Union City sits on a historic rail junction in the East Bay industrial corridor, and its sharpest risk lives where freight changes mode - the terminal-operating and gate systems, the yard operational technology and the interchange data that release a container. CyberFortify runs manual OT/ICS, API, cloud and network penetration tests here, aligned to the TSA surface-transportation security framework, NIST CSF, NIST 800-82 and SOC 2. Delivered remotely from our Gulf base on a daily overlap window, with on-site work where it genuinely helps. Fixed price, audit-ready reporting, free retest.
// 01 Why Union City businesses need penetration testing
Follow a single container through Union City and you watch it change hands more times than the trip suggests. It arrives on a rail car, is lifted onto a chassis, clears a gate against a booking reference, and leaves on a truck bound for a warehouse or the ports a few miles west. Every one of those moves is a decision made by software - a terminal-operating system, a gate and appointment system, a yard-management layer - trusting that the reference, the driver and the equipment are what they claim to be.
That is the character of this market. Freight rail and intermodal terminals are surface-transportation critical infrastructure, and the systems behind them were built to move freight quickly rather than to withstand an adversary. Interchange with railroads, drayage carriers and steamship lines runs on EDI and container-tracking feeds that reach far beyond the fence line, which turns a private operational system into a shared authorisation surface. The failure mode is concrete: a container released to the wrong party, a hazardous-materials manifest exposed, or a yard system reached through the business network because the boundary between IT and OT held only on paper.
Scanning does not find that class of flaw. A scanner reports an unpatched service; it cannot tell you that changing an interchange reference in a gate request releases a container that is not yours, or that a drayage partner's over-scoped integration account can read another operator's shipment data. Those are authorisation and segmentation decisions, and confirming them takes a tester who understands terminal operations and the operational technology behind the yard.
// 02 Compliance and regulatory drivers in Union City
Rail and intermodal operators answer to a surface-transportation security regime, the industrial-control standards behind their yard systems, and the consumer-privacy statute covering the corporate and driver data they hold. These are the requirements we most often map evidence against.
TSA surface-transportation security
The TSA surface-transportation security directives and framework for freight rail set expectations for network segmentation, access control, incident response and tested cyber resilience. Independent testing is how operators evidence those controls actually hold.
NIST 800-82 & NIST CSF
NIST 800-82 guides security for the yard and terminal operational technology, while NIST CSF anchors the wider programme. Both rest on demonstrating that segmentation and access controls survive an attacker, not just an audit checklist.
IEC 62443
Where terminal equipment, cranes, gate automation and yard control run on industrial control systems, IEC 62443 frames zone-and-conduit segmentation and secure integration - the model we test the IT-to-OT boundary against.
CCPA / CPRA
California's consumer-privacy regime adds rights, risk-assessment expectations and cybersecurity-audit duties across corporate, customer and driver personal data. Our privacy-regulation guidance sets out how it maps to a testing programme.
SOC 2 & ISO 27001
Logistics-technology, container-tracking and terminal-software vendors selling into rail and intermodal operators face security review before contract. SOC 2 reports and ISO 27001 A.8.29 evidence both rest on independent penetration testing.
PCI DSS v4.0 - Req 11.4
Gate, demurrage, drayage and billing systems that handle cards must penetration-test the cardholder environment and prove segmentation from the wider terminal network under Req 11.4.5.
// 03 Penetration testing services for Union City
Union City engagements weight operational technology and interfaces over generic perimeters, because that is where freight, data and money change hands. OT and terminal-system testing leads; API and cloud follow, since interchange and tracking platforms live there; web and network cover the corporate and gate front doors.
OT/ICS pen testing
Yard, terminal and gate operational technology - segmentation, the IT-to-OT boundary, equipment-control exposure and safe-testing of industrial systems.
API pen testing
Terminal-operating, container-tracking, EDI and interchange interfaces - broken object-level authorisation, partner-identifier abuse and cargo-data exposure.
Cloud pen testing
Identity, tenant isolation, storage exposure and service-account scope across the platforms hosting tracking, appointment and logistics systems.
Web application pen testing
Gate portals, appointment and driver-facing applications and customer dashboards, tested against the OWASP Top 10 and business-logic abuse.
Network pen testing
External, internal and Active Directory testing, plus segmentation checks between corporate, gate and yard operational-technology environments.
Red teaming
Goal-based adversary simulation, including ransomware scenarios, testing whether an intrusion is detected before a terminal stops moving freight.
// 04 How we deliver to Union City
We will not pretend otherwise: CyberFortify is a Gulf-based firm on UTC+3, and Union City sits ten to eleven hours behind us. We have no California office and no local staff. What we have is a working pattern built around that gap: our late afternoon and evening is your morning, and we hold that window open daily for stand-ups, live triage and read-outs. Testing continues while Union City is offline, so results are waiting when your day starts.
What runs remotely
API, web, cloud, external and much OT-boundary testing from our secure environment - the large majority of terminal, tracking and logistics-technology scope. Findings land in a shared channel as confirmed, and critical issues are escalated immediately.
