Location · Penetration Testing in Union City, California

Penetration testing in Union City for the rail yards and intermodal terminals that move the freight.

CyberFortify delivers manual, exploit-driven penetration testing to Union City's freight-rail, intermodal-terminal, logistics-technology and industrial operators - an East Bay junction built on the corridor where containers change between rail, truck and the ports. We test the terminal-operating and gate systems, the yard operational technology and the container and cargo data that move with the freight, and map every finding to the TSA surface-transportation security framework, NIST 800-82 and NIST CSF.

Aligned with: TSA surface-transportation security · NIST 800-82 · NIST CSF · IEC 62443 · CCPA/CPRA · SOC 2 · PCI DSS 4.0 · OWASP · PTES
TSA
Surface-transport aligned
OT
Yard & terminal testing
100%
Manual testing
Free retest
Serving Union City: Freight rail & rail-yard operations · intermodal terminals · drayage & trucking · logistics & supply-chain tech · warehousing & distribution · industrial & manufacturing · hazardous-materials handlers · transport & SaaS · professional services Serving Union City: Freight rail & rail-yard operations · intermodal terminals · drayage & trucking · logistics & supply-chain tech · warehousing & distribution · industrial & manufacturing · hazardous-materials handlers · transport & SaaS · professional services
// Executive summary

Union City sits on a historic rail junction in the East Bay industrial corridor, and its sharpest risk lives where freight changes mode - the terminal-operating and gate systems, the yard operational technology and the interchange data that release a container. CyberFortify runs manual OT/ICS, API, cloud and network penetration tests here, aligned to the TSA surface-transportation security framework, NIST CSF, NIST 800-82 and SOC 2. Delivered remotely from our Gulf base on a daily overlap window, with on-site work where it genuinely helps. Fixed price, audit-ready reporting, free retest.

// 01 Why Union City businesses need penetration testing

Follow a single container through Union City and you watch it change hands more times than the trip suggests. It arrives on a rail car, is lifted onto a chassis, clears a gate against a booking reference, and leaves on a truck bound for a warehouse or the ports a few miles west. Every one of those moves is a decision made by software - a terminal-operating system, a gate and appointment system, a yard-management layer - trusting that the reference, the driver and the equipment are what they claim to be.

That is the character of this market. Freight rail and intermodal terminals are surface-transportation critical infrastructure, and the systems behind them were built to move freight quickly rather than to withstand an adversary. Interchange with railroads, drayage carriers and steamship lines runs on EDI and container-tracking feeds that reach far beyond the fence line, which turns a private operational system into a shared authorisation surface. The failure mode is concrete: a container released to the wrong party, a hazardous-materials manifest exposed, or a yard system reached through the business network because the boundary between IT and OT held only on paper.

Scanning does not find that class of flaw. A scanner reports an unpatched service; it cannot tell you that changing an interchange reference in a gate request releases a container that is not yours, or that a drayage partner's over-scoped integration account can read another operator's shipment data. Those are authorisation and segmentation decisions, and confirming them takes a tester who understands terminal operations and the operational technology behind the yard.

// 02 Compliance and regulatory drivers in Union City

Rail and intermodal operators answer to a surface-transportation security regime, the industrial-control standards behind their yard systems, and the consumer-privacy statute covering the corporate and driver data they hold. These are the requirements we most often map evidence against.

R.01 · Surface transport

TSA surface-transportation security

The TSA surface-transportation security directives and framework for freight rail set expectations for network segmentation, access control, incident response and tested cyber resilience. Independent testing is how operators evidence those controls actually hold.

R.02 · OT standard

NIST 800-82 & NIST CSF

NIST 800-82 guides security for the yard and terminal operational technology, while NIST CSF anchors the wider programme. Both rest on demonstrating that segmentation and access controls survive an attacker, not just an audit checklist.

R.03 · Industrial control

IEC 62443

Where terminal equipment, cranes, gate automation and yard control run on industrial control systems, IEC 62443 frames zone-and-conduit segmentation and secure integration - the model we test the IT-to-OT boundary against.

