Heavy Duty Trucking Logo
MenuMENU
SearchSEARCH

Cyber Security: Connect at Your Own Risk

How fleets can enjoy greater connectivity without risking more cyber attacks. Part eight of our Trucking in the 21st Century series.

David Cullen
David Cullen[Former] Business/Washington Contributing Editor
Read David's Posts
October 16, 2017
Cyber Security: Connect at Your Own Risk

 

8 min to read


Connectivity — trucking shorthand for plugging into the Internet of Things — is a positive trend being advanced by industry suppliers and embraced by forward-leaning fleets to better control operating costs and boost productivity.

Ad Loading...

It all sounds good. Until it doesn’t.

The appeal is easy enough to grasp. Connect every digital device so that data can be shared and leveraged across multiple, interconnected systems. In trucking, that means linking everything from in-cab computers to smartphones to hardware so reams of data can be intelligently managed and leveraged.

Ad Loading...

Expanding connectivity can make trucking operations smarter and nimbler and thus more profitable. But it also heightens exposure to cybersecurity threats. When everything is connected, a sophisticated criminal or merely a disgruntled ex-employee or unhappy customer can more easily gain access to computerized systems to wreak havoc on unsuspecting or poorly guarded businesses.

Ron Godine, vice president, information and cloud technology for fleet-management provider TMW Systems, points out that increased connectivity via in-cab devices gives outsiders the ability to “touch all the systems that affect the vehicle and learn your location. If they know your location, what can they do? How can they target you? There’s safety concerns with just knowing your location, where you’re going and how fast you’re going. Any of those things are a security awareness risk.”

Hackers can then gain access to a fleet’s trucking management solution and back office systems to learn about customers, loads, and financial information, cautions Godine. “What we’ve seen is that people can get into a system by automation and by hacking accounts, and then they peruse data like any other user.”

Alan Gordon, chief information officer of Cisive, parent of Driver iQ, which provides employee screening services, says that “small- and mid-sized companies can get lulled into thinking ‘Who would go after me?’ but truck fleets are just as much in the crosshairs as any business.”

Ignorance is not bliss

“The reality is that ignorance is bliss,” says Ben Wiesen, vice president of products and support for Carrier Logistics, which provides transportation-management solutions. “We would not go through life walking across eight-lane highways without looking. But we see numerous trucking operations doing just that when it comes to cybersecurity. The fact is wherever computer systems are operating, serious concern and caution should be taken” to avoid cyberattacks.

Ad Loading...

“As everything we use becomes more connected, the more risk there will be that criminals will gain control of computers,” he continues. “The IT industry dedicates huge resources to cybersecurity. On the other hand, fleets don’t think they’re in a tech industry. Yet fleets are so reliant on their computer systems. For all the nuts and bolts, the computer is the heartbeat of trucking.”

As for who is at risk for what, Wiesen says that typically depends on the size of the fleet. “Yes, there’s the risk of information being stolen on customers or drivers. But those are targeted actions with less likely reward when aimed at a smaller, lesser-known trucking company. It’s not a big risk for most fleets, but information could be stolen to poach drivers or customers.”

By contrast, he says, “the biggest risk is horizontal; that is, it runs across all businesses.”

Examples of horizontal risk include hacking or email planting to install malware, which can steal data or disrupt operations, and the newest threat — ransomware viruses. “Ransomware attacks are conducted by sophisticated criminal enterprises that effectively ‘kidnap’ a computer system remotely and demand a ransom to unlock it again. These attacks are a very real concern for everyone. They can take out any computer that has value to someone.”

Ben Barnes, systems director for McLeod Software, reports that the fleet-management provider has helped nearly 30 customers that incurred ransomware attacks so far this year. “This type of threat has become huge to the average fleet.” He says cyberattacks used to be aimed at specific businesses, like the massive breaches of everything from mega retailers to Hollywood studios, but “ransomware will attack any target of opportunity — it’s a quantity approach.”

Ad Loading...

Barnes says these crooks may only ask for $100 or $500 to release a machine from their clutches. Once the ransom is paid, however, “there’s no guarantee they will give you the codes to release the computer. But if you have your system backed up or other means to recover your data, you may not want to pay at all. One company loaded up a new server to recover from the attack; others have paid because they did not have backups.”

