Wilkens: How fleets can use threat intelligence to strengthen cybersecurity and prevent fraud

Threat intelligence can help trucking fleets prioritize cyber risks, reduce fraud, and make better security decisions using guidance from the CISA, NSA, and FBI.

Key takeaways

  • Threat intelligence helps fleets prioritize cybersecurity efforts based on real risks instead of headlines.
  • Fleet-relevant advisories can identify practical steps to reduce cyber and fraud risks before attacks occur.
  • Sharing threat information through NMFTA and trusted sources strengthens security across trucking.

How do you decide where to spend your security budget and focus your security team’s time? If the answer is “defending against the latest type of attack that hit the news,” or “where my security vendor recommended,” then you are not alone. This is often the answer.

We buy a security tool because it defends against a potential attack path that we heard about, we run training because it came due again, and we end up trying to spread our security resources across all of the threats that we can imagine (which is a long list these days). Meanwhile, the bad actors trying to get into our networks and steal our cargo are organized and are comparing notes with one another. They often adapt faster than we do to new emerging technologies.

The threats aimed at trucking are not generic. Fictitious pickups and carrier impersonation are costing us millions across the industry; ransomware groups have specifically targeted transportation companies and leveraged the fact that a fleet that can’t dispatch its freight is dead in the water to extort payments. This is not random bad luck; these are deliberate techniques which specific bad actors use. They shift over time and adapt to the defenses we put in place. This is why defending against them on instinct, or on a playbook from last year, is a losing game.

What’s the answer? Threat intelligence. Without any of the jargon, threat intelligence is organized knowledge about who is targeting you, how they are doing it, and what they are after. It is timely and relevant to you specifically. It is also actionable; there is something you can do with it to improve your security. A deluge of alerts is not threat intelligence; it’s noise. Intelligence is the filtered, relevant, and decision-ready pieces of that flood of information.

If we think about this in operational terms, our dispatch teams are already working this way. They route around bad weather, known high theft locations, and route restrictions because they understand the environment and use the signals that are relevant to their requirements. Threat intelligence follows the same logic, pointed at cybersecurity and fraud reduction.

Here’s an example. On July 9, the National Security Agency (NSA), the Cybersecurity and Infrastructure Security Agency (CISA), the Federal Bureau of Investigation (FBI), and more than a dozen other agencies jointly warned that Russian state-sponsored actors are hunting on the internet for poorly configured routers, using default credentials and a couple of old, unpatched flaws to copy those devices’ configurations and burrow deeper into target networks. Their targets were in critical infrastructure sectors.

Since trucking is not specifically listed on the advisory as a most-targeted sector, it would be easy to read this and move on. However, that would be a mistake. Not all intelligence arrives pre-labeled for your business, but this advisory is specifically speaking to critical infrastructure sectors.

The skill is to read it and ask a simple question: can this impact us? In this example, the answer is a definitive yes. Every single fleet runs routers and other edge devices, and all too often those have default configurations and out-of-date firmware just like the advisory describes. The advisory itself also indicates that the mitigations they discuss can prevent attacks from other bad actors as well.

The point of this example is to show that when information is specific, actionable, and relevant, it allows you to change something specific that you are doing in an informed manner (i.e., implementing the recommended mitigations in this advisory). This example does not stop at “be worried about this threat.” It hands you a step-by-step to-do list to address the issue: disable the risky legacy features, patch the specific vulnerabilities and retire equipment too old to support, require multi-factor authentication (MFA) to reach network gear, and tightly limit who is allowed to manage those devices.

None of these are obscure technical fixes; they are components of basic cyber-hygiene. However, the advisory stands as a reminder that the most sophisticated attackers out there are still taking advantage of the doors we are inadvertently leaving open. Good threat intelligence should always take a threat and turn it into a few concrete decisions you can make in response.

The catch is that intelligence is only worth something if three qualities are present. It must be relevant to your operation. It must reach the person who makes the decisions on security actions. And it must change behavior.

An advisory that sits unread in an inbox, or a warning that is read but never passed to the security provider or internal team, is worth absolutely nothing. There are countless sources of intelligence out there. The trick is getting it to the right people in a form that they can use.

Good intelligence comes from several places: government agencies like the example above, information shared across our own sector, warnings from our peers, and many threat intelligence vendors. I would argue that industry sharing matters most out of these, because a technique that hit one carrier this month is often about to hit others.

That is part of why the National Motor Freight Traffic Association (NMFTA) opened its Threat Report Portal. This is a channel built for verified members of the transportation community to report and receive fleet-relevant cyber-threats and fraud alerts. It is one source among many, but it is one built specifically for our industry.

To harden the operation, threat intelligence needs to inform decisions. It allows us to allocate our security resources to where the real risk is, and not just where the latest headline might suggest.

Good threat intelligence helps teams respond to the techniques being actively used against them because they were warned about them in advance. This helps us become more adaptive and less attractive to the bad actors.

There is also a collective benefit here for the industry. When we act on specific, timely information relevant to our vertical and share those tactics with our peers, we help harden the entire transportation sector.

None of this requires a bigger budget or a dedicated intelligence team. It requires a habit. This week, take one recent threat advisory you have received (the example above is a fine place to start) and sit down with your IT lead, your security team, or your managed services provider (MSP)/managed security services provider (MSSP) and answer two questions: Does this apply to us, and if so, what are the specific things we are going to change because of it?

Do that consistently, and threat alerts start to become tools to help you choose the right battles to fight, rather than trying to fight them all at once.

About the Author

Ben Wilkens

Ben Wilkens

Ben Wilkens, CISSP, CISM, is the director of cybersecurity at the National Motor Freight Traffic Association. In his role at NMFTA, Ben spearheads research initiatives and leads teams dedicated to developing cybersecurity technologies, methodologies, and strategies to safeguard information systems and networks. He collaborates with academic institutions, industry partners, and government agencies to advance cybersecurity practices and knowledge.

Sign up for our eNewsletters
Get the latest news and updates

Voice Your Opinion!

To join the conversation, and become an exclusive member of FleetOwner, create an account today!