LogisticsEdge
Supply Chain Guide Intermediate

Air cargo cybersecurity risk: logistics controls for 2026

Air cargo cybersecurity risk is now an operational issue. Here are the controls UK forwarders and shippers should put in place before 2026 contracts renew.

By 12 min read 2,456 words
air cargo cybersecurity supply chain risk
Air cargo cybersecurity risk: logistics controls for 2026
In this article

    Key Takeaways

    • Air cargo cybersecurity risk sits in booking portals, visibility tools, airway bill data, supplier access and incident response, not only in airline systems.
    • IATA’s aviation cybersecurity programme points to new 2026 industry groups, IOSA cybersecurity practices and supply-chain oversight guidance that freight operators should track.
    • UK teams should use the NCSC supply-chain security principles to map suppliers, set access rules, verify controls and improve them continuously.
    • Cyber Essentials is not enough on its own, but it is a useful baseline when you need evidence that a smaller supplier has basic technical controls.
    • Practical controls include tighter portal access, supplier assurance, phishing training, data minimisation, change controls and rehearsed fallback procedures.
    • The best test is operational: can you still move urgent air freight if a platform, forwarder account, warehouse system or airline messaging route is unavailable?

    Air cargo cyber risk is now an operational risk

    Air cargo depends on trusted data moving quickly between shippers, forwarders, handlers, airlines, customs systems, screening providers and destination agents. That makes cybersecurity a logistics control issue, not a separate IT concern. If an attacker gets into a booking portal, email account or visibility platform, the damage can show up as missed cut-offs, diverted freight, fraudulent collection, wrong documents or delayed customs clearance.

    The air freight process is especially exposed because it compresses time. Ocean freight gives you days to catch an error in a bill of lading, routing instruction or commercial invoice. Air cargo often gives you hours between booking, collection, screening, uplift and arrival.

    The data is also valuable. Shipment references, consignee details, commodity descriptions, invoices, airway bill numbers, GPS data, portal logins and delivery appointments can all help criminals identify high-value cargo or impersonate a trusted party. That matters for general cargo, but it matters more for pharmaceuticals, electronics, aerospace parts, luxury goods and time-critical spares.

    For UK importers and exporters, the risk is practical. Your exposure may sit with a freight forwarder, a handling agent, a software platform, a customs broker, a warehouse, or a small overseas supplier that only sends documents by email. If your controls only cover your own network, you have missed the parts of the chain where air cargo work actually happens.

    What changes in 2026

    2026 is the year many air cargo operators should treat cyber controls as part of carrier and forwarder selection. The direction from industry bodies is clear: cyber risk is being pulled into aviation safety, security, airworthiness, supply-chain oversight and crisis response rather than left as a generic technology risk.

    According to IATA’s aviation cybersecurity programme, the association is establishing several Subject Matter Expert groups in 2026, including the Aviation Cybersecurity Industry Study Group, the International Cybersecurity Standards and Regulations Study Group, the Cybersecurity Innovation Study Group and an International Aviation Cybersecurity Crisis group. That does not create a direct legal duty for every UK shipper, but it signals where airline and aviation-security assurance is heading.

    IATA’s Aviation Cybersecurity Library also points operators towards IOSA Standards and Recommended Practices on cybersecurity in ISM Edition 16, plus a newer discipline covering cybersecurity for safety, security and airworthiness. For freight teams, the useful takeaway is simple: cyber controls are no longer just about protecting office systems. They increasingly affect whether partners can prove that cargo data, operational systems and aviation workflows are controlled.

    The same direction is visible in cargo security. Pre-loading advance cargo information regimes have made accurate data part of aviation security screening. That means the integrity of cargo data matters before the shipment is accepted for transport. A cyber incident that changes consignor, consignee, commodity or routing data can become a security and compliance problem as well as a service problem.

    This is not a reason to panic or overbuy security tools. It is a reason to ask sharper operational questions. Who can change routing instructions? What happens if a forwarder portal is unavailable at 16:00 on a Friday? Which supplier accounts have access to documents that would let someone redirect cargo?

    Where the weak points usually sit

    The highest-risk points are the handovers where people trust a system message, email trail or portal update without independent challenge. Air cargo has many of those handovers. A shipper books with a forwarder, the forwarder books with an airline or consolidator, a haulier collects the freight, a handler receives it, screening confirms it, and destination parties arrange clearance and delivery.

