A dry port is a customs border that happens to sit in the desert. Al-Saih handles containers that arrive on trucks, leave on rail, and change legal custody in between - and the only evidence of what happened is held in software. CyberFortify runs manual network, API and cloud testing plus safe OT-boundary work for freight, customs and processing businesses here, aligned to NCA ECC and OTCC, the Saudi PDPL and ISO 27001. Fixed price, audit-ready reporting, free retest.
// 01 Why Al-Saih operators need penetration testing
Cargo stops being a physical problem the moment it is sealed. From then until the seal is broken at destination, a container is whatever the paperwork says it is - and at an inland terminal like Al-Saih's, that paperwork is a set of database rows. A box rolls through a gate, a plate and seal number are read, a weight is captured, a customs declaration is lodged, and a rail handover message tells a freight operator to accept custody. Nobody opens the doors to check. The record travels instead of the inspection, which makes the record the thing worth attacking.
This is not the same problem as securing a warehouse. A dry port sits at three boundaries at once: a mode boundary where road becomes rail, a custody boundary where liability transfers between carriers, and a customs boundary where goods are declared while still far inland. Each is implemented as an interface - a terminal operating system talking to a gate application, a weighbridge feeding a yard management module, an electronic message crossing to a rail operator or a broker. Interfaces built for throughput are rarely built to be suspicious of their counterparties, and standing integrations carry more authority than anyone remembers granting.
The failure modes follow. A consignee amended after a gate-in event. A discrepancy closed out by an account that should only be able to read. A seal number reconciled against the wrong movement. A weight adjusted so a load passes a check it should have failed. None of these look like an intrusion; they look like ordinary operational corrections, which is why they survive. Around the terminal, Al-Kharj's dairy and agri-industrial base extends the same logic into plant and cold-chain systems, where a batch or despatch record carries the traceability a food business is built on. A scan will find an unpatched service. It cannot tell you who can rewrite the custody history of a shipment.
// 02 Compliance and regulatory drivers in Al-Saih
Freight, customs and processing businesses in Al-Kharj answer to a national baseline, an operational-technology overlay where handling equipment is involved, and a data regime reaching drivers as much as customers.
NCA ECC - Cybersecurity Defence domain
The ECC sets the Kingdom-wide floor, and its Cybersecurity Defence domain obliges periodic, independent penetration testing with tracked remediation. Our reporting drops straight into that control set.
NCA OTCC for terminal & plant equipment
Where gate lanes, weighbridges, cranes or processing lines are in scope, the OTCC applies - segmentation, controlled remote access and hardening, tested without touching a live movement.
Customs declaration & manifest integrity
A distinct question: can a bill of lading, manifest line, seal number, weighing result or declaration be altered, replayed or authorised by the wrong party? We test write paths, approval logic and audit-trail completeness.
Saudi PDPL
Driver identities, licence and vehicle records, gate photography and employee files are personal data under the PDPL. We test where it leaks through portals and reporting extracts.
PCI DSS 4.0 Requirement 11.4
Terminals, hauliers and brokers taking card payment for handling, storage or demurrage inherit Requirement 11.4 - annual internal and external testing plus segmentation testing of the cardholder data environment.
ISO 27001 control A.8.29
Logistics and processing businesses certify to win freight and retail contracts. A.8.29 requires security testing in development and acceptance; our findings satisfy an auditor without translation.
// 03 Penetration testing services for Al-Saih
Engagements here begin at the interfaces - the messages moving between terminal, customs, rail and haulier - then work outward to the network and the applications people log into. Terminal operators lead with API and network testing; processors and suppliers with web and cloud.
API pen testing
The core service here: manifest, declaration, booking and rail-handover interfaces tested for broken object-level authorisation, replay, message tampering and over-trusted partner credentials.
Network pen testing
External perimeter, internal Active Directory and segmentation testing between corporate IT, the terminal environment and gate and yard equipment networks.
Web application pen testing
Manual OWASP Top 10 testing of booking portals, broker and haulier self-service, track-and-trace and despatch applications - focused on who can amend what.
Cloud pen testing
Configuration-aware testing of the hosted visibility, telematics and ERP platforms freight and processing businesses run, including identity and storage exposure.
Mobile app pen testing
iOS and Android testing for driver check-in, proof-of-delivery and yard apps that carry credentials into an uncontrolled physical environment.
Red teaming
Goal-based simulation with a cargo objective - could an intruder alter a custody record and leave the operational picture looking normal?
// 04 How we deliver to Al-Saih
Most of this work reaches its targets over the same connections your partners use, so it runs remotely. Al-Kharj keeps Arabia Standard Time (UTC+3), our own clock, and read-outs come in Arabic or English. On-site attendance is scheduled where a gate house, yard network or plant floor needs a tester present.
