Shipping & Logistics Cybersecurity Checklist
A 45-point cybersecurity readiness checklist for shipping and logistics operators.
Built for freight, trucking, warehousing, and terminal operators running distributed sites on a flat network and a clock that doesn’t stop. Mapped to the threats that actually take down logistics operations: wire fraud, ransomware at a single site, and the new USCG marine cybersecurity rule.
Free download
Get the checklist as a PDF
We’ll email a formatted PDF you can print, share with your ops team, or use to brief your insurer. The full checklist is also below on this page.
How to use this
Walk this list with whoever owns IT, whether that’s an internal admin or your MSP. Mark each item In place / Partial / Gap. Two categories are worth extra attention for most mid-size operators: “Distributed Site & Network,” because remote terminals and yards are harder to standardize than a single headquarters, and “Wire Fraud & Payment Verification,” because business email compromise remains one of the most common ways logistics companies actually lose money.
Wire Fraud & Payment Verification
- Written callback-verification procedure for any change to bank/payment instructions
- Dual-approval required for wire transfers above a set threshold
- Vendor/broker payment details verified through a channel independent of email
- Finance team has run a tabletop on a BEC/wire-fraud scenario in the last 12 months
- Out-of-band verification required before releasing a load against a new or changed customer account
Email & Identity Security (Microsoft 365 / Azure)
- Multi-factor authentication enforced on all M365 accounts, no exceptions for dispatch or ops staff
- Conditional Access policies restrict sign-in by location/device risk
- DMARC set to enforcement (reject), not just monitoring
- Mail flow rules flag external senders spoofing internal domains
- Privileged Identity Management (or equivalent) on all admin accounts
Distributed Site & Network Segmentation
- Network segmentation exists between HQ, terminals, and warehouse sites (no flat WAN)
- A single site compromise cannot reach systems at another site without crossing a monitored boundary
- Guest/visitor and IoT/dock-door devices are on a separate VLAN from operational systems
- Firewall configurations are centrally managed, not per-site ad hoc
- Remote/branch sites have the same MFA and endpoint standards as HQ
TMS / WMS / EDI & Vendor Systems
- Transportation Management System (TMS) and Warehouse Management System (WMS) included in vulnerability scanning scope
- EDI gateways and integrations reviewed for authentication strength and data exposure
- Vendor/partner system access reviewed and de-provisioned on offboarding
- Third-party carrier and broker portal credentials are unique, not shared or reused
- API integrations with customer or partner systems inventoried and access-scoped
Endpoint & Fleet Device Security
- EDR deployed on laptops, warehouse PCs, and back-office servers
- Ruggedized handheld/scanner devices included in patch management scope
- Telematics and ELD (electronic logging device) systems reviewed per FMCSA cybersecurity best practices for aftermarket electronics
- Lost/stolen device procedure includes remote wipe capability
- Personal devices accessing dispatch or email systems are enrolled in MDM
Backup, Recovery & Business Continuity
- Immutable backups in place for TMS, WMS, and financial systems
- Recovery time objective (RTO) tested at least annually with a real restore, not just a backup-completed report
- A single warehouse or terminal outage has a documented failover or manual-ops procedure
- Backup scope includes EDI and integration configuration, not just data
- Business continuity plan assigns named owners, not just a document on a shelf
Incident Response & Partner Notification
- Written incident response plan naming who calls customers, carriers, and insurers, and in what order
- IR retainer or in-house capability with a defined SLA for logistics-specific scenarios (ransomware at a site, BEC, TMS outage)
- Customer/broker contract language reviewed for security-incident notification obligations
- Annual tabletop exercise covers at least one distributed-site ransomware scenario
- Post-incident review process feeds back into the segmentation and vendor-access controls above
Maritime & Surface Transportation Regulatory Alignment
- If operating U.S.-flagged vessels, OCS facilities, or MTSA-regulated facilities: aware of and scoping against the Coast Guard’s Cybersecurity in the Marine Transportation System final rule, effective July 16, 2025
- Cybersecurity plan requirements and reporting obligations under the new MTSA cyber rule assigned to a named owner
- If moving freight by pipeline or rail, aware of applicable TSA security directives (pipeline SD-01, rail 1580/82 series) covering cyber mitigation and testing
- Insurance carrier’s cyber questionnaire reviewed against actual controls (not assumed answers)
- Customer/shipper RFP security questionnaires answerable from current documentation, not built from scratch each time
Governance & Documentation
- Named person (not “IT” generically) owns the security program
- Vendor/partner risk review process exists for any system touching customer freight or payment data
- Security policy set reviewed in the last 12 months
- Cyber insurance policy reviewed against actual control posture, not renewed on autopilot
- Evidence of controls (logs, scan reports, training records) organized well enough to hand to an insurer or customer auditor on short notice
Sources & further reading
This checklist reflects the Coast Guard’s Cybersecurity in the Marine Transportation System final rule, effective July 16, 2025 for owners and operators of vessels and facilities regulated under MTSA; TSA’s pipeline and surface transportation cybersecurity security directives for rail and pipeline operators; and FMCSA guidance on securing ELD and telematics systems. Requirements vary by mode and by whether your facility or fleet falls under MTSA, so confirm applicability with your regulator or counsel before treating this checklist as a compliance determination.
Frequently asked questions
Does the USCG cybersecurity rule apply to my company?
The rule applies to owners and operators of vessels, facilities, and Outer Continental Shelf facilities regulated under the Maritime Transportation Security Act (MTSA), including many ports, terminals, and marine facility operators. It took effect July 16, 2025. If you're a trucking or rail-only logistics operator without MTSA-regulated facilities, this specific rule doesn't apply to you, though TSA and FMCSA requirements may.
What cybersecurity rules apply to freight rail and pipeline operators?
TSA has issued a series of security directives for freight rail, passenger rail, and pipeline operators covering cybersecurity coordinator designation, incident reporting, vulnerability assessments, and incident response planning. The specific directive and requirements depend on your transportation mode; TSA's industry cybersecurity page is the authoritative source for current directives.
Why does wire fraud show up on a cybersecurity checklist for logistics companies?
Business email compromise, fake carrier setups, and fraudulent payment redirects are among the most common ways logistics and freight brokerage companies actually lose money to cybercrime, often without any system being technically breached. A checklist that only covers network security while ignoring payment verification controls misses where a lot of real losses happen.
Do I need a cybersecurity coordinator if I'm not MTSA-regulated?
MTSA-regulated facilities and vessels are required to designate one under the USCG rule. Even if you're not MTSA-regulated, naming a single accountable owner for cybersecurity, even part-time, is a practical step that shows up as a gap in almost every logistics company we assess.
How does this checklist relate to cyber insurance requirements?
Cyber insurance applications increasingly ask about many of the same controls covered here: MFA, backup testing, incident response plans, and vendor risk management. Working through this checklist before your next renewal typically surfaces the same gaps an underwriter's questionnaire would, with time to fix them before you're asked.
Aloha, let’s talk
Want this as a scoped remediation plan instead of a checklist?
A 30-minute call gets you a fixed-scope plan for the gaps that matter most for a distributed logistics operation, every gap with an owner, a timeline, and a cost.
Further reading
Analysis from the team that runs the SOC.