Cyber insurance for trucking companies
Cyber liability covers what happens when the technology your operation runs on is compromised — breach response, system restoration, business interruption, and in many policies funds-transfer fraud, which is the exposure freight actually gets hit by.
Your general liability policy almost certainly does not cover it. Most GL forms exclude electronic data explicitly.
I don’t believe in telling business owners, “You need this policy,” without explaining WHY. I want you to understand the risk first. Then, we can talk about the solution.
So before anything about a policy: here is what a trucking operation actually exposes.
Count how much of your business is a computer
Nobody thinks of a trucking company as a technology business. Then you list what a modern carrier touches every day:
- ELDHours, location and driver identity
- TMS and dispatch platformCustomer, lane and rate data
- Business emailThe single most attacked surface you own
- BankingDirect access to money
- Factoring portalInvoices and remittance details
- Load boardsIdentity, and a route into broker relationships
- Driver filesLicenses, medical cards, SSNs — regulated personal data
- Accounting softwarePayroll and tax records
- Cloud storageRate cons, BOLs, contracts, insurance documents
Your company doesn’t have to be a technology company to have a technology problem.
The three losses that actually happen to carriers
Not theoretical ones. These are the shapes a cyber loss takes in freight specifically:
- Funds-transfer fraud. An email that appears to come from a broker, factoring company or vendor, advising new remittance details. The payment goes out correctly, to the wrong account. Because you authorized it, recovery is difficult and coverage varies enormously between policies.
- Business interruption. Your TMS, ELD portal or email is locked or down. Trucks keep rolling but nothing can be dispatched, invoiced or proven, and the loss is the revenue you could not earn plus the cost of getting back up.
- Data breach involving driver files. You hold licenses, medical certificates and Social Security numbers. If that is exposed, notification obligations and the cost of handling it are real, and they scale with how many people are affected rather than with how big your company is.
Do you even need this?
Honest answer: a one-truck owner-operator who invoices through a factoring company, uses one email address with multi-factor authentication on, and holds nobody else's data has a modest exposure. Buying a large cyber policy there is probably not the best use of the money.
The exposure becomes real when any of these are true:
- You employ drivers and therefore hold their personal files
- You move money electronically in volume, or use a factoring portal daily
- Your dispatch or TMS system going down would stop you invoicing
- You hold customer data under a contract that requires you to protect it
- A broker or shipper contract requires cyber cover — increasingly common
What to ask before you buy
- Is social engineering and funds-transfer fraud included, and what is the sub-limit? This is usually a separate, smaller limit than the headline number.
- Is ransomware covered, including the extortion payment and the restoration cost?
- How is business interruption measured — from what moment, and with what waiting period?
- Is there a breach-response team included? For a small carrier, having someone to call at 6am is worth more than a slightly higher limit.
- What controls does the policy require you to maintain? Many now require multi-factor authentication as a condition. Not having it can void a claim.
That last one matters more than the price. A cheaper policy with a control warranty you are not meeting is not cheaper — it is unpurchased.
Understand the risk, then decide
Tell me what systems you run and who you hold data for. If the honest answer is that your exposure is small, that is what you will hear.
Insurance is offered through Shay Denise, a licensed property and casualty producer. Coverage is subject to the terms, conditions and exclusions of the policy actually issued. Nothing on this page is a binder, a quote, or an offer of coverage.
No regulation reaches this yet
Nothing in the federal motor carrier rules requires cyber coverage, and nothing filed with FMCSA reflects it. That is precisely why it is worth understanding on its own terms rather than waiting for a rule. The requirements below are the ones that do exist for the same operation.
For-hire carriers hauling non-hazardous property in vehicles with a GVWR of 10,001 lb or more must carry at least $750,000 in public liability coverage.
Commonly got wrong: Part 387 was last amended 91 FR 45660, 21 Jul 2026 — the $750,000 figure survived that amendment.
There is no federal cargo-insurance minimum and no federal cargo filing requirement for general freight. The federal cargo rules reach household goods carriers only.
Commonly got wrong: THE most misreported figure in the industry. §387.301T(b) is headed "Household goods motor carriers-cargo insurance" and its prohibition reaches only household goods carriers. §387.303T(c) is headed "Household goods motor carriers: Cargo liability". There is no $100,000 anywhere in Part 387 — that number is a broker and shipper CONTRACT norm, not a regulation. Important caveat to publish alongside it: carrier liability for loss or damage to general freight is a separate body of law (the Carmack Amendment, 49 U.S.C. 14706) and is unaffected. No insurance mandate does not mean no liability.
Cyber insurance questions
Why would a cybercriminal target a small trucking company?
Because you move money and hold data, not because you are large. A four-truck carrier has banking credentials, a factoring portal, driver personal information, customer records and load board logins. Attackers automate; they look for weak access, not for big names.
What does cyber liability actually cover?
Broadly two halves. First-party covers your own losses: breach response, forensics, notifying affected people, restoring systems, business interruption, and in many policies funds-transfer fraud and ransomware. Third-party covers your liability to others whose data you held. Which half matters most depends on whose information you hold and how much of your operation stops when a system goes down.
Is funds-transfer fraud covered?
Sometimes, and it is the single most important question to ask. The common scenario in freight is an email that looks like it comes from a broker or a factoring company, with new remittance details. The money leaves legitimately, on your instruction, which is exactly why many policies treat it differently from a hack. Ask specifically whether social engineering and funds-transfer fraud are included and at what sub-limit.
Does my general liability policy cover a cyber loss?
Almost certainly not. General liability responds to bodily injury and property damage. Most modern GL forms carry explicit electronic-data exclusions. Assuming you are covered because you have "business insurance" is the most common gap we see.
What does cyber insurance cost for a small carrier?
It is one of the cheaper lines on a commercial policy for a business this size — typically far less than your auto liability. Pricing turns on your revenue, how much sensitive data you hold, and what controls you have in place. Multi-factor authentication on email and banking usually moves the premium more than anything else you can do.
What can I do that costs nothing?
Turn on multi-factor authentication for email, banking, factoring and your load boards. Verify any change of payment details by calling a number you already had, never one in the email. Keep an offline backup. Those three habits prevent most of what a small carrier is actually exposed to.