Skip to main content

Resource ยท Trucking & Logistics ยท Readiness

Trucking cybersecurity readiness checklist.

Cybersecurity designed around your fleet's operation, exposure and growth, not just the number of computers.

Twelve checks for carriers, brokers and 3PLs. Each one names what good looks like, the evidence to keep for shipper questionnaires and insurance renewals, and the gap we see most often on a dispatch floor. Score it in one sitting: Ready, Partial, or Gap.

By Stefan Efros, CEO & Founder, EFROS
Updated ยท

How to score it.

Mark a check Ready only if you can produce the evidence today, without building it first. Partial means the control exists but the coverage or the evidence does not. Gap means it is not there.

With eight or more Gaps, the fastest path is to fix the Money and Email items first. The FBI's 2025 Internet Crime Report puts business email compromise above $3 billion in reported losses, and in freight it usually starts with one mailbox and one changed payment instruction.

01

Out-of-band verification for every payment change

Money
What good looks like

Any change to remittance details, factoring instructions or a carrier's banking gets verified by calling a number you already hold, not a number from the email or the new rate confirmation. The rule is written down, applies to everyone including the owner, and has no exception for a load that has to move now.

Evidence to keep

The written procedure, the call-back log or ticket for the last three changes, and the settlements screen showing the change was made after verification.

Gap we see most

The rule exists in someone's head. Under deadline pressure, the dispatcher or the settlements clerk verifies using the phone number printed on the document that is itself the forgery.

02

Phishing-resistant MFA on email, TMS, load boards and factoring portals

Identity
What good looks like

Security keys, passkeys or certificate-based sign-in on the accounts that move money and freight. SMS codes and plain push approvals are treated as a stopgap, not the destination, because an adversary-in-the-middle page relays both.

Evidence to keep

The policy showing which methods are allowed, a sign-in report for the billing and dispatch group, and the list of accounts still on SMS with a date to move them.

Gap we see most

Email is protected, but the load board, the factoring portal and the TMS each have their own login with a password the whole desk knows.

03

Named accounts on the dispatch floor, no shared logins

Identity
What good looks like

Every dispatcher, planner and after-hours cover has an account in their own name across email, the TMS and the load boards. Access is removed within one shift of a departure, including load board seats and the factoring portal.

Evidence to keep

A user list per system with a named owner, the offboarding checklist, and the last three completed offboardings with timestamps.

Gap we see most

One shared dispatch login is the standard answer to weekend coverage. When a rep leaves, nobody can tell which loads that seat touched.

04

DMARC at enforcement, with impersonation protection

Email
What good looks like

SPF, DKIM and DMARC published for every sending domain, and DMARC moved past p=none to quarantine or reject. Lookalike domain and executive impersonation protection turned on for dispatch, billing and the owner.

Evidence to keep

Current DNS records, a DMARC aggregate report showing your senders pass alignment, and the anti-impersonation policy covering the dispatch and billing mailboxes.

Gap we see most

DMARC sits at p=none for years because nobody wants to break the TMS notification emails or the marketing platform, so anyone can still spoof the domain.

05

Mailbox rule and forwarding alerts

Email
What good looks like

Alerts fire when a rule forwards mail outside the company, hides a folder, or deletes rate confirmations automatically. Someone owns the alert and knows what to do with it at 6 a.m.

Evidence to keep

The alert policy, the last alerts with what was done about them, and a tenant report of external forwarding rules.

Gap we see most

The attacker's first move after taking a mailbox is a rule that hides the replies. Nothing is watching for it, so the fraud runs for weeks.

06

Carrier and broker vetting that survives an identity swap

Freight
What good looks like

Onboarding verifies MC and DOT numbers against the federal record, checks that contact details match what is registered rather than what the packet says, and re-checks when a carrier suddenly changes phone, email or remittance. Double-brokering red flags are written down and taught.

