THANK YOU FOR SUBSCRIBING
A featured contribution from Leadership Perspectives, a curated forum for enterprise security leaders, nominated by our subscribers and vetted by the Enterprise Security Magazine Editorial Board.



Information Security, or Info Sec for short, has climbed the ladder of strategic relevance on many companies in many sectors and industries, especially for those highly exposed to digital risks because their business is digital either based or heavily rely on IT systems to efficiently operate or just to simply operate! We are used to seeing structured InfoSec programs on sectors such as finance, healthcare, critical infrastructures, and utilities but as digital moves deep into all types and sizes of businesses and organizations, addressing digital risks is becoming a top priority not only for CIOs or tech leaders but for the company as a whole.
Myself as a tech leader in a logistics company, I have been offered a first-row seat on how this concern is turning InfoSec as a main strategic pillar in logistics. Before you say ‘only now you see that?!,’ allow to clarify that for longa time, cyber and digital resilience had a central role in developing businesses in logistics, but turning into a strategic pillar is a completely different level since that implies placing digital risks in the core decisions of a company.
From that first-row seat I mentioned early I see three main pressure vectors that are pushing InfoSec into the core of the strategy:
Business Continuity: LSP, 3PL, freight forwarders and all kind of logistic providers fully rely on digital platforms to execute their operations such as Transport Management Systems, Warehouse Management Systems, ERP, middleware stacks for system integrations etc. Those business applications depend on computing technology, being on-prem or cloud, to function in a secure and performant way. That means that digital assets are the top risks for business continuity, so protecting them, having disaster and recover plans and having a continuous risk management strategy for those assets, is now a must have and not only a plus.
“A successful infosec program can be the enabler for a more competitive company by improving efficiency, better addressing risks, preventing reputational damages and be ready for a business environment that is more and more digital.”
Regulatory and Legal: For those operating in the European space, the NIS2 regulation, is a reinforcement on how cyber resilience is in the political and governmental arena now. Transportation was already considered an important sector, but now the regulation contemplates fines and executive bodies of organizations can be considered personally liable. Just like personal data protection regulation back in 2018, now cyber and network security must be addressed in a regulatory perspective.
Customers and Market: If the first two were not sufficient to create awareness, customers and market itself will certainly do. A logistics service provider stands in the middle and oftenin a very wide extension of supply chains and value chains, so one should expect to address demanding requirements from the top tier player of a chain. (Some) European automotive companies follow the TISAX referential, Pharma & Healthcare the GxP standards and B2C, such as the e-commerce, retail and consumer goods, require robust and effective personal data protection controls. InfoSec requirements are moving from orders winners to order qualifiers, and those who develop businessin logistics companies are being more and more challenged.
For a logistics company to address this reality in a structured and cost-efficientway and avoid the trap of flowing between adhocand uncoordinated/unrelated initiatives, InfoSec should be in the core the organization strategy in the form a coordinated program aligned with the business goals. A successful infosec program can be the enabler for a more competitive company by improving efficiency, better addressing risks, preventing reputational damages and be ready for a business environment that is more and more digital.