Skip to main content

Why Portcullis

Criminal infiltration is a business risk, not only a security one.

Freight runs on trust: in staff, in agents, in customers and in the instructions that arrive every day. Organised crime groups exploit that trust to move goods, money and information through legitimate businesses.

Portcullis focuses on the points where trust can be exploited inside legitimate freight operations.

What criminal ingress means

Criminal ingress is when an organised crime group gets a foothold inside a legitimate freight business. It usually starts with a person, a counterparty or a message that is not what it seems, not a break-in.

Once inside, criminals use the business's systems, paperwork and reputation to move goods they could not move alone. The business can face financial loss, reputational damage, lost customers and investigation.

Three ways in

People

Staff are targeted because they can open doors. Approaches may come outside work, build over time and involve money, pressure or both.

  • Bribery and inducements
  • Threats and duress
  • Debt and vulnerability
  • Information leakage

Counterparties

False businesses create relationships that look legitimate on paper, then use them to route illicit goods or extract value.

  • False overseas agents
  • Impersonated suppliers
  • Newly formed customers
  • Fraudulent credit requests

Communications

Faked or altered messages exploit busy teams, often at the moment goods are released or payments are made.

  • Look-alike domains
  • Changed bank or delivery details
  • False identities
  • Social engineering

A specialist role

Portcullis is designed to complement broader security, customs and cyber frameworks by focusing specifically on criminal ingress through people, counterparties and commercial relationships.

It is not a police force, a regulator, a trade association, a physical security company or a cybersecurity provider. It gives freight businesses a practical standard for this one risk, and the tools to meet it.

How it works in practice

  1. Assess

    Understand your exposure, starting with the Initial Exposure Check and continuing through certification.

  2. Educate

    Give staff the knowledge to recognise approaches, false counterparties and manipulated instructions.

  3. Verify

    Apply CLUES consistently before committing to new counterparties and unusual shipments.

  4. Inform

    Stay aware of emerging methods through Portcullis Intelligence as it launches.

  5. Support

    Know what to do, and who to tell, when something feels wrong.

Complementary to broader frameworks

Many freight businesses already work to one or more established schemes. Portcullis is designed to sit alongside them, focused on a risk they do not treat as their primary subject.

Framework descriptions are provided for context only and do not imply endorsement, partnership or formal recognition.

How Portcullis relates to other frameworks
FrameworkPrimary focus
AEOCustoms compliance and supply-chain security status.
TAPAPhysical security standards for facilities and transport.
Cyber EssentialsBaseline technical controls against common cyber attacks.
FORSFleet operation standards for safety and efficiency.
PortcullisCriminal infiltration through people, counterparties and commercial relationships.

Start with your own exposure.

The Initial Exposure Check takes about five minutes.