Skip to main content
  • For Support:

    815-308-2095

  • New Client
    815-788-6041

Free NMFTA Cybersecurity Risk Check:
Where Does Your Small Fleet Actually Stand?

NMFTA Cybersecurity Best Practices Risk Check

  • 9 quick questions
  • Takes about 2 minutes
  • No sign-up to see your result

Your top next moves

    Nothing critical flagged. Keep everything current and re-check yearly.

    Book a call

    Use the interactive risk check below to see where your operation stands against NMFTA’s own cybersecurity framework for owner-operators and small fleets.

    Answer 8 quick questions, weighted toward dispatch, billing, your TMS, and load-board or factoring logins since that’s where a real attack actually costs you money, and get your readiness score in about 2 minutes: your risk level, the specific gaps to close, and a printable checklist you can hand to your team or IT provider.

    No sign-up to see your result.

    What the NMFTA Cybersecurity Framework Actually Covers
    (the short version)

    NMFTA, the National Motor Freight Traffic Association, publishes a Cybersecurity Best Practices Guidebook written specifically for owner-operators and small fleets (generally under 50 trucks), built on the NIST Cybersecurity Framework and the CIS 18 Critical Security Controls but rewritten in plain language for trucking.

    It organizes controls into four progressive tiers so an operation with no in-house IT person has a clear starting point:

    Tier One (Prerequisites)

    Covers the handful of basics every fleet should have regardless of budget: updated software, tested backups, strong unique passwords, and multi-factor authentication (MFA).

    Tier Two (Initial)

    Adds staff awareness training, endpoint protection, a written incident response plan, secured Wi-Fi, and limiting who can access what.

    Tier Three (Intermediate)

    Covers layered network access, VPN-secured remote access, email security, encryption, and a documented inventory of your systems.

    Tier Four (Advanced)

    Adds continuous monitoring, formal written policies, and a prioritized plan for closing remaining gaps.

    The checklist below is organized around those same four tiers, translated into the systems a small fleet actually runs day to day: dispatch, your TMS, ELD and telematics portals, load boards, and factoring or accounting logins, not the trucks themselves.

    The Full NMFTA-Aligned Small Fleet Checklist

    Work through each area. Anything you can’t confirm is a gap. If you can’t prove it, neither can your insurance broker.

    • 1. Login and backup basics (NMFTA Tier One: Prerequisites)

      ✓ Every login, dispatch, TMS, ELD portal, load boards, factoring or accounting software, uses its own strong, unique password. No shared logins, no default passwords left in place.

      ✓ Multi-factor authentication (MFA) required everywhere it’s offered, especially dispatch, TMS, banking, and factoring logins.

      ✓ Software and operating systems set to update automatically wherever possible.

      ✓ Backups of dispatch, billing, and TMS data that someone has actually tested by restoring them. NMFTA recommends the 3-2-1 rule: 3 copies, on 2 types of media, with 1 copy off-site.

    • 2. Staff Awareness and the Fraud that Actually Costs Money (NMFTA Tier Two: Initial)

      ✓ Dispatchers and billing staff trained at least once a year to recognize a fake load-board message, a spoofed carrier-portal or FMCSA login page, or a “customer” or broker asking to reroute a payment.

      ✓ Office Wi-Fi secured with WPA2 encryption or better, using a password you set yourself, not the one printed on the router.

      ✓ Each employee’s access limited to the systems their job requires (least privilege): a dispatcher shouldn’t also be able to reach payroll or the company bank account.

      ✓ A written incident response plan naming who to call and how operations continue if a system goes down.

    • 3. Locking Down Remote Access and Back-Office Systems (NMFTA Tier Three: Intermediate)

      ✓ A VPN, or the vendor’s own secure login, required any time someone accesses your TMS, ELD portal, or bank/factoring account remotely.

      ✓ Email security (SPF/DMARC or a secure email gateway) configured to catch messages spoofing your bank, a broker, or a fuel-card provider.

      ✓ Financial systems (accounting, payroll, banking) kept on a separate, more restricted part of your network than general office use.

      ✓ A documented inventory of every system, device, and login your fleet actually uses.

