If you’ve been around our terminal here at HMD Trucking in Chicago at all, you know that we love to talk about what keeps American freight moving. While lane rates, new engine technology, and handling unpredictable Midwest winters are topics we can’t avoid, they only lead us back to one thing: keeping our drivers safe, our trucks rolling, and our business protected.
For decades, protecting a trucking company meant putting good drivers behind the wheel of reliable equipment and locking up the yard at night. However, the industry has changed. Today, freight runs on data as much as it does on diesel. Electronic Logging Devices (ELDs) and live GPS tracking, cloud-based Transportation Management Systems (TMS), and automated load boards constitute the digital backbone of modern logistics.
This digital layer makes trucking operations much more efficient but also more vulnerable to new risks. Cybercrime is no longer targeting just big tech firms or financial institutions; it is now actively attacking American motor carriers.
The government has begun to develop mandatory cybersecurity regulations for national supply chains. The Cybersecurity and Infrastructure Security Agency (CISA) is writing rules for the Cyber Incident Reporting for Critical Infrastructure Act (CIRCIA).
Most mid-sized carriers do not realize that they are part of the federal "critical infrastructure." A cyberattack is not just an issue for your IT managers and technicians anymore; instead, it is a major operational challenge. Understanding mandatory cybersecurity incident reporting is equally critical for fleet executives, safety directors, owner-operators, and professional CDL drivers.
Contents:
- The New Reality: How Mid-Sized Carriers Got Drafted into Critical Infrastructure
- Cybersecurity in Trucking: Why It Is Moving from the Back Office to the Rig
- Digital Hijacking: How Cybercriminals Are Stealing Loads Without Touched Keys
- Cyber Insurance Traps: Why Missing a Deadline Can Void Your Coverage
- Operational Playbook: How Motor Carriers Can Prepare
- Protecting the Future of American Freight
The New Reality: How Mid-Sized Carriers Got Drafted into Critical Infrastructure
When most people hear the term “critical infrastructure,” they think of nuclear plants, military bases, water treatment plants, or major oil pipelines. You may not instantly classify a mid-size dry van or reefer fleet in the same category. But federal regulations view the situation differently.
President's Policy Directive 21 (PPD-21) and National Security Memorandum 22 (NSM-22) classify Transportation Systems as one of the sixteen critical infrastructure sectors in the U.S. Congress has directed CISA to define who must report a cyber incident under the Cyber Incident Reporting for Critical Infrastructure Act.
CISA established a two-part framework to determine who is covered:
Track 1: Size-Based Thresholds
Any business in the critical infrastructure industry whose size exceeds the Small Business Administration (SBA) small business size standard is a covered entity. For NAICS Code 484 (Truck Transportation), which covers local, long-distance, truckload, and less-than-truckload operations, the SBA size standard is $33.5 million annually. If your trucking business has greater than $33.5 million in gross annual revenue, you are a critical infrastructure business under federal law.
Track 2: Sector-Based Criteria
Size is not the only trigger. Smaller fleets can be brought onto the coverage net if their disruption is seen as a risk to public safety and national security. In trucking, this applies directly to fleets moving placarded Hazardous Materials (HAZMAT) or carriers providing critical logistics support to the Department of Defense.
Many family-owned and mid-sized carriers operating between 50 and 200 power units cross that $33.5 million revenue mark. If your business meets these criteria, you must comply with federal cybersecurity incident reporting mandates.
Cybersecurity in Trucking: Why It Is Moving from the Back Office to the Rig
For years, cybersecurity was treated as a secondary concern in freight. As long as the servers ran and dispatch could send load sheets, leadership rarely focused on digital security.
That approach is no longer viable. Cybersecurity in trucking has evolved into a daily operational priority because modern threat actors are targeting the freight ecosystem directly.
Consider what happens when a carrier’s dispatch system or TMS goes offline:
- Drivers on the road lose access to digital load tenders, routing updates, and customer delivery confirmations.
- Terminal managers cannot assign incoming freight or generate accurate Bills of Lading.
- Accounting departments are cut off from billing portals, delaying driver settlement checks and fuel card resets.
- Maintenance bays lose access to diagnostic platforms and preventive maintenance schedules.
Digital compromise immediately impacts physical operations. When systems fail, trucks stop moving, revenue halts, and driver satisfaction plummets.
