The Global Shield: Collaborative Cyber Resilience for global e-Commerce and logistics
The discussion focused on the UPU’s effort to strengthen cyber resilience across the global e-commerce and logistics ecosystem, based on the premise that online purchases depend on a vast, digitally interconnected delivery network rather than just a shopping website. The moderator argued that because cybercriminals now target entire ecosystems, no country, postal operator, or business can protect itself alone, making collective defence essential. André Pharand presented preliminary findings from a UPU cybersecurity survey conducted at the end of 2024, which received 152 responses from 192 member countries, a 76 per cent response rate. He said the data showed only about half of operators were implementing or developing the eight cyber hygiene measures, with especially weak performance in risk management, incident response, and crisis management. Pharand also highlighted a growing capacity squeeze: workloads are rising, budgets are not keeping pace, only about 35 per cent of operators are linked to a national incident response team, and many respondents asked for training, funding, guidance, and expert support. Massimiliano Aschi described a threat landscape driven by industrial-scale criminal organisations that use AI to find vulnerabilities, tailor attacks, and lower the technical barrier for malicious actors, making attacks faster and harder to prevent. He argued that collaboration within and across sectors is now unavoidable, but progress has been limited by resource shortages, mistrust, and uneven capabilities, so resilience must be approached systemically rather than in a fragmented way. Tracy Hackshaw explained that UPU Work Proposal 309 aims to create a minimum security baseline for the postal sector, provide a roadmap for less advanced operators, and support equitable access to training, capacity-building, and other resources. He also stressed the need to educate customers about spoofed parcel messages and abuse of postal identities, noting that operators often learn of such attacks only when customers report them. André’s recommendations were to provide funding, shared training and expert teams, recovery playbooks, priority support for the least prepared operators, and practical assessments to verify readiness. The panel presented Post-ISAC, Trust .post, .post domains, and Secure .post as practical mechanisms for threat sharing, trusted digital identity, and public-facing security tools.
During discussions with the audience, speakers said the UPU plans to work with national cyber authorities, CERTs, sectoral CERTs, other ISACs, and FIRST to build resilience nationally and globally, while also noting cooperation with the World Customs Organization on security and data-sharing issues.
The session concluded that cyber resilience in e-commerce and logistics depends on stronger trust, coordination, and support for weaker operators across the whole supply chain.
- The session framed e-commerce as far more than online shopping interfaces: a click on “buy” activates a complex global logistics network of posts, customs, airlines, warehouses and transport systems, meaning a cyberattack on one node can disrupt the wider ecosystem. This led to the central argument that no country or organisation can defend itself alone and that collective defence is necessary.
- André Pharand’s survey findings showed significant cybersecurity gaps across the postal network despite strong participation from UPU members. The 2024 survey received 152 responses from 192 members, found only around 50% implementation/development across core cyber hygiene measures, and highlighted weak areas such as risk management, incident response and crisis management, with notable regional disparities.
- A major theme was the gap between rising cyber demands and limited capacity. Respondents reported increasing cybersecurity workloads without matching budget growth; some operators even saw budgets cut. Many operators also lacked links to national incident response structures, and open comments stressed needs for funding, training, templates, guidance and access to experts.
- Massimiliano Aschi emphasised that cyber threats are now driven by industrial-scale criminal ecosystems, increasingly accelerated by the malicious use of AI. He argued that attacks are becoming faster, harder to detect and easier for less-skilled actors to launch, making systemic, cross-sector and cross-border cooperation essential rather than optional.
- The discussion focused heavily on UPU’s practical and policy response: Work Proposal 309 aims to establish a minimum cybersecurity baseline and equitable support for less prepared countries, while initiatives such as Post-ISAC, Trust .post, .post domains and Secure .post are intended to turn policy into operational resilience through trusted domains, shared threat intelligence, training and public-facing security tools.
- The overall purpose of the discussion was to examine how the Universal Postal Union and its partners can strengthen cyber resilience across the global postal, logistics and e-commerce ecosystem. The panel aimed to connect policy, survey evidence and operational experience in order to identify vulnerabilities, explain why coordinated defence is necessary, and present concrete mechanisms and recommendations to improve sector-wide resilience.
- The overall tone was professional, collaborative and urgent. It began in an accessible, explanatory way by broadening the audience’s understanding of what e-commerce really entails, then became more serious and cautionary as speakers described systemic vulnerabilities, capability gaps and the growing threat from organised cybercrime and AI-enabled attacks. By the end, the tone shifted slightly towards constructive problem-solving and cautious optimism, with emphasis on shared platforms, partnerships and practical support for weaker operators.
Mayssam Sabra opened by challenging the audience’s instinctive association of e-commerce with a website, shopping cart or platform. She argued that the real system begins after the customer clicks “buy now”, “purchase now” or “submit”, because that action triggers a vast international logistics chain of warehouses, trucks, airlines and post offices connected through digital systems. For that reason, she said, no country, post office, organisation or business can protect itself alone, and the discussion needed to focus on collective defence across an interconnected ecosystem. She introduced the UPU as the UN specialised agency for the postal and logistics sector, based in Bern, Switzerland, linking 192 countries, co-facilitating WSIS Action Line C7, and sitting “at the very heart of this global engine” with a commitment to strengthen cyber resilience in the sector. Sabra then introduced the speakers as bringing different but complementary perspectives: André Pharand on survey findings and policy, Massimiliano Aschi on operational security, and Tracy Hackshaw on UPU policy and platform implementation. She said the session would look behind the curtain at what the UPU was doing to translate broad goals on cyber resilience into practical action. André Pharand grounded the discussion in a UPU cybersecurity survey conducted at the end of 2024. He said the postal, courier, express and parcel sector is especially exposed because cross-border flows depend on interconnected systems spanning origin posts, customs, destination posts and airlines, and because delivery disruption quickly affects customers and businesses used to rapid fulfilment. He also noted that operators differ greatly in institutional form, with some privatised, some governmental and some expected to be self-funding, even though they face similar cyber challenges. The survey was sent to all 192 UPU members and received 152 responses, a 76 per cent response rate. Pharand said this provided a solid basis for preliminary analysis across very large and very small operators. The results showed an uneven baseline: across eight cyber hygiene measures, implementation and development rates were only around 50 per cent overall, and some operators had discontinued measures, decided against them or never considered them. The weakest areas were risk management, incident response and crisis management, with industrialised countries, Europe and the Arab region performing relatively better than other regions. He stressed that these gaps were tied not only to technology but also to staffing, teams and resources. Pharand said cybersecurity workloads were rising faster than budgets, particularly in some regions such as Latin America, and in eight cases operators reported growing workloads even after cybersecurity budgets had been completely cut. He also highlighted limited connection to national response structures: only about 35 per cent of operators reported links with an affiliated national ISIRT, which he described as a national-level incident response team, while 68 per cent of respondents said they were aware of the dot-post initiative. Open comments reinforced the same pattern. Pharand said 26 per cent of respondents provided free-text comments, and 50 per cent of those comments related to capability and funding needs. Operators asked for templates, training, guidance, subject-matter experts and broader support because they lacked the budget and expertise to put measures in place on their own. His conclusion was that the main gap was capacity rather than awareness. When asked later for recommendations, Pharand proposed setting up and providing funding to posts that need it, while recognising that not all operators require the same level of support. He also called for training, shared experts, possible “SWAT team” support, recovery playbooks, timely central assistance from the UPU, prioritisation of the least prepared posts, and digital assessments to verify readiness and track progress over time. Massimiliano Aschi shifted the discussion to the wider threat environment. He said the survey figures were “really impressive” because they reflected a broader reality: cybercrime now operates through an industrial-scale criminal supply chain with structured organisations, divisions of labour and profit-sharing. According to Aschi, these actors continuously scan the public internet for vulnerabilities and can launch targeted or large-scale campaigns quickly, making attacks harder to detect and prevent. He warned in particular about the misuse of artificial intelligence. In his account, AI is being used to identify vulnerabilities across software, devices, networks and infrastructure, and to generate attack tools tailored to what is found. He stressed that this lowers the skill barrier for attackers while increasing the speed, scale and sophistication of threats. From this, Aschi argued that collaboration within the postal sector and across sectors was no longer optional. He said existing international efforts had delivered limited results compared with the scale and speed of organised cybercrime because of resource constraints, scepticism, lack of trust, misaligned interests and uneven capabilities. In his view, physical-digital and fully digital services now have to be protected as one interdependent ecosystem, with attention not only to continuity but also to integrity, compliance and ethics. Tracy Hackshaw then explained the UPU’s policy response. She said Dubai Work Proposal 309 is specifically about cyber resilience for the postal sector. Returning to the image of a parcel moving through a delivery chain, she argued that digital disruption can break that chain just as physical disruption can, with knock-on effects across supply chains, payments, transport and related infrastructure. She said the UPU was trying to establish a minimum security baseline and wanted all operators to become at least “stable” or “good”, using André’s survey data as the baseline from which to improve. Hackshaw also emphasised customer education and public-facing trust issues. She noted that many attacks exploit parcel urgency through spoofed messages and fake delivery notifications, and that operators often do not even know these campaigns are circulating unless customers report them. She said the UPU wanted to pool the knowledge and resources of stronger operators to help weaker ones and to use its position as a UN organisation to build trust across the sector. She linked this to Trust.post and the .post domain. Hackshaw argued that .post is a trust mechanism because it is backed by a UN system agency and restricted to verified, authenticated entities rather than private individuals, which helps reduce impersonation risks in a threat environment where attackers can create convincing lookalike websites and domain names.
