Cybersecurity designed around your fleet's operation, exposure and growth, not just the number of computers.
Twelve checks for carriers, brokers and 3PLs. Each one names what good looks like, the evidence to keep for shipper questionnaires and insurance renewals, and the gap we see most often on a dispatch floor. Score it in one sitting: Ready, Partial, or Gap.
Mark a check Ready only if you can produce the evidence today, without building it first. Partial means the control exists but the coverage or the evidence does not. Gap means it is not there.
With eight or more Gaps, the fastest path is to fix the Money and Email items first. The FBI's 2025 Internet Crime Report puts business email compromise above $3 billion in reported losses, and in freight it usually starts with one mailbox and one changed payment instruction.
01
Out-of-band verification for every payment change
Money
What good looks like
Any change to remittance details, factoring instructions or a carrier's banking gets verified by calling a number you already hold, not a number from the email or the new rate confirmation. The rule is written down, applies to everyone including the owner, and has no exception for a load that has to move now.
Evidence to keep
The written procedure, the call-back log or ticket for the last three changes, and the settlements screen showing the change was made after verification.
Gap we see most
The rule exists in someone's head. Under deadline pressure, the dispatcher or the settlements clerk verifies using the phone number printed on the document that is itself the forgery.
02
Phishing-resistant MFA on email, TMS, load boards and factoring portals
Identity
What good looks like
Security keys, passkeys or certificate-based sign-in on the accounts that move money and freight. SMS codes and plain push approvals are treated as a stopgap, not the destination, because an adversary-in-the-middle page relays both.
Evidence to keep
The policy showing which methods are allowed, a sign-in report for the billing and dispatch group, and the list of accounts still on SMS with a date to move them.
Gap we see most
Email is protected, but the load board, the factoring portal and the TMS each have their own login with a password the whole desk knows.
03
Named accounts on the dispatch floor, no shared logins
Identity
What good looks like
Every dispatcher, planner and after-hours cover has an account in their own name across email, the TMS and the load boards. Access is removed within one shift of a departure, including load board seats and the factoring portal.
Evidence to keep
A user list per system with a named owner, the offboarding checklist, and the last three completed offboardings with timestamps.
Gap we see most
One shared dispatch login is the standard answer to weekend coverage. When a rep leaves, nobody can tell which loads that seat touched.
04
DMARC at enforcement, with impersonation protection
Email
What good looks like
SPF, DKIM and DMARC published for every sending domain, and DMARC moved past p=none to quarantine or reject. Lookalike domain and executive impersonation protection turned on for dispatch, billing and the owner.
Evidence to keep
Current DNS records, a DMARC aggregate report showing your senders pass alignment, and the anti-impersonation policy covering the dispatch and billing mailboxes.
Gap we see most
DMARC sits at p=none for years because nobody wants to break the TMS notification emails or the marketing platform, so anyone can still spoof the domain.
05
Mailbox rule and forwarding alerts
Email
What good looks like
Alerts fire when a rule forwards mail outside the company, hides a folder, or deletes rate confirmations automatically. Someone owns the alert and knows what to do with it at 6 a.m.
Evidence to keep
The alert policy, the last alerts with what was done about them, and a tenant report of external forwarding rules.
Gap we see most
The attacker's first move after taking a mailbox is a rule that hides the replies. Nothing is watching for it, so the fraud runs for weeks.
06
Carrier and broker vetting that survives an identity swap
Freight
What good looks like
Onboarding verifies MC and DOT numbers against the federal record, checks that contact details match what is registered rather than what the packet says, and re-checks when a carrier suddenly changes phone, email or remittance. Double-brokering red flags are written down and taught.
Evidence to keep
The onboarding packet with its verification steps, the record of the last carriers onboarded, and the process that triggers when contact details change mid-relationship.
Gap we see most
Vetting happens once at onboarding. Then a stolen carrier identity reuses clean authority with new contact details, and the load is gone.
07
A real inventory of the TMS, ELD, telematics and EDI stack
Systems
What good looks like
One list of every system that touches loads, hours of service or customer data: TMS, ELD and telematics, load boards, factoring, EDI and API integrations. Each has a named internal owner, an admin account list, and a record of who at the vendor can reach your data.
Evidence to keep
The inventory with owners, admin lists per system, and the API keys or integration accounts with creation dates and last review.
Gap we see most
The ELD and telematics portals were set up by whoever installed the units. Nobody knows how many admin accounts exist, and integrations from a vendor you left last year still hold valid tokens.
08
Vendor security evidence, before the breach and not after
Systems
What good looks like
For the systems that would stop the operation or expose customer data you hold current security evidence: a SOC 2 Type II report or a documented control mapping, a breach notification clause with a deadline in it, and a written answer on what happens to your data when the contract ends.
Evidence to keep
The evidence file per vendor with the date received, the contract clause, and the review date in the calendar.
Gap we see most
The TMS contract has no notification deadline, so the first you hear about the vendor's incident is from a customer or from the news.
