no later than 72 hours after becoming aware of it.
- Timing
- In force since May 2018. The Cyber Security and Resilience Bill, introduced to Parliament in November 2025, would update the regime.
Customer requirements
- Applies to
- Logistics providers whose customers are in scope of NIS2 or DORA.
- What it asks
- Those customers must manage the security of their suppliers, so contracts can carry security obligations, incident notification duties, and rights to evidence.
- Timing
- As customers renew contracts and review their critical suppliers.
Recommended engagements
Zero Trust Transformation
Limits how far a compromise at one site, partner connection, or business unit can spread across the network.
View engagementAI Factory Design
Brings AI for planning, forecasting, and document handling under common rules before pilots spread across depots and countries.
View engagementNIS2 Readiness Diagnostic
Establishes which of your entities NIS2 applies to in each Member State before programme spending starts.
View engagementNIS2 Programme Design and Delivery
Turns diagnostic findings into a funded programme across transport, warehousing, and supplier contracts.
View engagementCase studies
Negotiating from a position of evidence: AWS Master Contract (EDP) advisory for a global logistics business
ASX-listed, multinational logistics client
Removing $600,000 in annual cloud waste: platform strategy and FinOps transformation for a global logistics business
ASX-listed, multinational logistics client
Scope before commitment: a NIS2 diagnostic across a multinational logistics group
EU-headquartered, multinational logistics client
Understand before you move: reducing lateral movement risk in a global logistics finance segment
ASX-listed, multinational logistics client
