Free NMFTA Cybersecurity Risk Check:
Where Does Your Small Fleet Actually Stand?
- 9 quick questions
- Takes about 2 minutes
- No sign-up to see your result
Your top next moves
Use the interactive risk check below to see where your operation stands against NMFTA’s own cybersecurity framework for owner-operators and small fleets.
Answer 8 quick questions, weighted toward dispatch, billing, your TMS, and load-board or factoring logins since that’s where a real attack actually costs you money, and get your readiness score in about 2 minutes: your risk level, the specific gaps to close, and a printable checklist you can hand to your team or IT provider.
No sign-up to see your result.
What the NMFTA Cybersecurity Framework Actually Covers
(the short version)
NMFTA, the National Motor Freight Traffic Association, publishes a Cybersecurity Best Practices Guidebook written specifically for owner-operators and small fleets (generally under 50 trucks), built on the NIST Cybersecurity Framework and the CIS 18 Critical Security Controls but rewritten in plain language for trucking.
It organizes controls into four progressive tiers so an operation with no in-house IT person has a clear starting point:
Covers the handful of basics every fleet should have regardless of budget: updated software, tested backups, strong unique passwords, and multi-factor authentication (MFA).
Adds staff awareness training, endpoint protection, a written incident response plan, secured Wi-Fi, and limiting who can access what.
Covers layered network access, VPN-secured remote access, email security, encryption, and a documented inventory of your systems.
Adds continuous monitoring, formal written policies, and a prioritized plan for closing remaining gaps.
The checklist below is organized around those same four tiers, translated into the systems a small fleet actually runs day to day: dispatch, your TMS, ELD and telematics portals, load boards, and factoring or accounting logins, not the trucks themselves.
The Full NMFTA-Aligned Small Fleet Checklist
Work through each area. Anything you can’t confirm is a gap. If you can’t prove it, neither can your insurance broker.
- 1. Login and backup basics (NMFTA Tier One: Prerequisites)
✓ Every login, dispatch, TMS, ELD portal, load boards, factoring or accounting software, uses its own strong, unique password. No shared logins, no default passwords left in place.
✓ Multi-factor authentication (MFA) required everywhere it’s offered, especially dispatch, TMS, banking, and factoring logins.
✓ Software and operating systems set to update automatically wherever possible.
✓ Backups of dispatch, billing, and TMS data that someone has actually tested by restoring them. NMFTA recommends the 3-2-1 rule: 3 copies, on 2 types of media, with 1 copy off-site. - 2. Staff Awareness and the Fraud that Actually Costs Money (NMFTA Tier Two: Initial)
✓ Dispatchers and billing staff trained at least once a year to recognize a fake load-board message, a spoofed carrier-portal or FMCSA login page, or a “customer” or broker asking to reroute a payment.
✓ Office Wi-Fi secured with WPA2 encryption or better, using a password you set yourself, not the one printed on the router.
✓ Each employee’s access limited to the systems their job requires (least privilege): a dispatcher shouldn’t also be able to reach payroll or the company bank account.
✓ A written incident response plan naming who to call and how operations continue if a system goes down. - 3. Locking Down Remote Access and Back-Office Systems (NMFTA Tier Three: Intermediate)
✓ A VPN, or the vendor’s own secure login, required any time someone accesses your TMS, ELD portal, or bank/factoring account remotely.
✓ Email security (SPF/DMARC or a secure email gateway) configured to catch messages spoofing your bank, a broker, or a fuel-card provider.
✓ Financial systems (accounting, payroll, banking) kept on a separate, more restricted part of your network than general office use.
✓ A documented inventory of every system, device, and login your fleet actually uses. - 4. Documentation and Ongoing Monitoring (NMFTA Tier Four: Advanced)
✓ Written, up-to-date cybersecurity policies you could hand to an insurance broker or a new hire.
✓ Regular review of security logs and alerts across dispatch, TMS, and financial systems.
✓ A prioritized list of known gaps and a plan to close them as your fleet grows.
How to read your gaps?
- 0 – 2 Gaps (No MFA, Backups, or Fraud Gaps)
Strong Shape
- 3 – 6 Gaps (Or 1 Critical Gap)
Real, findable gaps concentrated in exactly the systems, dispatch, billing, remote logins, that an attacker actually goes after, not the trucks.
- 7+ Gaps or 2+ Critical Gaps
An attacker would likely get into your back office today, and the financial hit would land on dispatch, billing, or your bank account.
NMFTA built this framework for operations under 50 trucks specifically because the assumption that a small fleet is beneath an attacker’s notice is exactly what makes it an easy one. NMFTA’s own guidance frames the real goal as becoming the least appealing target, not the most convenient one.
Most of the items above, MFA, tested backups, VPN, email filtering, live in your IT setup, not a policy binder, which is the half of this framework a managed IT partner operates for you.
NMFTA Cybersecurity Risk Check FAQ
NMFTA, the National Motor Freight Traffic Association, publishes a Cybersecurity Best Practices Guidebook written specifically for owner-operators and small fleets, generally those with under 50 trucks. It’s built on the NIST Cybersecurity Framework and the CIS 18 Critical Security Controls, tailored for trucking, and organized into four progressive maturity tiers so a fleet without an in-house IT department has a clear, low-cost starting point.
NMFTA built its small fleet guidebook around the opposite assumption: that weak basics, not fleet size, make an operation an easy target. The guidebook frames the goal as making your operation the least appealing target, not the most convenient one. An attacker looking for a fast payday doesn’t check your truck count before trying a stolen password or a fake rate confirmation.
Usually not directly. The trucks themselves rarely hold anything worth stealing on their own. The real financial exposure sits in the back office: dispatch software, your TMS, billing and factoring accounts, and load-board or carrier-portal logins. A compromised dispatch account or a rerouted payment does more damage, faster, than anything that touches the truck itself.
No. The tiers are designed to be progressive. Tier One (Prerequisites) covers the handful of controls, passwords, MFA, tested backups, that every fleet should have regardless of size or budget. Tiers Two through Four add more sophistication as time and resources allow. Most owner-operators and small fleets get the most value from solidly completing Tiers One and Two first.
Cyber-insurance carriers increasingly ask for proof of the same basics this checklist covers: MFA, trained staff, and tested backups, before they’ll write or renew a policy. Being able to document these controls, not just describe them, is what keeps a renewal conversation from turning into a denial or a premium increase. LeadingIT’s cyber insurance readiness check covers that side in more depth.
The NMFTA guidebook is written specifically for operations with roughly 50 or fewer assets, including true owner-operators, and it assumes limited or no in-house IT staff and a limited budget. That’s why its recommendations prioritize low-cost or free controls. Fleet size changes how much you have to lose. It doesn’t change whether the basics apply.
Ready to close your gaps?
If your result flagged gaps in MFA, backups, or staff awareness around dispatch and billing fraud, most of that is technical and training work an IT partner handles day to day.
LeadingIT helps Chicagoland trucking, distribution, and logistics operations build the access controls, backups, and monitoring that NMFTA’s framework calls for, delivered as a managed service, not a certification LeadingIT holds (NMFTA doesn’t issue one).
Email yourself the full result from the tool above, book a free 30-minute gap review, or contact us and see how we support transportation and logistics operations as a managed service.