Skip navigation and search
Open in Microsoft Edge
Job vacancies Job vacancies

Cybersecurity

Cybersecurity is fundamental to maintaining trust in PostNord’s services. Our information security program is built on internationally recognized standards, including ISO/IEC 27001, and is designed to protect customers, partners, and society while enabling secure and reliable operations.
For suppliers
For business customers

For consumers

Scammers sometimes send fraudulent messages pretending to be from PostNord or other logistics companies. To protect yourself, we recommend using the official PostNord app to track parcels and reduce the risk of fraud.

See our tips on how to avoid fraud and phishing (in Swedish).

If you are unsure about a message, please contact PostNord’s customer service.

PostNord handles personal data in accordance with the General Data Protection Regulation (GDPR). For more information, please visit our GDPR page.

Our approach to cybersecurity

Cybersecurity is integrated into how PostNord operates, develops services, and manages risk. Our approach is based on internationally recognized standards and focuses on protecting information, systems, and operations across the organization.

We apply a risk-based approach aligned with ISO/IEC 27001 and continuously improve our capabilities through governance, monitoring, and regular follow-up. This helps us maintain secure and reliable services for customers, partners, and society.

Certifications and assurance

PostNord is certified according to ISO/IEC 27001, the internationally recognized standard for information security management. The certification supports our commitment to managing information security risks in a structured and effective way.

Our information security management system is subject to regular audits and reviews, including independent third-party assessments and internal risk evaluations. These activities help ensure that our controls remain effective and continuously improve over time.

How we protect our systems and data

PostNord applies a combination of governance, technology, processes, and employee awareness to protect information, systems, and services. Our security controls are designed to reduce risk, strengthen resilience, and support secure operations across the organization.

Governance and risk management

Information security is managed through a structured governance framework aligned with ISO/IEC 27001. We conduct regular risk assessments, reviews, and audits to identify and address risks and support continuous improvement.

Access and identity management

Access to systems and information is managed according to business needs and the principle of least privilege. PostNord uses identity and access management controls, including multi-factor authentication, to help protect critical systems and data.

Monitoring and incident response

We continuously monitor our systems and networks to identify and manage potential security threats. Dedicated incident response processes help us detect, investigate, and respond to security events in a timely manner.

Application and infrastructure security

Security is integrated throughout the lifecycle of our systems and services. We apply practices such as vulnerability management, secure development, and testing to help maintain a strong security posture.

People and awareness

Employees and consultants play an important role in maintaining security. We provide regular training and awareness activities to strengthen cybersecurity knowledge and support responsible behavior.

Resilience and continuity

PostNord maintains business continuity and disaster recovery capabilities to support the availability of critical services and operations. These capabilities are regularly reviewed and tested to strengthen resilience and preparedness.

Report a security vulnerability

Responsible disclosure contributes to a safer digital environment. If you believe you have discovered a security vulnerability affecting PostNord systems or services, we encourage you to report it through our vulnerability disclosure process.

We review submitted reports and work to investigate, and address identified issues in a responsible manner.

For business customers For suppliers