    Email remains a common weak point because it carries commercial invoices, packing lists, collection instructions, airway bill drafts and payment details. A compromised mailbox can be used to alter bank details, insert a new delivery address, request a rushed collection, or add a fake contact to a live shipment. The faster the cargo is moving, the more credible the “urgent change” can sound.

    Portal access is the second weak point. Booking systems, tracking platforms, document repositories and warehouse management portals often hold enough information to target a shipment. If accounts are shared, if former staff still have access, or if multi-factor authentication is not enforced, an attacker may not need to breach a carrier directly. They can use a weaker partner account instead.

    Data reuse is another problem. The same shipment reference may appear in email subject lines, tracking portals, invoices, transport labels and customer service messages. Once a criminal understands the pattern, they can make a fraudulent request look plausible. That is why logistics teams should treat operational data as sensitive, even when it is not personal data in the narrow sense.

    The final weak point is fallback. Many teams know how to book air freight when the systems are working; fewer have a tested process for when a forwarder portal, customs system interface, warehouse connection or airline messaging route is down. If a cyber incident forces staff into improvised workarounds, the risk of documentary errors, duplicate instructions and fraud rises sharply.

    Apply the NCSC supply-chain model to freight partners

    The NCSC supply-chain security guidance is a good UK-specific framework because it is built around supplier control rather than abstract cyber maturity. The guidance sets out 12 principles across four stages: understand the risks, establish control, check your arrangements, and improve continuously. NCSC records the guidance as reviewed on 22 October 2025, so it is current enough to use for 2026 supplier reviews.

    Start with the first stage: understand the risks. For air cargo, that means listing the suppliers that can affect a shipment’s movement, documents, data or release. Include freight forwarders, customs brokers, cargo handlers, hauliers, overseas agents, warehouse providers, screening partners and technology platforms. If a supplier can change a shipment record, see invoice data, issue collection instructions or access your customer portal, they belong on the map.

    The second stage is control. Put minimum rules into contracts and onboarding checks. These should cover named user access, multi-factor authentication, leaver processes, incident notification, subcontractor disclosure, document handling, bank-detail change controls and tested business continuity procedures. For higher-risk lanes or commodities, add tighter rules on who can approve routing, release and delivery changes.

    The third stage is checking. Ask for evidence that matches the risk. For a small domestic haulier, Cyber Essentials may be a sensible baseline. For a digital forwarder handling high-value air freight, you may need more: access-control evidence, incident-response procedures, penetration test summaries, supplier oversight processes and a clear explanation of how shipment data is protected.

    NCSC’s additional supply-chain guidance describes Cyber Essentials certification as a tangible and efficient way to gain assurance that suppliers have implemented fundamental technical controls against untargeted commodity attacks. Treat that wording carefully. It is a baseline, not a substitute for checking shipment-specific controls. A supplier can have Cyber Essentials and still run weak release procedures, shared portal accounts or poor incident escalation.

    Controls forwarders and shippers should put in place

    The first control is named access. Shared logins are hard to investigate and easy to abuse. Every portal account used for booking, tracking, document exchange or warehouse access should belong to a named person, protected by multi-factor authentication and removed quickly when someone leaves. The same rule should apply to overseas agents and temporary staff wherever the platform allows it.

    The second control is change verification. Build a rule that material changes need an independent check, especially for delivery addresses, consignee details, bank accounts, routing, collection times and nominated contacts. Do not verify a suspicious email by replying to the same email thread. Use a known phone number, existing portal contact, or pre-agreed escalation route.

    The third control is data minimisation. Give each party the shipment data they need, not the full commercial picture by default. A collection haulier may need weights, pieces, address, booking reference and handling instructions; they may not need invoice values, customer contracts or wider purchase-order data. This reduces the value of a compromised account.

    The fourth control is staff training built around real freight scenarios. Generic phishing modules are less useful than examples involving airway bill drafts, urgent cut-off changes, fake carrier notifications, amended bank details and fraudulent warehouse release requests. Staff should know which changes must be challenged even when the shipment is late.

    The fifth control is incident rehearsal. Decide what you will do if a forwarder portal is unavailable, a supplier reports a mailbox compromise, a shipment record changes unexpectedly, or a customer receives a suspicious payment request. Write the process before the incident. Include operational leads, IT, finance, customer service and any outsourced customs or warehouse providers.

    These controls should sit beside standard freight management basics. If you are reviewing forwarder performance, add cyber and data handling to the same process as service, cost, claims and escalation. Our guide to freight forwarder selection covers the wider supplier questions; for air freight, the cyber section now deserves equal weight with carrier access and response times.