She also said the UPU had done an official launch of Secure.post alongside the ISAC in Bern the previous week, on 23 June. Secure.post, she explained, would provide tools and information for both operators and individuals, including a live link-checking tool, password generators, training resources, email and website testing, and access to standards and best practices. The discussion also covered Post-ISAC as a practical mechanism for collective action. Aschi described it as having “remarkable potential” because it brings together operators from all five continents despite major differences in maturity and resources. He said this mattered because operators are linked through data exchanges, tracking systems, customs procedures and payments, and because many posts also provide financial services and may be in insurance, telecommunications, logistics and e-commerce. In his view, Post-ISAC could build local capacity by enabling participants to share threat, incident and best-practice information, creating an early-warning system in which an attack identified in one country can help others prepare. He also suggested postal operators could act as a distributed international sensor network and that a sector-specific ISAC could filter large volumes of threat intelligence into more relevant, usable information. Hackshaw gave a practical illustration of how the platform would work. If a post in Asia were attacked, she said, the operator could confidentially share relevant threat information so that others could prepare for similar attacks. Operators could share indicators, explain how they survived an incident, or ask for help while under attack. She described the ISAC as a collaborative “shield” built through trusted exchange and mutual support. Audience questions were handled briefly. On the role of CERTs and related national structures, Hackshaw said the UPU roadmap included work with national cybersecurity authorities, which are usually connected to national and sectoral CERTs, and that the organisation was finalising a cooperation agreement with FIRST because it could not provide effective support alone. Aschi added that collaborative initiatives such as Post-ISAC could lower access costs through economies of scale and move cyber defence away from isolated models. On spoofing, Hackshaw said the right-hand side of .post is protected through top-level domain controls and that confusingly similar versions would not be allowed, which is why the protected domain matters. On cooperation with the World Customs Organization, Sabra said the UPU and WCO work through a contact committee covering illicit goods, trafficking, physical security and cybersecurity, while Aschi added that customs risk assessment in Europe increasingly depends on exchanged data, though this remains at an early stage. In the closing remarks, Pharand returned to the uneven maturity of operators, noting that some have internal IT departments and access to consultants while others have very limited IT capacity and may not even factor cybersecurity into plans for e-commerce services. He said the survey showed clear room for improvement and a chance to help less-resourced posts reach an acceptable level. Aschi closed with a warning that internet-based service providers face a worsening threat environment and may soon confront “a new epidemic based on AI misusage”. He called for stricter cooperation, stronger trust and support for weaker countries through both funding and capabilities. Sabra then invited participants to continue the conversation at the UPU booth, number 14, at Palexpo from Wednesday 8 July to Friday 10 July. Overall, the speakers broadly agreed that e-commerce depends on an interconnected digital and physical postal-logistics system, that cyber risk in that system is shared, and that weaker operators can expose the wider network.
They also agreed that the main challenge is uneven capability, especially in response, recovery, staffing, funding and links with national cyber bodies.
The discussion pointed towards a practical agenda centred on funding and training support, shared expertise, threat and incident information sharing among operators, trusted digital infrastructure through .post, public-facing tools through Secure.post, and stronger cooperation with national and international partners.
The knowledge base confirms that the Universal Postal Union is a United Nations specialised agency, headquartered in Berne/Bern, Switzerland, and that it is one of the WSIS Action Line co-facilitators in the area of e-business [S16] and [S65]. It also confirms the figure of 192 UPU members [S64].
The knowledge base supports the broader factual premise that cyber resilience requires cooperation across stakeholders and borders. This is echoed in material stressing that industry cannot 'go it alone' and that governments, critical infrastructure owners, providers, and other actors must act collectively [S61]. Related material on regional cyber cooperation also underlines the need for confidence building, capacity building, and coordinated implementation [S68].
The knowledge base provides supporting context that cross-border parcel traffic depends heavily on data-rich logistics and customs systems. It notes that parcel tracking uses 'digital wrappers' containing data on products, exporters, importers, and other global tracking information [S25]. It also highlights customs risk assessment and cross-border parcel security dependencies involving postal and other external data sources, including the UPU [S37].
The knowledge base confirms that the UPU has 192 members, so a survey sent to all UPU members would indeed have gone to 192 entities [S64].
The knowledge base adds context that developing regions and smaller operators face greater cybersecurity challenges and need targeted support. It describes UPU initiatives such as secure.post, starter packages for small island developing states and least developed countries, and partnerships for capacity building, which aligns with the report's emphasis on resource and capability gaps [S3].
The knowledge base directly corroborates this figure in discussion of postal integration with national cybersecurity frameworks, stating that only 35% of posts are affiliated with national information security incident response teams [S3].
E-commerce depends on an invisible, globally interconnected logistics and postal infrastructure, so a cyberattack on one part of the chain can disrupt the whole ecosystem; protection therefore requires collective defence rather than isolated action (Mayssam Sabra)
Arg. 1Mayssam Sabra argues that e-commerce is not just an online purchase interface but a deeply interconnected global logistics system. Because the system is digitally linked across many actors, a cyberattack on one component can cascade across the network, which means security must be organised collectively rather than by isolated organisations acting alone.
She explains that what looks like a simple online purchase actually triggers a large engine of logistics involving airplanes, trucks, warehouses and post offices working together to deliver parcels . She then states that because this network is digital and interconnected, an attack on one part of the chain can cause the whole ecosystem to collapse, and therefore no country, post office, organisation or business can protect itself alone and the network must be shielded together .
on: Cyber resilience in the postal sector requires collective and coordinated action rather than isolated defence by individual operators or countries.
UPU and WCO cooperation through contact mechanisms helps address security at policy and operational levels, including physical security, illicit goods and cybersecurity in cross-border postal flows (Mayssam Sabra)
Arg. 2Mayssam Sabra presents UPU-WCO cooperation as an existing mechanism for managing cross-border postal security risks. Her point is that this coordination covers both strategic and operational issues, showing that cyber resilience in postal flows is tied to broader customs and security cooperation.
In response to an audience question, she says the UPU and the World Customs Organization work together through a contact committee that covers security topics generally . She specifies that these discussions include illicit goods, trafficking, physical security issues and cybersecurity, and that the two bodies meet regularly to address these issues at both policy and operational levels .
on: Building resilience requires stronger links between the postal sector and national or international cyber response bodies, including CERTs, ISACs and broader institutional partners.
on: How mature and effective current cross-border customs/data-sharing approaches already are
Postal and logistics networks involve many interconnected actors such as posts, customs, airlines and delivery systems, making the sector especially exposed to systemic cyber vulnerabilities and high-impact disruption (André Pharand)
Arg. 1André Pharand argues that the logistics and postal sector is structurally vulnerable because shipments move through many interconnected organisations and technical systems. This interdependence means a single cyber incident can produce major downstream disruption, particularly in a sector where fast delivery is expected.
He notes that cross-border goods can touch an origin post, customs agency, destination post and airline, all of which are tied together by interconnected systems that can create vulnerabilities . He adds that logistics companies are frequent targets, alongside healthcare, because of the impact attacks can create, giving the example of a carrier being unable to deliver for two or three days when customers expect next-day delivery .
on: E-commerce and postal logistics form an interconnected digital-physical ecosystem in which a cyberattack on one part can cascade across the wider network, so resilience cannot be treated as an isolated organisational issue.
The UPU survey of member countries showed broad participation and found only moderate adoption of core cyber hygiene measures, with some operators still not considering cybersecurity at all (André Pharand)
Arg. 2André Pharand says the UPU survey provides a solid evidence base across member countries, but the results show uneven and only moderate uptake of basic cyber hygiene. He highlights that some operators have not only failed to implement measures but have not even considered cybersecurity yet.
He reports that the survey was sent to 192 UPU members, received 152 responses and achieved a 76% response rate, which he describes as a solid dataset with good regional participation . He then says adoption across the eight cyber hygiene measures is roughly around 50% when combining implementation and development, and notes that some posts have discontinued, rejected or never even considered cybersecurity .
The weakest areas are response and recovery capabilities, especially risk management, incident response and crisis management, which depend on teams and resources as much as on technology (André Pharand)
Arg. 3He argues that the sector’s main weakness is not basic recognition of cyber risks but the ability to respond and recover when incidents occur. In his view, these weak areas are strongly tied to institutional capacity, staffing and resources, not just technical tools.
