Organizations in the transportation sector filed 80 ransomware complaints and 82 data breach complaints with the FBI's Internet Crime Complaint Center in 2025, according to the FBI 2025 Internet Crime Report, published in April 2026. In Canada, the Canadian Centre for Cyber Security recorded a 122 percent rise in ransomware incidents in transportation from 2022 to 2023 in its National Cyber Threat Assessment 2025-2026. And one transportation rule now makes the test mandatory: under the US Coast Guard's cybersecurity rule for the Marine Transportation System, owners and operators of US-flagged vessels and MTSA-regulated facilities must complete a penetration test with each Cybersecurity Plan renewal, and the first plans are due by 16 July 2027.
Where Stingrai fits: Stingrai is a CREST-accredited penetration testing service provider at firm level, headquartered in Toronto with a London office and founded in 2021. Two named penetration testers from a team holding OSCE³, OSWE, OSEP, CREST CRT and CISSP staff each human-led engagement, backed by 18 published CVEs. For a carrier, 3PL, freight broker or terminal operator that means the external perimeter and the remote access that drivers, dispatchers and vendors use; segmentation testing between corporate IT and warehouse, terminal or vessel networks; Active Directory and Microsoft 365 with Entra ID; authorization testing across every shipper, carrier and broker role in booking and tracking portals and partner APIs; and phishing and vishing aimed at dispatch, carrier onboarding and the people who change payment details. It is delivered as a one-time annual engagement or a continuous program through the PTaaS portal, with retesting and an attestation letter included. Published pricing is US$3,000 for an Autonomous Pentest and US$6,800 for a Hybrid Pentest covering one web application and its APIs (pricing); network, OT boundary, red team and multi-site scopes are quoted.
Quick answer: who are the best penetration testing companies for logistics and transportation in 2026?
The best penetration testing companies for logistics and transportation in 2026 are Stingrai, NCC Group, IOActive, Pen Test Partners, Raxis, Dragos, GuidePoint Security, Kroll, ABS Consulting and Bishop Fox. Stingrai ranks first for named, certified penetration testers across the IT, cloud, portal and people side of freight and transport operations, with retesting and an attestation letter included, one-time or continuous. NCC Group, IOActive and Pen Test Partners follow for fleet-scale maritime testing, research-led testing of vessel, aircraft and rail systems, and a transport practice that spans aviation, maritime, rail and logistics.

What logistics and transportation operators are actually required to test
Of the published rules in either country, one makes a penetration test mandatory for a transportation operator, and it covers only US-flagged vessels and Coast Guard-regulated facilities. TSA's rail directive names penetration testing as one example of what an assessment plan can include. TSA's 2023 aviation amendment is not public. Everything else asks for assessments, regular testing, plans and incident reporting without naming a penetration test, which is why most logistics and freight testing arrives through customer contracts and trade programs.
US Coast Guard: 33 CFR part 101, subpart F
The Coast Guard published its final rule, Cybersecurity in the Marine Transportation System, on 17 January 2025 at 90 FR 6298, effective 16 July 2025. It applies to owners and operators of US-flagged vessels, facilities and Outer Continental Shelf facilities that must have a security plan under 33 CFR parts 104, 105 and 106, and not to foreign-flagged vessels (section 101.605). Section 101.650(e)(2) is the only published transportation requirement in this guide that makes the test mandatory:
(2) Penetration testing. In conjunction with Cybersecurity Plan renewal, the owner, operator, or designated CySO must ensure that a penetration test has been completed. Following the penetration test, a letter certifying that the test was conducted, as well as all identified vulnerabilities, must be included in the VSA, FSA, or OCS FSA, in accordance with 33 CFR 104.305, 105.305, and 106.305.
An approved plan is valid for five years (section 101.630(d)(3)), so the test falls at least once in each approval cycle. The regulatory text ties the test to renewal; the Coast Guard's cost analysis (90 FR 6298) also assumed a test with the first plan submission, so confirm the expectation with the Captain of the Port (COTP), Officer in Charge, Marine Inspections (OCMI) or Marine Safety Center that approves your plan. Penetration test results must be available to the Coast Guard on request (section 101.660). The rule defines a penetration test as "a test of the security of a computer system or software application by attempting to compromise its security and the security of an underlying operating system and network component configurations" (section 101.615).
The compliance dates in the current text, which the eCFR shows unamended since 16 July 2025: cybersecurity training for all personnel by 12 January 2026 and annually after that (section 101.650(d)(4)); a Cybersecurity Assessment no later than 16 July 2027 and annually after that, sooner on a change of ownership (section 101.650(e)(1)); and Cybersecurity Plans submitted for approval no later than 16 July 2027 (section 101.655). The final rule asked for comment on a possible delay for US-flagged vessels, and no delay or amendment had been published in the Federal Register as of 1 October 2026.
The rest of section 101.650 reads like a test plan: multifactor authentication on password-protected IT and remotely accessible OT, segmentation between IT and OT with every connection logged and monitored, no OT on the public internet without a documented justification, monitoring of every third-party remote connection, and known exploited vulnerabilities in critical systems patched or mitigated without delay. A penetration test is the most direct way to show those controls work before the Captain of the Port asks.