    A practical 2026 control checklist

    Use a short checklist that operations teams can actually maintain. Long security questionnaires often fail because nobody owns the answers after onboarding. A leaner control set, reviewed every quarter for high-risk suppliers, is usually more useful.

    Control areaWhat to checkEvidence to keep
    Portal accessNamed users, MFA, leaver process, admin ownerUser list, access policy, last review date
    Shipment changesIndependent verification for release, routing and payment changesWritten procedure and escalation contacts
    Supplier assuranceCyber Essentials or equivalent baseline for relevant suppliersCertificate, questionnaire or audit notes
    Data handlingLimits on invoice values, customer data and document sharingData-sharing map and contract clauses
    Incident responseNotification times, backup contacts and fallback booking processIncident plan and rehearsal record
    SubcontractingDisclosure of agents, handlers and technology platformsSupplier list and material-change clause

    This checklist works best when it is tied to cargo risk. A low-value sample shipment on a familiar lane does not need the same level of assurance as urgent aerospace parts, controlled goods or high-value electronics. Use lane, commodity, value, time sensitivity and destination risk to decide which partners need deeper review.

    Do not turn this into a one-off procurement exercise. Supplier access changes, platforms change, overseas agents change, and new visibility tools get added mid-contract. Review the controls after a near miss, suspected phishing attempt, portal outage, claims event or major route change.

    Air cargo teams should also link this checklist to customs and document quality. A cyber incident can create errors in commercial invoices, packing lists, declarations and security filings. If your team is already tightening document controls, connect the work to commercial invoice requirements and customs clearance procedures so the same people own both accuracy and access.

    How to handle a cyber incident in live air cargo

    The first priority is containment without losing operational visibility. Freeze suspicious changes, disable compromised accounts, preserve the email or portal evidence, and switch to known-good contact routes. If cargo is already collected or screened, tell the forwarder, handler and destination agent exactly which instructions are trusted and which are under review.

    The second priority is protecting release and payment. Put a temporary hold on delivery-address changes, consignee amendments, release notes and bank-detail changes until they are independently verified. If high-value cargo is involved, ask the forwarder or warehouse to confirm whether any duplicate release instruction, amended collection note or new contact has appeared.

    The third priority is customs and security data. Check whether commodity descriptions, consignor details, consignee details, weights, pieces, values or routing information have changed. If declarations or advance cargo information have already been submitted, work with the forwarder or broker to decide whether a correction is needed. Do this quickly, but keep an audit trail of who approved each correction.

    The fourth priority is customer communication. Tell affected customers what has happened, which instructions remain valid, and how you will verify any further changes. Avoid vague reassurances. A practical message should state the shipment reference, the control action taken, the trusted contact route and what the customer should ignore or report.

    After the shipment is stable, hold a short review. Identify which control failed: access, verification, supplier assurance, data sharing, escalation or fallback. Then change that control. If the answer is only “train staff again”, the same weakness will probably return.

    Frequently Asked Questions

    Is air cargo cybersecurity mainly an airline problem? No. Airlines matter, but many practical risks sit with shippers, forwarders, brokers, handlers, portals, overseas agents and warehouse providers. If one of those parties can change shipment data or release instructions, their controls affect your cargo.

    Should UK shippers ask every freight supplier for Cyber Essentials? Cyber Essentials is a useful baseline for many UK suppliers, and NCSC points to it as a practical assurance route for fundamental controls. It should not be the only test for high-risk air cargo. You still need shipment-specific checks on access, release changes, incident reporting and subcontractors.

    What is the fastest control to improve? Start with change verification. Require independent checks for bank details, delivery addresses, routing changes, consignee amendments and urgent release requests. This reduces fraud risk quickly because it targets the point where attackers usually try to turn access into cargo movement or payment.

    How often should supplier cyber controls be reviewed? Review critical air cargo suppliers at least quarterly, and review lower-risk suppliers when contracts renew or systems change. Also review after any phishing attempt, portal outage, suspected compromise, claims event or unexplained shipment-data change.

    Does PLACI make cyber controls more important? Yes, because pre-loading cargo security relies on accurate shipment data before uplift. If cargo data is altered or submitted through a compromised process, the issue can affect security screening, clearance readiness and operational movement.

    The weekly briefing

    Practical UK logistics and customs insight, every week. No fluff.

    From the desk

    Practitioner-written UK customs & logistics intelligence