Evidence to keep

The onboarding packet with its verification steps, the record of the last carriers onboarded, and the process that triggers when contact details change mid-relationship.

Gap we see most

Vetting happens once at onboarding. Then a stolen carrier identity reuses clean authority with new contact details, and the load is gone.

07

A real inventory of the TMS, ELD, telematics and EDI stack

Systems
What good looks like

One list of every system that touches loads, hours of service or customer data: TMS, ELD and telematics, load boards, factoring, EDI and API integrations. Each has a named internal owner, an admin account list, and a record of who at the vendor can reach your data.

Evidence to keep

The inventory with owners, admin lists per system, and the API keys or integration accounts with creation dates and last review.

Gap we see most

The ELD and telematics portals were set up by whoever installed the units. Nobody knows how many admin accounts exist, and integrations from a vendor you left last year still hold valid tokens.

08

Vendor security evidence, before the breach and not after

Systems
What good looks like

For the systems that would stop the operation or expose customer data you hold current security evidence: a SOC 2 Type II report or a documented control mapping, a breach notification clause with a deadline in it, and a written answer on what happens to your data when the contract ends.

Evidence to keep

The evidence file per vendor with the date received, the contract clause, and the review date in the calendar.

Gap we see most

The TMS contract has no notification deadline, so the first you hear about the vendor's incident is from a customer or from the news.

09

Coverage that includes the shop, the yard and the cab

Endpoints
What good looks like

Endpoint detection on every machine, including the shop PC that runs diagnostics, the yard kiosk and the after-hours dispatch laptop. Driver tablets and phones are enrolled in management with screen lock, encryption and remote wipe.

Evidence to keep

The coverage report compared against the asset list, the enrollment report for tablets and phones, and the list of exceptions with a reason.

Gap we see most

Office laptops are covered. The shop machine with the diagnostic software and local admin rights is not, and it sits on the same network as everything else.

10

Immutable, tested backups, including Microsoft 365

Continuity
What good looks like

Backups an attacker holding your admin password cannot delete, covering servers, the data you are responsible for in the TMS, and the Microsoft 365 tenant. A restore was actually tested in the last twelve months and the test is documented.

Evidence to keep

Backup configuration showing immutability or an air gap, the last restore test with date and result, and the retention period written down.

Gap we see most

Microsoft 365 is assumed to be backed up by Microsoft. It is not, in the sense people mean, and a ransomware or deleted-mailbox scenario proves it at the worst time.

11

A dispatch continuity plan that works with the TMS down

Continuity
What good looks like

A written answer to one question: how do we cover loads, reach drivers and produce hours-of-service records if the TMS or the portal is unavailable for two days. Contacts, the load list and customer notification are reachable offline, and the plan has been walked through with the people who would run it.

Evidence to keep

The continuity procedure, the offline contact and load export with its refresh cadence, and notes from the last walkthrough.

Gap we see most

The plan is the owner's phone. Driver contact details and hours-of-service records live only in the system that is down.

12

Monitoring and an incident response plan with names in it

Response
What good looks like

Sign-ins, endpoints and the money-moving systems are monitored outside business hours, because freight does not stop at 5 p.m. The plan names who declares an incident, who calls the insurer, the customer and law enforcement, and which channel the team uses when email cannot be trusted.

Evidence to keep

The plan with version and date, the named contacts, the out-of-band channel, and notes from the last tabletop exercise.

Gap we see most

There is monitoring but no owner after hours, or a plan written for an office that never mentions loads in transit, cargo claims, or the customer who has to be told.

The evidence pack.

Shipper security questionnaires and cyber-insurance renewals ask for the same eight artifacts. Keep them current and the next questionnaire becomes an attachment instead of a fire drill. The cyber-insurance readiness checklist covers the carrier side in more depth.