R.04 · Consumer privacy

CCPA / CPRA

California's consumer-privacy regime adds rights, risk-assessment expectations and cybersecurity-audit duties across corporate, customer and driver personal data. Our privacy-regulation guidance sets out how it maps to a testing programme.

R.05 · Vendor assurance

SOC 2 & ISO 27001

Logistics-technology, container-tracking and terminal-software vendors selling into rail and intermodal operators face security review before contract. SOC 2 reports and ISO 27001 A.8.29 evidence both rest on independent penetration testing.

R.06 · Payments

PCI DSS v4.0 - Req 11.4

Gate, demurrage, drayage and billing systems that handle cards must penetration-test the cardholder environment and prove segmentation from the wider terminal network under Req 11.4.5.

// 03 Penetration testing services for Union City

Union City engagements weight operational technology and interfaces over generic perimeters, because that is where freight, data and money change hands. OT and terminal-system testing leads; API and cloud follow, since interchange and tracking platforms live there; web and network cover the corporate and gate front doors.

A.08

OT/ICS pen testing

Yard, terminal and gate operational technology - segmentation, the IT-to-OT boundary, equipment-control exposure and safe-testing of industrial systems.

A.05

API pen testing

Terminal-operating, container-tracking, EDI and interchange interfaces - broken object-level authorisation, partner-identifier abuse and cargo-data exposure.

A.04

Cloud pen testing

Identity, tenant isolation, storage exposure and service-account scope across the platforms hosting tracking, appointment and logistics systems.

A.01

Web application pen testing

Gate portals, appointment and driver-facing applications and customer dashboards, tested against the OWASP Top 10 and business-logic abuse.

A.02

Network pen testing

External, internal and Active Directory testing, plus segmentation checks between corporate, gate and yard operational-technology environments.

A.07

Red teaming

Goal-based adversary simulation, including ransomware scenarios, testing whether an intrusion is detected before a terminal stops moving freight.

// 04 How we deliver to Union City

We will not pretend otherwise: CyberFortify is a Gulf-based firm on UTC+3, and Union City sits ten to eleven hours behind us. We have no California office and no local staff. What we have is a working pattern built around that gap: our late afternoon and evening is your morning, and we hold that window open daily for stand-ups, live triage and read-outs. Testing continues while Union City is offline, so results are waiting when your day starts.

What runs remotely

API, web, cloud, external and much OT-boundary testing from our secure environment - the large majority of terminal, tracking and logistics-technology scope. Findings land in a shared channel as confirmed, and critical issues are escalated immediately.

What we do on-site

Internal network, wireless, segmentation and hands-on yard and terminal OT testing where a tester genuinely needs to be on the wire. We travel when it adds value and say so when it does not.

Every engagement opens with a free 30-minute scoping call and a fixed-price quote within the hour. For live terminal and yard systems we agree test windows around gate hours and operational peaks, and a free retest proves the fixes.

// 05 Industries we secure in Union City

Union City's risk profile is shaped by its position on the rail corridor - freight rail and intermodal terminals at the core, a dense drayage and warehousing economy around them, and the logistics technology that ties it together.

Freight rail & yardsRail-yard ops · interchange · rail-adjacent OT
Intermodal terminalsTerminal-operating systems · gates · equipment control
Drayage & truckingDispatch · appointment systems · ELD integrations
Logistics & supply-chain techContainer tracking · EDI · visibility platforms
Warehousing & distributionWMS · automation · order and inventory data
Industrial & hazmat handlersControl systems · manifest & shipment data

// 06 Our methodology

Union City engagements follow the same audit-defensible process we run everywhere, tuned to the freight exchange at the centre of this market. Testing is grounded in the PTES and NIST SP 800-115, with exploitation mapped to MITRE ATT&CK tactics - including the ICS matrix for yard systems - and application work driven by OWASP, including the API Security Top 10. As a CREST Accreditation Pathway firm we lead with manual testing - automation supports the tester, never replaces one, and never runs unsupervised against operational technology.

