Heavy Duty Trucking Logo
MenuMENU
SearchSEARCH

Why Trucking Companies Need to Plan Now for a Cyber Attack

Transportation and logistics companies are now among the top-targeted industries by computer hackers. What can you do to prevent and prepare for a ransomware attack or a malicious computer virus?

Deborah Lockridge
Deborah LockridgeEditor and Associate Publisher
Read Deborah's Posts
October 7, 2019
Why Trucking Companies Need to Plan Now for a Cyber Attack

 

6 min to read


Harold Sumerford, CEO of J&M Tank Lines, talks about his fleet's experience with a cyber attack.

Photo by Deborah Lockridge

When Harold Sumerford’s phone rang at 2:30 a.m. on April 2, he knew the news couldn’t be good. But he figured it was probably the safety department – not the CFO telling him the company’s entire computer system was down from a ransomware attack.

Ad Loading...

The CEO of J&M Tank Lines, Sumerford shared the headaches and lessons learned from that experience as part of a panel discussion on cybersecurity on Oct. 6 during the American Trucking Associations’ Management Conference and Exhibition in San Diego.

Although the company was able to get the email and phone systems back up in a few hours, it took four days to get functional again. While they had backups, he said, in layman’s terms, the computer system “could see the data but didn’t know what it meant.”

Ad Loading...

It was a painstaking process to go through all the lines of code and make it interpretable by the computer system. And during those four days, they weren’t able to bill any customers or enter anything into the system. Drivers got their paychecks only because J&M simply paid them the exact same amount they received the previous week.

J&M was just one example of a rapidly growing problem with cybersecurity in the trucking industry. Transportation and logistics companies are now among the top-targeted industries by computer hackers, according to the panel. 

In fact, a recent article on ZDNet reported that “hackers are deploying previously unknown tools in a cyberattack campaign targeting shipping and transport organizations with custom trojan malware.”

Sharon Reynolds, chief information security officer, Omnitracs, said normally she would put up a montage of recent cyber security headines – but there have been so many lately, you might as well just put "your company name here."

Photo by Deborah Lockridge

Trucking's Cybersecurity Vulnerabilities

Sharon Reynolds, chief information security officer for Omnitracs, explained that the “attack surface” vulnerable to hackers in the trucking industry is ever-expanding and includes:

  • CAN bus exploits on vehicles

  • Connectivity via satellite, wireless, cellular and Bluetooth

  • Internet-facing networks and platforms

Ad Loading...

Trucks, laptops, mobile phones, etc., connect to web services. Then there are web-based platforms we use such as GoToMeeting or SalesForce that are also points of connection. 

“So when you talk about the attack surface, think about the whole ecosystem,” she said. “These are all points of ingress and egress.”

The Human Factor

Sometimes the point of vulnerability isn’t technology-based at all, but human-based

Moderator Ken Craig, vice president of special projects for McLeod Software, later shared with HDT a story of a “white-hat” test probing a company’s defenses. 

The “hacker,” unable to find a weakness via computer, called the company’s main phone line and went down the company directory until he found someone whose outgoing voice mail said they were on vacation for the next two weeks.

Ad Loading...

Then he mimicked that employee’s voice to call the company’s IT help desk, saying she was having trouble logging in remotely, and got the access information needed.

“A high number of people do not survive these attacks financially,” Sumerford said. “This has to be a strategic priority.”

6 Things to do to Protect Your Company from Hackers

The panel offered a number of strategies to help prevent cyberattacks and mitigate their consequences:

1. Conduct an assessment.

Joseph Saunders, CEO of RunSafe Security, said there are many assessments available that you can use as a framework to evaluate the vulnerabilities in your organization. 

Ad Loading...

Generally, he said, there are about 100 questions to ask yourself. You can do it internally or hire an outside party to help (but don’t pay more than $15,000, he said.) It’s a good idea to do a new assessment once a year.

2. Conduct a penetration test

In a penetration test, an outside party, a “white hat hacker,” tests and probes your systems looking for vulnerabilities. Don’t tell your team you’re doing it, or they will become more vigilant and skew the results. This is a separate assessment from the self-assessment, and the results may be similar, or the white hat may find something that you did not uncover previously. 

Like the assessment, don’t just do it once. Repeat every year or two.

As an example of a penetration test, Reynolds cited the Cyber Truck Challenge held in Detroit annually. "We bring our equipment, and college students and professional white-hat hackers hack our devices in an NDA (non-disclosure agreement) environment, and we get that feedback and can go back and say you to developers, you missed this."

Ad Loading...

Joseph Saunders, CEO, RunSafe Security, talks about how to prioritize cyber security weaknesses at your company.

Photo by Deborah Lockridge

3. Prioritize the risks

You can apply a simple risk management framework, Saunders said. 

On one axis, plot the weaknesses you uncover based on the likelihood of an attack. On the other axis, plot them based on the significance of their impact. The items in the upper-right-hand quadrant that are both most likely and can do the most damage are the ones you want to address first.

“You only have a finite number of resources you can throw at this,” Reynolds added. “So identify the most critical things — but have your containment and mitigation plan in place for those critical systems.”

4. Apply software patches

Ad Loading...

Saunders compared software patches to washing your hands – it’s something that can prevent viruses, but only if you do it consistently. Yes, it’s a pain, but make it a regular part of operations and maintenance. 

Talk to your suppliers and vendors. They’re regularly coming up with fixes for weaknesses they find in their offerings, and you need to come up with procedures and practices to install them consistently.

5. Consider insurance

One of the things J&M Tank Lines did after its attack was purchase a cyber insurance plan. 

“Cyber insurance is becoming really critical,” said Omnitracs’ Reynolds. “Like any other business risk we insure for, it’s important to view it as a business risk.” 