One high-profile transportation company affected by such an attack was FedEx subsidiary TNT Express, one of many companies hit by a cyber virus in June. The ransomware encrypted data on machines and demanded $300 ransoms for recovery. FedEx had to refer customers to its own network while TNT reverted to using manual systems to operate. At press time, it was expected that the company’s quarterly profit would take a hit.

Wiesen also cautions that there is a potential for access through computer hardware on a truck (see previous story). “Think of the news stories about ‘nanny cams’ being taken over to gain control of a home computer. There has been concern expressed about hacking into infotainment systems on cars as well as what might happen with self-driving cars and all the connections they will have.” And the same would go for commercial vehicles.

Whatever their chosen route of attack, Cisive’s Gordon says there are two distinct types of hackers to deflect: the insider, and the external threat. The insider may hack into a program at any business for nefarious effect, while the external agent tends to target larger firms. “They know they exist — brand recognition — and will scan them for weak points where security protocols are not up to date. When they find a way in, they will exploit it.”

He further distinguishes the enemy by what they are after. “Some hackers are disruptors who say they do it because they love a challenge, while others are bona fide criminals. They will go after credit card data or customer lists and sell those on the ‘dark web.’ And there’s also corporate espionage that goes on. Hacking to get ahold of internal information on customers and pricing, sometimes sold as ‘competitive intelligence.’ And there is ransomware, which is a growing threat.”

Ad Loading...

Gordon sees the main external vulnerability for fleets as having outdated or unsecured operating systems. But he says that’s easy to fix, as “most use software that continues to receive regular security updates,” adding that third-party software run on your systems must be secure, too. He also cautions that a lot of fleets have customized software. “Especially if this is web-facing, it must be written with an eye to security. Also, a lot of firewalls are only concerned with what is going in. But you should also watch outgoing data to help counter any insider threats.”

Wall off the threat

TMW’s Godine says the aim of cybersecurity is to “put more walls” between criminals and your valuable data. These include using encryption and multi-factor authentication, which beefs up the traditional username/password by adding such authentication factors as PIN numbers, trusted device authentication, and fingerprint, face, and even voice recognition.

“It’s about making the wall high enough or making multiple walls that hackers have to climb over. You can’t just put in one solution and be done. You have to put in multiple solutions, because any one of them can be compromised.”

On the other hand, cyber criminals and other bad actors might just sneak in through holes in the walls — especially if you make it easy for them. That is to say, “clicking on that email” remains the most common way to launch a security breach.

That’s why it’s just as key to drill staff on adhering to security protocols as it is to invest in high-tech security measures. Godine advises fleets to make sure they have a digital access policy — and that it’s enforced and reviewed. “Usernames and account passwords should have appropriate complexity. Default passwords, easy-to-guess passwords, similar passwords used across the company should all be avoided. People go ‘ho-hum’ at that stuff, but that’s the way most people hack into systems.”

Ad Loading...

Lloyd Palum doesn’t see fleets being any more likely than other businesses to incur cyberattacks. The chief technology officer for Vnomics, which provides fleet-management solutions, says the difference is that truck fleets may be unaware of the threat. For example, someone could hack in and disrupt dispatching.

Palum says the best line of defense for fleets, as for any business, is to stay on top of threat assessments and commit to following best practices for cybersecurity, including securing communications and keeping software up to date in a timely fashion. “Bear in mind that in many attacks, wireless and Wi-Fi systems are targeted, so you want to keep those as secure as possible. Regularly updating software is critical to avoid falling prey to known risks uncovered since the last updates were issued. Fleets are typically not well-versed in cyber best practices, but [technology] vendors can advise them.”

The best defense is a good offense, he says. “You always want to confirm that all the ‘actors’ on your network or systems are always behaving as would be expected.” Actively monitor for “anomalous actions” that could signify a cyber breach has occurred or is being attempted. He notes that there are service providers that can be contracted to monitor network behavior.

Palum also suggests that fleets without full-blown IT teams may take comfort from computing in the cloud. “Cloud computing is nothing more than renting space in someone else’s computer,” he points out. “If you’re using a reputable cloud provider, they will be on top of cybersecurity. They actively monitor their networks. But you do need to know that data coming to and from those computers to yours is secure and that all system users are authenticated.”

