A warehouse can be full of stock, every vehicle can be roadworthy and every driver can be ready to leave. But if nobody can access the transport management system, retrieve delivery information or print the right paperwork, very little is going anywhere.
That is the awkward reality of modern logistics: physical operations now depend heavily on digital systems.
A recent cyberattack affecting CEVA Logistics brought that dependency into sharp focus. The company confirmed that part of its European contract logistics operation had been affected, with at least eight warehouses reportedly disrupted. The consequences travelled beyond CEVA itself. Pokémon Center warned of delays affecting some UK orders, while customers of several CEVA clients were told that delivery-related personal information may have been exposed. The investigation was still developing at the time of writing, so the full technical cause and impact were not yet public. TechRadar, Infosecurity Magazine
The important lesson is not that one logistics provider experienced an incident. Cyberattacks happen across every sector.
The lesson is that a problem inside one technology environment can quickly become a warehouse problem, a customer-service problem, a delivery problem and a data-protection problem for numerous other organisations.
For UK transport and logistics leaders choosing an IT partner in 2026, that changes the buying question. You are not simply looking for somebody who can reset passwords and maintain laptops. You are choosing part of your operational resilience.
Transport and logistics companies combine several characteristics that attackers, unfortunately, find rather appealing:
A professional-services firm might tolerate a short interruption by rearranging a few meetings. A transport operator may have vehicles waiting, warehouse teams standing idle and customers asking where their goods have gone.
That is why managed IT services for logistics and transport companies should be evaluated against operational outcomes, not simply a list of technical tools.
The right question is not, “Do you support Microsoft 365?”
It is, “How will you help us continue operating when Microsoft 365, our warehouse platform, our connectivity or one of our suppliers is unavailable?”
That small change in wording tells you a great deal about the provider answering it.
Before comparing UK managed service providers, identify what the business needs to keep moving during disruption.
This is your minimum viable operation: the smallest workable version of the business that can safely receive instructions, manage stock, allocate work, communicate with drivers and serve customers.
Depending on the company, that might include:
Ask prospective providers to map the dependencies between these systems. A glossy dashboard is not much comfort if your transport management system depends on a connection, identity service or ageing server nobody realised was critical.
Good IT support for transport companies begins with understanding the operation. Technology comes second.
The CEVA incident is also a reminder that logistics data does not remain neatly inside one company. Order details, addresses and contact information are routinely shared across retailers, warehouses, carriers and technology platforms.
Every connection creates operational value. It also creates another relationship that must be secured.
An MSP should be able to explain how it will protect:
The National Cyber Security Centre recommends asking how an MSP secures its own access to customer systems, including the use of two-step verification and least privilege. It also advises organisations to examine certifications, responsibilities, incident reporting and supplier access rather than assuming these are covered. NCSC guidance on choosing an MSP
Certifications such as Cyber Essentials Plus can provide useful evidence of a provider’s security baseline. They are not a magic force field, but they are considerably more useful than being told, “Don’t worry, security is built in.”
Ask for evidence. Calmly. A capable provider will be expecting the question.
“Your data is backed up” is not a continuity plan.
You need to know what is backed up, how frequently, where copies are kept, how those copies are protected and how long restoration is likely to take.
Two measures are particularly useful:
Your payroll system and live transport planning platform are unlikely to need identical recovery arrangements. Treating them as though they do either wastes money or creates risk.
The NCSC warns that attackers frequently target backup systems during ransomware incidents. It recommends assessing whether backups are resistant to deletion or alteration and ensuring that restoration is genuinely possible. NCSC ransomware-resistant backup principles
A potential MSP should therefore be able to answer:
The test matters more than the reassuring green tick beside “backup completed”. A backup that has never been restored is a little like an emergency vehicle that has never been started. It may be perfectly fine. That is not quite the same as knowing.
Many logistics operations start early, finish late or run continuously. Buying business-hours support for a round-the-clock operation can create an expensive gap.
Check whether 24/7 assistance is included, optional or limited to certain types of incident. More importantly, establish what the provider means by “support”.
There is a meaningful difference between:
The NCSC suggests that urgent issues would ordinarily warrant a response in under an hour, while also noting that faster service can affect cost. Your agreement should go further by defining severity according to business impact. NCSC guidance on service levels
For example, one faulty office laptop is inconvenient. Thirty warehouse scanners being unable to authenticate is an operational incident, even if every device technically remains switched on.
Look for clear escalation routes, meaningful first responses and senior involvement when a critical service is affected. The helpdesk should understand the difference between “one user cannot print” and “dispatch cannot print”.
An MSP receives privileged access to systems belonging to many customers. That makes its internal security and continuity arrangements part of your risk.
Ask how the provider:
The contract should state who is responsible for what. It should also cover any third parties the MSP uses to deliver its service, notification times, liability, data handling and what happens when the relationship ends.
Ambiguity tends to be very relaxed during the sales process. It becomes remarkably energetic during an incident.
A good provider will resolve day-to-day issues. A valuable provider will also reduce the number and impact of those issues over time.
For logistics businesses, proactive management might include:
This is where fleet and transport IT management becomes a business discipline rather than an accumulation of support tickets.
Ask to see an example service report. It should tell you what is working, what is deteriorating, which risks require a decision and what the provider recommends doing next. It should not require a decoder ring and three cups of coffee.
Security controls reduce the likelihood of an incident. They cannot reduce it to zero.
Your provider should help you prepare for ransomware, a cloud outage, loss of depot connectivity, a compromised supplier and the theft or loss of operational devices.
The NCSC recommends creating response playbooks for an organisation’s most likely and highest-impact incidents. These should define contacts, triage, containment, evidence preservation and the involvement of leadership, legal, HR or communications teams. NCSC incident-management guidance
For a logistics company, a tabletop exercise should include operational questions:
A practical rehearsal often discovers something a vulnerability scanner cannot: the process depends on one person, one spreadsheet or one supplier nobody can contact after 6pm.
When evaluating UK managed service providers, ask each candidate the same questions:
Listen for clear explanations, sensible questions and evidence. Be cautious when every answer is a product name.
My view is simple: in logistics, managed IT should be purchased as a continuity and risk-management capability, not as a cheaper helpdesk.
The recent CEVA story demonstrates why. The reported impact did not remain within the affected provider’s technical environment. It reached warehouses, commercial customers and people waiting for orders in the UK and elsewhere.
That is how digital risk behaves in a connected supply chain. It moves.
The best provider will not promise that nothing will ever go wrong. It will help you understand your exposure, strengthen the fundamentals and prove that the business can continue when something does.
Before signing a managed IT contract, book a black box assessment to assess your cybersecurity exposure and identify the systems, suppliers and operational dependencies that matter most.