When discussing the regional analysis, he says the biggest struggles appear in risk management, incident response and crisis management . He explicitly links these shortcomings to teams and resources more than to purely technical aspects , and later summarises that response and recovery are the real weak spots .
on: The postal sector faces serious capability gaps, especially among less-resourced operators, and support should focus on training, expertise, resources and practical help rather than awareness alone.
Cybersecurity workloads are rising faster than budgets, and in some cases operators face growing demand even after budget cuts, revealing a serious capacity squeeze (André Pharand)
Arg. 4André Pharand argues that postal operators are under growing operational pressure because cyber responsibilities are increasing without matching financial support. This creates a structural capacity squeeze that makes it difficult for operators to keep pace with the threat environment.
He says respondents ranked workload growth very highly, showing that most believe cybersecurity demands are increasing . He contrasts this with budget trends, stating that budgets are not keeping up, highlighting a particularly large gap in Latin America and noting that eight operators saw workload rise even after their cybersecurity budgets were cut completely .
Many postal operators lack links to national incident response structures, limiting coordination with broader national cyber resilience mechanisms (André Pharand)
Arg. 5He contends that one important institutional gap is weak connection between postal operators and national cyber response bodies. Without those relationships, operators are less able to benefit from national-level coordination, intelligence and emergency support.
He states that only about 35% of postal operators have any link with an affiliated national incident response team . He describes this as a lack of alignment, interconnectivity and integration, even though postal operators are often linked to government ownership or oversight .
on: Building resilience requires stronger links between the postal sector and national or international cyber response bodies, including CERTs, ISACs and broader institutional partners.
The major constraint is not basic awareness but lack of capability, funding, expertise and staffing, particularly among less-resourced operators (André Pharand)
Arg. 6André Pharand argues that the central challenge is implementation capacity rather than simple awareness of cyber risks. Operators, especially those with fewer resources, need money, training and expert support to turn awareness into effective resilience.
He says operators’ open comments focused heavily on capability and funding, with requests for more training, funding, guidance and access to subject matter experts . He concludes explicitly that capacity, not awareness, is the gap, and says even strong scores on hygiene factors do not make organisations immune to attack .
on: The postal sector faces serious capability gaps, especially among less-resourced operators, and support should focus on training, expertise, resources and practical help rather than awareness alone.
on: Whether the principal security emphasis should be on institutional/operator capacity or on public-facing trust and anti-spoofing mechanisms
Postal operators are at very different levels of maturity, from highly capable organisations to those with minimal IT support, which creates uneven resilience across the network (André Pharand)
Arg. 7He argues that the postal network is highly uneven in cyber maturity, with some operators well resourced and others barely equipped to address cybersecurity. This disparity matters because the network’s resilience depends on the preparedness of all participants, not just the strongest ones.
He notes earlier that operators range from very large organisations such as USPS to very small posts like Curacao Post, with different operating contexts but similar challenges . In his concluding remarks, he says some operators have their own IT departments and consultants while others barely have IT support, some are not even thinking about cybersecurity yet, and in some cases the responsible IT function is elsewhere in government .
on: The postal sector faces serious capability gaps, especially among less-resourced operators, and support should focus on training, expertise, resources and practical help rather than awareness alone.
The UPU should prioritise least-prepared posts, as they have the greatest need and stand to benefit most from targeted support (André Pharand)
Arg. 8André Pharand argues that limited support should be directed first to the operators with the weakest preparedness. He presents this as both a fairness and efficiency measure, because these posts are the ones actively asking for help and are likely to gain the most from intervention.
In listing recommendations, he says the UPU should prioritise the least prepared posts because they are the ones asking for support and they will benefit the most from it . This recommendation follows his broader survey findings showing uneven maturity and resource shortages across operators .
The UPU should provide direct funding support where needed, alongside shared training, expert assistance and recovery playbooks to help operators both prevent and recover from attacks (André Pharand)
Arg. 9He proposes a practical support package for member countries that combines finance, training and operational recovery tools. The idea is not just to harden systems before attacks, but also to improve operators’ ability to recover quickly when incidents happen.
He recommends setting up and providing funding to posts that require support, while recognising that not all operators need it . He also calls for training, shared experts, a SWAT-team-style support model, and recovery assistance through a playbook and timely centralised support from the UPU .
on: Operational defence should be supported by shared platforms and practical mechanisms for confidential threat intelligence exchange, early warning and coordinated response.
Cybercrime now operates at industrial scale through coordinated criminal supply chains, making attacks faster, more targeted and harder to prevent, especially as AI lowers the barrier for attackers (Massimiliano Aschi)
Arg. 1Massimiliano Aschi argues that cybercrime has evolved into a highly organised industrial ecosystem with specialised roles and coordinated operations. He stresses that AI is amplifying this threat by speeding up attack development, improving targeting and enabling less-skilled actors to launch sophisticated attacks.
He says cyberattacks are sustained by an industrial-scale criminal supply chain run by structured organisations with distributed roles, capabilities and profits, enabling continuous scanning of the public internet and both targeted and large-scale campaigns . He then explains that malicious use of AI helps identify weaknesses in software, devices and networks, generate tailored attack tools, reduce the need for advanced expertise and allow attacks to occur at unprecedented speed and frequency .
The sector should move from isolated defence to collaborative, ecosystem-wide protection because operators are all part of the same supply chain and the weakest link affects all others (Massimiliano Aschi)
Arg. 2He argues that resilience must be understood systemically because postal, logistics and digital service actors now create value through interdependent chains. This means fragmented protection is no longer adequate, and trusted coordination across the ecosystem is essential to reduce systemic vulnerability.
He states that collaboration within and across sectors is no longer optional because hybrid physical-digital services are increasingly interconnected and value creation depends on complex stakeholder, supplier and service-provider chains that must be regarded as a single ecosystem . He adds that without trusted mechanisms of coordination, organisations will continue operating in isolation and remain exposed to severe systemic vulnerabilities .
on: Cyber resilience in the postal sector requires collective and coordinated action rather than isolated defence by individual operators or countries.
Post-ISAC can convert threat intelligence into practical protection by enabling trusted international sharing of threat data, incidents and good practice across operators with different maturity levels (Massimiliano Aschi)
Arg. 3Massimiliano Aschi presents Post-ISAC as a mechanism for translating information-sharing into operational defence. Its value lies in bringing together operators with varying capacities under a trusted coordinating structure so they can exchange actionable intelligence and strengthen each other’s security posture.
He says Post-ISAC is an international community spanning all five continents and a wide range of cyber maturity levels, response capabilities and resource levels, allowing very different needs and realities to be addressed under recognised coordination . He also says operators can share threats, incidents and best practices, building a collective body of intelligence and knowledge that no single operator could create alone .
on: Operational defence should be supported by shared platforms and practical mechanisms for confidential threat intelligence exchange, early warning and coordinated response.
Information shared through Post-ISAC can turn an attack in one country into an early warning for others, improving anticipatory defence across the network (Massimiliano Aschi)
Arg. 4He argues that the practical value of shared intelligence is that local incidents can become network-wide warnings. This allows the system to anticipate threats earlier and adapt before the same attack pattern spreads elsewhere.
He explicitly states that an attack detected in one country can become an early warning for all, strengthening anticipatory response capabilities across the network . He further explains that global exchange can produce local benefits and that the territorial reach of postal operators creates the potential for an international network of sensors that can relay timely information about fraud patterns, technology abuse and attack waves .
on: Operational defence should be supported by shared platforms and practical mechanisms for confidential threat intelligence exchange, early warning and coordinated response.
Collaborative models can reduce costs through economies of scale and help weaker participants access preparedness and response capabilities they could not develop independently (Massimiliano Aschi)
Arg. 5He argues that cooperation is not only strategically desirable but economically efficient. Shared initiatives can spread the cost of services and training across participants, making advanced preparedness and response more accessible to countries and operators with fewer resources.
In answering the question on CERT cooperation, he says the scale and reach of the postal ecosystem can maximise the impact of investments in preparedness and threat response, and that training and awareness initiatives can generate substantial returns . He adds that while access to services may be costly for many countries, these costs can be reduced significantly through economies of scale, and that participation in initiatives like Post-ISAC can be a game changer .
on: Building resilience requires stronger links between the postal sector and national or international cyber response bodies, including CERTs, ISACs and broader institutional partners.
A shift is needed from isolated, island-based security models to collaborative protection barriers that mitigate shared cyber risk across the ecosystem (Massimiliano Aschi)
Arg. 6Massimiliano Aschi argues that many operators still defend themselves in isolation, which leaves the wider ecosystem fragmented and exposed. He calls for participatory security arrangements that create a shared protective barrier across the network.
