Cybersecurity
For consumers
Scammers sometimes send fraudulent messages pretending to be from PostNord or other logistics companies. To protect yourself, we recommend using the official PostNord app to track parcels and reduce the risk of fraud.
See our tips on how to avoid fraud and phishing (in Swedish).
If you are unsure about a message, please contact PostNord’s customer service.
PostNord handles personal data in accordance with the General Data Protection Regulation (GDPR). For more information, please visit our GDPR page.
Our approach to cybersecurity
Cybersecurity is integrated into how PostNord operates, develops services, and manages risk. Our approach is based on internationally recognized standards and focuses on protecting information, systems, and operations across the organization.
We apply a risk-based approach aligned with ISO/IEC 27001 and continuously improve our capabilities through governance, monitoring, and regular follow-up. This helps us maintain secure and reliable services for customers, partners, and society.
Certifications and assurance
PostNord is certified according to ISO/IEC 27001, the internationally recognized standard for information security management. The certification supports our commitment to managing information security risks in a structured and effective way.
Our information security management system is subject to regular audits and reviews, including independent third-party assessments and internal risk evaluations. These activities help ensure that our controls remain effective and continuously improve over time.
How we protect our systems and data
PostNord applies a combination of governance, technology, processes, and employee awareness to protect information, systems, and services. Our security controls are designed to reduce risk, strengthen resilience, and support secure operations across the organization.
Governance and risk management
Information security is managed through a structured governance framework aligned with ISO/IEC 27001. We conduct regular risk assessments, reviews, and audits to identify and address risks and support continuous improvement.
Access and identity management
Access to systems and information is managed according to business needs and the principle of least privilege. PostNord uses identity and access management controls, including multi-factor authentication, to help protect critical systems and data.
Monitoring and incident response
We continuously monitor our systems and networks to identify and manage potential security threats. Dedicated incident response processes help us detect, investigate, and respond to security events in a timely manner.
Application and infrastructure security
Security is integrated throughout the lifecycle of our systems and services. We apply practices such as vulnerability management, secure development, and testing to help maintain a strong security posture.
People and awareness
Employees and consultants play an important role in maintaining security. We provide regular training and awareness activities to strengthen cybersecurity knowledge and support responsible behavior.
Resilience and continuity
PostNord maintains business continuity and disaster recovery capabilities to support the availability of critical services and operations. These capabilities are regularly reviewed and tested to strengthen resilience and preparedness.
Report a security vulnerability
Responsible disclosure contributes to a safer digital environment. If you believe you have discovered a security vulnerability affecting PostNord systems or services, we encourage you to report it through our vulnerability disclosure process.
We review submitted reports and work to investigate, and address identified issues in a responsible manner.