    • 4. Documentation and Ongoing Monitoring (NMFTA Tier Four: Advanced)

      ✓ Written, up-to-date cybersecurity policies you could hand to an insurance broker or a new hire.

      ✓ Regular review of security logs and alerts across dispatch, TMS, and financial systems.

      ✓ A prioritized list of known gaps and a plan to close them as your fleet grows.

    How to read your gaps?

    • 0 – 2 Gaps (No MFA, Backups, or Fraud Gaps)

      Strong Shape

    • 3 – 6 Gaps (Or 1 Critical Gap)

      Real, findable gaps concentrated in exactly the systems, dispatch, billing, remote logins, that an attacker actually goes after, not the trucks.

    • 7+ Gaps or 2+ Critical Gaps

      An attacker would likely get into your back office today, and the financial hit would land on dispatch, billing, or your bank account.

    NMFTA built this framework for operations under 50 trucks specifically because the assumption that a small fleet is beneath an attacker’s notice is exactly what makes it an easy one. NMFTA’s own guidance frames the real goal as becoming the least appealing target, not the most convenient one. 

    Most of the items above, MFA, tested backups, VPN, email filtering, live in your IT setup, not a policy binder, which is the half of this framework a managed IT partner operates for you.

    NMFTA Cybersecurity Risk Check FAQ

    What is the NMFTA Cybersecurity Best Practices Guidebook?

    NMFTA, the National Motor Freight Traffic Association, publishes a Cybersecurity Best Practices Guidebook written specifically for owner-operators and small fleets, generally those with under 50 trucks. It’s built on the NIST Cybersecurity Framework and the CIS 18 Critical Security Controls, tailored for trucking, and organized into four progressive maturity tiers so a fleet without an in-house IT department has a clear, low-cost starting point.

    Is a small fleet really worth attacking?

    NMFTA built its small fleet guidebook around the opposite assumption: that weak basics, not fleet size, make an operation an easy target. The guidebook frames the goal as making your operation the least appealing target, not the most convenient one. An attacker looking for a fast payday doesn’t check your truck count before trying a stolen password or a fake rate confirmation.

    If we get attacked, are our trucks what’s at risk?

    Usually not directly. The trucks themselves rarely hold anything worth stealing on their own. The real financial exposure sits in the back office: dispatch software, your TMS, billing and factoring accounts, and load-board or carrier-portal logins. A compromised dispatch account or a rerouted payment does more damage, faster, than anything that touches the truck itself.

    Do I need to reach NMFTA’s Tier Four (Advanced) to be considered secure?

    No. The tiers are designed to be progressive. Tier One (Prerequisites) covers the handful of controls, passwords, MFA, tested backups, that every fleet should have regardless of size or budget. Tiers Two through Four add more sophistication as time and resources allow. Most owner-operators and small fleets get the most value from solidly completing Tiers One and Two first.

    How does this connect to cyber insurance?

    Cyber-insurance carriers increasingly ask for proof of the same basics this checklist covers: MFA, trained staff, and tested backups, before they’ll write or renew a policy. Being able to document these controls, not just describe them, is what keeps a renewal conversation from turning into a denial or a premium increase. LeadingIT’s cyber insurance readiness check covers that side in more depth.

    Does a one- or two-truck operation really need all of this?

    The NMFTA guidebook is written specifically for operations with roughly 50 or fewer assets, including true owner-operators, and it assumes limited or no in-house IT staff and a limited budget. That’s why its recommendations prioritize low-cost or free controls. Fleet size changes how much you have to lose. It doesn’t change whether the basics apply.

    Ready to close your gaps?

    If your result flagged gaps in MFA, backups, or staff awareness around dispatch and billing fraud, most of that is technical and training work an IT partner handles day to day.

    LeadingIT helps Chicagoland trucking, distribution, and logistics operations build the access controls, backups, and monitoring that NMFTA’s framework calls for, delivered as a managed service, not a certification LeadingIT holds (NMFTA doesn’t issue one).

    Email yourself the full result from the tool above, book a free 30-minute gap review, or contact us and see how we support transportation and logistics operations as a managed service.