A Manchester-based logistics firm that recently completed a £2.3 million cybersecurity overhaul has confirmed it continues to click ‘Accept All Cookies’ on every website visited by its 340 employees, thereby voluntarily sharing company data with an estimated 12,000 third-party advertising partners across the globe.
Hargreaves Transport Solutions, which handles sensitive cargo manifests for pharmaceutical and defence clients, implemented what it described as a ‘military-grade, zero-trust network architecture’ in January. The system includes biometric authentication, encrypted communications, regular penetration testing, and a dedicated threat response team working from a purpose-built security operations centre in Warrington. It does not, however, include any guidance on cookie consent policies.
The revelation came to light when a member of the IT security team noticed that a staff laptop had shared browsing data with 847 separate organisations within a single morning, all of whom now have tracking cookies monitoring the device’s activity. The laptop in question belonged to someone researching suppliers for industrial coolant, though 419 marketing firms, 67 data brokers, and what appears to be a Estonian company called DataHarvest Solutions are now also closely following this procurement journey.
“We take data protection extremely seriously,” said Rebecca Norton, the company’s Chief Information Security Officer, speaking from an office protected by retinal scanners, air-gapped servers, and a Faraday cage for mobile devices. “Every email is encrypted. Every file transfer is logged. Every USB port is disabled. We have achieved ISO 27001 certification and our incident response time is under four minutes.”
When asked about the cookie situation, Norton explained that the consent pop-ups were ‘quite annoying’ and that clicking ‘Accept All’ was simply more convenient than scrolling through hundreds of partner organisations to make individual selections.
“I did try clicking ‘Manage Preferences’ once, but there were 600 companies listed and I had a meeting in three minutes. It seemed easier to just accept them all and move on.”
The company’s newly installed intrusion detection system, which cost £180,000 and monitors all network traffic for suspicious patterns, has been configured to ignore cookies entirely. This decision was made after the system generated 4,000 alerts in its first hour of operation, all related to third-party tracking scripts attempting to communicate with servers in jurisdictions the company’s own data governance policy explicitly prohibits.
Martin Eccleston, a cybersecurity consultant who was not involved in the Hargreaves project, suggested this represented a fairly typical enterprise approach to digital security. “Organisations will spend extraordinary sums building walls around their data, then open the front door and invite in anyone with a tracking pixel,” he said. “I once worked with a bank that required six forms of authentication to access internal systems but let Google Analytics see everything anyway.”
Hargreaves Transport Solutions has indicated it may address the cookie issue in its next security review, scheduled for 2027. In the meantime, staff have been asked to use strong passwords, avoid phishing emails, and continue accepting all cookies because declining them individually would impact productivity.