What we do on-site
Internal network, wireless, segmentation and hands-on yard and terminal OT testing where a tester genuinely needs to be on the wire. We travel when it adds value and say so when it does not.
Every engagement opens with a free 30-minute scoping call and a fixed-price quote within the hour. For live terminal and yard systems we agree test windows around gate hours and operational peaks, and a free retest proves the fixes.
// 05 Industries we secure in Union City
Union City's risk profile is shaped by its position on the rail corridor - freight rail and intermodal terminals at the core, a dense drayage and warehousing economy around them, and the logistics technology that ties it together.
// 06 Our methodology
Union City engagements follow the same audit-defensible process we run everywhere, tuned to the freight exchange at the centre of this market. Testing is grounded in the PTES and NIST SP 800-115, with exploitation mapped to MITRE ATT&CK tactics - including the ICS matrix for yard systems - and application work driven by OWASP, including the API Security Top 10. As a CREST Accreditation Pathway firm we lead with manual testing - automation supports the tester, never replaces one, and never runs unsupervised against operational technology.
Scoping & rules of engagement
Targets, terminal and OT surfaces, interchange-partner boundaries, safe-testing limits, test accounts and escalation paths agreed in writing first.
Fixed quote in 1hReconnaissance & threat modelling
Attack surface mapped around the freight exchange itself - which system releases a container, on whose authority, and where the IT-to-OT boundary actually sits.
ATT&CK alignedManual exploitation
Weaknesses are exploited and chained under controlled conditions, with cross-operator access proven using seeded test records - never live cargo, manifest or hazmat data.
Controlled exploitReporting & free retest
Executive summary, CVSS-scored detail and mapping to TSA surface-transportation, NIST 800-82, NIST CSF, SOC 2 or CCPA/CPRA - plus a free retest once fixes ship.
Audit-ready// 07 Why CyberFortify for Union City
A scan-and-report vendor
Automated output rebadged as a penetration test, blind to terminal authorisation logic and to operational technology, unable to reason about who a booking reference belongs to or what an interchange partner may request.
CyberFortify
A Gulf-based, CREST-pathway team candid about the time difference and structured around it. Manual exploitation aimed at the authorisation seam and the IT-to-OT boundary between terminals, yards and their partners, findings mapped to your assessors' frameworks, fixed pricing and a free retest.
Union City engagements most often pair an OT/ICS assessment with an API penetration test, since a terminal's risk splits between the operational technology in the yard and the interchange and tracking interfaces in front of it. Where a stalled terminal is a business-continuity event, we add red teaming to test detection under a ransomware scenario.
// 08 Frequently asked questions
Do you test terminal-operating and gate systems for Union City intermodal facilities?
Yes - the terminal-operating system and the gate are the operational core, so they are where we concentrate. We test the authorisation model that decides which container moves, which chassis leaves and which driver is admitted: whether a booking or interchange reference can be enumerated or substituted to release a container that is not yours, whether gate and appointment interfaces trust identifiers they should verify, and whether operator roles are enforced per action rather than only at login. We also test the exposure of the yard-management and equipment-control layer, and the IT-to-OT boundary that is supposed to keep business systems and yard operational technology apart.
How do you test intermodal container-tracking and interchange data between partners?
We treat the interchange as its own target rather than assuming it inherits either partner's security. We test the container-tracking, EDI and interchange interfaces directly: how a railroad, drayage carrier or steamship line authenticates to your terminal, whether service credentials are over-scoped, and whether a partner or facility identifier in a request can be changed to read another operator's shipment, booking or hazardous-materials data. We test from the positions a real attacker would occupy, including a hostile interchange partner and a compromised integration account.
Which regulations and standards drive penetration testing for Union City rail and terminal operators?
Freight rail and intermodal terminals are surface-transportation critical infrastructure, and the TSA surface-transportation security directives and framework set the expectation for network segmentation, access control and tested resilience. NIST 800-82 guides security for the yard and terminal operational technology, and many operators anchor the wider programme to NIST CSF, with IEC 62443 where industrial control systems are in scope. CCPA/CPRA covers corporate and driver personal data and adds risk-assessment duties, logistics-technology vendors carry SOC 2, and card-handling gate and billing systems fall under PCI DSS 4.0 Requirement 11.4.
With your team in the Gulf, how does the time gap work for a Union City engagement?
We should be plain: CyberFortify is a Gulf-based firm on UTC+3, ten to eleven hours ahead of Union City, with no California office or local staff. We work a deliberate daily overlap window - our late afternoon and evening is your morning - reserved for stand-ups, live triage and read-outs. Testing continues while your team is offline, so findings are usually waiting when you start the day, and we schedule anything that touches live terminal or yard systems around your operating peaks.
How fast can we get a quote for a Union City engagement?
Book a free 30-minute scoping call and we return a fixed-price quote, usually within the hour and always within one business day. The report is written to hand straight to an auditor, and a remediation retest is included once your fixes ship.