11,444
Internet-facing assets discovered
Across 5 scanned organisations
757
Supplier connections mapped
Script · cert · ASN · DNS · header
66
Fix Now priorities
Requiring immediate action
5/5
Suppliers common to all 5 orgs
Google · Microsoft · GitHub · jQuery · Meta
Why transportation attack surfaces carry structural risk
Transportation and logistics companies form the backbone of European supply chains — moving raw materials, finished goods, chemicals, and freight across borders and continents. They operate complex digital ecosystems: real-time fleet management platforms, driver communication apps, cargo tracking portals, customer booking interfaces, and EDI integrations with retailers, ports, and customs authorities. Each digital touchpoint is an element of the external attack surface, continuously visible to anyone scanning the public internet.
Yet cybersecurity investment in transportation has historically lagged behind the digital transformation of logistics operations. Many transport operators run web platforms built on commodity stacks with limited in-house security expertise, creating a pattern of accumulated external hygiene debt — vulnerable software libraries, misconfigured HTTP headers, and DNS records that have never been reviewed since initial deployment.
This report draws on simultaneous scans of five transportation organisations across Belgium, the Netherlands, and the United Kingdom — spanning road freight specialists, chemical tank logistics, rail freight, international relocation logistics, and regional road haulage. The findings reveal a sector where three of five organisations carry Header D ratings, where one UK road haulier has six of its eleven web applications rated F, and where five technology suppliers are embedded in the external estate of every organisation scanned.
All organisations in this report are anonymised. Technology suppliers and infrastructure providers are named as they appear on the external attack surface.
Sector Benchmark
How do transportation organisations compare?
ThingsRecon scanned five transportation organisations simultaneously — from a Belgian road transport and logistics group to a UK regional road haulier. All five received an overall score of C, but the variation in individual risk indicators is substantial. Three organisations carry Header D ratings, three carry DNS C ratings, and the most alarming single finding is the application profile of a UK road haulage operator: 6 of its 11 web applications received an F rating, meaning more than half its customer-facing estate has critical application-level vulnerabilities.
Organisation
Assets
Suppliers
Fix Now
Fix Soon
Score
Weak indicators
Company ARoad transport & logistics · BE
2,550
68
17
22
C
Headers D · Software C · App C · SSL B
Company BChemical tank logistics · NL
3,004
79
21
24
C
App C · Cert C · Headers C
Company CRail freight operator · UK
2,526
52
3
7
C
DNS C · Headers C · Software C
Company DInternational logistics · BE
1,774
38
6
9
C
Headers D · DNS C · SSL C · Cert C
Company ERoad haulage · UK
1,590
50
19
11
C
App D · Software D · Headers D · DNS C
Critical — application F ratings detected at road haulage operator
One road haulage organisation in this benchmark has 6 of its 11 web applications rated F — the most severe application risk classification, indicating critical vulnerabilities on live, publicly accessible web services. With an overall Application D rating and Software D rating, this organisation also carries 13 Fix Now software findings alongside 6 Fix Now application findings. In a transport context, F-rated applications commonly include freight booking portals, driver dispatch interfaces, and customer shipment tracking systems — platforms where a successful exploit could expose sensitive cargo manifests, client data, or operational systems. This profile requires immediate remediation prioritisation.
Sector-wide Risk Patterns
Structural vulnerabilities across the transportation digital estate
The patterns below appear consistently across transportation organisations regardless of sub-sector, size, or country. They reflect the reality of logistics operators who have digitalised customer-facing operations rapidly — adding booking portals, tracking dashboards, and partner integrations — without equivalent security investment in the underlying web infrastructure.
Application Security
Critical
One organisation carries an Application D rating with 6 of 11 web applications rated F — the most severe finding across this benchmark. Transportation web applications — freight booking platforms, shipment tracking portals, driver management systems — represent direct operational and commercial exposure when compromised. Fix Now application findings appear across three of five organisations.
HTTP Security Headers
High
Three of five organisations carry D ratings for HTTP security headers — indicating that customer-facing logistics portals, freight booking interfaces, and partner integration endpoints lack CSP, HSTS, and related browser security controls, exposing users to clickjacking, script injection, and man-in-the-middle attacks on every authenticated session.
Software Supply Chain
High
Software risk of C or worse appears at four of five organisations, including one D rating. The D-rated organisation has 13 Fix Now software findings — known-vulnerable JavaScript library versions deployed on live applications. When known-vulnerable libraries meet application-level weaknesses, the risk profile escalates significantly.
