Cyber incidents in Logistics jumped 61% in 2025.
A 61% year-on-year rise in logistics cyber incidents. Ports, rail, and 3PL operators now operating under SOCI CIRMP, ATSA, MTOFSA, IMO MSC.428(98), and the Cyber Security Act — simultaneously. The regulatory stack is dense and the threat trajectory is compounding.
Why Transport & Logistics is in the crosshairs
Five shifts shaping the Transport & Logistics threat environment — what attackers are now doing, and how regulators are tightening the expectation from documented programmes to continuously evidenced ones.
Attackers have shifted from individual companies to shared transportation networks
Supply Chain 24/7's framing captures the strategic shift — hackers are going after shared transportation networks where a single breach can ripple across thousands of businesses. DP World Australia (November 2023) delayed 30,000+ containers across four ports via a single Citrix vulnerability. Port of Nagoya's 2023 LockBit 3.0 attack disrupted about 10% of Japan's trade for two days. The cascade is the attack.
The regulatory stack is now SOCI plus ATSA plus MTOFSA plus IMO — at once
Australian transport entities face overlapping obligations from the SOCI Act and CIRMP Rules, the Transport Security Amendment Act 2025 (which adds all-hazards including cyber to ATSA and MTOFSA), the Cyber Security Act 2024, the Privacy Act, and — for Australian-flagged and Australian-calling ships — IMO Resolution MSC.428(98) and the ISM Code. Most competitors focus on one framework at a time. The operational reality is all of them simultaneously.
Nation-state activity now includes physical surveillance via compromised IoT
The May 2025 CISA joint advisory described Russian state-sponsored activity against Western logistics and technology companies shipping aid to Ukraine — including the compromise of more than 10,000 internet-connected cameras near ports, rail hubs, and border crossings. Transport sector cyber compromise has moved beyond data theft and disruption to physical-domain surveillance. The dual IT/physical dimension is distinctive to this sector.
Legacy IT and OT converge uniquely here
Ships built twenty to thirty years ago still on international routes. Port cargo-handling systems predating OT security as a concept. Rail signalling originally designed for air-gapped safety, now IP-connected. Road fleet management systems retrofitted into trucks from the 2000s. KNP Logistics' collapse via a single weak password illustrates how non-rocket-science the entry points remain.
CIRMP is moving from documented programme to evidence-based programme
Business-critical data and secondary data storage systems came into CIRMP scope on 4 April 2025. The Enhanced CIRMP Rules (registered June 2026) deliver further enhancements for designated asset classes — including critical freight infrastructure and freight services — with foreign ownership, control and influence (FOCI) obligations and a cyber framework uplift to ML2-equivalent phasing in over 24 months. Board-approved annual CIRMP reports are increasingly expected to reference evidence of control effectiveness, not just compliance attestation.
What regulators and experts are saying
Western logistics and technology companies involved in shipping military and humanitarian aid to Ukraine were targeted by Russian state-sponsored threat actors… CISA (alongside other agencies) issued a joint cybersecurity advisory, urging logistics organizations to assume they are targeted, increase monitoring and threat hunting, and strengthen network defenses.
In 2025 alone, cyber incidents tied to logistics jumped 61%, climbing from 132 cases to 213. Hackers are moving away from hitting individual companies and instead going after shared transportation networks, where a single breach can ripple across thousands of businesses.
In minutes, 56,000 devices were encrypted, operations halted, and global trade felt the shockwave — $10 billion in losses, including $350 million for Maersk alone.
TSA Act 2025 and expanded CIRMP scope are now live
The Transport Security Amendment Act 2025 (Royal Assent 27 March 2025) brings aviation and maritime transport security into an "all-hazards" framework including cyber. Business-critical data and secondary data storage systems came into SOCI CIRMP scope from 4 April 2025. The Enhanced CIRMP Rules — including an ML2-equivalent cyber uplift for designated asset classes — have been in force since June 2026.
The SOCI Act designates transport as one of 11 critical infrastructure sectors. Within transport, the CIRMP obligations directly capture critical freight infrastructure and critical freight services assets — while critical aviation and critical port assets sit under the separate all-hazards regimes of the Aviation Transport Security Act 2004 and the Maritime Transport and Offshore Facilities Security Act 2003, not Part 2A of the SOCI Act. For entities in CIRMP scope, Section 8 of the CIRMP Rules requires compliance with one of five specified cyber security frameworks — the Essential Eight, AESCSF, NIST CSF, ISO/IEC 27001, or the US DOE C2M2. The Transport Security Amendment (Security of Australia's Transport Sector) Act 2025 (Royal Assent 27 March 2025) amends ATSA and MTOFSA to add an "all-hazards" framework explicitly including cyber — the mechanism by which cyber obligations are being layered onto aviation and maritime security. For Australian-flagged and Australian-calling ships, IMO Resolution MSC.428(98) and the ISM Code require cyber risk management to be integrated into the Safety Management System. The Cyber Security Act 2024 applies in parallel. Port operators are explicitly advised to align ISPS Code physical-security plans with CIRMP to avoid duplication. The Enhanced CIRMP Rules 2026 lift the cyber framework baseline to ML2-equivalent for designated asset classes, phasing in over 24 months to June 2028.
Source: Cyber and Infrastructure Security CentreApplies to SOCI CIRMP-regulated transport entities — critical freight infrastructure and critical freight services assets. (Critical aviation and port assets are covered by the separate Aviation and Maritime Transport Security Acts.) Section 8 of the CIRMP Rules requires compliance with a specified framework plus demonstrable risk minimisation and mitigation.