He says participation in initiatives such as Post-ISAC could shift cyber defence from an isolated, island-based model to a more collaborative and participatory approach . He adds that this would help break the isolation in which many operators still act and foster an ecosystem-wide protective barrier that mitigates shared cyber risk .
on: Building resilience requires stronger links between the postal sector and national or international cyber response bodies, including CERTs, ISACs and broader institutional partners.
Cross-border postal risk assessment increasingly depends on data exchange, and smarter use of data flows can improve customs and shipment risk controls, although this approach is still maturing (Massimiliano Aschi)
Arg. 7He argues that cross-border shipment security is becoming more data-driven, with risk evaluation increasingly based on information exchanged across networks. However, he also cautions that this approach is still at an early stage and has not yet fully matured into a highly effective system.
Speaking from the European context, he says risk evaluation is increasingly being approached through data exchange and that international network data flows are becoming especially relevant for assessing shipment risks . He adds that this can make customs controls smarter, but he believes the approach is still only beginning and is not yet mature enough to produce fully significant results .
on: How mature and effective current cross-border customs/data-sharing approaches already are
Because physical delivery now depends heavily on digital systems, disruption in the digital chain can create ripple effects across payments, transport, supply chains and trade (Tracy Hackshaw)
Arg. 1Tracy Hackshaw argues that postal delivery and e-commerce remain grounded in physical goods movement, but this physical movement is now dependent on digital infrastructure. As a result, a break in the digital chain can trigger wider disruption well beyond the postal operator itself.
He asks the audience to think first about a physical parcel and notes that universal postal service depends on delivering to everyone . He then says that in the digitally connected world, a disruption in one part of the chain can create ripple effects across connected systems such as supply chains, payment systems, transit and transport systems .
on: E-commerce and postal logistics form an interconnected digital-physical ecosystem in which a cyberattack on one part can cascade across the wider network, so resilience cannot be treated as an isolated organisational issue.
Work Proposal 309 aims to establish cyber resilience for the postal sector by creating a minimum security baseline so that all countries can reach at least a stable level of protection (Tracy Hackshaw)
Arg. 2Tracy Hackshaw presents Work Proposal 309 as a framework for sector-wide cyber resilience. Its purpose is to ensure that every country and operator can achieve at least a minimum acceptable level of security rather than leaving resilience to a few advanced players.
He identifies Work Proposal 309 as the proposal on cyber resilience for the postal sector . He says the goal is to establish a minimum security baseline for the sector and to get everyone at least to a stable or 'good' level, with the current data serving as a starting baseline for further recommendations .
The UPU framework is designed to help countries progress step by step and to support equitable allocation of training, capacity-building and awareness resources (Tracy Hackshaw)
Arg. 3He argues that the UPU strategy is meant to be progressive rather than all-or-nothing, helping less advanced operators improve incrementally. At the same time, it is intended to distribute resources more fairly so that countries with weaker capacity can access training and awareness support.
He says the system offers a standardised roadmap to move countries from an earlier stage to at least a more stable level and eventually further along in their development . He also states that embedding this thinking into the UPU work plan is meant to enable equitable allocation of capacity-development, training and sensitisation resources for operators, the wider sector and customers .
on: The postal sector faces serious capability gaps, especially among less-resourced operators, and support should focus on training, expertise, resources and practical help rather than awareness alone.
Digital trust is essential for e-commerce and trade; without trusted digital infrastructure, countries remain dependent on cash and excluded from fuller participation in the digital economy (Tracy Hackshaw)
Arg. 4Tracy Hackshaw argues that trust in digital systems is a precondition for digital commerce. Where that trust is weak, consumers and markets fall back on cash and physical processes, limiting participation in the digital economy.
He says that if people do not trust the digital infrastructure in their country, they do not trust the digital economy or trade to happen . He links this to many least developed economies where cash remains dominant because trust in digital systems is not there, and says the aim is to use global cyber standards to certify countries as safe partners in the global supply chain .
Cyber resilience should be treated as a standard utility for all countries, not a luxury for those with resources, because the global network is only as secure as its most vulnerable operator (Tracy Hackshaw)
Arg. 5He argues for a universalist approach to cyber resilience in the postal sector. Because the whole network depends on all participants, basic cyber protection should be available to every country as a shared standard rather than a premium capability for well-funded operators.
He says the UPU wants the next several years of work to ensure digital inclusion and build a global framework in which cyber resilience is not a luxury for the well-resourced but a standard utility for all . He reinforces the point by stating that the global network is only as secure as its most vulnerable operator and that resilience must be strengthened at every step of the chain .
on: The postal sector faces serious capability gaps, especially among less-resourced operators, and support should focus on training, expertise, resources and practical help rather than awareness alone.
Post-ISAC offers confidential, rapid collaboration so operators can share indicators, learn how others survived attacks, and seek help while under attack (Tracy Hackshaw)
Arg. 6Tracy Hackshaw explains Post-ISAC as a practical operational channel for secure peer-to-peer support. Its function is not only to distribute threat information but also to allow operators to exchange lessons from incidents and obtain assistance during attacks.
He gives a practical example of an attack on a post in Asia and says the ISAC allows that post to share the information causing the threat securely and confidentially with other participants so they can prepare for a widespread or future attack . He adds that the ISAC also helps organisations learn what others did to survive attacks and seek help while they are currently under attack .
on: Operational defence should be supported by shared platforms and practical mechanisms for confidential threat intelligence exchange, early warning and coordinated response.
The .post domain, supported through Trust.post, provides a more secure and verified namespace that reduces spoofing risk and strengthens trust in postal digital services (Tracy Hackshaw)
Arg. 7He argues that the .post top-level domain is a security and trust mechanism, not merely a branding choice. Because access is restricted to verified entities, it helps reduce spoofing and gives users a more trustworthy digital identifier for postal services.
He says many attacks come through the domain name system and that .post functions as a trusted mark backed by a UN system agency . He explains that ordinary domains can be easily purchased and spoofed, especially where letters such as A, I, L and O can be visually manipulated, whereas only verified and authenticated entities can access .post, with no individual registrations allowed .
on: Trust and anti-spoofing measures in the public-facing digital layer are an important part of postal cyber resilience, including domain verification and user-facing tools.
on: Whether the principal security emphasis should be on institutional/operator capacity or on public-facing trust and anti-spoofing mechanisms
Secure.post is intended as a public-facing platform offering tools, guidance, training resources and best practice to help both organisations and individuals improve cyber resilience (Tracy Hackshaw)
Arg. 8Tracy Hackshaw presents Secure.post as the public-service layer of the UPU cyber resilience effort. It is designed to make practical security tools and educational resources directly available, including to people beyond postal operators themselves.
He says Secure.post has been officially launched and will provide a public-facing environment with information and tools . He gives examples including a live link-checking tool, upcoming password generators, training information from partners, email and website testing, and access to best practices and standards for both individuals and organisations .
on: Trust and anti-spoofing measures in the public-facing digital layer are an important part of postal cyber resilience, including domain verification and user-facing tools.
Building resilience requires linking UPU efforts with national cybersecurity authorities, national and sectoral CERTs, and other ISACs to form a stronger chain of protection at both country and global levels (Tracy Hackshaw)
Arg. 9He argues that UPU initiatives must be connected to national cyber institutions rather than operating in parallel. By linking with national authorities, CERTs and sector-specific structures, the postal sector can build layered resilience that works domestically and internationally.
He says the UPU roadmap includes working with national cybersecurity authorities and that this is measured as a KPI rather than left as an informal aspiration . He adds that these authorities are generally linked to national CERTs and C-CERTs, and ideally to sectoral CERTs as well, with the goal of creating another chain of resilience within countries while also connecting globally and working with other ISACs .
on: Building resilience requires stronger links between the postal sector and national or international cyber response bodies, including CERTs, ISACs and broader institutional partners.
Partnership with international incident response communities such as FIRST is important because the UPU cannot provide effective protection alone and must optimise resources through cooperation (Tracy Hackshaw)
Arg. 10Tracy Hackshaw argues that international partnerships are necessary because the UPU’s own resources are limited. Cooperation with established response communities like FIRST allows the UPU to extend its reach and improve effectiveness through shared expertise and networks.
He states that the UPU is finalising a partnership with FIRST, the Forum of Incident Response and Security Teams, and is working through the final details of a cooperation agreement . He says the intention is to optimise UPU resources by working with FIRST teams around the world because the UPU cannot do this by itself and must cooperate to help everyone .
on: Building resilience requires stronger links between the postal sector and national or international cyber response bodies, including CERTs, ISACs and broader institutional partners.
A major attack vector is phishing and parcel-related scam messages that exploit customer urgency, so customer education is an essential part of sector resilience (Tracy Hackshaw)
Arg. 11He argues that cyber resilience in the postal sector is not only a back-end institutional issue but also a public-facing consumer protection issue. Because attackers exploit people’s urgency about package delivery, educating customers becomes a core defensive measure.