01

Scoping & rules of engagement

Targets, terminal and OT surfaces, interchange-partner boundaries, safe-testing limits, test accounts and escalation paths agreed in writing first.

Fixed quote in 1h
02

Reconnaissance & threat modelling

Attack surface mapped around the freight exchange itself - which system releases a container, on whose authority, and where the IT-to-OT boundary actually sits.

ATT&CK aligned
03

Manual exploitation

Weaknesses are exploited and chained under controlled conditions, with cross-operator access proven using seeded test records - never live cargo, manifest or hazmat data.

Controlled exploit
04

Reporting & free retest

Executive summary, CVSS-scored detail and mapping to TSA surface-transportation, NIST 800-82, NIST CSF, SOC 2 or CCPA/CPRA - plus a free retest once fixes ship.

Audit-ready

// 07 Why CyberFortify for Union City

A scan-and-report vendor

Automated output rebadged as a penetration test, blind to terminal authorisation logic and to operational technology, unable to reason about who a booking reference belongs to or what an interchange partner may request.

CyberFortify

A Gulf-based, CREST-pathway team candid about the time difference and structured around it. Manual exploitation aimed at the authorisation seam and the IT-to-OT boundary between terminals, yards and their partners, findings mapped to your assessors' frameworks, fixed pricing and a free retest.

Union City engagements most often pair an OT/ICS assessment with an API penetration test, since a terminal's risk splits between the operational technology in the yard and the interchange and tracking interfaces in front of it. Where a stalled terminal is a business-continuity event, we add red teaming to test detection under a ransomware scenario.

// 08 Frequently asked questions

Do you test terminal-operating and gate systems for Union City intermodal facilities?

Yes - the terminal-operating system and the gate are the operational core, so they are where we concentrate. We test the authorisation model that decides which container moves, which chassis leaves and which driver is admitted: whether a booking or interchange reference can be enumerated or substituted to release a container that is not yours, whether gate and appointment interfaces trust identifiers they should verify, and whether operator roles are enforced per action rather than only at login. We also test the exposure of the yard-management and equipment-control layer, and the IT-to-OT boundary that is supposed to keep business systems and yard operational technology apart.

How do you test intermodal container-tracking and interchange data between partners?

We treat the interchange as its own target rather than assuming it inherits either partner's security. We test the container-tracking, EDI and interchange interfaces directly: how a railroad, drayage carrier or steamship line authenticates to your terminal, whether service credentials are over-scoped, and whether a partner or facility identifier in a request can be changed to read another operator's shipment, booking or hazardous-materials data. We test from the positions a real attacker would occupy, including a hostile interchange partner and a compromised integration account.

Which regulations and standards drive penetration testing for Union City rail and terminal operators?

Freight rail and intermodal terminals are surface-transportation critical infrastructure, and the TSA surface-transportation security directives and framework set the expectation for network segmentation, access control and tested resilience. NIST 800-82 guides security for the yard and terminal operational technology, and many operators anchor the wider programme to NIST CSF, with IEC 62443 where industrial control systems are in scope. CCPA/CPRA covers corporate and driver personal data and adds risk-assessment duties, logistics-technology vendors carry SOC 2, and card-handling gate and billing systems fall under PCI DSS 4.0 Requirement 11.4.

With your team in the Gulf, how does the time gap work for a Union City engagement?

We should be plain: CyberFortify is a Gulf-based firm on UTC+3, ten to eleven hours ahead of Union City, with no California office or local staff. We work a deliberate daily overlap window - our late afternoon and evening is your morning - reserved for stand-ups, live triage and read-outs. Testing continues while your team is offline, so findings are usually waiting when you start the day, and we schedule anything that touches live terminal or yard systems around your operating peaks.

How fast can we get a quote for a Union City engagement?

Book a free 30-minute scoping call and we return a fixed-price quote, usually within the hour and always within one business day. The report is written to hand straight to an auditor, and a remediation retest is included once your fixes ship.

Ready for a pen test in Union City?

Book a free 30-minute scoping call. Our team will recommend the right model and quote a fixed-price engagement - usually within the hour.

Schedule scoping call → Contact CyberFortify →