Sector: Postal, Parcel and Courier Services

Penetration Testing for UK Postal, Parcel and Courier Services

CREST-accredited penetration testing for UK postal operators, courier and last-mile delivery companies, and the fulfilment, warehouse and locker-network providers behind them. We test parcel tracking and customer portals, warehouse and fulfilment platforms, and depot and driver apps, with UK GDPR evidence for the addresses and delivery data every parcel carries. Redirection, proof-of-delivery and depot-permission boundaries checked throughout.

  • Unlimited retesting
  • Unlimited pre-retesting
  • No hidden fees
Accredited & recognised
Cyber Essentials certified Cyber Essentials Plus certified IASME certifying body ISO 27001 certified ISO 9001 certified Crown Commercial Service supplier UK Cyber Security Council member
CREST
Approved Provider
PCI DSS
Aligned Methodology
UK GDPR
Article 32 Evidence
24h
Scope to Active Test
CLIENT REFERENCE
“I would highly recommend EJN Labs to any organisation seeking reliable, detailed, and well-managed penetration testing services, particularly for government or enterprise-level projects.”
SquareOneImran SaghirProject Lead, SquareOneRead the SquareOne case study →
CLIENT REFERENCE
“There wasn’t another company we could find that could deliver what we needed in the timeframe we needed. The client loved it, and we got instant ROI from the engagement.”
CelloriDan WilcocksonFounder, CelloriRead the Cellori case study →
See all case studies →
REGULATORY CONTEXT
3

trust boundaries we test on every tracking, depot or locker platform: who can see a delivery address, who can redirect a parcel, and whether a proof-of-delivery record can be tampered with.

What UK GDPR, PCI DSS & Retail Buyers Expect

UK GDPR. A tracking number, delivery address and contact number are personal data, and a public-facing tracking page that reveals more than the reference number it was given is a common source of address exposure. Article 32(1)(d) requires a process for regularly testing, assessing and evaluating the effectiveness of your security measures. It does not name penetration testing as the method, but a test is the most direct evidence that your controls work. UK GDPR Article 32.

PCI DSS. Platforms that take card payments for postage, shipping labels, redelivery fees or locker access sit inside PCI DSS 4.0.1. Requirement 11.4.2 and 11.4.3 call for internal and external penetration testing at least once every 12 months and after significant change, and 11.4.1 expects a documented testing methodology. PCI Security Standards Council.

Redirection and delivery-scam risk. A parcel redirected to an address the sender never chose, whether through a compromised account, a manipulated hold-for-collection request or a spoofed rescheduling message, is a well-known abuse pattern in last-mile delivery. We test the controls around an address or redirection change: what verifies the request, what gets logged, and whether a customer is notified before a parcel moves.

Who we test for. National and regional postal operators, courier and last-mile delivery companies, click-and-collect and locker-network operators, and the fulfilment or third-party logistics (3PL) providers and marketplace integrations behind them. Depot and driver-facing apps are covered under our mobile application penetration testing methodology.

SCOPE

What We Test for UK Postal, Parcel & Courier Services

TRACK

Parcel Tracking & Customer Portals

Public tracking-by-reference pages and logged-in customer accounts. IDOR across tracking numbers and delivery addresses, account-to-account data leakage, and whether a tracking reference alone can expose more than its own parcel.

WMS

Fulfilment & Warehouse Management

Warehouse management systems (WMS), pick-pack-ship workflows and shipping-label generation. Multi-client and multi-tenant separation for 3PL operators handling several retailers on one platform, and inventory or consignment-record tampering.

DEPOT

Depot & Driver Apps

Driver rounds, proof-of-delivery capture and depot-management apps. Depot-to-depot and driver-to-driver permission separation, round-reassignment authority, and whether a delivery photo or signature can be altered after capture.

PUDO

Redelivery, Hold & Locker Networks

Redelivery scheduling, hold-for-collection requests, and pick-up-drop-off (PUDO) locker networks. Address and redirection-change verification, and PIN or QR-code replay against locker access points.

API

Carrier, Marketplace & EDI Integrations

APIs and EDI feeds behind marketplace and retailer integrations, interline agreements with other carriers, and label-generation plugins. OWASP API Top 10 testing for object-level authorisation and cross-retailer data leakage on shared platforms.

