Case Study

Logistics Leader Fortifies Digital Supply Chain Against Sophisticated AI-driven Cyberattacks

Trigent’s VAPT and cybersecurity solutions safeguard the extended cloud, telematics, and connected devices’ digital footprint

About the Client​

Our client is a leading intermodal drayage provider specializing in efficient and reliable transportation services. With 250 employees and a network of 900+ owner-operator drivers, they handle 275,000+ moves annually across 19 locations. In addition to intermodal trucking, they offer refrigerated container handling, hazmat transportation, and ancillary services such as transloading and pickup/delivery. With advanced software and hardware, they ensure on-time performance, seamless 24/7 operations, and secure logistics solutions.

Business Challenge​

Our client is at the forefront of using tech innovations to enhance visibility and customer efficiencies. Their technology suite includes onboard cameras, blockchain, EDI, API integrations, online container tracking, and online quoting, all powered by modern cloud applications accessible 24/7 by shippers, contractors, receivers, drivers, and staff. Hence, ensuring continuous availability is crucial.

The company recognizes that cloud applications and connected devices increase the potential for cyberattacks. As the client places a premium on customer trust, they are committed to ensuring their software and systems’ security and data integrity. Recognizing that conventional measures are insufficient against sophisticated AI-enabled cyberattacks, the client set a high-security threshold and initiated proactive steps to achieve it.

Trigent Solution

Security Assessment Planning

Working with the client team, our cybersecurity experts identified all the connections between the central application and the tech elements they employed. This defined the perimeter of their IT ecosystem and identified obscure weaknesses likely to be targeted in cyberattacks. Our team designed custom tests to assess the vulnerabilities and pinpoint potential weaknesses.

Penetration and Vulnerability Testing

The first step was Penetration Testing. We utilized automated tools and manual methods for the custom tests, effectively simulating real-world attacks to identify security gaps. The grey box assessment approach provided a nuanced view of the application’s security posture, allowing us to understand how vulnerabilities might be exploited in practice.

Next, we employed Dynamic Application Security Testing (DAST) to assess the application at runtime, ensuring vulnerabilities were identified during live operations. We ensured comprehensive coverage of potential security threats by aligning testing with established compliance standards such as the OWASP Top 10 and SANS Top 25. Given the nature of their business operations, this reinforced the application’s defenses against a broad spectrum of vulnerabilities and specific exposures.

Our team executed these advanced tests by leveraging Burp Suite Professional and OWASP ZAP. Burp Suite allowed for in-depth testing of advanced web and mobile application vulnerabilities.

Trigent’s Assessment Methodology Highlights

Results of the Security Assessment

The exercise uncovered unexpected vulnerabilities in edge elements of the expanded threat surface. These included four critical and four high-severity risks that required immediate attention.

Client Benefits

By addressing the identified vulnerabilities and taking corrective actions, the client achieved several key benefits:

Burp-suite
owasp-top10
iis-8
asp-dot-net
Microsoft sql server