Ontario runs on aircraft and freight - an airport that never fully sleeps, air-cargo docks, and the distribution parks feeding them - and the sharpest risk sits where operational systems meet shared tenant networks. CyberFortify runs manual network, API, cloud and web penetration tests here, aligned to TSA aviation and air-cargo security requirements, NIST SP 800-82 / CSF, CCPA/CPRA and SOC 2. Delivered remotely from our Gulf base on a daily overlap window, with on-site work where it genuinely helps. Fixed price, audit-ready reporting, free retest.
// 01 Why Ontario businesses need penetration testing
Watch a pallet move through ONT and you cross a surprising number of systems and companies before it ever leaves the ramp. A shipment is booked and manifested, screened against known-shipper records, handed to a ground handler, loaded by ramp crews working off electronic tasking, and cleared to fly - each step touching a different operator's software on a network that many tenants share.
That shared quality is what makes Ontario different from a warehouse town or a seaport. An airport is a landlord to airlines, cargo carriers, forwarders and concessionaires, and the operational technology that moves bags and freight lives close to the corporate systems that bill and roster. When the boundary between airport operational networks, tenant networks and back-office IT is soft, a foothold from one tenant's ordinary phishing-grade breach can reach a system that was never meant to be internet-adjacent.
Scanning does not find that class of problem. A scanner flags a missing patch; it cannot tell you that a flat VLAN lets a compromised forwarder workstation talk to a cargo-handling controller, that a booking API returns another shipper's air waybill when you change an identifier, or that a ground-handler service account can read manifest data it should never see. Those are segmentation and authorisation decisions, and confirming them takes a tester who understands both the operation and the protocol.
// 02 Compliance and regulatory drivers in Ontario
Aviation and air-cargo operators answer to a federal transportation-security regime, a set of control-system and cybersecurity standards for the operational side, and California's consumer-privacy statute for everything else they hold. These are the requirements we most often map evidence against.
TSA aviation & air-cargo programmes
The Transportation Security Administration governs airport, airline and air-cargo security, including known-shipper and indirect-air-carrier context. Independent testing evidences the technical controls behind those obligations.
NIST SP 800-82 for airport OT
Baggage, cargo-handling and ramp systems are industrial control systems. We test them to 800-82 conventions - safety-first, no disruptive probing of live equipment without an agreed window.
NIST CSF
Most airport and logistics operators anchor the wider security programme to NIST CSF. Penetration testing feeds the Identify and Protect functions with real, exploited evidence rather than a questionnaire.
CCPA / CPRA & the CPPA
California's consumer-privacy regime adds rights, risk-assessment expectations and cybersecurity-audit duties overseen by the California Privacy Protection Agency across booking, passenger and employee data. Our privacy-regulation guidance compares the regimes.
SOC 2 & ISO 27001
The cargo-booking, manifest and logistics-tech platforms selling into airlines and forwarders face security review before contract. SOC 2 reports and ISO 27001 A.8.29 evidence both rest on independent testing.
PCI DSS v4.0 - Req 11.4
Freight-payment portals, parcel counters and convention-centre ticketing must penetration-test the cardholder environment and prove segmentation under Req 11.4.5.
// 03 Penetration testing services for Ontario
Ontario engagements weight segmentation and operational exposure over the public front door, because that is where a shared airport becomes a single attack surface. Network and OT testing lead for airport and ground-handling operators; API and cloud follow for the cargo and logistics platforms; web and mobile cover the booking and tracking front ends.
Network pen testing
External, internal and Active Directory testing, plus segmentation checks between airport operational, tenant and corporate networks - the boundary that matters most here.
API pen testing
Cargo booking, air-waybill, manifest and known-shipper interfaces - broken object-level authorisation, scope enforcement and machine-to-machine credential handling.
Cloud pen testing
Identity, tenant isolation, storage exposure and service-account scope across the platforms hosting logistics, tracking and manifest data.
Web application pen testing
Shipper portals, freight-tracking and cargo-quote applications, tested against the OWASP Top 10 and business-logic abuse.
Mobile app pen testing
Ramp, driver and shipment-tracking apps - local data storage, certificate handling and the API traffic behind the screen.
Red teaming
Goal-based adversary simulation, including ransomware scenarios, testing whether an intrusion reaches operational systems before the cargo operation halts.
// 04 How we deliver to Ontario
We will not dress it up: CyberFortify is a Gulf-based firm on UTC+3, and Ontario sits roughly ten to eleven hours behind us, with no California office and no local staff. What we have is a pattern built around that gap: our late afternoon and evening is your morning, and we hold that window open daily for stand-ups, live triage and read-outs. Testing continues through the California night - which suits a cargo operation that runs around the clock - so results are waiting when your day starts.
What runs remotely
API, web, cloud, external and much internal testing from our secure environment - the large majority of cargo-platform, logistics and tenant scope. Findings land in a shared channel as confirmed, and critical issues are escalated immediately.