Often the chosen CIRMP framework for SOCI transport entities with Australian IT estates. SOCI requires ML1 minimum, rising to ML2 for designated asset classes under the Enhanced CIRMP Rules 2026 (phasing in to June 2028). NodeZero validates the Essential Eight strategies directly.
Where NodeZero appliesFrequently chosen by Australian transport operators with multinational parents or international operations. CSF function areas (Identify, Protect, Detect, Respond, Recover) map directly to NodeZero findings.
Where NodeZero appliesCommon choice for large port, logistics, and aviation operators with existing ISO 27001 certification. NodeZero findings feed Annex A control evidence and internal audit input.
Where NodeZero appliesAustralian Energy Sector Cyber Security Framework. Used by transport entities adjacent to or dependent on energy infrastructure (notably some bulk ports and rail networks carrying energy products).
Where NodeZero appliesWidely held by large port, airport, shipping, and logistics-tech operators as a structured CIRMP-supporting framework.
Where NodeZero appliesCommonly chosen as the CIRMP Section 8 framework for Australian transport entities; ML2-equivalent uplift for designated asset classes phasing in to June 2028.
Where NodeZero appliesMandatory ransomware payment reporting within 72 hours for transport and logistics entities over $3M turnover — captures ports, freight, 3PLs, postal, and logistics tech.
Where NodeZero appliesTransport entities hold passenger data, parcel recipient data, fleet telematics driver data, and customer PII subject to APP 11 and the NDB scheme.
Where NodeZero appliesExpected of logistics technology vendors (TMS, WMS, port community systems, freight platforms) delivering into enterprise and SOCI-regulated customers.
Where NodeZero appliesA cascade of new obligations
Multiple new regulatory requirements are hitting simultaneously — each increasing the compliance burden and the consequences of failure.
SOCI CIRMP Rules — 2025 Measures No. 1 Rules
4 Apr 2025From 4 April 2025, business-critical data and secondary data storage systems came into CIRMP scope. Responsible entities must establish and maintain processes that minimise or eliminate the material risk of a cyber hazard occurring, and mitigate its relevant impact. Failing to adopt or maintain a CIRMP carries civil penalties of up to 1,000 penalty units for a body corporate, per contravention.
Source: Cyber and Infrastructure Security CentreTransport Security Amendment (Security of Australia's Transport Sector) Act 2025
27 Mar 2025Royal Assent 27 March 2025. Amends ATSA and MTOFSA to introduce an "all-hazards" security framework explicitly including cyber threats, supply chain dependencies, insider threats, and third-party vulnerabilities. Aviation and maritime entities previously regulated only under ATSA/MTOFSA now face SOCI-adjacent risk management expectations.
Source: Aviation and Maritime Transport Security Reforms Impact AnalysisTSA Act 2025 — all-hazards cyber for aviation
27 Mar 2025Critical aviation assets remain regulated under ATSA rather than the SOCI CIRMP. The Transport Security Amendment (Security of Australia's Transport Sector) Act 2025 layers an all-hazards framework — explicitly including cyber — into that regime, with subordinate regulations to follow.
Source: Cyber and Infrastructure Security CentreCyber Security Act 2024 — mandatory ransomware reporting
30 May 2025Mandatory 72-hour reporting of ransomware payments to ASD for entities over $3M turnover — captures essentially every tier of the sector above sole-operator level. Stacks with SOCI: a ransomware event at a SOCI-regulated port or freight operator triggers both the SOCI 12/72-hour notification and the Cyber Security Act 72-hour payment report.
Source: Cyber Security Act 2024Enhanced CIRMP Rules 2026 (FOCI + ML2 uplift)
In force June 2026The Enhanced CIRMP Rules 2026 (registered 9 June 2026) deliver the consulted enhancements — foreign ownership, control and influence obligations and a cyber framework uplift to ML2-equivalent for designated asset classes including critical freight, phasing in over 24 months to June 2028.
Source: Federal Register of Legislation — LIN 26/075NodeZero produces the continuous evidence. Drochaid helps you bridge to the full CIRMP and TSA Act programme.
CIRMP obligations extend well beyond cyber testing — they cover governance, supply chain, personnel, physical, and business continuity. NodeZero directly validates the cyber hazard obligations under Section 8. Drochaid helps you bridge from NodeZero's testing evidence to the full annual CIRMP report, Board approval package, and TSA Act 2025 subordinate regulation preparedness.
Find your organisation
See how the changes affect you specifically
Ports & maritime
The 20 SOCI-critical Australian ports, shipping lines, port service providers, and offshore facilities. Regulated under the SOCI Act (asset registration and incident reporting), MTOFSA (post-TSA Act 2025 all-hazards), and — for Australian-flagged and calling ships — IMO MSC.428(98).
View details →Aviation, rail & freight infrastructure
Critical aviation assets (under the Aviation Transport Security Act, with cyber being layered in via the 2025 Transport Security Amendment Act), rail freight operators, freight infrastructure, and logistics technology platforms.
View details →Road freight & 3PL
Linfox, Toll, Team Global Express, Mainfreight, DSV and the mid-tier 3PL ecosystem. Not all SOCI-regulated — but all in Cyber Security Act scope and in prime customers' third-party risk registers.
View details →The only autonomous pentesting platform that is:
References
Everything cited on this page — regulator reports, incident coverage, and official framework documentation.
See your CIRMP and TSA Act 2025 cyber posture before your CISC assessor does
Book a baseline mapped to your chosen CIRMP framework and the all-hazards cyber component