TSA security directives for freight and passenger rail
TSA regulates rail cybersecurity through security directives, not regulations. The current SD 1580/82-2022-01E, Rail Cybersecurity Mitigation Actions and Testing, took effect on 3 May 2026 and expires on 2 May 2027. It applies to the freight railroads in 49 CFR 1580.101 (Class I railroads, railroads carrying rail security-sensitive materials in a high threat urban area, and their host railroads) and to other freight and passenger railroads TSA designates. Each must run a TSA-approved Cybersecurity Implementation Plan covering segmentation so operational technology keeps running if IT is compromised, access control, continuous monitoring and risk-based patching, and must treat Positive Train Control as a Critical Cyber System where it operates PTC.
Section III.F requires a Cybersecurity Assessment Plan with a cybersecurity architecture design review within the first 12 months after plan approval and at least once every two years after that, and "other assessment capabilities designed to identify vulnerabilities based on evolving threat information and adversarial capabilities, such as penetration testing of Information Technology systems, including the use of 'red' and 'purple' team (adversarial perspective) testing." At least one third of the plan's measures must be assessed each year, and 100 percent over any three-year period, with an annual report to TSA that names the assessment methods used and their results.
The companion directives SD 1580-21-01E for freight rail and SD 1582-21-01E for passenger rail and rail transit, effective 16 January 2026 to 15 January 2027, require a Cybersecurity Coordinator, incident reports to CISA no later than 72 hours after an incident is identified, a Cybersecurity Incident Response Plan and a one-time vulnerability assessment on a TSA form. TSA's September 2026 notice on the related information collection states that the 1580-21-01 and 1582-21-01 series remain in effect and lists the 2022-01 series' plan and report collections as current.
TSA's proposed surface cyber rule
TSA's proposed rule, Enhancing Surface Cyber Risk Management, published on 7 November 2024 at 89 FR 88488, would turn the rail directives into regulation. TSA estimated it would apply a full cyber risk management program to 73 of the approximately 620 freight railroads and 34 of the approximately 92 public transportation agencies and passenger railroads operating in the United States, require 71 over-the-road bus owner/operators to report cybersecurity incidents, and cover 115 pipeline systems and facilities. The proposed Cybersecurity Assessment Plan repeats the directive's penetration testing example and adds that assessments must not be conducted by "individuals who have oversight or responsibility for implementing" the program.
Comments closed on 5 February 2025. As of 1 October 2026 the Federal Register shows no final rule. TSA's entry in the 2026 Unified Agenda, released on reginfo.gov with the 2026 Regulatory Plan (introduction published in the Federal Register on 14 August 2026), lists it as a long-term action with the final rule "To Be Determined", and TSA's section of that Regulatory Plan lists three other actions for fiscal year 2026. Until a final rule appears, the directives are what binds.
TSA cybersecurity measures for airports and airlines
On 7 March 2023 TSA issued an emergency amendment to the security programs of certain airport and aircraft operators. TSA's announcement says covered operators must have an approved implementation plan covering segmentation between IT and OT, access control, continuous monitoring and patching, and must "proactively assess the effectiveness of these measures", on top of earlier requirements to report significant incidents to CISA, name a cybersecurity point of contact, adopt an incident response plan and complete a vulnerability assessment. The amendment itself is not published, so whether it names penetration testing cannot be confirmed from public sources. Airline and airport testing should be scoped to the assessment program the operator has agreed with TSA.
CTPAT for carriers, 3PLs, brokers and terminals
US Customs and Border Protection's Customs Trade Partnership Against Terrorism is voluntary, and its "Must" criteria are mandatory for members. The minimum security criteria are published separately for highway, rail, sea and air carriers, third party logistics providers, customs brokers, consolidators, and marine port authorities and terminal operators. Criterion 4.3 is a "Must" in every version we checked, including the 3PL criteria of October 2021: "CTPAT Members using network systems must regularly test the security of their IT infrastructure. If vulnerabilities are found, corrective actions must be implemented as soon as feasible." The guidance describes vulnerability scanning and testing whenever the network changes, and the criteria do not mention penetration testing. Criterion 4.2 also requires "policies and procedures to prevent attacks via social engineering", which matters for freight fraud.
Canada: Bill C-8 and the Critical Cyber Systems Protection Act
Bill C-8 received royal assent on 15 June 2026 as Statutes of Canada 2026, chapter 9, and Schedule 1 of the Critical Cyber Systems Protection Act it enacts lists "Transportation systems that are within the legislative authority of Parliament" among six vital services and systems. The Act is not in force: the Justice Laws consolidation, current to 21 September 2026, marks it not in force, and Schedule 2, which will list the classes of designated operators, is empty. Once a class is designated, its operators get 90 days to establish a cyber security program, must report incidents to the Communications Security Establishment within a prescribed period of no more than 72 hours and keep records in Canada, with penalties of up to C$15 million per violation, and the Minister of Transport is one of the six named regulators. The Act never mentions penetration testing. Our Bill C-8 guide covers the obligations section by section.
Canada: Marine Transportation Security Regulations
Canada's Marine Transportation Security Regulations, current to 21 September 2026 and last amended in 2014, require a vessel security assessment to address "its radio and telecommunication systems, including computer systems and networks" (section 233), the same element in a marine facility security assessment (section 318), and a vulnerability assessment that considers "the procedures to protect radio and telecommunications equipment, including computer systems and networks" (section 321). The regulations do not mention cyber security or penetration testing.