What we do on-site
Airport operational-technology, ramp-network, wireless and segmentation testing where a tester genuinely needs to be on the wire, plus in-person workshops with security and operations teams. We travel when it adds value and say so when it does not.
Every engagement opens with a free 30-minute scoping call and a fixed-price quote within the hour. For live airport and cargo environments we agree test windows around operational load and screening cut-offs, and a free retest proves the fixes.
// 05 Industries we secure in Ontario
Ontario's risk profile is shaped by an air-cargo gateway, the distribution economy around it, and the many tenants who share airport infrastructure.
// 06 Our methodology
Ontario engagements follow the same audit-defensible process we run everywhere, tuned to the mix of operational technology and shared networks at the centre of this market. Testing is grounded in the PTES and NIST SP 800-115, with control-system work following NIST SP 800-82 conventions, exploitation mapped to MITRE ATT&CK tactics, and application work driven by OWASP, including the API Security Top 10. As a CREST Accreditation Pathway firm we lead with manual testing - automation supports the tester, never replaces one.
Scoping & rules of engagement
Targets, OT boundaries, tenant and trading-partner scope, test accounts, safe windows and escalation paths agreed in writing first.
Fixed quote in 1hReconnaissance & threat modelling
Attack surface mapped around the seams - which tenant can reach what, which service account calls the cargo API, and where operational networks touch corporate IT.
ATT&CK alignedManual exploitation
Weaknesses are exploited and chained under controlled conditions, with segmentation crossings and cross-shipper access proven using seeded test records - never live cargo or passenger data, and no disruptive probing of running equipment.
Controlled exploitReporting & free retest
Executive summary, CVSS-scored detail and mapping to TSA, NIST 800-82, NIST CSF, CCPA/CPRA or SOC 2 - plus a free retest once fixes ship.
Audit-ready// 07 Why CyberFortify for Ontario
A scan-and-report vendor
Automated output rebadged as a penetration test, blind to network segmentation and authorisation logic, unable to reason about which tenant a foothold sits in or what an over-scoped cargo service account can reach.
CyberFortify
A Gulf-based, CREST-pathway team candid about the time difference and structured around a 24-hour operation. Manual exploitation aimed at the seam between airport operational tech, tenant networks and cargo platforms, findings mapped to your assessors' and TSA-facing reviewers' frameworks, fixed pricing and a free retest.
Ontario engagements most often pair a segmentation-focused network test with an API assessment of the cargo and logistics platforms, since the airport's risk splits between the boundaries that separate its tenants and the authorisation logic in the software they share. Where a stalled cargo operation is the worst outcome, we add red teaming to test detection under a ransomware scenario.
// 08 Frequently asked questions
Do you test airport operational technology and ground-handling systems around ONT?
Yes - it is a core part of what Ontario operators ask us for. We test the operational technology behind baggage and cargo handling, ramp and gate systems, and the controllers and interfaces that sit between them and the corporate network. We work to NIST SP 800-82 conventions for control-system safety: passive reconnaissance first, no disruptive probing against live equipment without an agreed window, and exploitation proven in a way that does not put a running operation at risk. The point is usually to show whether an attacker who lands on the business network can reach a system that moves aircraft, cargo or bags.
How do you test air-cargo booking, manifest and known-shipper data?
We treat the cargo platform as an authorisation problem, not just an application. We test whether a booking, air waybill or manifest belonging to one forwarder or shipper can be read or altered by another, whether known-shipper and chain-of-custody records can be enumerated or forged, and whether the API enforces scope on every request rather than trusting a session. We also test the integrations that pass manifest and screening data between the airline, ground handler and forwarder, since those machine-to-machine links often carry over-scoped service credentials.
Which regulations drive penetration testing for Ontario aviation and air-cargo operators?
The Transportation Security Administration governs aviation and air-cargo security, including airport, airline and air-cargo programmes and the known-shipper and indirect-air-carrier context, and independent testing is a practical way to evidence the technical controls behind those obligations. Airport operational technology is usually anchored to NIST SP 800-82 and the wider NIST CSF. On the data side, CCPA/CPRA adds consumer rights, risk-assessment and cybersecurity-audit duties overseen by the California Privacy Protection Agency, aviation-logistics technology vendors add SOC 2, and any operator taking card payments falls under PCI DSS 4.0 Requirement 11.4.
You are not based in California - how does the time difference actually work?
We will be straight about it: CyberFortify is a Gulf-based firm on UTC+3, roughly ten to eleven hours ahead of Ontario, with no California office and no local staff. We hold a deliberate daily overlap window - our late afternoon and evening lands on your morning - for stand-ups, live triage and read-outs. Testing carries on through the California night, which suits a 24-hour cargo operation, so confirmed findings are usually waiting when your team starts the day.
How fast can we get a quote for an Ontario engagement?
Book a free 30-minute scoping call and we return a fixed-price quote, usually within the hour and always within one business day. The report is written to hand straight to an auditor or a TSA-facing reviewer, and a remediation retest is included once your fixes ship.