  • Current DNS records with SPF, DKIM and DMARC at enforcement
  • The MFA method policy plus a sign-in report for billing and dispatch
  • Endpoint coverage measured against the asset list
  • Backup configuration with immutability and the last restore test
  • Vendor list with security evidence and breach notification clauses
  • Incident response plan with named contacts and the last tabletop
  • The written payment-change verification procedure with call-back logs
  • Offboarding checklist with the last completed removals

Where the freight-specific risk sits.

Transportation is one of the sixteen critical infrastructure sectors, which is a description of the target, not a compliment. What makes freight different from a generic office is that downtime has a clock on it, and money moves on documents: a rate confirmation, a remittance change, a factoring instruction.

The FBI's guidance on that fraud is blunt and worth reading to your team: use secondary channels to verify requests for changes in account information. On the identity side, CISA is equally direct that push notifications and one-time codes are not phishing-resistant, which matters when the account in question can move a load.

For ransomware, the federal position in the #StopRansomware Guide is that paying is not recommended and guarantees nothing, which is exactly why the backup and dispatch-continuity checks above carry more weight than any single product. Threat material specific to motor freight is published by the NMFTA, and carrier authority can be checked against the federal record through FMCSA SAFER.

FAQ.

We run a small fleet. Is a twelve-item checklist overkill?

The list is scoped by how you operate, not by how many trucks or computers you have. A ten-truck carrier that runs its own dispatch, uses a factoring company and takes loads off a board has the same exposure surface as a much larger one, because the attacker is after the rate confirmation and the remittance change, not your server count. Work the Money and Email items first; they carry most of the loss in freight.

Which items do we fix first if we can only do three things?

Out-of-band verification for payment changes, phishing-resistant MFA on the accounts that move money and freight, and tested immutable backups. The first two close the fraud path that the FBI reports as the largest single loss category in business email compromise. The third decides how long a ransomware event keeps you off the road.

Our customers and our insurer keep sending questionnaires. Does this help?

Yes, that is the second use of the list. The evidence column is written to match what shipper security questionnaires and cyber-insurance renewals ask for. Keeping those artifacts current turns a two-week scramble into an attachment, and it is the same evidence pack a broker needs to keep coverage in force.

What about ELDs and telematics specifically?

Treat them as third-party systems with administrative access to your operation, because that is what they are. Inventory the portals, know who at the vendor can reach your data, keep the admin account list short and reviewed, and make sure your hours-of-service records survive an outage. Federal rules require you to produce those records; they do not run your security program for you.

Cite this resource

Reference this resource with attribution under CC-BY-4.0. Copy any of the formats below for academic papers, blog posts, AI citations, or vendor evidence packages.

APA (7th edition)
Efros, S. (2026, September). Trucking Cybersecurity Readiness Checklist. EFROS. https://efros.com/resources/trucking-cybersecurity-readiness-checklist/
MLA (9th edition)
Efros, Stefan. "Trucking Cybersecurity Readiness Checklist." EFROS, September 2026, https://efros.com/resources/trucking-cybersecurity-readiness-checklist/.
Chicago (author-date)
Efros, Stefan. 2026. "Trucking Cybersecurity Readiness Checklist." EFROS. https://efros.com/resources/trucking-cybersecurity-readiness-checklist/.
IEEE
S. Efros, "Trucking Cybersecurity Readiness Checklist," EFROS, September 2026. [Online]. Available: https://efros.com/resources/trucking-cybersecurity-readiness-checklist/
BibTeX
@misc{efros2026truckingcybersec,
  author = {Stefan Efros},
  title = {Trucking Cybersecurity Readiness Checklist},
  year = {2026},
  month = {September},
  publisher = {EFROS},
  url = {https://efros.com/resources/trucking-cybersecurity-readiness-checklist/},
  note = {Accessed: September 2026}
}
Plain text URL
https://efros.com/resources/trucking-cybersecurity-readiness-checklist/

Site-wide citation metadata is also published as a CITATION.cff file at /CITATION.cff for citation-management tools and academic indexers.