Canada: Partners in Protection
The Canada Border Services Agency's Partners in Protection program asks applicants to document firewalls, antivirus software, password policies, secure access for remote workers, device inventory and disposal, a cyberattack response plan and access removal when an employee leaves. It does not ask for a test.
PIPEDA and Quebec Law 25
Carriers and brokers that hold driver, customer and consignee data answer to PIPEDA, whose Principle 4.7 requires "security safeguards appropriate to the sensitivity of the information", whose section 10.1 requires a report to the Privacy Commissioner of any breach creating a real risk of significant harm, and whose breach regulations require a record of every breach for 24 months. Quebec's private sector act, as amended by Law 25, requires reasonable security measures (section 10) and prompt notice to the Commission d'accès à l'information of incidents presenting a risk of serious injury (section 3.5). Neither names a test.
Rule | Names penetration testing? | Cadence | What the evidence has to show |
|---|---|---|---|
Coast Guard, 33 CFR 101.650(e)(2) | Yes | With each Cybersecurity Plan renewal; plans approved for 5 years | A letter certifying the test was conducted and all identified vulnerabilities, filed in the VSA, FSA or OCS FSA |
TSA SD 1580/82-2022-01E (rail) | As an example of an assessment capability | Architecture review every 2 years; one third of measures a year, all within 3 years | Annual report of assessment methods and results |
TSA SD 1580-21-01E and 1582-21-01E | No | One-time vulnerability assessment | Coordinator, 72-hour reporting to CISA, incident response plan |
TSA surface cyber rule (proposed) | As an example; not final | Proposed annual plan and report | Independent assessors |
TSA aviation amendment (2023) | Not public | Not public | Assessment of implementation plan measures |
CTPAT criterion 4.3 | No | Regular, and on network change | IT infrastructure tested and vulnerabilities fixed |
Critical Cyber Systems Protection Act | No; not in force | Annual program review once designated | Program, 72-hour incident reports, records in Canada |
Marine Transportation Security Regulations | No | With each security assessment | Computer systems and networks addressed |
Partners in Protection | No | Annual profile review | Cyber controls and a response plan |
PIPEDA and Quebec Law 25 | No | None | Reasonable safeguards; breach reports and records |
What the 2022 to 2026 incident record shows

The FBI chart counts complaints, not attacks, and the Cyber Centre judges that ransomware actors choose victims by opportunity rather than sector. The organizations' own disclosures show where transport and logistics attacks land:
Expeditors, February 2022. In its first-quarter 2022 report, the freight forwarder said it shut down most of its systems globally after a targeted cyber-attack and had "limited ability to conduct operations for a period of approximately three weeks", incurring about US$40 million in incremental demurrage charges and about US$20 million in investigation, recovery, remediation and shipment claim costs in the quarter.
Port of Seattle, August 2024. The port, which runs Seattle-Tacoma International Airport and maritime facilities, attributed the attack to the Rhysida ransomware group and in April 2025 began sending about 90,000 notices; the data came from "previously used Port systems for employee, contractor, and parking data".
WestJet, June 2025. The airline found "a sophisticated, criminal third party" in its systems on 13 June 2025; data obtained included names, contact details and "information and documents provided in connection with their reservation and travel", but no payment card numbers or passwords, according to WestJet's update.
Collins Aerospace, September 2025. RTX reported ransomware on systems supporting its MUSE passenger processing software, which lets airlines share check-in, gate and baggage resources at airports; customers "shifted to back-up or manual processes" with flight delays and cancellations.
Russian GRU unit 26165, 2022 to 2025. A joint advisory co-sealed by the Canadian Centre for Cyber Security says the unit targeted "dozens of entities" across "air, sea, and rail" in 13 countries including the United States, got in through credential guessing, spearphishing and exploitation of corporate VPNs and other internet-facing systems, and went after "additional entities in the transportation sector that had business ties to the primary target".
Fraud is the other half of the picture. Verisk CargoNet recorded 3,594 supply chain crime events across the United States and Canada in 2025, with estimated losses of nearly US$725 million, up 60 percent, and expects "theft by deception groups" to focus on "misdirecting shipments tendered to legitimate carriers" (CargoNet, January 2026). The FMCSA's Motus registration system, announced on 19 May 2026, adds identity checks with government-issued ID and facial scans because, under the old process, "All they needed was an email, name, and physical address" (FMCSA). Business email compromise cost US$3.05 billion across 24,768 complaints to the FBI in 2025, as our BEC statistics detail.
The logistics and transportation attack surface: what a good scope covers
A test that stops at the corporate firewall misses where freight, passengers and payments actually move.

Transportation and warehouse management systems. TMS, WMS and yard management hold every load, rate and dock appointment. Test authentication, role separation between dispatch, warehouse and finance users, and how far integration service accounts reach.
EDI and partner APIs. Tenders, status messages and invoices flow through EDI gateways, file transfer drop points and REST APIs to shippers, carriers and brokers. Test that one partner's credentials cannot read or change another partner's shipments, the authorization flaw scanners miss, as our BOLA and IDOR guide explains.
Customer, carrier and broker portals. Booking, tracking, quoting, document upload and payment portals must keep every shipper, carrier and consignee out of each other's data, across every role.
Telematics, fleet platforms and driver apps. Fleet management and telematics platforms, and driver and proof-of-delivery apps on iOS and Android, along with the backend APIs they call.