CLOUD

Cloud Infrastructure

AWS, Azure and GCP configuration for tracking, address and payment data. Encryption at rest, IAM scoping, audit logging and tenant boundaries where a single platform serves several retailer or courier brands.

INFRA

Depot, Sortation & Corporate Networks

Segregation between sortation-machinery control systems, depot floor networks and corporate IT. Active Directory attacks and the boundary between managed office devices and warehouse or sortation equipment.

PHISH

Phishing Defence

Targeted phishing simulation against depot, finance and customer-service staff, using courier-aware lures such as spoofed redelivery-fee texts and driver-impersonation messages.

OUR PROCESS

From Scope to Attestation in 4-6 Weeks

01

Scoping Call

30-minute technical scoping call covering tracking, fulfilment, depot and locker systems in scope, peak-season testing windows, and rules of engagement. Fixed-price quote within 24 hours.

02

Active Testing

3-15 days of hands-on testing by CREST-certified UK-based pen testers, against staging or non-production environments with synthetic address and parcel data wherever possible. Daily status updates.

03

Reporting

Executive summary plus full technical report with CVSS scores, reproduction steps, screenshots, and specific remediation. 60-minute walkthrough call.

04

Free Retest

After remediation, we retest at no extra charge. Letter of attestation provided for buyer due diligence, PCI DSS evidence or audit.

CREDENTIALS

Verified Accreditations Auditors Accept

Every credential below is independently verifiable. UK procurement teams, FCA supervisors, ISO 27001 / SOC 2 auditors, and cyber insurance underwriters all recognise these standards.

GET YOUR QUOTE

Get a CREST postal and courier pen test quote in 24 hours

A fixed-price quote back in one business day, from a named CREST assessor. No sales pipeline, no chasing.

  • CREST and IASME accredited. Testing your auditors and clients already recognise.
  • Fast-track testing within 24 hours where required. Free retest of every fix included.
  • Live findings via your client portal, not a four-week PDF.
  • Fixed price from £3,500 for a single-role, single-app scope, agreed up front. Most engagements run £5,000 and up. No day-rate surprises.
What clients say
There wasn’t another company we could find that could deliver what we needed in the timeframe we needed. The client loved it, and we got instant ROI from the engagement.
CelloriDan WilcocksonFounder, Cellori

Under NDA Further named references available on a scoping call.

What happens next
  1. We reply within one business day with a fixed-price quote from a named CREST assessor.
  2. You approve the scope and we book a start date, usually within 24 hours.
  3. Live findings land in your client portal as we test, with a free retest of every fix.
Accredited & recognised
CREST member Cyber Essentials certified Cyber Essentials Plus certified IASME certifying body ISO 27001 certified ISO 9001 certified UK Cyber Security Council Crown Commercial Service supplier

Get your fixed pen test quote in 24 hours

24h reply CREST tester Free retests

or book a 20-min scoping call first

We reply within one business day. Your data stays with us. No newsletter signup.

COMPLIANCE READY

Reports Aligned to Every Framework

Findings map to specific control references in each framework, so your audit team submits the report directly without translation work.

UK GDPR

Article 32(1)(d) evidence that you regularly test the effectiveness of your security measures, for address, tracking and contact data.

PCI DSS 4.0.1

Requirement 11.4.1-11.4.3 internal and external testing for postage, label and locker-access payment environments.

ISO 27001

Annex A 8.8 technical vulnerability management, once you declare that control applicable.

Cyber Essentials Plus

Certified directly by us as an IASME certification body, alongside your test.

Cyber Insurance

Findings and remediation documented against the questions on your broker or insurer’s proposal form. Requirements vary by insurer and policy.

Retailer & Marketplace Due Diligence

An independent report you can attach to retailer, marketplace and 3PL client security questionnaires.

PRICING

Indicative Engagement Pricing

Fixed-price quotes confirmed during scoping. Free retest, executive summary, walkthrough call, and letter of attestation included.

✦ ALWAYS · ON EVERY TIER · NO EXCEPTIONS ✦
Free retests, no time limit
Free rescheduling
No cancellation fees
24-hour scope to active testing
Live findings to client portal
Executive + technical report
60-min walkthrough call
Letter of attestation
SMALL / SMB
£3,500–£8,000
Depends on service + scope

External / web / API / mobile single-target engagement. CREST-certified delivery. Around 3 to 5 working days from kickoff to report.

