Long Beach, California – Cooperation has become one of the trucking industry’s strongest arguments in the fight against cybercrime, and that message was repeated throughout the National Motor Freight Traffic Association’s cybersecurity conference in Long Beach.
The call for greater collaboration echoed discussions from last year’s conference, where industry participants highlighted the growing cybersecurity risks facing trucking and the need to share information about attacks.
That discussion has since turned into a concrete initiative: the NMFTA’s Threat Report Portal. The platform gives companies that have experienced a cybersecurity breach as well as those that detected an attempted attack and successfully stopped it a place to share what happened anonymously.
Ben Wilkens, NMFTA’s director of cybersecurity, led the launch of the portal in May. Following a soft launch, the platform is now fully operational and open to anyone who registers.
In an interview on the sidelines of the NMFTA conference, Wilkens said the organization would like to see more companies use the portal and, in particular, contribute information.
Nobody will know your name
Wilkens emphasized that anonymity is central to the portal.
Two cybersecurity terms help explain the type of information NMFTA is seeking: TTP, meaning Tactics, Techniques and Procedures, and IOC, or Indicator of Compromise. Microsoft defines an IOC as evidence that someone may have breached an organization’s network or endpoint.
According to Wilkens, information that could indicate the involvement of a threat actor might include “file hashes and things like that, specific IP addresses, things that can be used in a detection method.”
The concept behind the portal emerged from a simple observation: cybercriminals often repeat successful tactics against different companies.
“The thought was, what if there was somewhere where we could share this, and it would go out to everyone in the industry,” Wilkens said.
Threat actors, he explained, may try a particular technique against one carrier. If it fails, they can simply move on to another carrier and use the same playbook again.
For Wilkens, sharing that playbook across the industry is an important part of the defense.
Anonymity was built into the portal from the beginning because NMFTA understood that companies might otherwise hesitate to report incidents.
“One of the concerns we had is that we didn’t want people to feel like they’re kind of exposing themselves to, hey, this happened to our organization,” Wilkens said.
The decision to keep the information anonymous was therefore made early in the development process.
Every report goes through a vetting process
Cybersecurity incidents submitted through the portal are not automatically published. NMFTA reviews each report before making it available to the wider community, Wilkens said.
“We will anonymize them,” he said. “We strip out all the identifying information. And then as soon as we’ve vetted the incident, we share it out with the entire community.”
Wilkens compared the concept to crowdsourcing, with the industry collectively contributing information that can help others identify and defend against threats.
But the process is controlled. Reports are “never automatically shared out,” Wilkens said. A member of the NMFTA team reviews every submission and verifies whether the reported incident is legitimate.
That review can sometimes be completed in about an hour, although more complex cases can take longer.
“We make sure that this informs the community in some meaningful way, and then once we go through those processes, then we can publish,” Wilkens said.
The process can move faster when the submitting company is already known to NMFTA and has an established relationship with the organization.
“We already trust the source,” Wilkens said.
The portal itself grew out of discussions at the 2025 cybersecurity conference. NMFTA staff worked on its development during the early months of the year. In the second quarter, the association conducted what Wilkens described as a “small beta test” involving a core group of carriers that had participated in the original discussions.
That test identified several “tweaks” that needed to be made before the platform was opened more broadly.
The full portal was released to the public in May.
Early numbers show strong interest
By early June, approximately 100 people had registered for the portal.
“We were already good,” Wilkens said, describing the initial response as encouraging.
The registrations span a broad section of the freight industry. According to Wilkens, they include some of the largest shippers and 3PLs, both in the United States and internationally, as well as smaller carriers.
“We have a really interesting range,” he said. “We have some of the biggest shippers and 3PLs, both domestically and internationally. So we’re getting a lot of traction.”
The challenge, however, is not necessarily attracting people who want to receive information. It is getting companies to contribute their own experiences.
“Polling people, they want to get the information, but the problem is getting people to share their information back in to the portal,” Wilkens said.
He characterized the current flow of submissions as “regular,” while making clear that NMFTA would like to see the number increase.
The reason is straightforward: companies traditionally concentrate on protecting their own networks and building defenses around their organizations. But Wilkens argues that cybersecurity cannot stop at the edge of an individual company.
“We all focus on building the walls around our organization to protect ourselves and really understanding the security aspect,” he said.
The industry also needs to pay attention to what is happening beyond those walls.
“What we need to also think about is what’s happening outside that wall? What’s happening in our neighbor’s environment that’s either successful or that they’ve defended against?”
For Wilkens, near misses are just as valuable as successful attacks when it comes to protecting the wider freight community.
“And sharing these near misses is equally as important as sharing the incidents that are successful,” he said, because the next carrier or broker may not have the same defenses in place.
A technique that fails against one company, in other words, could succeed against another.
That is precisely the gap the NMFTA Threat Report Portal is designed to address: turning individual cybersecurity experiences including attacks that were stopped before causing damage into information that can help protect the broader transportation community.


