Warehouse automation and the OT boundary. Sorters, conveyors, automated storage and their PLC networks. Active testing belongs on the IT side and at the boundary; inside OT, use passive and architecture-led methods under strict rules of engagement, as our red team rules of engagement checklist sets out.
Ports, terminals and vessels. Terminal operating systems, gate systems, vessel IT and OT, and satellite links, the critical IT and OT systems a Coast Guard Cybersecurity Plan has to cover.
Rail and aviation operations. Dispatch and crew systems and the Positive Train Control environment the TSA rail directive calls a Critical Cyber System; common-use check-in, gate and baggage systems at airports, often run by a supplier.
Microsoft 365, Entra ID and Active Directory. Dispersed terminals, yards and depots run on shared accounts and legacy authentication. Test Conditional Access exceptions, consent grants and Kerberos and delegation paths to domain admin.
Remote and vendor access. VPNs, remote support tools and equipment makers' connections into OT; the Coast Guard rule requires every third-party remote connection to be monitored and documented.
Freight fraud and carrier-identity BEC. Test carrier onboarding, the process for changing remittance details, help desk password resets and lookalike domains with phishing and vishing, as our social engineering testing guide describes.
How we ranked them
Ten vendors were scored against ten criteria. Every accreditation was checked on the CREST Marketplace, and every vendor entry links to a page on the vendor's own site, verified on 1 October 2026.
Published transportation or logistics security work on the vendor's own site: a sector page, case study or sector-specific service.
Firm-level accreditation on the CREST Marketplace.
Coverage of the attack surface above, from portals and APIs to the OT boundary and people.
Safe testing near operations, with published practice for live OT, vessel and rail systems.
Named testers, identified with their certifications before signing.
Retest policy stated in writing.
Delivery: a findings portal, and both one-time and continuous options.
Evidence regulators and customers accept, from a Coast Guard test letter to input for a TSA assessment report and CTPAT criterion 4.3.
North American delivery in the United States, Canada or both.
Independence from the operator's IT provider, OT vendor and plan author.
The 10 companies at a glance
# | Company | HQ | Accreditations (CREST Marketplace) | Delivery model | Named testers | Retest | Published pricing | Best for |
|---|---|---|---|---|---|---|---|---|
1 | Stingrai | Toronto, ON (London, UK office) | Penetration Testing, firm level | Human-led, hybrid or autonomous; one-time or continuous; PTaaS portal | Yes, two per human-led engagement | Included | Yes, US$3,000 and US$6,800 | IT, cloud, portals and people at carriers, 3PLs and terminals |
2 | NCC Group | Manchester, UK (Chicago regional HQ; Waterloo, ON office) | Penetration Testing, Threat Led Penetration Testing, Incident Response and more | Consultant-led plus autonomous testing at scale; portal | Not stated | Not stated | No | Fleet-wide and maritime programs |
3 | IOActive | Seattle, WA | Penetration Testing | Research-led assessments; hardware labs | Not stated | Not stated | No | Vessel, aircraft and rail systems |
4 | Pen Test Partners | Buckingham, UK (New York office) | Penetration Testing, Threat Led Penetration Testing, Incident Response, application and mobile testing | Consultant-led; PTaaS; portal | Not stated | Not stated | No | One specialist across aviation, maritime, rail and logistics |
5 | Raxis | Atlanta, GA | Not listed | Point-in-time or continuous; Raxis One portal; on-site test device | Team bios published | Included | No | US carriers, transit and logistics firms |
6 | Dragos | Washington, DC | Not listed | OT assessments, penetration testing and purple team; platform | Not stated | Not stated | No | Rail, transit and maritime OT |
7 | GuidePoint Security | Reston, VA | Penetration Testing | Consultant-led plus PTaaS | Not stated | Shown in a case study | No | Aviation services and multi-site operators |
8 | Kroll | New York, NY (Toronto office) | Penetration Testing, Incident Response, Security Operations Centre | Consultant-led beside MDR and incident response | Not stated | Not stated | No | Testing next to an incident response provider |
9 | ABS Consulting | Spring, TX | Not listed | Maritime OT consulting with testing | Not stated | Not stated | No | Ports, terminals and MTSA facilities |
10 | Bishop Fox | Tempe, AZ | Penetration Testing | Consultant-led plus continuous platform | Not stated | Not stated | No | Travel and transport technology platforms |
"Not stated" means the vendor's own site does not say. Ask for it in writing.
1. Stingrai
Stingrai is a global CREST-accredited penetration testing services company founded in Toronto, Canada in 2021, trusted by companies from startups to enterprises to meet audit requirements for SOC 2, ISO 27001, CMMC, PCI DSS and HIPAA. OSCE³, OSWE, OSEP, CREST CRT certified pentesters, who are also world-class security researchers and bug bounty hunters. Choose from fully human-led or hybrid (AI agents plus human penetration testers) engagements across web, API, mobile, AI and LLM, cloud, network, Active Directory and social engineering penetration tests and red team engagements.
What a carrier's security committee can check. The firm-level accreditation is on the CREST Marketplace supplier page for Stingrai Inc, separate from the CREST CRT certifications individual testers hold. Stingrai is rated 5.0 out of 5 across 20 reviews on Clutch. The team has published 18 CVEs, including CVE-2025-50674, a local root vulnerability in OpenMediaVault, and CVE-2024-32136, an SQL injection in a WordPress plugin, and team members are listed in the Halls of Fame of Apple, Google, the US Department of Defense and the US Federal Reserve. Two named penetration testers run each human-led engagement, reviewed by the team lead and an engagement partner, under founder Arafat Afzalzada, who has 11 years in offensive security.