DNS Infrastructure
High
DNS C ratings appear at three of five organisations. Misconfigured DNS records — dangling records pointing to decommissioned platforms, weak DNSSEC configurations, or incomplete SPF records — create subdomain takeover and email spoofing exposure on exactly the domains customers use to access freight and tracking services.
Supplier Concentration
Medium
Five technology suppliers appear in all five transportation organisations simultaneously: Google, Microsoft, GitHub, the OpenJS Foundation, and Meta Platforms. Google achieves the highest average digital proximity of any supplier at 57%. A supply chain compromise affecting any of these five universal suppliers propagates simultaneously across the entire sector.
Certificate & SSL Hygiene
Medium
Certificate risk of C appears at three organisations, with D-rated certificates at two. SSL service risk of C appears at one organisation. Certificate mismanagement and weak SSL configurations on freight portals and partner APIs create man-in-the-middle exposure on sessions carrying sensitive logistics and client data.
Cookie & Session Security
Medium
Cookie D ratings appear across four of five organisations, with Fix Soon cookie findings present at all five. Poorly configured session cookies missing Secure, HttpOnly, or SameSite attributes on freight booking and dispatch platforms create session theft exposure without any server intrusion required.
Sector verdict: The transportation sector's external attack surface reflects rapid digitalisation on top of infrastructure not built with security-first principles. With 66 Fix Now items across five organisations — including a road haulage operator with 6 F-rated applications and 19 total Fix Now items — the remediation workload is concentrated and urgent. NIS2 classifies road, rail, and intermodal transport operators as important entities, creating a compliance dimension that amplifies the business case for continuous external attack surface monitoring.
NIS2 Directive — Transport Sector Obligations
Road, rail, air, and waterborne transport operators are classified as important entities under NIS2 Annex II. Rail freight operators providing network-critical services may qualify as essential entities under Annex I. Both tiers trigger mandatory obligations under Article 21: ICT risk management, vulnerability handling, supply chain security (Article 21.2.d), use of cryptography, and incident reporting within 72 hours (Article 23). UK transport operators fall under the NIS Regulations and sector-specific DfT and ORR cybersecurity guidance for rail.
Why Transportation Needs This
Discovery. Prioritisation. Monitoring.
Transportation organisations manage digital estates that grow continuously — new customer tracking portals, fleet management APIs, partner EDI integrations, and driver communication platforms are added regularly, often by operational teams without security review. ThingsRecon maps every publicly visible asset and supplier connection from a single seed domain, with no agents required and no access to internal systems.
01
Continuous Discovery
Logistics digital estates expand with every new route, partnership, or acquisition. ThingsRecon discovers every subdomain, freight portal, partner API endpoint, and third-party script continuously — including DNS records that have become dangling as platforms are retired or migrated.
02
Risk Prioritisation
With 66 Fix Now items across five organisations — and 19 at a single road haulage operator — transport security teams cannot address everything simultaneously. ThingsRecon scores every finding by exploitability and business proximity.
03
Supply Chain Monitoring
Five technology suppliers appear in every transportation organisation scanned. ThingsRecon monitors every supplier connection for changes — new scripts, CDN routing shifts, certificate rotations — before they become incidents requiring notification under NIS2 Article 23.
Supply Chain Intelligence
The suppliers inside every transportation digital estate
ThingsRecon maps the technical supply chain — every third-party component detected on the external attack surface via scripts, certificates, DNS, ASN routing, and HTTP headers. These are suppliers standard TPRM questionnaires miss because they were never deliberately onboarded: they arrived embedded in freight management platforms, booking engines, analytics tools, and customer portal templates.
Sector-wide supplier connections757
Across 5 transportation organisations — detected via script, cert, ASN, DNS, and header vectors. The large majority are undeclared in any TPRM register.
Universal suppliers (all 5 orgs)5
Google, Microsoft, GitHub, OpenJS Foundation / jQuery, and Meta Platforms each appear in all 5 transportation organisations.
Fix Now items — most affected org21
Company B (chemical logistics) leads on Fix Now count, driven by application and software findings across its 83-app estate.
Highest Google proximity66%
Google reaches 66% digital proximity at Company A (Belgian road transport) — the highest of any supplier in this benchmark.