He says many attacks in the sector take the form of messages or emails claiming a parcel is late or urgent, which prompts users to click malicious links because they want their package . He concludes that educating customers about where and how these attacks happen is vitally important .
on: Whether the principal security emphasis should be on institutional/operator capacity or on public-facing trust and anti-spoofing mechanisms
Many posts do not even know their brands or URLs are being spoofed unless customers report it, which shows a gap in visibility and public awareness (Tracy Hackshaw)
Arg. 12Tracy Hackshaw argues that postal operators often lack visibility into the abuse of their own brands in scams. This creates a reactive rather than proactive security posture, since operators may only discover spoofing after customers notify them.
He says that many posts do not even know customers are receiving scam messages unless those customers tell them . He adds that this means operators may be unaware that their URLs or email addresses are being spoofed or abused, which is a gap the UPU wants to address partly through customer education .
For many users, e-commerce is associated mainly with visible platforms such as Amazon or shopping websites, but this hides the deeper logistical and digital dependencies that create cyber risk (Audience)
Arg. 1The audience contributions show that people often think of e-commerce in terms of visible consumer-facing platforms rather than the infrastructure behind them. This helps illustrate the gap between public perception and the much broader digital and logistics ecosystem discussed by the panel.
When asked what first comes to mind with e-commerce, audience members answered 'Amazon' and 'Platform, platform' . These examples support the moderator’s point that users tend to focus on websites and marketplaces rather than the interconnected systems underneath them .
Questions from participants highlighted practical trust concerns such as spoofing risks in domain names and the importance of secure naming and verification mechanisms (Audience)
Arg. 2Audience interventions brought attention to a concrete trust issue: whether domain names themselves can be spoofed and how security controls address that risk. This shows that naming, verification and user trust are seen as practical operational concerns, not just abstract policy matters.
One audience participant asked directly how the panel deals with the fact that there is an 'O' in the word 'post' and similarly an 'I' in 'first', raising the problem of visually similar characters and spoofing in domain names . The question itself illustrates participant concern about the reliability of secure naming and verification mechanisms in practice .
on: Trust and anti-spoofing measures in the public-facing digital layer are an important part of postal cyber resilience, including domain verification and user-facing tools.
Audience interventions also underscored the importance of CERT cooperation and customs data-sharing as operational challenges and opportunities in strengthening cyber resilience (Audience)
Arg. 3The audience highlighted two operational areas where resilience depends on wider coordination: cooperation with CERTs and information-sharing for cross-border customs risk assessment. These questions show that participants saw institutional connectivity and data exchange as practical levers for improving sector security.
One participant asked what the major challenge and opportunity were for helping CERTs strengthen prevention and cooperation with corporate and supply-chain partners . Another asked how UPU cooperation with the World Customs Organization could improve risk assessment and data-sharing for cross-border postal shipments in the context of growing e-commerce .
Session Knowledge Graph
Speakers · Topics · Arguments · Relationships
All four speakers described e-commerce as relying on a deeply interconnected logistics and postal system rather than a simple online storefront. Mayssam Sabra said a click to buy triggers a global engine of logistics and warned that an attack on one part of the chain can collapse the wider ecosystem . André Pharand similarly stressed that cross-border shipments pass through multiple connected actors such as origin posts, customs, destination posts and airlines, creating vulnerabilities and potentially high-impact disruption . Massimiliano Aschi argued that hybrid physical-digital services now depend on complex interdependent chains that must be regarded as a single ecosystem, making fragmented resilience inadequate . Tracy Hackshaw reinforced that digital disruption can trigger ripple effects across payment, transport and supply-chain systems .
E-commerce depends on an invisible, globally interconnected logistics and postal infrastructure, so a cyberattack on one part of the chain can disrupt the whole ecosystem; protection therefore requires collective defence rather than isolated action (Mayssam Sabra)
Postal and logistics networks involve many interconnected actors such as posts, customs, airlines and delivery systems, making the sector especially exposed to systemic cyber vulnerabilities and high-impact disruption (André Pharand)
The sector should move from isolated defence to collaborative, ecosystem-wide protection because operators are all part of the same supply chain and the weakest link affects all others (Massimiliano Aschi)
Because physical delivery now depends heavily on digital systems, disruption in the digital chain can create ripple effects across payments, transport, supply chains and trade (Tracy Hackshaw)
This aligns with broader policy framing that digital trade depends on tightly coupled physical and data flows, including parcel tracking and cross-border data exchange [S38]. It is also consistent with critical infrastructure thinking that Internet-dependent transport and communications systems are exposed to cascading cyber risk and require a holistic approach [S36], and with OEWG discussions stressing protection of the entire supply chain [S43].
There was strong agreement that no single operator, post or country can manage these risks alone. Mayssam Sabra explicitly said that no country, post office, organisation or business can protect itself alone and that the network must be shielded together . Massimiliano Aschi said collaboration within and across sectors is no longer optional, warned against operating in isolation, and called for a move away from island-based security models towards collaborative protective barriers . Tracy Hackshaw likewise argued for linking UPU efforts with national authorities, CERTs, sectoral CERTs, other ISACs and FIRST because the UPU cannot do this alone . André Pharand's recommendations also assumed coordinated support through shared experts, centralised recovery assistance and common playbooks .
E-commerce depends on an invisible, globally interconnected logistics and postal infrastructure, so a cyberattack on one part of the chain can disrupt the whole ecosystem; protection therefore requires collective defence rather than isolated action (Mayssam Sabra)
The sector should move from isolated defence to collaborative, ecosystem-wide protection because operators are all part of the same supply chain and the weakest link affects all others (Massimiliano Aschi)
A shift is needed from isolated, island-based security models to collaborative protection barriers that mitigate shared cyber risk across the ecosystem (Massimiliano Aschi)
Building resilience requires linking UPU efforts with national cybersecurity authorities, national and sectoral CERTs, and other ISACs to form a stronger chain of protection at both country and global levels (Tracy Hackshaw)
Partnership with international incident response communities such as FIRST is important because the UPU cannot provide effective protection alone and must optimise resources through cooperation (Tracy Hackshaw)
The UPU should provide direct funding support where needed, alongside shared training, expert assistance and recovery playbooks to help operators both prevent and recover from attacks (André Pharand)
This is directly reinforced by postal-sector discussions calling for collaboration among operators, national authorities, and international organisations, including the rollout of Post-ISAC and shared responsibility models [S34]. It also fits wider international cybersecurity policy that promotes cross-border cooperation, points of contact, and use of existing bilateral, regional, and global mechanisms for critical infrastructure protection [S43].
The speakers agreed that the central problem is uneven capability and resourcing across operators, especially weaker ones. André Pharand said the weak points are response, recovery, risk management and crisis management, and that the gap is capacity rather than awareness, with operators specifically asking for training, funding, guidance and experts . He also underlined the major differences in maturity between postal operators, from highly capable organisations to those with barely any IT support . Tracy Hackshaw said the UPU wants to establish a minimum baseline, help countries move step by step, allocate training and capacity resources more equitably, and ensure cyber resilience is a standard utility for all rather than a luxury . Massimiliano Aschi added that collaborative arrangements can reduce costs through economies of scale and help participants access preparedness and response capabilities they could not build alone .
The major constraint is not basic awareness but lack of capability, funding, expertise and staffing, particularly among less-resourced operators (André Pharand)
The weakest areas are response and recovery capabilities, especially risk management, incident response and crisis management, which depend on teams and resources as much as on technology (André Pharand)
Postal operators are at very different levels of maturity, from highly capable organisations to those with minimal IT support, which creates uneven resilience across the network (André Pharand)
The UPU framework is designed to help countries progress step by step and to support equitable allocation of training, capacity-building and awareness resources (Tracy Hackshaw)
Cyber resilience should be treated as a standard utility for all countries, not a luxury for those with resources, because the global network is only as secure as its most vulnerable operator (Tracy Hackshaw)
Collaborative models can reduce costs through economies of scale and help weaker participants access preparedness and response capabilities they could not develop independently (Massimiliano Aschi)
This reflects documented gaps in the postal sector, including low affiliation with national incident response teams, underfunded cyber workloads, and weaker implementation in developing regions [S34][S35]. It is also consistent with wider digital policy emphasis on capacity development, help-desk style support, and avoiding one-size-fits-all approaches for developing countries [S44], as well as concerns about digital divides limiting less-resourced actors' capabilities [S39].
The speakers broadly agreed on the value of practical, shared operational mechanisms. Massimiliano Aschi described Post-ISAC as an international community where operators can share threats, incidents and best practices, and said that an attack in one country can become an early warning for all . Tracy Hackshaw gave a matching practical example, explaining that if one post is attacked, the ISAC allows secure and confidential sharing so others can prepare, learn survival measures or seek help while under attack . André Pharand's recommendations aligned with this logic by calling for shared experts, central support and recovery playbooks rather than leaving operators to respond alone .
