20,277
Internet-facing assets discovered
Across 5 scanned organisations
975
Supplier connections mapped
script · cert · ASN · DNS · header
216
Fix Now priorities
Requiring immediate action
4/5
Universal suppliers across all orgs
Microsoft · Google · GitHub · jQuery
Why logistics operators carry compounding cyber exposure
Modern logistics operations are digital at their core. Warehouse management systems, transport management platforms, track-and-trace portals, customs and compliance integrations, carrier APIs, and customer self-service portals create sprawling web estates that span dozens — sometimes hundreds — of publicly reachable applications. Each touchpoint is an entry point that sits in the open internet, exposed to reconnaissance and exploitation without an attacker ever needing to breach a perimeter.
Logistics operators also occupy a critical node in global supply chains. They hold freight data, customer PII, EDI connections to hundreds of clients and partners, and in many cases direct integrations with customs authorities and port systems. Compromise of a logistics operator's web estate can ripple outward: spoofed shipment notifications, fraudulent invoice diversion, and access to customer order data are all credible outcomes from external attack surface weaknesses that could be identified and exploited in hours.
This report draws on simultaneous scans of five logistics organisations across Belgium, the Netherlands, and the United Kingdom — spanning automated warehouse systems, port and chemical transport, e-commerce fulfilment, contract logistics, and temperature-controlled cargo operations. The findings reveal a sector where software vulnerabilities are pervasive across all five operators, where security headers are missing from four of five organisations, and where one operator's email infrastructure is critically unprotected — leaving its domains open to spoofing and fraud.
All organisations in this report are anonymised. Technology suppliers and infrastructure providers are named as they appear on the external attack surface.
Sector Benchmark
How do logistics operators compare?
ThingsRecon scanned five logistics organisations simultaneously. Four carry an overall score of C; one carries a D — the only D observed across the benchmark. The variation in individual risk indicators is striking: software risk is D at four of five organisations, header security is D at four of five, and one operator carries a sector-worst Email F rating. Org D, the largest estate scanned, runs 338 publicly exposed applications with 139 Fix Now priorities — the highest single-organisation Fix Now count in this benchmark.
Organisation
Assets
Suppliers
Fix Now
Fix Soon
Key Indicators
Score
Org AAutomated warehouse · NL
3,384
87
16
4
C
App B · Header B
Software D
Org BPort & chemical logistics · BE
2,374
57
20
15
C
Header D · App C
SSL C (3×F-rated)
Org CE-commerce fulfilment · UK
2,575
50
23
1
C
App D · SSL D
Software D · Header D
Org DContract logistics · BE
8,506
119
139
71
C
Header D · Software D
92 F-rated apps
Org ETemperature-controlled cargo · NL
3,438
56
18
44
D
Email F · Header D
Software D
Sector Total5 organisations
20,277
—
216
135
—
Software D: 4/5 orgs
Header D: 4/5 orgs
Sector-wide Risk Patterns
Where the sector is consistently exposed
Looking across all five organisations simultaneously, two risk categories stand out as systemic failures rather than isolated weaknesses. Software vulnerabilities and missing security headers appear at nearly every operator — irrespective of estate size or geography — pointing to sector-level underinvestment in web security hygiene.
Software Risk
Critical — 4/5
All five organisations carry D-rated software risk. Outdated JavaScript libraries, unpatched server components, and vulnerable third-party dependencies are embedded across logistics web estates, creating persistent client-side and server-side attack vectors. Across the sector, 91 software-linked Fix Now items require immediate remediation.
Header Security
High — 4/5
Four of five organisations score D for header risk. Critical protections — Content Security Policy, X-Frame-Options, Strict-Transport-Security, and Referrer-Policy — are missing or misconfigured across significant portions of each estate. This leaves logistics portals and customer-facing applications exposed to clickjacking, injection, and information leakage attacks.
Application Risk
High — Orgs C & D
Org C's application estate scores D overall; 6 of its 11 publicly reachable web applications are rated F — a failure rate of 55%. Org D, the sector's largest operator, runs 338 applications of which 92 are F-rated and 36 D-rated, totalling 128 applications with serious ratings. Combined application Fix Now priorities across these two organisations exceed 160 items.
Email Authentication
Critical — Org E
Org E is the only organisation in this benchmark carrying an F for email risk. With no email authentication controls in place, its domain can be exploited to conduct spoofed communications against customers, carriers, and regulatory authorities. This is particularly damaging in a sector where email is a primary channel for shipment updates, proof-of-delivery notices, and payment instructions.
