Early access for UK transport operators View the Founding Customer Programme

NIS2 security policy

GLS is designed to support the security, continuity and governance expectations introduced by the EU NIS2 Directive. While not all freight operators fall directly within scope, the same controls benefit all operators by improving cyber resilience, operational transparency and accountability.

Version: 0.7 Last reviewed: Jan 2026 Review cycle: Annual or upon material change

Purpose

This policy explains how GLS supports customers who are subject to the EU NIS2 Directive. It describes the platform security, continuity and governance controls that enable operators to demonstrate responsible management of digital infrastructure and operational data.

Scope

This policy applies to all GLS tenants, users and hosted environments, including development, staging and production workloads.

Principles

  • Security-by-design rather than bolt-on controls
  • Tenant isolation and least-privilege access
  • Traceability and accountability for key actions
  • Backup and continuity aligned to operational importance
  • Clear governance responsibilities and oversight

Controls implemented in GLS

Access control

Access to GLS is tenant-scoped and role-based. Elevated permissions are explicitly granted. Authentication supports secure password management practices and can be extended to MFA-capable identity providers.

Tenant isolation

Operational and commercial data is logically separated by tenant. Access to data requires valid tenant context and authorisation.

Logging & traceability

Security-relevant actions are logged and retained so that operators can review activity and provide evidence to auditors or regulators.

Business continuity

GLS includes resilient architecture and backup processes designed to reduce operational disruption. Restoration procedures are tested and continuously improved.

Secure development & change management

Platform changes are deployed through controlled release processes, reducing the risk of unreviewed or unintended change.

Alignment with NIS2

This policy supports alignment with NIS2 requirements relating to access control, logging, continuity, risk management and governance. GLS does not replace an operator’s internal organisational responsibilities, but forms part of a defendable control framework.

Responsibilities

GLS is responsible for the design and operation of platform-level controls. Customers remain responsible for internal user permissions, operational use of the system and the accuracy of submitted data.

Review

This policy is reviewed at least annually, or sooner where material change occurs in platform design, regulation or risk exposure.