Post-ISAC can convert threat intelligence into practical protection by enabling trusted international sharing of threat data, incidents and good practice across operators with different maturity levels (Massimiliano Aschi)
Information shared through Post-ISAC can turn an attack in one country into an early warning for others, improving anticipatory defence across the network (Massimiliano Aschi)
Post-ISAC offers confidential, rapid collaboration so operators can share indicators, learn how others survived attacks, and seek help while under attack (Tracy Hackshaw)
The UPU should provide direct funding support where needed, alongside shared training, expert assistance and recovery playbooks to help operators both prevent and recover from attacks (André Pharand)
This is strongly supported by the postal-sector proposal for a federated Post-ISAC and secure shared services for maximum confidentiality and sector-wide threat exchange [S35]. It also mirrors established cyber policy frameworks that prioritise information exchange, early warning, situational awareness, and incident response, including cooperation with CERT structures [S40][S42], and broader analysis showing that scaled information-sharing regimes can create network benefits if trust is built into them [S41].
There was agreement that postal cyber resilience depends on stronger institutional connectivity. André Pharand highlighted a gap, saying only about 35% of postal operators have links with national incident response teams . Tracy Hackshaw said the UPU roadmap includes working with national cybersecurity authorities, national and sectoral CERTs, other ISACs and FIRST in order to create a chain of resilience domestically and globally . Massimiliano Aschi supported this by arguing for a shift from isolated models to collaborative protective barriers and by stressing that economies of scale make such shared approaches especially valuable . Mayssam Sabra also pointed to existing institutional cooperation with the World Customs Organization through a contact committee addressing security issues at policy and operational levels .
Many postal operators lack links to national incident response structures, limiting coordination with broader national cyber resilience mechanisms (André Pharand)
Building resilience requires linking UPU efforts with national cybersecurity authorities, national and sectoral CERTs, and other ISACs to form a stronger chain of protection at both country and global levels (Tracy Hackshaw)
Partnership with international incident response communities such as FIRST is important because the UPU cannot provide effective protection alone and must optimise resources through cooperation (Tracy Hackshaw)
Collaborative models can reduce costs through economies of scale and help weaker participants access preparedness and response capabilities they could not develop independently (Massimiliano Aschi)
A shift is needed from isolated, island-based security models to collaborative protection barriers that mitigate shared cyber risk across the ecosystem (Massimiliano Aschi)
UPU and WCO cooperation through contact mechanisms helps address security at policy and operational levels, including physical security, illicit goods and cybersecurity in cross-border postal flows (Mayssam Sabra)
This directly matches evidence that most postal operators lack integration with national incident response teams and that stronger partnerships with CERTs and other institutions are being pursued as a remedy [S34][S35]. It is also in line with international practice emphasising exchanges between national CERTs, regional associations, and formal points-of-contact networks for real-time cooperation [S43].
A clear area of agreement emerged around the importance of trusted digital identifiers and public-facing protection tools. Tracy Hackshaw argued that many attacks come through the DNS, that .post serves as a trusted mark backed by verified registration, and that Secure.post will offer public tools such as link checking, password generation, training and testing resources . The audience directly reinforced the practical relevance of this issue by questioning spoofing risks associated with letters in domain names, showing shared concern about whether naming and verification mechanisms are secure in practice .
The .post domain, supported through Trust.post, provides a more secure and verified namespace that reduces spoofing risk and strengthens trust in postal digital services (Tracy Hackshaw)
Secure.post is intended as a public-facing platform offering tools, guidance, training resources and best practice to help both organisations and individuals improve cyber resilience (Tracy Hackshaw)
Questions from participants highlighted practical trust concerns such as spoofing risks in domain names and the importance of secure naming and verification mechanisms (Audience)
This is reinforced by the UPU's .post initiative, framed as providing secure digital identity for postal operators and supported by secure platform services [S34][S35]. More broadly, digital policy discussions on trust emphasise concrete trust-building mechanisms such as labels, transparency tools, and reliable digital services rather than abstract appeals to trust alone [S30][S31], while DNS governance discussions underline the role of safer domain practices and validation mechanisms in maintaining trustworthy digital environments [S32][S33].
Both framed the postal and logistics environment as a deeply interconnected system in which many actors and systems are linked, making cascading disruption plausible if one component is attacked. Sabra made this point conceptually at the outset , while Pharand grounded it in the concrete flow of cross-border shipments through posts, customs and airlines . These speakers all argued that sector resilience must be collective. Sabra said protection cannot be done alone . Aschi said interdependent services require a systemic perspective and trusted coordination . Hackshaw translated that into institutional practice by advocating links with national authorities, CERTs, ISACs and global partners . All three treated resource inequality and limited capability as a central challenge. Pharand said operators need funding, training and expertise, and that capacity rather than awareness is the main gap . Hackshaw proposed a roadmap and equitable allocation of training and sensitisation resources . Aschi added that shared initiatives can reduce costs and make stronger preparedness accessible to weaker participants . Both presented Post-ISAC as a practical tool for turning intelligence-sharing into operational defence. Aschi emphasised the strategic value of collective intelligence and early warning across continents , while Hackshaw gave a practical illustration of secure sharing during or after an attack . Pharand identified a structural weakness in the lack of links between postal operators and national incident response bodies . Hackshaw then proposed the remedy: deliberate integration with national cybersecurity authorities, CERTs, sectoral CERTs, ISACs and FIRST . Their viewpoints align around the need for stronger institutional integration. The audience's questions showed concern about spoofing and naming trust , which closely matched Hackshaw's emphasis on phishing, spoofed URLs and the need for .post, Trust.post and user education as part of resilience .
An unexpected area of consensus was the prominence given to naming and trust infrastructure. Rather than focusing only on internal technical controls, both the speaker and the audience converged on the importance of secure public-facing identifiers and user tools. Hackshaw argued that DNS-based spoofing is a major attack path and promoted .post and Secure.post as protective instruments , while the audience independently raised concerns about spoofable characters in domain names .
A notable consensus emerged around cyber resilience as a matter of equitable development rather than simply technical compliance. Pharand wanted the least-prepared posts prioritised , Hackshaw argued that resilience should be a standard utility for all countries and tied it to digital inclusion , and Aschi stressed that collaborative models can lower costs and support weaker participants . This broadens the conversation beyond conventional cyber defence.
It was striking how consistently both panellists and audience members returned to institutional cooperation beyond the postal sector itself. The audience raised CERT cooperation and customs data-sharing as practical priorities . Pharand identified weak links with national incident response bodies , Hackshaw advocated formal connections to national authorities, CERTs, ISACs and FIRST , Aschi called for collaborative barriers instead of isolation , and Sabra pointed to UPU-WCO contact mechanisms already addressing security issues at policy and operational levels .
The speakers showed strong agreement on the core diagnosis: e-commerce and postal logistics are part of a single interconnected digital-physical ecosystem; cyber risk is systemic; and isolated defence is insufficient. They also broadly agreed that the biggest weaknesses lie in uneven capability, weak response and recovery capacity, and insufficient links to national and international cyber response structures .
Mayssam Sabra presents UPU-WCO cooperation through a contact committee as an established mechanism that regularly addresses security issues at both policy and operational levels, suggesting a functioning cooperative framework for cross-border postal security . Massimiliano Aschi, however, describes data-driven risk evaluation in customs as only at the beginning and not yet mature enough to produce fully significant results, which implies a more cautious assessment of present operational effectiveness .
UPU and WCO cooperation through contact mechanisms helps address security at policy and operational levels, including physical security, illicit goods and cybersecurity in cross-border postal flows (Mayssam Sabra)
Cross-border postal risk assessment increasingly depends on data exchange, and smarter use of data flows can improve customs and shipment risk controls, although this approach is still maturing (Massimiliano Aschi)
External sources suggest a mixed picture rather than settled maturity: customs and e-commerce discussions show data sharing can improve risk profiling and clearance but remain under development and unevenly implemented [S37]. Postal-sector materials likewise list cross-border intelligence sharing and coordination mechanisms as ongoing needs rather than fully solved issues [S35], while WTO-era e-commerce governance remains contested on several data-related questions [S38].
André Pharand argues that the central problem is implementation capacity inside postal operators: funding, training, expert support, staffing, and response/recovery capability rather than mere awareness . Tracy Hackshaw places stronger practical emphasis on public-facing trust infrastructure such as the verified .post namespace, Secure.post tools, and customer education against phishing and spoofed parcel messages . These positions do not directly contradict each other, but they prioritise different routes to resilience.
The major constraint is not basic awareness but lack of capability, funding, expertise and staffing, particularly among less-resourced operators (André Pharand)
The .post domain, supported through Trust.post, provides a more secure and verified namespace that reduces spoofing risk and strengthens trust in postal digital services (Tracy Hackshaw)
A major attack vector is phishing and parcel-related scam messages that exploit customer urgency, so customer education is an essential part of sector resilience (Tracy Hackshaw)
External sources support both sides of this emphasis debate. Capacity-building, funding, training, and operational integration with incident response bodies are repeatedly presented as urgent priorities for the postal sector [S34][S35]. At the same time, authoritative discussions of digital trust and DNS safety emphasise secure digital identity, domain governance, validation, and proactive anti-abuse measures as core trust and security tools [S30][S32][S33].