How a logistics or transportation engagement is tested. Network testing covers the external perimeter, including the VPNs and remote access that drivers, dispatchers and vendors use, then lateral movement inside and segmentation testing that shows whether the corporate network can reach warehouse, terminal or vessel systems. The Active Directory assessment follows ACL abuse and Kerberos and delegation paths to domain admin, and cloud testing covers AWS, Azure with Entra ID and Google Cloud, including consent grants and Conditional Access gaps. Booking, tracking and carrier onboarding portals and partner APIs are tested black, grey or white box, authenticated across every shipper, carrier, broker and consignee role, for broken authorization, IDOR and business logic. Mobile testing covers driver and proof-of-delivery apps on iOS and Android with their backend APIs, and Wi-Fi assessments cover warehouses and yards, on-site or remote. Phishing and vishing campaigns test dispatch, carrier onboarding and the people who change payment details, physical assessments test facility entry, and red teaming runs assumed breach, black-box full chain or threat intelligence-led scenarios.
Evidence and delivery. Findings post to the PTaaS portal as they are confirmed, each with a working proof of concept and remediation guidance, with live chat to the assigned testers and Jira and Slack integration. Reports are redactable, which matters when a shipper's security team asks for evidence and the Coast Guard treats a Cybersecurity Plan as sensitive security information. Retesting is included, and every human-led and hybrid report ships with an attestation letter and a verified badge, which an owner can file with the findings when the Coast Guard rule asks for a letter confirming the test in the vessel or facility security assessment. Stingrai runs both one-time annual engagements timed to a plan renewal or customer audit and continuous programs that test after every change, such as a new terminal, an acquisition or a new EDI partner.
Where Snipe fits. Snipe, Stingrai's autonomous AI penetration testing agent for web applications and their APIs, covers the booking, tracking and carrier portals and the APIs behind them. It hunts broken authorization, IDOR and business logic flaws, reviews code, and opens AutoFix pull requests. The Autonomous tier is Snipe alone, with no penetration testers; in a Hybrid engagement Snipe and the penetration testers test together throughout, with the testers directing its focus. Networks, Active Directory, cloud, the OT boundary, Wi-Fi and social engineering are tested by penetration testers.
Pricing: US$3,000 for an Autonomous Pentest and US$6,800 for a Hybrid Pentest per assessment of one web application and its APIs, or US$650 and US$1,275 per month on 12-month continuous plans, on the pricing page. Every other scope is quoted through get a quote.
Strength: every claim a shipper's or regulator's reviewer will ask about has a public source, from the CREST listing to the CVE records. Limitation: Stingrai's published services stop at the IT side of the OT boundary, so device-level testing of PTC, ship control or warehouse PLC networks belongs with an OT specialist such as Dragos or IOActive, and the fixed-price packages cover web applications and their APIs only. Best for: carriers, 3PLs, freight brokers, terminal operators and transport technology vendors in the US and Canada that need named, certified penetration testers across IT, cloud, portals and people, with a retest and an attestation letter, one-time or continuous.
2. NCC Group
NCC Group is headquartered in Manchester, England, with its North American regional headquarters at 11 E Adams Street in Chicago and a Canadian office in Waterloo, Ontario. Its most relevant published work for this sector is a case study, Securing an Entire Fleet Through Scalable Network Penetration Testing, for a global transportation operator in maritime transportation and logistics whose vessels each ran their own Active Directory environment and network: NCC Group combined Horizon3's NodeZero autonomous testing, for a consistent baseline across the fleet, with expert-led manual penetration testing of bespoke systems. Other case studies cover a maritime technical assessment with a simulated onboard red team attack, a multi-vessel OT review, and risk-based assessments of connected aircraft systems for a government client. CREST lists the broadest accreditation set here, including Penetration Testing, Threat Led Penetration Testing, Incident Response, Cyber Threat Intelligence, Security Operations Centre and Vulnerability Assessment, with 19 years of membership. A Cyber Services Portal is among its customer portals. Named testers, retest terms and pricing are not stated.
Strength: published penetration testing at fleet scale, backed by the widest accreditation set in this list. Limitation: the transport case studies do not name client regions, so confirm the North American team that will deliver. Best for: operators with large fleets or many sites that need consistent testing at scale plus red teaming.
3. IOActive
IOActive, Inc. lists its address at 1426 Elliott Avenue West in Seattle and runs embedded device and silicon labs in Seattle and Madrid. Its transportation practice pages are the most specific in this ranking. On maritime, it describes penetration tests of "intermodal terminal operating systems, core vessel information systems, and remotely operated vessels", and summaries of dozens of maritime assessments covering vessels, shore IT and OT networks, SATCOM, ports and web applications. On aviation, it cites penetration testing of cabin management systems and engagements at airports. On rail, it lists assessments of locomotive systems, attack scenarios against Positive Train Control and penetration tests of locomotive monitoring software, and membership of the American Public Transportation Association's Control and Communications Security working group. CREST lists Penetration Testing with eight years of membership, under the United Kingdom. Named testers, retest terms, a findings portal and pricing are not stated.