SSL Services
Medium — Orgs B & C
Org B has three F-rated SSL services; Org C's SSL service risk rates D overall. Misconfigured or deprecated TLS on externally reachable services undermines transport-layer security for partner integrations and API endpoints — a particular concern for EDI connections and carrier API traffic.
Sector verdict: Software vulnerability debt is the defining risk pattern across this logistics benchmark. Combined with widespread header misconfiguration, the sector's external web estate presents an attacker with multiple low-effort, high-value entry points — particularly at operators running large numbers of applications with inconsistent security controls.
Three Pillars of Risk
The structural vulnerabilities defining this sector
The five organisations scanned collectively expose 476 web applications to the public internet. Org D alone runs 338 — of which 128 carry F or D ratings. At this scale, consistent security policy enforcement becomes operationally difficult, and gaps multiply silently across teams and geographies.
01
Fragmented Application Estates
The five organisations scanned collectively expose 476 web applications to the public internet. Org D alone runs 338 — of which 128 carry F or D ratings. At this scale, consistent security policy enforcement becomes operationally difficult, and gaps multiply silently across teams and geographies.
02
Software Component Debt
Four of five logistics operators carry D-rated software risk. Unpatched JavaScript libraries, outdated CMS versions, and vulnerable server components embedded in logistics portals provide attackers with known, documented exploit paths — without requiring any novel technique. This is the sector's highest-volume Fix Now category, with 91 immediate remediation items identified.
03
Email Infrastructure Blind Spot
Org E's F-rated email configuration means its domain can be weaponised to send fraudulent shipping notifications, delivery confirmation requests, or payment instructions without technical detection. In a sector where email is the primary customer communication channel, this is a direct enabler of business email compromise at scale — targeting the operator's entire customer and partner network.
NIS2 Directive — Important Entities
Logistics operators providing transport and warehousing services qualify as important entities under NIS2 Annex II (transport sector). The Directive — enforceable across EU member states from October 2024 — requires systematic risk management, incident reporting within 24 hours, and demonstrable control over supply chain cyber risks. Email authentication failures, widespread software vulnerabilities, and unprotected public-facing applications each represent concrete NIS2 compliance gaps that national competent authorities are empowered to investigate and sanction.
The technology layer connecting logistics operators
975 supplier connections were mapped across the five organisations. Four suppliers — Microsoft, Google, GitHub, and jQuery — appear in every organisation's external estate, forming a shared technology layer that underpins logistics operations across Belgium, the Netherlands, and the UK regardless of business model or estate size.
Total supplier connections975
Across 5 logistics organisations · script, cert, ASN, DNS, header
Unique connected suppliers~200+
Sector-wide vendor footprint
Universal suppliers (5/5 orgs)4
Microsoft · Google · GitHub · jQuery
Highest single-org count354
Org D (contract logistics) · 119 unique suppliers
Supplier
In sector
Max proximity
Category
Significance
Microsoft Corporationmicrosoft.com
59% at Org E
Cloud · Infra
5 / 5
Azure hosting, M365 mail, Active Directory — deeply embedded in logistics infrastructure and operational tooling
Google LLCgoogle.com
55% at Org D
Analytics · Cloud
5 / 5
Google Analytics, Tag Manager, Workspace services, and cloud APIs present across every logistics web estate
GitHub Inc.github.com
45% at Org D
Dev · CDN
5 / 5
Front-end assets and developer tooling served from GitHub across all five organisations; proximity peaks at the largest estate
OpenJS Foundation / jQueryopenjsf.org
45% at Org D
Library · Script
5 / 5
jQuery embedded across logistics portals and booking systems; outdated versions contribute directly to D-rated software risk at multiple orgs
Amazon Technologies (AWS)amazon.com
62% at Org B
Cloud · CDN
4 / 5
AWS infrastructure underpins logistics platforms, API gateways, and content delivery for four of the five organisations scanned
Supplier Spotlight — Universal Presence
Microsoft Corporation
microsoft.com | Present in 5/5 logistics organisations | Avg proximity 55%
Sector presence
All 5 / 5 organisations — the highest universality score of any supplier in this benchmark
Digital proximity range
49% (Org C) → 59% (Org E) — classified as High across every organisation
Connection vectors
Azure cloud hosting, Microsoft 365 mail infrastructure, authentication services, CDN delivery, and embedded scripts
Highest proximity
59% at Org E (temperature-controlled cargo) — the same operator carrying an Email F rating on its Microsoft-hosted mail domain
Microsoft's universal presence across this logistics benchmark is both a strength and a concentration risk. Its cloud infrastructure, mail services, and authentication platforms are embedded in the operational fabric of every organisation scanned. At Org E, where Microsoft proximity peaks at 59% and email authentication is rated F, a compromise or spoofing of Microsoft-associated mail infrastructure could cascade across the entire customer and partner network. Logistics operators relying on Microsoft for both operational tooling and external communications should treat email authentication hardening as a non-negotiable baseline control.