This is an unexpected disagreement because the panel is otherwise highly aligned on the need for cooperation. Yet when discussing customs and cross-border data-sharing, Mayssam highlights an already functioning UPU-WCO process that meets regularly at policy and operational level , whereas Massimiliano gives a more reserved practitioner view, saying smarter data-driven customs risk evaluation is still only beginning and not yet mature . The tension is subtle but notable: institutional cooperation exists, but its practical maturity appears less certain.
The discussion featured very low direct disagreement. Speakers overwhelmingly converged on the diagnosis that e-commerce and postal logistics form an interconnected cyber-risk ecosystem requiring collective action, stronger trust mechanisms, and support for weaker operators . The main differences were about emphasis and implementation pathway: André Pharand stressed funding, staffing, training, recovery playbooks and prioritising the least prepared posts ; Tracy Hackshaw stressed minimum baselines, trust infrastructure such as .post and Secure.post, and customer-facing anti-phishing measures ; Massimiliano Aschi stressed strategic collaboration, Post-ISAC, early warning, economies of scale, and the growing AI-enabled threat environment ; Mayssam Sabra framed the issue in terms of collective defence and highlighted existing institutional cooperation including with WCO .
All four speakers agree on the same broad goal: protecting an interconnected postal and e-commerce ecosystem through collective resilience rather than isolated defence . However, they emphasise different pathways to achieve it: Mayssam frames the need conceptually as collective defence ; André prioritises funding, training, shared experts and readiness assessments ; Massimiliano stresses trusted collaboration, ecosystem-wide intelligence sharing and systemic coordination through mechanisms like Post-ISAC ; Tracy focuses on policy baselines, equitable capacity-building, trust infrastructure such as .post and Secure.post, and customer awareness .
E-commerce depends on an invisible, globally interconnected logistics and postal infrastructure, so a cyberattack on one part of the chain can disrupt the whole ecosystem; protection therefore requires collective defence rather than isolated action (Mayssam Sabra) Postal and logistics networks involve many interconnected actors such as posts, customs, airlines and delivery systems, making the sector especially exposed to systemic cyber vulnerabilities and high-impact disruption (André Pharand) The sector should move from isolated defence to collaborative, ecosystem-wide protection because operators are all part of the same supply chain and the weakest link affects all others (Massimiliano Aschi) Because physical delivery now depends heavily on digital systems, disruption in the digital chain can create ripple effects across payments, transport, supply chains and trade (Tracy Hackshaw)
These speakers share the goal of helping weaker or less-prepared operators improve resilience, but differ in their preferred means. André argues for direct funding, shared expert teams, recovery playbooks and prioritisation of the least prepared posts . Tracy emphasises a standardised roadmap and equitable allocation of training, capacity-building and awareness resources within the UPU work plan . Massimiliano highlights economies of scale and collaborative participation models such as Post-ISAC as a cost-reducing way to spread preparedness and response capability .
The UPU should provide direct funding support where needed, alongside shared training, expert assistance and recovery playbooks to help operators both prevent and recover from attacks (André Pharand) The UPU framework is designed to help countries progress step by step and to support equitable allocation of training, capacity-building and awareness resources (Tracy Hackshaw) Collaborative models can reduce costs through economies of scale and help weaker participants access preparedness and response capabilities they could not develop independently (Massimiliano Aschi)
Both speakers support Post-ISAC as a key operational tool, but they frame its function somewhat differently. Tracy stresses immediate practical assistance: confidential sharing, learning how others survived incidents, and getting help while under attack . Massimiliano places more emphasis on Post-ISAC as a strategic intelligence and coordination mechanism that creates anticipatory early warning and a collective knowledge base across operators with different maturity levels .
Post-ISAC offers confidential, rapid collaboration so operators can share indicators, learn how others survived attacks, and seek help while under attack (Tracy Hackshaw) Post-ISAC can convert threat intelligence into practical protection by enabling trusted international sharing of threat data, incidents and good practice across operators with different maturity levels (Massimiliano Aschi) Information shared through Post-ISAC can turn an attack in one country into an early warning for others, improving anticipatory defence across the network (Massimiliano Aschi)
Both speakers support broader institutional cooperation beyond the UPU itself, but they highlight different partner structures. Tracy focuses on linking UPU work with national cybersecurity authorities, national and sectoral CERTs, other ISACs, and a partnership with FIRST . Mayssam points to the UPU-WCO contact committee as an existing channel covering operational and policy coordination on cross-border security matters . They agree on cooperation as the goal, while differing on the most salient institutional pathways.
Building resilience requires linking UPU efforts with national cybersecurity authorities, national and sectoral CERTs, and other ISACs to form a stronger chain of protection at both country and global levels (Tracy Hackshaw) UPU and WCO cooperation through contact mechanisms helps address security at policy and operational levels, including physical security, illicit goods and cybersecurity in cross-border postal flows (Mayssam Sabra)
- E-commerce is not only a consumer-facing website or platform; it relies on a deeply interconnected global postal and logistics infrastructure, so cyber risk in one part of the chain can affect the entire ecosystem.
- The postal and logistics sector is especially exposed to systemic cyber disruption because it depends on many interconnected actors, including postal operators, customs, airlines, payment systems, transport and delivery networks.
- Cybercrime now operates through coordinated, industrial-scale criminal supply chains, and the misuse of AI is making attacks faster, more scalable, more targeted and easier for less-skilled attackers to carry out.
- The discussion repeatedly stressed that isolated defence is no longer sufficient; cyber resilience for e-commerce and logistics requires collective, ecosystem-wide protection.
- UPU survey findings showed only moderate adoption of core cyber hygiene measures across member countries, with some operators still not actively considering cybersecurity.
- The main weakness identified across the postal network is not awareness alone, but limited capability in response and recovery, especially in risk management, incident response and crisis management.
- Cybersecurity workloads are increasing faster than available budgets, creating a capacity squeeze, particularly for less-resourced postal operators.
- Postal operators are at very different levels of maturity, from highly capable organisations to those with minimal IT support, creating uneven resilience across the global network.
- Many operators lack sufficient links with national incident response structures such as CERTs or CSIRTs, which weakens broader coordination and resilience.
- Work Proposal 309 was presented as the UPU policy basis for building a minimum cybersecurity baseline across the postal sector so that no country is left digitally vulnerable.
- The UPU’s strategy is framed around inclusive cyber resilience: cyber protection should be treated as a standard utility for all members, not a luxury only available to better-resourced countries.
- The least-prepared postal operators were identified as priority beneficiaries for support because they are the most vulnerable and their weaknesses can affect the entire network.
- Recommended practical measures included funding support, training, shared expert assistance, recovery playbooks and readiness assessments to help operators improve both prevention and recovery.
- Post-ISAC was presented as a practical mechanism for turning threat intelligence into operational protection by enabling confidential international sharing of incidents, indicators, lessons learned and early warnings.
- The .post domain and Trust.post were described as mechanisms to strengthen trust and reduce spoofing risk by offering a verified and more secure namespace for postal digital services.
- Secure.post was introduced as a public-facing cyber resilience platform intended to provide tools, guidance, training resources and best practices for organisations and individuals.
- Customer-facing phishing and parcel scam messages were highlighted as a major vulnerability, making public awareness and customer education an important part of cyber resilience.
- Cooperation with national cybersecurity authorities, CERTs, sectoral CERTs, other ISACs and international bodies such as FIRST was seen as essential for building both national and global protective chains.
- Cross-border postal and customs risk assessment increasingly depends on data exchange, and smarter use of data flows was identified as a growing but still maturing area of operational resilience.
“Mayssam Sabra reframed e-commerce by saying that it does not end when a customer clicks ‘buy’; that click triggers ‘a massive invisible global engine of logistics’ and that ‘a cyber attack on one part of its chain can cause the entire ecosystem to collapse’.”
“André Pharand highlighted that the key gap is not simple awareness but capacity: roughly half of cyber hygiene measures are only implemented or under development, response and recovery are weak spots, and rising workload is not matched by budgets.”
“Massimiliano Aschi argued that cyberattacks are now sustained by ‘a truly industrial-scale supply chain’ of criminal organisations, and that AI has become a disruptive enabler that lowers the skill barrier for attackers while increasing speed and sophistication.”
“Massimiliano Aschi stated that ‘collaboration among stakeholders within the same sector, as well as cross-sector cooperation, is no longer a matter of choice, but an unavoidable necessity’.”
“Massimiliano Aschi warned that ‘without such mechanism of coordination and trust, the risk is that we will continue to operate in isolation… visible, vulnerable, and sooner or later, bound to be struck’.”
