Menu

Call us on 03450 21 21 51

The Courier, Express and Parcel industry is booming. But cyber security must grow alongside revenues. Here’s why
The SRM Blog

The Courier, Express and Parcel industry is booming. But cyber security must grow alongside revenues. Here’s why

Ian Armstrong

Written by Ian Armstrong

20th January 2021

Share this article

courier cybersecurity

The headline figures for the Courier, Express and Parcel (CEP) sector in 2020 are nothing short of impressive. In fact, with an estimated 23% year-on-year growth (UK) in an economy where many other industries are in dire straits, and there’s good reason for CEP business leaders to be jumping for joy.

But as demand grows and businesses expand, it never takes cyber criminals long to identify a successful industry as a tempting target. And there are many aspects of the CEP sector that makes it appealing to hackers. For one, delivery companies handle vast quantities of personal data on a daily basis – data that has substantial value on the dark web. Secondly, the digital transformations taking place in many CEP businesses, in terms of management systems, parcel tracking apps, handheld devices and enterprise wearables, is taking place fast; and this makes it difficult to ensure that security measures keep pace with productivity.

Already, there have been a number of high-profile attacks in the sector, including one particularly large ransomware attack in Canada back in August. The courier divisions of TFI International, a major North American transportation and logistics firm, reportedly had a significant portion of its 20,000-strong customer database stolen. This was followed by a threat to release the information on the dark web if a ransom was not settled.

October also saw UK courier business Whistl suffer a data breach caused by a cyber attack – thought to be focused on employee information and business financial data. As a result, Whistl notified the ICO under UK law and GDPR (which remained applicable during the Brexit transition period in 2020).

Earlier in 2020, Australian courier company, Toll, was forced to shut down several key systems in order to contain a significant security incident – providing us with another stark example of how breaches can cause financial, operational and reputational damage.

Such fast-moving data and changing demands on a daily basis make CEP organisations particularly hard to protect. And that’s before we consider the challenge presented by returns. Yet as the holders of valuable data and an integral part of the growing supply chain to online retailers, it is crucial that delivery firms up their game. Not least because the penalty of failure to protect data can be many times greater than the cost of taking preventative measures in the first place.

Another consideration for businesses in the sector currently enjoying unprecedented growth is the challenge of preventing insider threats. As more delivery drivers are required, the need to train teams in best practice and rigorously vet personnel becomes paramount.

 

Tackling vulnerabilities early

As we know, supply chains (particularly large and complex ones) can be challenging to secure. Vulnerabilities can be inherent or introduced and they may be exploited at any point. As the likes of retailers lean on the post and parcel industry more and more, the value of keeping every link between merchant and consumer safe is ever increasing.

In order to improve risk posture and reduce the likelihood of a breach, CEP businesses need to first understand their risk exposure, then they need support to establish control, before performing the necessary checks to ensure that the entire chain remains safe and secure. Finally, the key message to any post and parcel organisation is that continuous improvement is essential to maintaining security in a sector that is, in itself, so fast moving.

As leading ISO 27001 consultants our team at SRM are perfectly equipped to guide courier, express and parcel companies through the process of improving security and developing essential processes and procedures. Not only can ISO 27001 compliance provide your CEP business with peace of mind, it also shows other organisations that they can trust you within their own supply chains.

Let us start by offering your courier, express and parcel business a free, no obligation scan today. You can get in touch and we’ll shine a light on where your current vulnerabilities lie.

Contact us