09
Coverage that includes the shop, the yard and the cab
Endpoints
What good looks like
Endpoint detection on every machine, including the shop PC that runs diagnostics, the yard kiosk and the after-hours dispatch laptop. Driver tablets and phones are enrolled in management with screen lock, encryption and remote wipe.
Evidence to keep
The coverage report compared against the asset list, the enrollment report for tablets and phones, and the list of exceptions with a reason.
Gap we see most
Office laptops are covered. The shop machine with the diagnostic software and local admin rights is not, and it sits on the same network as everything else.
10
Immutable, tested backups, including Microsoft 365
Continuity
What good looks like
Backups an attacker holding your admin password cannot delete, covering servers, the data you are responsible for in the TMS, and the Microsoft 365 tenant. A restore was actually tested in the last twelve months and the test is documented.
Evidence to keep
Backup configuration showing immutability or an air gap, the last restore test with date and result, and the retention period written down.
Gap we see most
Microsoft 365 is assumed to be backed up by Microsoft. It is not, in the sense people mean, and a ransomware or deleted-mailbox scenario proves it at the worst time.
11
A dispatch continuity plan that works with the TMS down
Continuity
What good looks like
A written answer to one question: how do we cover loads, reach drivers and produce hours-of-service records if the TMS or the portal is unavailable for two days. Contacts, the load list and customer notification are reachable offline, and the plan has been walked through with the people who would run it.
Evidence to keep
The continuity procedure, the offline contact and load export with its refresh cadence, and notes from the last walkthrough.
Gap we see most
The plan is the owner's phone. Driver contact details and hours-of-service records live only in the system that is down.
12
Monitoring and an incident response plan with names in it
Response
What good looks like
Sign-ins, endpoints and the money-moving systems are monitored outside business hours, because freight does not stop at 5 p.m. The plan names who declares an incident, who calls the insurer, the customer and law enforcement, and which channel the team uses when email cannot be trusted.
Evidence to keep
The plan with version and date, the named contacts, the out-of-band channel, and notes from the last tabletop exercise.
Gap we see most
There is monitoring but no owner after hours, or a plan written for an office that never mentions loads in transit, cargo claims, or the customer who has to be told.
The evidence pack.
Shipper security questionnaires and cyber-insurance renewals ask for the same eight artifacts. Keep them current and the next questionnaire becomes an attachment instead of a fire drill. The cyber-insurance readiness checklist covers the carrier side in more depth.
โCurrent DNS records with SPF, DKIM and DMARC at enforcement
โThe MFA method policy plus a sign-in report for billing and dispatch
โEndpoint coverage measured against the asset list
โBackup configuration with immutability and the last restore test
โVendor list with security evidence and breach notification clauses
โIncident response plan with named contacts and the last tabletop
โThe written payment-change verification procedure with call-back logs
โOffboarding checklist with the last completed removals
Where the freight-specific risk sits.
Transportation is one of the sixteen critical infrastructure sectors, which is a description of the target, not a compliment. What makes freight different from a generic office is that downtime has a clock on it, and money moves on documents: a rate confirmation, a remittance change, a factoring instruction.
For ransomware, the federal position in the #StopRansomware Guide is that paying is not recommended and guarantees nothing, which is exactly why the backup and dispatch-continuity checks above carry more weight than any single product. Threat material specific to motor freight is published by the NMFTA, and carrier authority can be checked against the federal record through FMCSA SAFER.
FAQ.
We run a small fleet. Is a twelve-item checklist overkill?
+
The list is scoped by how you operate, not by how many trucks or computers you have. A ten-truck carrier that runs its own dispatch, uses a factoring company and takes loads off a board has the same exposure surface as a much larger one, because the attacker is after the rate confirmation and the remittance change, not your server count. Work the Money and Email items first; they carry most of the loss in freight.
Which items do we fix first if we can only do three things?
+
Out-of-band verification for payment changes, phishing-resistant MFA on the accounts that move money and freight, and tested immutable backups. The first two close the fraud path that the FBI reports as the largest single loss category in business email compromise. The third decides how long a ransomware event keeps you off the road.
Our customers and our insurer keep sending questionnaires. Does this help?
+
Yes, that is the second use of the list. The evidence column is written to match what shipper security questionnaires and cyber-insurance renewals ask for. Keeping those artifacts current turns a two-week scramble into an attachment, and it is the same evidence pack a broker needs to keep coverage in force.
What about ELDs and telematics specifically?
+
Treat them as third-party systems with administrative access to your operation, because that is what they are. Inventory the portals, know who at the vendor can reach your data, keep the admin account list short and reviewed, and make sure your hours-of-service records survive an outage. Federal rules require you to produce those records; they do not run your security program for you.
Reference this resource with attribution under CC-BY-4.0. Copy any of the formats below for academic papers, blog posts, AI citations, or vendor evidence packages.
APA (7th edition)
Efros, S. (2026, September). Trucking Cybersecurity Readiness Checklist. EFROS. https://efros.com/resources/trucking-cybersecurity-readiness-checklist/
MLA (9th edition)
Efros, Stefan. "Trucking Cybersecurity Readiness Checklist." EFROS, September 2026, https://efros.com/resources/trucking-cybersecurity-readiness-checklist/.