“Tracy Hackshaw argued that cyber resilience should be ‘not a luxury for those who have the resources but a standard utility for all’, adding that ‘our global network is only as secure as the most vulnerable operator’.”
“Tracy Hackshaw observed that many attacks exploit customer behaviour, such as fake parcel-delay messages, and that ‘the majority of [postal operators] don’t even know that these customers are getting those messages’ unless customers report them.”
“André Pharand’s recommendations included funding support, shared experts, recovery playbooks, prioritising the least prepared posts, and verifying readiness through practical digital assessments.”
“Massimiliano Aschi described Post-ISAC as turning global exchange into local benefit: ‘An attack detected in one country can become an early warning for all’, and postal operators’ territorial reach could form an ‘integrated international network of sensors’.”
“Tracy Hackshaw explained that the .post top-level domain is valuable because it is restricted to verified entities, unlike easily spoofed domains, and that this can provide a trusted mark in a phishing-heavy environment.”
“In response to the audience question on CERTs, Massimiliano Aschi argued that initiatives like Post-ISAC could shift cyber defence ‘from an isolated, island-based model to a more collaborative and participatory approach’, helping to ‘break the isolation in which many operators still act’.”
“In his closing remarks, Massimiliano Aschi warned that ‘we are going to face a new epidemic based on AI misusage’ and linked this to the need to support weaker countries because ‘the weakest part of the chain needs to be supported’.”
What final recommendations will emerge from the UPU cybersecurity survey after feedback on the preliminary findings is incorporated?
He stated that the survey findings and recommendations were preliminary and intended to gather feedback before producing a final set of recommendations. This is important because the final recommendations will shape practical policy and support for member countries.
Why did industrialised countries participate less in the survey, and how might this affect the completeness of the sector-wide cybersecurity picture?
He noted lower participation from industrialised countries and speculated that they may feel more self-sufficient. This matters because uneven participation may leave gaps in benchmarking, comparison, and planning across the global postal network.
How can postal operators strengthen weak areas such as risk management, incident response and crisis management, especially where staff and resources are limited?
He identified these as the weakest areas across regions and linked them to capacity rather than awareness. This is important because these capabilities determine whether operators can recover quickly from cyber incidents and avoid wider systemic disruption.
How can the gap between rising cybersecurity workload and inadequate or declining budgets be addressed across different regions?
He highlighted a clear mismatch between increasing demand and insufficient funding, including cases where budgets were cut entirely. This is important because without sustainable funding, even aware and motivated operators cannot implement essential protections.
Why do only around 35% of postal operators have links with affiliated national CSIRTs/CERTs, and how can those connections be expanded?
André identified the low level of linkage, an audience member asked directly about the challenge and opportunity for CERT cooperation, and Tracy described plans to work with national cybersecurity authorities and FIRST. This is important because stronger links with national incident-response bodies would improve prevention, coordination and recovery.
What concrete support model should the UPU provide to member countries: funding, templates, training, shared experts, playbooks, or direct recovery assistance?
He summarised operator requests and later proposed specific recommendations including funding, training, shared experts and recovery playbooks. This is important because the design of the support model will determine whether less-prepared operators can realistically improve resilience.
How can the least prepared postal operators be prioritised and assisted without leaving others behind?
André recommended prioritising the least prepared posts, Tracy stressed that no country should be left digitally vulnerable, and Massimiliano emphasised support for weaker countries as part of the same supply chain. This is important because the weakest operators can expose the whole ecosystem to systemic risk.
How can practical digital assessments be designed to verify postal operators’ readiness and track improvement over time?
He proposed verifying readiness through practical checks and a digital assessment. This is important because measurable assessment is necessary to understand progress, target assistance and maintain accountability.
How can a truly shared strategic vision for cyber resilience be built across the postal and logistics ecosystem despite lack of resources, trust, alignment and differing interests?
He argued that the main obstacle is not only technical capability but also the absence of a common strategic vision across interconnected stakeholders. This is important because fragmented approaches leave systemic vulnerabilities unaddressed.
How should hybrid physical-digital and public-interest services be protected using a systemic rather than fragmented resilience model?
He stressed that resilience must cover interconnected physical, digital and public-interest services, including operational continuity, information integrity, compliance and ethics. This is important because postal systems increasingly underpin essential services and cross-border commerce.
What incentive mechanisms and practical operational support can encourage stronger cooperation on service resilience?
He explicitly said cooperation should be aimed at strengthening resilience through incentives and operational support. This is important because collaboration often fails without concrete mechanisms that make participation useful and feasible.
How can malicious use of artificial intelligence in cyberattacks against e-commerce and logistics be detected, prevented and mitigated?
He repeatedly warned that AI is accelerating attacks, lowering the skill threshold for malicious actors and creating an unprecedented threat volume. This is important because AI-enabled threats could rapidly outpace current defensive models across the sector.
How can the UPU establish and enforce a minimum cybersecurity baseline for all postal operators regardless of development stage?
She described the goal of getting all operators to at least a stable minimum level of security. This is important because uneven baseline security across countries undermines the trust and safety of the whole global network.
How can customers be better educated to recognise phishing, spoofed parcel messages and fraudulent postal links?
She noted that customers often receive scam messages about delayed parcels and that many postal operators are unaware until customers report them. This is important because customer-facing fraud directly harms trust in e-commerce and can bypass organisational defences.
How can stronger trust in digital infrastructure and the digital economy be built, especially in least-developed economies where cash remains dominant?
She linked cyber standards, trust marks and secure infrastructure to broader digital inclusion and adoption. This is important because lack of trust inhibits e-commerce growth and reduces the benefits of digital trade and postal modernisation.
How effective can Post-ISAC become as a practical mechanism for sharing threat intelligence, early warnings and best practices across operators with very different levels of cyber maturity?
Both speakers described Post-ISAC as a tool for confidential sharing, anticipatory warning and collective intelligence, but its long-term effectiveness remains an implied area for development and evaluation. This is important because information sharing is central to collective defence in a distributed global network.
How can postal operators be used as an integrated international network of local cyber sensors to detect fraud patterns, technology abuse and new attack waves?
He suggested that the territorial presence of postal operators creates sensor-like potential for the wider community. This is important because local observations could provide early warning and improve global situational awareness.
How can sector-specific threat intelligence be filtered and curated so that operators receive actionable information rather than overwhelming volumes of raw data?
He noted that understanding sector-relevant technologies allows the community to produce curated intelligence feeds focused on stakeholder needs. This is important because usable intelligence is more valuable than large quantities of unfocused threat data.
How secure and scalable are Trust.post, Secure.post and the .post top-level domain as practical anti-spoofing and trust-building tools?
Tracy presented these platforms as key practical tools, and an audience member challenged the spoofing issue directly. This is important because their credibility depends on whether they can materially reduce impersonation, phishing and misuse in real-world conditions.
What technical and governance limitations remain in preventing spoofing on the left side of the domain name, even if .post is protected on the right side by ICANN rules?
The audience member raised a precise technical concern, and Tracy answered mainly regarding the protected top-level domain. The broader issue of left-side spoofing remains a follow-up area. This is important because many phishing attacks rely on lookalike naming at the subdomain or domain-label level.
What is the main challenge and main opportunity in helping national CERTs strengthen prevention and collaboration with corporate and supply-chain partners?
The audience member posed this explicitly, and both Tracy and Massimiliano answered in part by pointing to cooperation, scale and shared resources. This is important because prevention depends on operational partnerships between public authorities and private-sector ecosystem actors.
How can partnership with FIRST be operationalised to improve the UPU’s global cyber resilience work?
She mentioned that a cooperation agreement with FIRST was being finalised but did not detail how it would function in practice. This is important because the effectiveness of this partnership could significantly expand incident-response capacity and international coordination.
How can economies of scale reduce the cost of cybersecurity services and preparedness for participating countries in the postal ecosystem?
He suggested that access costs could be significantly reduced through collective approaches such as Post-ISAC. This is important because affordability is a major barrier for many countries and pooled models may unlock broader participation.
How does UPU cooperation with the World Customs Organization enhance risk assessment and data sharing for cross-border postal shipments in the context of growing e-commerce?
Ahmed Omar asked this directly, Tracy described the UPU-WCO contact committee, and Massimiliano added a Europe-based perspective on data-driven risk evaluation. This is important because customs-post collaboration is critical for secure and efficient cross-border e-commerce flows.
How mature and effective are data-driven methods for customs risk evaluation based on international data exchanges, and what results can they produce?
He said such approaches are becoming important but are still only at the beginning and not yet mature enough to produce major results. This is important because better use of data could improve smarter controls, reduce friction and strengthen security in cross-border logistics.
How can countries and operators with weak or outsourced IT functions build the internal capability needed to support secure e-commerce growth?
In his closing remarks, he pointed out that some operators lack their own IT departments or rely on government entities, and may not even consider cybersecurity at the start of e-commerce development. This is important because basic institutional capability is a prerequisite for any sustained cyber resilience strategy.