What runs remotely
External perimeter, API and integration, web, cloud and mobile testing from our secure environment during your business hours, with anything critical escalated the moment it is confirmed.
What we do on-site
Internal network, wireless, gate and yard segmentation and OT-boundary review at the terminal or plant, sequenced with operations so no lane, crane or line is affected while testing runs.
Every engagement opens with a free 30-minute scoping call. Operational constraints, excluded techniques, freight windows and escalation contacts are fixed in writing before testing starts - alongside a fixed-price quote and a free retest.
// 05 Industries we secure in Al-Saih
Al-Kharj's economy runs on moving containers and processing what the region grows. CyberFortify tests across the sectors that define its risk profile:
// 06 Our methodology
Al-Saih engagements follow the audit-defensible process CyberFortify runs everywhere, with cargo-integrity questions written into the test plan rather than bolted on. IT testing is grounded in the Penetration Testing Execution Standard (PTES) and NIST SP 800-115, with exploitation mapped to MITRE ATT&CK, including ATT&CK for ICS where handling or plant equipment is in scope. As a CREST Accreditation Pathway firm we lead with manual testing, and automation is never turned loose on a network that moves freight.
Scoping & operational constraints
Targets, custody interfaces, partner integrations, permitted techniques and freight windows agreed in writing before any packet is sent.
Fixed quote in 1hReconnaissance & abuse-case modelling
Attack surface mapped around the custody chain: who can create, amend or approve a manifest line, weighing result, seal record or declaration, and from where.
ATT&CK mappedControlled exploitation
Weaknesses proven on the IT and integration side, validated at the operational boundary under agreed conditions - live movements are never the target.
Evidence-ledReporting & free retest
Executive summary, CVSS-scored technical detail and NCA ECC, OTCC and ISO 27001 mapping - followed by a free retest once the fixes ship.
Audit-ready// 07 Why CyberFortify for Al-Saih
A commodity scan vendor
A supplier who runs a tool against your public addresses, never opens the terminal operating system or the partner interfaces around it, and hands you a severity list silent on whether a custody record can be rewritten.
CyberFortify in the Gulf
A Gulf-based, CREST-pathway team in your time zone that tests the custody chain as a system: authorisation logic in the applications, trust between integrated partners, segmentation around gate and yard equipment. Manual exploitation, findings mapped to NCA ECC and OTCC, fixed pricing, free retest.
A typical Al-Saih engagement pairs an API assessment of the customs, manifest and rail-handover interfaces with segmentation testing across the corporate and terminal environments.
// 08 Frequently asked questions
What does penetration testing actually cover at a dry port?
The systems that decide what a container is and where it goes: the terminal operating system and its yard management module, the gate application reading plates and seal numbers, weighbridge and scanning integrations, the interfaces carrying customs declarations, and the rail handover messages exchanged with the freight operator. We test the authorisation logic in each, because most cargo-integrity failures are a permission problem rather than an exploit.
Why is cargo-custody data treated as a security asset rather than paperwork?
Because at an inland terminal the record is the cargo. Nobody opens a sealed box to confirm the bill of lading; downstream parties act on the manifest, the declaration and the seal number as recorded in your systems. Anyone who can amend a consignee, re-weigh a load, close out a discrepancy or backdate a gate event has changed the legal reality of that shipment without touching it. So we test write paths and audit trails as hard as the perimeter.
Can you test terminal and rail systems without disrupting freight movements?
Yes, and the constraint is agreed before we begin. Gate lanes, cranes, weighing equipment and the rail handover interface are treated as operational technology under NCA OTCC: we validate exposure and segmentation, and exercise exploitation against staging or read paths, never against equipment moving a load. Destructive techniques and automated scanning of control networks are excluded in writing during scoping.
Which regulations apply to a freight or processing business in Al-Kharj?
The NCA Essential Cybersecurity Controls set the national baseline, and the Cybersecurity Defence domain drives periodic penetration testing. Where handling, weighing or plant control counts as operational technology, the NCA OTCC applies alongside it. Driver and staff data falls under the Saudi PDPL, card handling adds PCI DSS 4.0 Requirement 11.4, and certified organisations use independent testing as evidence for ISO 27001 control A.8.29.
We are an agri-processor, not a terminal. Is this relevant to us?
Directly. Al-Kharj's dairy and agri-industrial plants are heavy users of the freight corridor and carry the same two-sided exposure: plant and cold-chain control on one side, order, batch and dispatch records on the other. A processor whose despatch data can be altered has a traceability problem, not merely an IT one. We scope those engagements around the boundary between plant systems and the commercial applications that instruct them.