At HMD Trucking, we view cybersecurity in trucking as an essential extension of physical safety. Just as we wouldn't send a tractor out with worn brakes, we cannot operate without securing our digital infrastructure.
The CIRCIA Breakdown: The 72-Hour Clock and 24-Hour Ransom Rules
Following public consultations and town hall sessions with over 1,200 industry representatives, CISA confirmed that the finalized CIRCIA regulations will be formally published. The rule establishes two strict reporting timelines for covered motor carriers:
1. The 72-Hour Incident Reporting Requirement
Covered carriers must report any "substantial cyber incident" to CISA within 72 hours. A reportable incident includes any compromise that causes the following:
- Significant loss of operational system availability or data confidentiality.
- Disruption of your core business operations or service delivery.
- Unauthorized access caused by a third-party vendor, managed service provider (MSP), or supply chain compromise.
The 72-hour timeline begins when your company forms a reasonable belief that an incident occurred – not when your IT team finishes its investigation. If your security logs show unauthorized administrative activity over the weekend, your 72-hour clock has likely already started.
2. The 24-Hour Ransomware Payment Requirement
If a carrier falls victim to a ransomware attack and makes a ransom payment – or has a third-party negotiator or insurer pay on their behalf – the payment must be reported to CISA within 24 hours of disbursement. This rule applies even if the underlying attack did not disrupt physical operations.
| Regulation / Framework | Oversight Agency | Primary Mandate | Reporting Timeline |
| CIRCIA Final Rule | CISA (DHS) | Substantial Cyber Incidents & Ransomware Payments | 72 Hours (Incidents) / 24 Hours (Ransoms) |
| Surface Cyber Rule | TSA | Cyber Risk Management (COIP) & Assessment Audits | Mandatory Threat Coordinator Status |
| Motus System Verification | FMCSA | Anti-Fraud Identity Proofing for Registrations | Live Facial Scan at Registration |
| SCAC Verification | NMFTA | Binding SCAC Credentials to Verified Documents | Continuous Real-Time Validation |
The Cost of Non-Compliance
The penalties for failing to meet these deadlines are harsh. In cases where CISA has reason to believe that the breach may have gone unreported, they send out an official Request for information (RFI). If a carrier fails to respond adequately, CISA may issue an administrative subpoena. Cases of noncompliance can be referred to the Department of Justice (DOJ) for civil enforcement that may include fines, contempt of court charges, and debarment from federal contracts.
Digital Hijacking: How Cybercriminals Are Stealing Loads Without Touched Keys
The explanation of such an extreme approach lies in the nature of the threat landscape that regulators are trying to cover. The growing overlap between cybercrime and traditional physical cargo theft is illustrated by the results of the 2026 NMFTA Transportation Industry Cybersecurity Trends Report.
Cyber-enabled cargo theft is increasingly being facilitated by stolen credentials, phishing, or even artificial intelligence, rather than just encrypting back-office files.
Mechanics of a Cyber-Enabled Cargo Theft:
- Phishing and Credential Harvesting: Baddies hijack login credentials through phishing emails, malicious links, or compromised APIs.
- FMCSA Account Hijacking: Cybercriminals use the login credentials for the Federal Motor Carrier Safety Administration (FMCSA) registration system. Using the credentials obtained from the hacker, they change the carrier's telephone number, email address, and dispatch number.
- Fraudulent Freight Booking: The contact information in the official registry, upon which a broker relies for an assurance of the identity, links directly to the fraudster. The criminal books a high-value freight shipment under the legitimate carrier MC number.
- Fictitious Pickup: The assailant sends a bogus truck to the shipper’s dock, takes the freight, and is gone before the real carrier or broker knows what happened. There has been an increase in the annual number of fictitious pickups from 66 cases to over 576 cases per year.
- API and ELD Exploitation: Bad actors monitor for vulnerable application programming interfaces (APIs) involving load boards, telematics devices, or fleet software. The APIs can be used to intercept load tenders, track high-value shipments, and redirect driver requests to the wrong location via spoof dispatch update messages.
To combat identity hijacking, the FMCSA launched Motus, a registration portal requiring identity verification and live facial scanning for administrative modifications. Similarly, the National Motor Freight Traffic Association (NMFTA) introduced SCAC Verified to bind Standard Carrier Alpha Codes directly to authenticated corporate documents, helping brokers confirm a carrier's identity before tendering freight.