Strength: research-grade testing of the systems on the vessel, aircraft or locomotive, not only the corporate network around them. Limitation: the CREST listing sits under the United Kingdom, so confirm which team delivers North American work, and specify the corporate IT and portal scope, which the transport pages do not emphasize. Best for: fleet operators, terminals, rail operators and equipment suppliers that need onboard and trackside systems tested.
4. Pen Test Partners
Pen Test Partners is headquartered in Buckingham, England, and lists a US office, Pen Test Partners Inc, at 115 Broadway in New York. Its transport systems testing page names the clients it works with: airlines, airports and ground handling; ship owners, operators and maritime service providers; rail operators, infrastructure owners and rolling stock suppliers; and "logistics, freight and last mile delivery networks". Separate maritime and aviation pages cover IACS UR E26 and E27 for new-build vessels, hardening electronic flight bags in line with AMC 20-25, and testing of passenger-facing cabin systems. CREST lists Penetration Testing, Threat Led Penetration Testing, Incident Response, Vulnerability Assessment, Application Security Testing and Mobile Application Security Testing, with 16 years of membership. It runs a PTaaS service and a client portal. Named testers, retest terms and pricing are not stated.
Strength: the only firm here whose transport page names logistics, freight and last-mile networks alongside aviation, maritime and rail. Limitation: its CREST listing describes a largely UK-based team with offices in Europe and the US, so confirm who will travel for on-site OT work in North America. Best for: airlines, airports, ship operators and logistics networks that want one specialist across modes.
5. Raxis
Raxis was founded in Atlanta in 2011 and lists its office on Peachtree Road there. Its transportation and critical infrastructure penetration testing page covers fleet management, telematics and dispatch; signal controllers, interlocking and SCADA-managed track; reservation, ticketing, baggage, crew and cargo systems; cargo management, vessel tracking and port logistics platforms; and the passenger apps and payment systems in PCI DSS scope, with testing aligned to TSA cybersecurity directives and NIST SP 800-82. Its penetration testing page states that "every Raxis engagement includes remediation retesting", delivery runs point-in-time or as a continuous service through the Raxis One portal, and a proprietary on-site device lets internal testing reach distributed locations without an engineer at each one. Team bios are published. Raxis is not on the CREST Marketplace, and pricing is not stated.
Strength: one transportation scope that runs from fleets and rail to aviation and ports, with retesting included. Limitation: no firm-level CREST accreditation, and the OT claims are framed as testing aligned to standards, so specify which OT systems will be touched and how. Best for: US carriers, transit operators and logistics firms that want one US team across IT, portals and field devices, with continuous coverage.
6. Dragos
Dragos describes itself on its homepage as privately held and headquartered in Washington, DC. Its transportation page offers "comprehensive assessments, threat hunting, penetration testing, and incident response specifically designed for transportation OT environments" across rail, maritime and transit, and names Positive Train Control and ship control systems as the attack surface. Its OT assessment services run from architecture reviews to penetration testing, its red team services include purple team exercises, and its blog has covered TSA's rail security directives and Positive Train Control risk since 2021. Dragos is not on the CREST Marketplace, and named testers, retest terms and pricing are not stated.
Strength: OT-native testing for PTC, ship control and transit systems, informed by its own threat intelligence on groups targeting transportation. Limitation: the platform sits at the centre of the relationship, and corporate IT, portals and cloud are not its published focus. Best for: railroads, transit agencies and terminal operators whose assessment plan needs OT-specific testing.
7. GuidePoint Security
GuidePoint Security lists its headquarters at 1900 Reston Metro Plaza in Reston, Virginia, with offices across the United States including New York and Tampa. Its published transportation evidence is an aviation customer story about a US-headquartered aviation services company with hundreds of locations worldwide: GuidePoint ran its annual external penetration test, tested two new applications, retested after remediation, ran an incident response tabletop exercise and added managed detection and response. CREST lists Penetration Testing with three years of membership. A PTaaS platform is offered. Named testers, a stated retest policy and pricing are not published.
Strength: a documented aviation engagement that includes the retest. Limitation: one case study, in aviation services rather than freight, and no Canadian office listed. Best for: aviation services and multi-site operators that want testing, tabletop exercises and managed detection from one US provider.
8. Kroll
Kroll is headquartered at One World Trade Center in New York and lists a Toronto office at 333 Bay Street. Its transportation evidence is a case study for one of the world's largest shipping companies, which manages around 600 vessels from nine ship management centres, where Kroll provides managed detection and response across offices and ships and also conducts managed vulnerability scanning and CREST-accredited penetration testing across the client's global infrastructure; it has also published on cyber crime in the shipping industry with marine insurer Skuld. CREST lists Penetration Testing, Incident Response and Security Operations Centre with eight years of membership, and Kroll's listing describes "over 100,000 hours of offensive security assessments per year". Named testers, retest terms, a findings portal and pricing are not stated.
Strength: testing, forensics and incident response under one contract, with a Toronto office. Limitation: the shipping case study centres on managed detection and response and mentions the penetration testing only in two brief passages, without scope, named testers or retest terms. Best for: operators that want their tester and their incident responder to be the same firm.
9. ABS Consulting
ABS Consulting, part of ABS Group and a wholly owned subsidiary of the American Bureau of Shipping, lists its address at 1701 City Plaza Drive in Spring, Texas. Its maritime cybersecurity page lists penetration testing among its maritime OT services, alongside OT cybersecurity assessments, program development and managed services, and calls the team "a vital collaborator with United States Coast Guard (USCG) and Department of Homeland Security". Its MTSA compliance page covers Cybersecurity Plans, risk assessments and training for the Coast Guard rule, and cites vulnerability assessments for MTSA-regulated facilities. ABS Consulting is not on the CREST Marketplace, and named testers, retest terms and pricing are not stated.