Top 5 common suppliers across scanned transportation organisations:
Supplier
Avg proximity
Vector
In
Found in
Google LLCgoogle.com · googleapis.com · maps.google.com
57%
script · header · dns
5/5
Company A, B, C, D, E
Microsoft Corporationmicrosoft.com · azure.com · office365.com
54%
script · header · ASN
5/5
Company A, B, C, D, E
GitHub Inc.github.com · githubusercontent.com
30%
script · header
5/5
Company A, B, C, D, E
OpenJS Foundation / jQueryjquery.com · code.jquery.com
30%
script
5/5
Company A, B, C, D, E
Amazon Technologies, Inc.amazon.com · aws.com
44%
ASN · cert · dns
4/5
Company A, B, C, E
Critical Supplier Spotlight
Google LLC
google.com · googleapis.com · maps.google.com | Avg proximity 57% | Max 66%
Found in
All 5 scanned transportation organisations
Digital proximity
66% max — highest proximity, at Company A
Connection vectors
JavaScript scripts · response headers · DNS · Analytics · Maps API
Logistics risk profile
Maps dependency · Analytics tracking
Google is the most deeply embedded technology supplier across every transportation organisation in this benchmark, reaching an average digital proximity of 57% with a peak of 66% at the Belgian road transport operator. Google Maps Platform powers real-time route planning and shipment tracking interfaces, Google Analytics captures granular freight portal usage data, and Google Cloud hosts freight management workloads. A misconfigured Google OAuth integration or a script injection targeting a Google Analytics tag can provide attackers with a foothold in logistics portal sessions or access to cargo tracking data.
Attack vector: Compromised Google Tag Manager container → malicious script injected into freight booking portal → customer session tokens harvested → authenticated access to shipment data and cargo manifests
Transportation sector attack path — F-rated application to operational disruption
1
Entry point
F-rated freight portal exploited — critical application vulnerability on a publicly accessible booking or tracking system requires no authentication to reach
Entry
No credential required — known-exploitable vulnerability
2
Pivot
Cargo manifests, customer data, and driver assignment records accessed — attacker maps operational routes, shipment schedules, and high-value cargo movements
Pivot
Operational data extracted; tokens used for authenticated access
3
Impact
Cargo theft enabled by advance route intelligence, ransomware deployed against freight management systems, or customer data exfiltrated for fraud
Impact
Sector Findings
Aggregated risk signals across all scanned organisations
The following findings reflect patterns observed across all five transportation organisations. Individual organisation-level findings with full asset detail are available through a full ThingsRecon engagement.
- Fix Now
F-rated applications on freight and logistics portals — One road haulage operator has 6 of its 11 live web applications rated F, with 6 Fix Now application findings. F-rated applications in a transport context include freight booking platforms, customer shipment tracking portals, and driver dispatch interfaces — all containing operationally sensitive cargo data.
- Fix Now
Software Fix Now findings across three organisations — Known-vulnerable JavaScript library versions appear across three of five organisations, totalling 32 Fix Now software items sector-wide. The D-rated road haulage operator carries 13 Fix Now software items alone.
- Fix Now
SSL F rating at road transport operator — One organisation carries an F-rated SSL service — the most severe TLS misconfiguration indicator — on its external estate, representing an immediately exploitable condition on freight portals relying on TLS to protect cargo data.
- Fix Soon
Header D ratings across three organisations — Three of five transport organisations — including two Belgian logistics operators — carry D ratings for HTTP security headers on their customer-facing freight portals and partner APIs.
- Fix Soon
DNS C ratings at three organisations including UK rail freight operator — Transport companies manage complex DNS portfolios spanning customer tracking subdomains, partner API endpoints, and legacy service domains — C-rated DNS indicates misconfigured or dangling records within these portfolios.
- Fix Soon
Cookie D findings across four organisations — D-rated cookies appear across four of five transport organisations, with Fix Soon cookie findings at all five, exposing authenticated sessions on freight and dispatch platforms to client-side theft.
- Monitor
Five universal technology suppliers — undeclared in TPRM registers — Google, Microsoft, GitHub, the OpenJS Foundation, and Meta Platforms appear in all five transportation organisations, typically detected via embedded scripts and cloud infrastructure routing rather than formal vendor contracts.
- Monitor
Certificate C ratings — complex TLS estate across logistics operators — Certificate risk of C appears at three organisations, with D-rated certificates detected at two, creating man-in-the-middle exposure on interfaces carrying cargo data between operators, customers, and partners.
Get the Full Picture
Your organisation's external attack surface — mapped in 24 hours
This sector report shows patterns across five anonymised organisations. A full ThingsRecon engagement gives you the complete asset inventory, supplier proximity map, and prioritised remediation backlog for your own estate — with no agents, no network access, and no internal onboarding required.
✦ Full asset inventory
✦ Application risk grading
✦ Supplier proximity scores
✦ Fix Now / Fix Soon list
✦ NIS2 Article 21 evidence
✦ Continuous monitoring
Request your scan