Cyber Insurance Traps: Why Missing a Deadline Can Void Your Coverage
Due to the increasing seriousness of cyber risk, the cyber insurance market has tightened underwriting standards. Insurance applications now function as complete technical audits.
In order to get cyber liability coverage, underwriters mandate that motor carriers have an implemented set of seven basic security controls:
- Multi-Factor Authentication: Multi-factor authentication should be enforced on all email accounts, remote access tools (VPN/RDP), admin accounts, and cloud software.
- Active Endpoint Detection and Response (EDR): Old-fashioned antivirus is no longer enough. EDR or Managed Detection and Response (MDR) technologies with the capability of real-time behavior monitoring and automated threat isolation support are something that insurance companies currently require.
- Immutable, Offsite Backups: Backups must be mathematically protected against deletion or alteration, stored offsite, and completely segregated from primary domain administrative credentials.
- Patch and Vulnerability Management: Carriers are required to have documented formal procedures for critical software patches to be applied within strict timeframes.
- Privileged Access Management (PAM): Administrative access rights need to be limited so that daily email and browsing tasks are not running under domain admin accounts.
- Security Awareness Training: Every company must conduct regular employee phishing simulations and record participant logs.
- Third-Party Vendor Verification: Carriers are required to evaluate the security practices of any third-party software and logistics technology suppliers to which they contract.
The Regulatory Exclusion Trap
Here is where CIRCIA compliance intersects directly with your bottom line: standard cyber liability policies contain compliance exclusions. If your fleet experiences a major cyber incident and fails to notify CISA within the mandatory 72-hour window or fails to satisfy CIRCIA's two-year log-preservation requirements, your insurer can dispute or deny the claim.
For a mid-sized carrier, losing insurance coverage during a major cyber incident leaves the business directly responsible for recovery costs, customer liabilities, and legal fees – a situation that can threaten company solvency.
Operational Playbook: How Motor Carriers Can Prepare
Preparing for federal cybersecurity incident reporting requirements under the Cyber Incident Reporting for Critical Infrastructure Act requires a proactive operational strategy.
Here is how motor carriers should prepare:
- Evaluate and Document Your Coverage Status: Review your gross annual receipts against the SBA $33.5 million threshold for NAICS 484. If your fleet moves placarded HAZMAT loads or holds defense transport contracts, document your status under CIRCIA's criteria. Retain this legal and operational analysis in your compliance records.
- Define “Reasonable Belief” and Craft Response Templates: Create an internal decision matrix to determine what technical aspects constitute "reasonable belief" of a covered incident. Create pre-approved CISA reporting templates so that your legal, safety, and IT staffs can submit accurate information within the 72-hour window without losing precious time during a breach.
- Secure Carrier Registrations and Credentials: Connect your administrative accounts to the FMCSA’s Motus system for biometric authentication. Enroll your SCAC in the NMFTA SCAC Verified program so that brokers can verify your corporate identity, protecting your fleet from identity theft.
- Upgrade Data Logging and Retention Infrastructure: CIRCIA requires covered entities to maintain incident and forensic logs for at least two years. Consider archiving your firewall logs, API logs, and authentication records on a write-once file server that is not affected by any network changes.
- Conduct Annual Tabletop Simulations: Run annual tabletop exercises to simulate actual events, such as a compromised dispatch system or an FMCSA account hijacking. Train senior management, safety managers, attorneys, and IT contractors to perform the exercises and determine whether they can respond to, contain, and report the incident within the timeframe set by the CIRCIA.
Key Takeaways for Drivers and Carriers
- If your trucking business generates over $33.5 million per year and/or hauls HAZMAT, you are considered critical infrastructure under federal law.
- CIRCIA requires covered incidents to be reported to CISA within 72 hours and ransomware payments to be made within 24 hours.
- Bad actors steal FMCSA registration records and carrier IDs to fake pickups and steal freight.
- Failure to meet federal reporting requirements or failing to implement mandatory security controls like MFA and immutable backups can void your cyber insurance coverage.
- Solutions like FMCSA Motus and NMFTA SCAC Verified help to protect your fleet’s identity and load security.
Protecting the Future of American Freight
HMD Trucking believes that ensuring the safety of our fleet and trucks means staying ahead of the new trends in our industry, whether it's trucking equipment, safety measures, or digital security. The implementation of federal rules under the Cyber Incident Reporting for Critical Infrastructure Act marks a shift in American transportation. We treat cybersecurity as a fundamental aspect of our business to protect our drivers, our customers, and our business.