Van Fleet World

Features

Hack-proof fleet operations: How to prevent business cyber breaches

  • 4 March 2026
  • 0
  • Matthew MacConnell

Matt MacConnell investigates how fleets could be at risk and what they can do to prevent cyber breaches. Fleets are busy. And not only must managers ensure their

Hack-proof fleet operations: How to prevent business cyber breaches

Matt MacConnell investigates how fleets could be at risk and what they can do to prevent cyber breaches.

Transport companies are prime targets for cyber-attacks

Fleets are busy. And not only must managers ensure their van fleets are in tip-top condition, but they also need to monitor fleet operators. Throw in a few hiccups along the way, and the eight-hour-plus day is soon over. Sure, focusing on the job at hand is essential — this pays the wages, after all — but busy schedules can also create significant security gaps that many fleet managers may miss.

Most fleets in 2026 will likely run digitalised systems to help reduce processing times, enabling jobs to be scheduled and actioned more quickly, while managers can allocate saved time elsewhere. It all makes perfect sense. Why bother with physical paperwork when data can be automatically calculated via a system?

However, as soon as your business is connected to the internet, you automatically open yourself to various dangerous people. It’s like walking around London with your mobile phone in your hand. If someone steals it, they’ll have access to bank accounts – more so if you’ve set up contactless payments – emails, and other personal information.

Therefore, protecting your fleet is essential. Think of it as one of the most significant insurance policies your company could have. If someone breaches your company’s network, they could have instant access to your data.

If you’re reading this, thinking your company is safe because it’s either large or has been around for many years, think again.

Kettering-based KNP Logistics Group was the parent company of the 158-year-old haulage firm Knights of Old. In 2023, the firm was hit by a major ransomware attack that disrupted key systems and financial data, resulting in the loss of 730 jobs.

Essentially, this catastrophically damaged KNP Logistic Group’s financial position and crippled its ability to secure funding and investment.

Knights of Old staff members were suddenly locked out of the company’s IT systems

So, what did the attack look like? In June 2023, Knights of Old staff members were suddenly locked out of the company’s IT systems, unable to access administrative systems, finances, or take customer payments, causing their fleets to halt operations and head back to base.

The attack was carried out by the notorious Akira hacking group, which gained access by guessing an employee’s password. The hackers then encrypted the company’s data and sent a ransom note demanding a £5m payment. Scary, right? Ultimately, nothing could be done to save or access the systems; the transport firm failed to raise funds and soon closed its headquarters.

What could have been done to prevent this? Despite the attack’s scale, it was preventable. For example, two-factor authentication would have installed a defence barrier, sending a code to an employee’s phone, email address, or authenticator app when prompted.

Likewise, up-to-date security systems would already have included this, and staff should have been trained to create and secure complex passwords. This incident was just one of 19,000 ransomware attacks in 2023. However, this number could be larger as many companies will remain hush, pay the ransom, and continue trading.

So, what can fleets do to protect themselves? Van Fleet World chatted with a few experts to find out.

George Aitkenhead, CEO and founding partner of Lithium Systems, a Scotland-based IT firm, told VFW: “If you’ve got a fleet or you rely on connected vehicles and logistics platforms, you really need to be thinking about how to keep your data and systems safe.”

George Aitkenhead, CEO and founding partner of Lithium Systems

Aitkenhead added that transport companies are prime targets, and criminals know how much valuable information is being sent and received. If ignored, a fallout can cripple finances and reputation in one go.

“Supply chain attacks are another weak spot that we have seen being exploited. You might have the best cybersecurity systems in your own business, but if a supplier drops the ball, it can quickly become your problem too. Asking your staff to question every third party interaction, particularly those of a financial nature, should be a top priority.”

Phishing attacks remain widespread, with over 90% of businesses experiencing some level of phishing in the past year. It’s not all about sophisticated & targeted hacking; sometimes it’s as simple as tricking an employee into clicking on a malicious link in an email. That’s why regular cybersecurity training is so necessary. If your staff know what to look out for, you’re already a step ahead.

“You can’t just rely on one line of defence. We always recommend a layered approach including backups (local & cloud), risk assessments, 24x7x365 monitoring, cyber awareness training for staff, strong incident response plans, and making sure your suppliers take cybersecurity as seriously as you do,” adds Aitkenhead.

It’s also a perfect time to embrace AI, scary as it can be. AI can help identify unusual network behaviour and kill it before it becomes a full-blown attack. Add data encryption and secure multi-factor authentication, and you’ll make life much more difficult for cybercriminals.

During a chat with Weightmans LLP, a UK-based law firm, we learned more about keeping your fleet safe.

Steve Sandford, partner at CyXcel, a Weightmans LLP business, said: “Cybersecurity begins with the basics. Enforce strong password policies and multi-factor authentication across all fleet systems. These simple steps dramatically reduce the risk of unauthorised access.

Cybersecurity begins with the basics, such as strong password policies and multi-factor authentication

Outdated software is a hacker’s best friend. Regularly update fleet management platforms, telematics systems, and websites. Apply security patches promptly to close vulnerabilities before attackers exploit them.”

Sandford added that it’s essential to limit system access to only those who require it. Permissions should also be regularly reviewed, and dormant accounts should be removed, as every unnecessary access point is an opportunity for attackers.

“Sensitive fleet data should never travel unprotected. Encrypt data both in transit and at rest and ensure secure communication channels for telematics and operational systems.

Technology alone won’t stop cyberattacks; people play a critical role. Provide regular training to help staff spot phishing attempts and understand safe online practices. Human error remains the leading cause of breaches.”

Monitoring tools should be implemented to detect suspicious activity early. Finally, combine this with a clear incident response plan, so your team knows exactly what to do if something goes wrong.

Steve Sandford, partner at CyXcel

“Fleet systems often integrate with external vendors. Ensure partners meet robust cybersecurity standards, as a weak link in the supply chain can compromise your entire operation, the effects of which could cause significant financial and reputational repercussions.”

Sounds scary? Well, it should. The bigger issue lies not only in a company’s fallout but also in the livelihoods of you and other employees.

To summarise, it’s essential to have a good cybersecurity policy in place. If you’re unsure of where to start, reach out to companies like Weightmans and Lithium Systems. However, key cybersecurity policy areas include access control, data handling, incident response, and employee training.

The above, of course, must be backed by strong leadership that can provide regular updates to address evolving threats.

Similarly, end-point security systems are essential, as they can detect and kill viruses, roll out regular software updates, and encrypt company devices. Many endpoint systems also include email security add-ons that can educate system users. For example, an endpoint system can deploy simulated phishing tests. If the employee clicks a link in the email, it will alert the endpoint administrator, who can then contact the employee’s manager to request that the employee undergo further training.

Before you log off tonight after a busy day, think. Is your fleet safe?

Leave a Reply

Your email address will not be published. Required fields are marked *