Get a fixed quote
ENTERPRISE
£18,000+
Depends on service + scope

Full-stack engagement (multiple cloud accounts, hybrid AD, complex web + API + mobile). Typically 12-15+ days.

Get a fixed quote

Full UK pen test cost guide

WHY EJN LABS

What You Get From Postal, Parcel & Courier Penetration Testing

Six concrete differentiators competitors don’t all match.

CREST-Certified Testers, Verifiable

Every test by a CREST-certified pen tester (CRT, CCT APP, CCT INF where applicable). Verify our company status at crest-approved.org.

24-Hour Startup, Where Required

From signed scope to active testing in a single business day for incident response, audit deadlines, or regulator-driven timelines.

Live Findings, Not 4-Week PDFs

Critical issues reported during testing through your client portal. Your team remediates while testing continues.

Audit-Ready Reports

Executive summary plus full technical report with CVSS scores and explicit framework mappings (ISO 27001, SOC 2, PCI DSS, FCA SYSC).

Free Retests, Standard

Verify remediation of every finding before close-out. Letter of attestation for audit submission included. Most competitors charge £1,500-£3,000 per retest.

UK-Based CREST Testers

Every engagement performed by vetted, UK-based CREST-certified testers, matched to your needs, security clearance, and compliance scope.

FAQ

Frequently Asked

Which regulations apply to a postal or courier platform?

There is no single postal-sector penetration testing mandate. UK GDPR Article 32(1)(d) requires you to regularly test the effectiveness of your security measures for the address and contact data every parcel carries, and PCI DSS 4.0.1 applies once your platform takes card payments for postage, labels or locker access. Beyond that, in our experience, retailer and marketplace customers commonly run their own supplier due diligence and ask for independent testing evidence directly.

Can you test our tracking portal without exposing real customer addresses?

Yes. We test against a non-production environment with synthetic tracking numbers, addresses and account data wherever possible, and we scope any production testing to avoid touching live customer records.

Do you test for parcel redirection or delivery-scam risk?

Yes. We test what verifies an address or redirection change, whether the change is logged, and whether the customer is notified before a parcel is redirected or a hold-for-collection request is actioned, covering both account-based changes and spoofed rescheduling messages.

Can you test our driver or depot app, including proof-of-delivery capture?

Yes. We test the driver app’s round data, proof-of-delivery photo or signature capture, and depot-management functions, checking device storage of delivery evidence and whether a captured proof-of-delivery record can be altered after the fact.

Do you test click-and-collect locker networks and PUDO points?

Yes. Pick-up-drop-off (PUDO) locker networks, including PIN or QR-code access, hold-duration limits, and the boundary between the courier’s locker-management platform and the retailer or marketplace that books a slot in it.

Can you test our warehouse management system’s integration with a retailer’s Shopify or Magento checkout before peak season?

Yes. We test the API or plugin integration between your WMS and a retailer’s storefront, including our dedicated Shopify and Magento methodologies, and we can prioritise scoping around a peak-season go-live date if you tell us during the scoping call.

Which postal, parcel and courier organisations do you test for?

National and regional postal operators, courier and last-mile delivery companies, click-and-collect and locker-network operators, and the fulfilment or third-party logistics providers and marketplace integrations behind them.

What’s in the report?

Executive summary (board-ready), technical report with CVSS 3.1 scores, reproduction steps, screenshots, specific remediation guidance, and a 60-minute walkthrough call. Letter of attestation issued after free retest.

Do you sign NDAs?

Yes. We sign client-supplied NDAs as standard. Engagement data is protected under our ISO 27001 (BSI-audited) information security management system.

How quickly can you start?

From signed scope to active testing in 24 hours where required. Standard pipeline is 3-5 business days from initial scoping call to test start.

Are your testers UK-based and what certifications do they hold?

Every engagement is performed by vetted UK-based CREST-certified testers matched to your engagement based on security clearance, compliance scope, and sector specialism. Testers hold CREST certifications relevant to their discipline (CRT, CCT APP, CCT INF, CCSAM).

EXPLORE EVERY SERVICE

20+ CREST-accredited testing services in one place

Web, mobile, API, cloud, AI, infrastructure, red team. Pick the test that fits your environment.

Penetration testing services
READY TO START

Get my Postal & Courier pen test scope

A CREST-certified UK-based pen tester will contact you within one business day with a fixed price aligned to your tracking, fulfilment, depot and locker systems.