Primary attack vector: email spoofing → freight invoice fraud · phishing of logistics customers · business email compromise via unprotected Microsoft-hosted domains
Illustrative Attack Path
1
Reconnaissance
External estate enumeration — 476 applications, 20,277 assets publicly visible
Entry
2
Initial Access — Email Spoofing
Org E's Email F rating enables domain spoofing; fraudulent shipment notifications or invoice requests sent to customers
Critical
3
Application Exploitation
Org C: 6 of 11 web apps rated F; Org D: 92 F-rated apps across logistics portals and partner systems
Pivot
4
Software Component Exploitation
D-rated software at all 5 orgs; known CVEs in jQuery and server components exploitable client-side without authentication
Pivot
5
Impact
Freight data, customer PII, WMS/TMS access, EDI partner connections, payment diversion
Impact
Sector Findings
Priority issues identified across the logistics benchmark
- Fix Now
Software vulnerabilities sector-wide — All five logistics organisations carry D-rated software risk. 91 software-linked Fix Now priorities identified across the benchmark, driven by outdated JavaScript libraries (including jQuery) and unpatched server components embedded in logistics portals, booking systems, and customer-facing applications. These represent known CVEs with documented exploit paths.
- Fix Now
Org D — 139 Fix Now priorities across 338 applications — The sector's largest estate carries the highest single-organisation Fix Now count in this benchmark. Of 338 publicly reachable applications, 92 are F-rated and 36 carry D ratings. At this scale, attack surface management without systematic tooling is not operationally achievable.
- Fix Now
Org E — Email F: domain open to impersonation — No SPF, DKIM, or DMARC records detected. This temperature-controlled cargo operator sends high-value business communications — delivery confirmations, customs documentation requests, and freight invoices — over an unprotected mail domain. Any party in its supply chain can be targeted with a spoofed communication that bypasses email security controls.
- Fix Soon
Org C — 6 of 11 web applications rated F — This e-commerce fulfilment operator has a small but critically exposed web estate. With application risk D, SSL service risk D, and software risk D, Org C's public footprint presents a high-density concentration of serious issues on a limited number of targets — making it straightforward to prioritise for an attacker focused on this operator.
- Fix Soon
Security headers missing from 4/5 organisations — Header risk is D at Orgs B, C, D, and E. Absent Content Security Policy, HSTS, X-Frame-Options, and similar controls leave logistics portals open to clickjacking attacks, cross-site scripting amplification, and information leakage — weaknesses that compound the damage potential of the software vulnerabilities already identified.
- Fix Soon
Org B — Three F-rated SSL services — Deprecated TLS configurations on externally reachable SSL services at this port logistics operator undermine the security of encrypted connections from carrier integrations and partner API traffic. Combined with Header D and Application risk C (6 F-rated apps), Org B presents a consistent pattern of web security underinvestment.
- Monitor
Amazon Web Services concentration risk across 4/5 organisations — AWS infrastructure underpins logistics platforms at four of the five organisations scanned, with digital proximity reaching 62% at Org B. Shared cloud infrastructure dependency across a sector that operates critical supply chain nodes creates correlated disruption risk if AWS availability or security events occur.
Unlock Your Organisation's Full Report
See exactly where your logistics operation is exposed
ThingsRecon scans your external attack surface from the outside in — no agents, no credentials, no internal access required. Within hours you receive a full picture of your web estate, supply chain dependencies, and prioritised remediation roadmap.
✦ Named asset inventory
✦ Fix Now / Fix Soon roadmap
✦ Supply chain exposure map
✦ Competitor benchmarking
✦ NIS2 gap assessment
✦ Email authentication audit
Request your scan