McLeod’s Barnes recommends wielding “a tool bag of stuff” to help prevent cyberattacks. “Your defense has to be company-specific, based for example on how open your systems are to the internet,” he says. “There are preventive best practices to put in place, such as educating users on security protocols, and putting a recovery plan in place as you would for any other contingency that can shut down your business. You want always to be in a preventive role, not in recovery mode.”

Subscribe to Our Newsletter

More Fleet Management

The Cyber Stop column header with photo of a smiling driver in truck with a laptop and a wi-fi icon
Fleet ManagementAugust 21, 2026

Public Wi-Fi Cybersecurity Risks: How Truck Drivers and Fleets Can Protect Their Data

Public Wi-Fi can expose truck drivers and fleets to credential theft, malware, and other cyber threats. Here’s how to reduce the risk on the road.

Read More →
Woman in white blazer superimposed on background showing a row of Fraley & Schilling truck, plus the HDT Truck Fleet Innovators 2026 logo
Fleet Managementby Deborah LockridgeAugust 19, 2026

For Nicky Cupp, Fleet Innovation Starts With Frustration

HDT Truck Fleet Innovator Nicky Cupp turns everyday pain points at Fraley & Schilling into opportunities for better technology and smarter processes.

Read More →
Headshot of Adam Buttgenbach with a Pepsi-branded Tesla Semi in the background
Fleet Managementby Deborah LockridgeAugust 18, 2026

Adam Buttgenbach’s Approach to Electric Trucks: Start With Where They Fit

HDT Truck Fleet Innovator Adam Buttgenbach helped PepsiCo build one of North America’s largest EV fleets by focusing on where electric trucks make operational sense.

Read More →
Ad Loading...
Deen Albert in collared shirt superimposed on background showing a Grand Island Express blue tractor pulling a trailer, plus the HDT Truck Fleet Innovators 2026 logo
Fleet Managementby Deborah LockridgeAugust 17, 2026

Deen Albert: Let Automation Do the Math, People Make the Decisions

HDT Truck Fleet Innovator Deen Albert makes sure people are still at the heart of operations at Grand Island Express, even while adopting artificial intelligence tools. AI-assisted dispatch helped boost revenue 25% with the same number of trucks.

Read More →
Illustration of computer screen with Trimble Arc Agent screen
Fleet Managementby Deborah LockridgeAugust 14, 2026

Trimble’s New AI Agent Takes Aim at Fleet Back-Office Busywork

Arc Agent works across Trimble TMS products to automate repetitive tasks such as freight orders, maintenance, invoices, fuel costs and more.

Read More →
Photos of three men and two women with HDT Truck Fleet Innovators 2026 logo
Fleet ManagementCover Storyby Deborah LockridgeAugust 13, 2026

How HDT’s 2026 Truck Fleet Innovators Are Rethinking Fleet Operations

Meet five trucking leaders who are challenging assumptions, solving operational problems, and putting innovative ideas to work.

Read More →
Ad Loading...
Graph showing how contract rates and spot rates converged in July
Fleet Managementby StaffAugust 12, 2026

Tight Trucking Capacity Pushes Rates Higher Even as Freight Volumes Fall

“Spot rates moving ahead of contract rates have historically signaled a tightening market, but we haven’t seen a capacity-driven market quite like this one,” said DAT's Dean Croke.

Read More →
Line graph showing container import volumes
Fleet Managementby StaffAugust 7, 2026

Import Cargo’s Early Peak Season is Winding Down

There was an early start to peak season this year at the nation's gateway ports, as retailers brought in merchandise ahead of tariff changes in late July and responded to other supply chain uncertainties,

Read More →
Blue infographic with graphs illustrating cargo theft trends in the second quarter of 2026
Fleet Managementby Deborah LockridgeAugust 6, 2026

Fewer Cargo Thefts, Bigger Losses: Criminals Target Higher-Value Loads

CargoNet says organized theft rings are stealing fewer shipments but choosing more valuable freight, including metals and technology, resulting in record losses.

Read More →
Ad Loading...
Illustration of a chalkboard with a hand drawing an arrow curving away from a partially erased straight arrow with the words "Embracing Change," the Heavy Duty Trucking Logo and the "cover feature" graphic.
Fleet Managementby Deborah LockridgeAugust 1, 2026

How Innovative Trucking Leaders Turn Change Into an Advantage

As the pace of change accelerates in trucking, the fleets that adapt best have more than the latest technology. They have cultures that embrace improvement.

Read More →