Ad Loading...

However, companies will generally require you to put a robust cyber security program in place as part of the deal. 

“You have to have good cyber hygiene or they won’t pay.” 

Sumerford said J&M just renewed its insurance; “We have a pretty in-depth cyber security plan of action.” Which leads us to…

6. Create an incident response plan

Don’t wait until you get that phone call at 2:30 a.m. to figure out what you’re going to do if and when your company is the victim of a cyber-attack, Saunders said. 

Ad Loading...

“Knowing what to do when you get that phone call in the middle of the night is key.” 

Questions to ask yourself include:

  • Who is in charge?

  • Who gets notified?

  • Who is the response team?

  • Who is your forensics team? The panel emphasized that it’s important to build the relationship with that forensics company before you have the attack. It’s not exactly a good time to be trying to set up a purchase order with your computers down. Set up a retainer arrangement, Reynolds suggested. “This way, you can call and say, ‘It’s happened, boots on the ground.’”

  • Who is your FBI or DHS contact? Again, the time to meet your FBI or Department of Homeland Security contact is not when you’re in the middle of a cyber attack situation. “You don’t want to cold-call the FBI,” Craig said.

  • Will you pay the ransom?

Long-term solutions

Saunders said while these are good things to do in the short term, in the long term, the industry needs to find better ways to “disrupt hacker economics.”

“Often times if they can find a vulnerability in one place, they’re going to do it again and again,” he said. In fact, automated exploits are used in nearly 70% of cyber-attacks. 

Ad Loading...

“This is an underground business as sophisticated as the ones you operate. The idea is to disrupt hacker economics.”

The military has learned this lesson with drones. 

“If you think about a fleet of drones… each one is functionally identical, they have the same software, so if there’s a vulnerability on one, it exists in all. The military figured out if you could make it functionally identical but logically unique, so each one is different from an attacker’s perspective, then they have to spend a lot of time to work on each drone. This disrupts the hacker economy.”

Subscribe to Our Newsletter

More Fleet Management

A woman holding a tablet with a screen showing rectangles of various colors
SponsoredSeptember 16, 2026

Color Match Smarter: Tools That Restore & Perform

For fleet managers and collision repair professionals keeping heavy-duty trucks on the road, getting the color right the first time isn't just about appearance — it's about efficiency, turnaround time, and bottom-line results. Discover how today's digital color tools are transforming the repair process from guesswork to precision.

Read More →
Mobile tablet showing Motus screen against highway background with Motus logo
Fleet Managementby StaffSeptember 15, 2026

FMCSA Pauses Biennial-Update Enforcement Amid Motus Transition

Carriers whose updates were due on or after June 1 have more time, while FMCSA works to stabilize its new registration system and warns of phishing sites impersonating its new carrier registration system, Motus.

Read More →
Geotab Whitepaper Cargo Theft Cover
SponsoredSeptember 14, 2026

2026 Blueprint for Countering Smarter Supply Chain Theft

Cargo theft is no longer just the cost of doing business. It's a multi-billion-dollar criminal enterprise exploiting vulnerabilities across your fleet, drivers, and supply chain.

Read More →
Ad Loading...
A monitor with a bar graph with a person sitting next to it wearing a headset.
SponsoredSeptember 1, 2026

How Telematics Improves Visibility, Control, and Performance in Refrigerated Fleets

Explore how telematics help refrigerated fleets improve visibility, uptime, efficiency, compliance, and cargo protection across connected cold chain operations.

Read More →
Graphic with U.S. and Canadian flags over background illustration of an ink-stamp that says Tariffs.
Equipmentby Deborah LockridgeAugust 24, 2026

What the U.S.-Canada Trade War Means for Trucking

Escalating U.S.-Canada tariffs could disrupt cross-border freight, reduce truck volumes, raise costs, and create new uncertainty for carriers on both sides of the border.

Read More →
Fleet Managementby News/Media ReleaseAugust 24, 2026

What Are Trucking’s Top Concerns for 2026?

The American Transportation Research Institute wants to know what's worrying trucking fleet managers, drivers, and other stakeholders in its annual Industry Issues survey.

Read More →
Ad Loading...
Four men in suits on the National Mall with giant video screen showing capitol building in the background
Fleet Managementby Deborah LockridgeAugust 24, 2026

American Trucking Associations Looks for a New Leader

ATA President and CEO Chris Spear abruptly left his job at the association on August 21, at a pivotal time for the trucking industry.

Read More →
The Cyber Stop column header with photo of a smiling driver in truck with a laptop and a wi-fi icon
Fleet ManagementAugust 21, 2026

Public Wi-Fi Cybersecurity Risks: How Truck Drivers and Fleets Can Protect Their Data

Public Wi-Fi can expose truck drivers and fleets to credential theft, malware, and other cyber threats. Here’s how to reduce the risk on the road.

Read More →
Woman in white blazer superimposed on background showing a row of Fraley & Schilling truck, plus the HDT Truck Fleet Innovators 2026 logo
Fleet Managementby Deborah LockridgeAugust 19, 2026

For Nicky Cupp, Fleet Innovation Starts With Frustration

HDT Truck Fleet Innovator Nicky Cupp turns everyday pain points at Fraley & Schilling into opportunities for better technology and smarter processes.

Read More →
Ad Loading...
Headshot of Adam Buttgenbach with a Pepsi-branded Tesla Semi in the background
Fleet Managementby Deborah LockridgeAugust 18, 2026

Adam Buttgenbach’s Approach to Electric Trucks: Start With Where They Fit

HDT Truck Fleet Innovator Adam Buttgenbach helped PepsiCo build one of North America’s largest EV fleets by focusing on where electric trucks make operational sense.

Read More →