Logistics Guide

If your TMS fails, your forwarding company does too.

Hacker attacks on logistics companies are increasing rapidly. The question is not if your company will be targeted, but when, and if your software is prepared for that.

Almost 80% of logistics companies in Germany have already been affected by a cyber-attack  (Sophos/techconsult, 2025)

On average, the loss per data incident in Germany amounts to €3.87 million  (IBM, 2025)

Cybersecurity in logistics: Why this issue is often underestimated

Digitisation makes forwarding companies more efficient, but also more vulnerable. Numerous managers still view IT security purely as an IT issue. That is risky.

Downtime

Only one successful attack is able to completely shut down your company:

  • Dispatchers can no longer work
  • Order data is no longer accessible
  • Communication with customers and partners breaks down
  • Cybercriminals use AI-supported accesses, phishing attacks or manipulated IoT devices on trailers

In a sector where every hour counts, this means immediate economic loss.

H3: Sensitive data is targeted
Customer data, delivery information, price agreements and contracts: Your data is particularly interesting for cybercriminals. The cost of a data leak is not only money, but also the trust of your customers.

EU compliance: NIS2 and Cyber Resilience Act


Two European rule sets have already become effective and concern logistics companies directly.

NIS2 obliges forwarding companies to:

  • take verifiable safety measures
  • report security incidents
  • create comprehensive documentations
  • hold their management personally liable for violations

The Cyber Resilience Act regulates that software in use must fulfil specific security standards. The risk of those who do not check for these factors doubles.

Complex IT landscapes


Multiple software systems, interfaces to customers and partners as well as external service providers make modern IT landscapes complex. Each additional starting point is a potential gateway for attackers.

Gaps in the software


A frequent misunderstanding: Firewalls and virus scanners alone are sufficient. In practise, however, security gaps are rooted deep in the software itself and are invisible, until an attacker uses them. Reactive measures are too late then.

It is crucial how safe the software is on which you company has built its business. Not all TMS solutions have been developed with the same safety requirements.

What a safe TMS means for your forwarding company

Modern transport management software needs to provide more than planning and dispatch. It needs to protect actively, continuously and without having to think about it constantly.

Find vulnerabilities before hackers do


The software is automatically checked for security gaps, not only after the release but already during development. Attackers cannot find any gateways.

No unexpected breakdowns due to known gaps


Each used software component is continuously checked for new safety risks. Known vulnerabilities are closed before they can turn into problems.

Realistic attack simulations before each version


Before a new version may be released to the customers, security experts test the system externally and internally–as if they were real attackers. Only enduring components are released.

Compliance-ready for NIS2 and other requirements


Structured safety processes, documented tests and precise recommendations for action help you to fulfil regulatory requirements, without any additional internal effort.

Fast reaction to new threats


If a new safety problem arises, the software provider reacts immediately. Security alerts are evaluated and fixed in all supported versions.

How CarLo implements that

 

Step 1: Safety starts with the design

Even before one single line of code is written, product managers and security experts analyse possible attack scenarios. Potential risks are eliminated before they emerge.
Result: Fewer structural vulnerabilities

Step 2: Automatic verification for every update

After each code modification, an automatic system checks the code for safety issues. This way, errors are detected before the software even runs.
Result: Errors are detected before they reach the customer

Step 3: Attack simulation before the release

Professional pentests simulate real hacker attacks from different perspectives. All found vulnerabilities are closed before delivery.
Result: Each release is safety-tested

Step 4: Continuous monitoring during operation

Even after release, the monitoring continues. New known security gaps in used components are automatically detected and fixed.
Result: Constant protection during live usage

You want to dig deeper? Download the technical security factsheet.

For those who would like to go into the details: Security processes, used testing methods and technical insights into the development approach of CarLo.

Cybersecurity at Soloplan–technical security factsheet

A practical document for IT managers and security supervisors in forwarding and logistics companies.

Content:

  • Specific security processes in the development cycle
  • Used testing and analysation methods
  • Threat modelling, SAST, DAST and penetration tests explained
  • Compliance-related information (NIS2, GDPR)

 

Are you ready to lead your forwarding company safely towards the future?

Our experts will be glad to personally show you how CarLo makes your transport processes not only more efficient, but also safer.

Similar articles

Logistics Guide
More information about the blocked content.

You are currently seeing a placeholder content of Smartsupp Chat. To access the actual content, click on the button below. Please note that data will be passed on to third-party providers.

Further information