Strength: deep maritime regulatory knowledge for ports, terminals and US-flagged vessels. Limitation: the same practice writes Cybersecurity Plans, so if it drafts yours, use a separate team or firm for the penetration test that checks it. Best for: MTSA facilities and US-flagged vessel operators building their first Coast Guard Cybersecurity Plan.
10. Bishop Fox
Bishop Fox lists its global headquarters at 1414 West Broadway Road in Tempe, Arizona, and describes itself as remote first, with a presence in 19 countries and 38 states. Its transport evidence is a case study for a global technology provider serving the travel and transportation sector: cloud penetration testing and PCI segmentation testing across its AWS-hosted environments, where the client called the segmentation testing "the most important part". CREST lists Penetration Testing with four years of membership, and its Cosmos platform supports continuous testing. Named testers, retest terms and pricing are not stated.
Strength: cloud and PCI segmentation depth for travel and transport technology platforms. Limitation: the published sector work is one technology vendor, and operational and OT scopes are not its published focus. Best for: booking, ticketing and transport software platforms running on AWS.
Firms considered and not ranked
Several familiar names were left out because their sites publish no transportation testing work we could verify, or because their sector work is not testing. DNV Cyber has a maritime OT practice and a CREST accreditation held through a Netherlands entity, but its site does not state North American delivery. 1898 & Co., the Burns & McDonnell consultancy, designs and implements OT cybersecurity programs for port operators, and we found no published penetration testing work on its transportation or ports pages. Thales holds its CREST accreditation through its Australian business. Optiv's airline case study is a cloud implementation rather than a test. CGI's transportation pages describe IT services, and the only transport penetration testing reference we found on its site is a 2014 UK discussion paper. NetSPI's only logistics item is a podcast interview, and Coalfire publishes no transportation material. ISA Cybersecurity, headquartered in Toronto, offers internal, external, wireless, mobile and web penetration testing, but its transportation material is two 2019 awareness articles, with no transport case study or sector service. Our national rankings for the USA and Canada cover the wider market, and the manufacturing ranking covers OT testing firms in more depth. One more exclusion applies to every buyer: the vendor that runs your TMS, WMS or OT should not be the firm that tests it.
How much does logistics and transportation penetration testing cost in 2026?
Logistics and transportation scopes usually span the perimeter and remote access, Active Directory, at least one customer or carrier portal, the OT boundary and a social engineering campaign. Stingrai publishes its package prices: US$3,000 for an Autonomous Pentest, which is Snipe alone with no penetration testers, and US$6,800 for a Hybrid Pentest, where penetration testers and Snipe test together, each per assessment of exactly one web application and its APIs. The same tiers run at US$650 and US$1,275 per month on 12-month continuous plans, and the "No High or Critical Finding = Don't Pay" guarantee applies to the Autonomous Pentest only. Every other scope, including networks, Active Directory, cloud, the OT boundary, red teaming and social engineering, is quoted through get a quote, with current figures on the pricing page.
The bands below are indicative, taken from our penetration testing cost guide for US dollars and the Canadian cost guide for standard Canadian scopes.
Logistics and transportation scope | Indicative US band | Indicative Canadian band (standard scope) |
|---|---|---|
Customer, carrier or broker portal (web application) | US$5,000 to US$30,000 | C$12,000 to C$25,000 |
EDI gateway or partner API | US$6,000 to US$30,000 | C$15,000 to C$25,000 |
External perimeter and remote access | US$5,000 to US$40,000 (network) | C$15,000 to C$35,000 |
Internal network and Active Directory | US$5,000 to US$40,000 (network) | C$20,000 to C$35,000 internal; C$25,000 to C$35,000 Active Directory |
Microsoft 365, Entra ID and cloud | US$10,000 to US$50,000 (cloud) | C$25,000 to C$40,000 (cloud) |
Driver or proof-of-delivery app (per platform) | US$7,000 to US$35,000 | C$18,000 to C$30,000 |
Red team or adversary simulation | Quoted per objective | C$45,000 to C$65,000 |
Annual testing budget, mid-market organization | US$20,000 to US$50,000 | C$60,000 to C$90,000 (PTaaS) |
OT boundary, terminal or vessel testing | Quoted per site | Quoted per site |
Neither guide publishes a band for OT, terminal or vessel testing, which depends on site count, travel and the rules of engagement. Three other things move a quote most: how many sites and domains are in scope, whether social engineering includes vishing and on-site work, and how many portal roles need authenticated testing. The cost calculator gives a starting figure.
Buyer checklist: questions to put to every vendor
The RFP template turns these into procurement language.
Who exactly will test, and can we see their names and certifications before we sign?
Where is your firm-level accreditation listed, and which legal entity will sign our statement of work?
How will you test the boundary into our warehouse, terminal, vessel or rail OT without touching live control systems? Ask for excluded systems, stop conditions, agreed windows and a test environment for anything fragile.
Can you produce what our regulator expects? A Coast Guard-regulated owner needs a letter confirming the test and the full list of vulnerabilities for its security assessment; a railroad needs results it can report against its TSA Cybersecurity Assessment Plan.
Will you test authorization between shippers, carriers and brokers in our portals, EDI gateways and partner APIs?
Will you test carrier onboarding and the payment-change process with phishing and vishing, and how do you handle call recording rules in each jurisdiction?
Are you independent of our TMS and WMS vendors, our managed security provider and whoever wrote our Cybersecurity Plan?
Is retesting included, and within what window?
How will you handle sensitive security information and where will our findings be kept? Confirm the handling rules for Coast Guard and TSA material and residency for Canadian operators.
Do you offer both a one-time annual test and continuous testing, including testing after a new terminal, an acquisition or a new EDI partner?
Frequently Asked Questions
Who are the best penetration testing companies for logistics and transportation in 2026?
The best penetration testing companies for logistics and transportation in 2026 are Stingrai, NCC Group, IOActive, Pen Test Partners, Raxis, Dragos, GuidePoint Security, Kroll, ABS Consulting and Bishop Fox. Stingrai ranks first: a CREST-accredited penetration testing service provider at firm level with two named penetration testers from a team holding OSCE³, OSWE, OSEP, CREST CRT and CISSP on every human-led engagement, testing remote access, Active Directory, Microsoft 365, the IT side of the OT boundary, shipper and carrier portals and partner APIs, and the staff who handle dispatch and carrier onboarding, with retesting and an attestation letter included on one-time or continuous terms. NCC Group, IOActive and Pen Test Partners follow.
Does the US Coast Guard cybersecurity rule require penetration testing?
Yes, for the operators it covers. Section 101.650(e)(2) of 33 CFR requires the owner, operator or Cybersecurity Officer of a US-flagged vessel, MTSA-regulated facility or Outer Continental Shelf facility to ensure a penetration test has been completed in conjunction with Cybersecurity Plan renewal, and to include a letter certifying that the test was conducted, with all identified vulnerabilities, in the vessel or facility security assessment. Plans are approved for five years, and test results must be available to the Coast Guard on request. Foreign-flagged vessels are not covered.
When are the Coast Guard cybersecurity compliance dates?
The final rule took effect on 16 July 2025. Cybersecurity training was due by 12 January 2026 and annually after that. The first Cybersecurity Assessment is due no later than 16 July 2027 and annually after that, and Cybersecurity Plans must be submitted to the Coast Guard for approval no later than 16 July 2027. The eCFR, current to 29 September 2026, shows no amendment to these dates, and no delay had been published in the Federal Register as of 1 October 2026.
Do TSA security directives require railroads to run penetration tests?
Not in so many words. Security Directive 1580/82-2022-01E, effective 3 May 2026 to 2 May 2027, requires covered freight and passenger railroads to keep a Cybersecurity Assessment Plan with an architecture design review at least every two years and other assessment capabilities, such as penetration testing of IT systems including red and purple team testing. At least one third of the implementation plan must be assessed each year and all of it within three years, with an annual report to TSA.
Has TSA finalized its surface cyber rule?
No. TSA proposed Enhancing Surface Cyber Risk Management on 7 November 2024, and comments closed on 5 February 2025. As of 1 October 2026 the Federal Register shows no final rule, and TSA's entry in the 2026 Unified Agenda lists it as a long-term action with the final rule date to be determined. The rail security directives remain the binding requirements.
Does Canada's Bill C-8 require transportation companies to run penetration tests?
No. Bill C-8 received royal assent on 15 June 2026, and the Critical Cyber Systems Protection Act it enacts lists federally regulated transportation systems as a vital service, but the Act is not in force, no operators are designated and it never mentions penetration testing. Once a class of transport operators is designated, each will need a cyber security program within 90 days, incident reports within no more than 72 hours and records kept in Canada, and testing is how an operator shows that program works.
Does CTPAT require penetration testing?
CTPAT is voluntary, but its "Must" criteria are mandatory for members. Criterion 4.3 requires members using network systems to regularly test the security of their IT infrastructure and to fix vulnerabilities as soon as feasible. The criteria for highway carriers, third party logistics providers, sea carriers and terminal operators do not mention penetration testing, and the guidance describes vulnerability scanning, so a penetration test is stronger evidence rather than a named requirement.
How much does logistics and transportation penetration testing cost in 2026?
Stingrai publishes US$3,000 for an Autonomous Pentest (Snipe alone, no penetration testers) and US$6,800 for a Hybrid Pentest per assessment of one web application and its APIs, or US$650 and US$1,275 per month on 12-month continuous plans; every other scope is quoted. Indicative bands from our cost guides put a US network test at US$5,000 to US$40,000 and a standard Canadian internal network test at C$20,000 to C$35,000. OT, terminal and vessel testing is quoted per site.
Related reading
Ready to scope a logistics or transportation penetration test?
The incidents that stop freight rarely start in the control room. They start with a VPN account nobody disabled, a portal that shows one shipper another shipper's loads, or a call that convinces someone to change a carrier's remittance details. Stingrai is a CREST-accredited penetration testing service provider whose testing supports the evidence a Coast Guard plan renewal, a TSA Cybersecurity Assessment Plan, CTPAT criterion 4.3 and SOC 2 or ISO 27001 programs ask for, delivered as a one-time annual engagement or as continuous coverage, with named penetration testers, retesting and an attestation letter. Book a free scoping call, get a quote for a network, OT boundary or red team scope, or see the published package prices on the pricing page.



