DrochaidHorizon3.ai
NodeZero/Industries/Transport & Logistics
The state of play — Transport & Logistics, 2026

Cyber incidents in Logistics jumped 61% in 2025.

A 61% year-on-year rise in logistics cyber incidents. Ports, rail, and 3PL operators now operating under SOCI CIRMP, ATSA, MTOFSA, IMO MSC.428(98), and the Cyber Security Act — simultaneously. The regulatory stack is dense and the threat trajectory is compounding.

61%
year-on-year increase in logistics-linked cyber incidents in 2025 — 132 cases rising to 213, with attack volumes forecast to double in 2026.
Supply Chain 24/7 — Cyberattacks on Logistics Are Set to Double in 2026
11%
of global targeted attacks during July 2023–June 2024 aimed at the transport sector, making it one of the top three target sectors — second only to public administration in Europe.
ENISA Threat Landscape 2024
70%
of the incidents IBM X-Force responded to in 2024 involved critical infrastructure organisations.
IBM X-Force 2025 Threat Intelligence Index
The trend

Why Transport & Logistics is in the crosshairs

Five shifts shaping the Transport & Logistics threat environment — what attackers are now doing, and how regulators are tightening the expectation from documented programmes to continuously evidenced ones.

Attackers have shifted from individual companies to shared transportation networks

Supply Chain 24/7's framing captures the strategic shift — hackers are going after shared transportation networks where a single breach can ripple across thousands of businesses. DP World Australia (November 2023) delayed 30,000+ containers across four ports via a single Citrix vulnerability. Port of Nagoya's 2023 LockBit 3.0 attack disrupted about 10% of Japan's trade for two days. The cascade is the attack.

The regulatory stack is now SOCI plus ATSA plus MTOFSA plus IMO — at once

Australian transport entities face overlapping obligations from the SOCI Act and CIRMP Rules, the Transport Security Amendment Act 2025 (which adds all-hazards including cyber to ATSA and MTOFSA), the Cyber Security Act 2024, the Privacy Act, and — for Australian-flagged and Australian-calling ships — IMO Resolution MSC.428(98) and the ISM Code. Most competitors focus on one framework at a time. The operational reality is all of them simultaneously.

Nation-state activity now includes physical surveillance via compromised IoT

The May 2025 CISA joint advisory described Russian state-sponsored activity against Western logistics and technology companies shipping aid to Ukraine — including the compromise of more than 10,000 internet-connected cameras near ports, rail hubs, and border crossings. Transport sector cyber compromise has moved beyond data theft and disruption to physical-domain surveillance. The dual IT/physical dimension is distinctive to this sector.

Legacy IT and OT converge uniquely here

Ships built twenty to thirty years ago still on international routes. Port cargo-handling systems predating OT security as a concept. Rail signalling originally designed for air-gapped safety, now IP-connected. Road fleet management systems retrofitted into trucks from the 2000s. KNP Logistics' collapse via a single weak password illustrates how non-rocket-science the entry points remain.

CIRMP is moving from documented programme to evidence-based programme

Business-critical data and secondary data storage systems came into CIRMP scope on 4 April 2025. The Enhanced CIRMP Rules (registered June 2026) deliver further enhancements for designated asset classes — including critical freight infrastructure and freight services — with foreign ownership, control and influence (FOCI) obligations and a cyber framework uplift to ML2-equivalent phasing in over 24 months. Board-approved annual CIRMP reports are increasingly expected to reference evidence of control effectiveness, not just compliance attestation.

On the record

What regulators and experts are saying

Western logistics and technology companies involved in shipping military and humanitarian aid to Ukraine were targeted by Russian state-sponsored threat actors… CISA (alongside other agencies) issued a joint cybersecurity advisory, urging logistics organizations to assume they are targeted, increase monitoring and threat hunting, and strengthen network defenses.
CISA and partners
Joint cybersecurity advisory
May 2025
In 2025 alone, cyber incidents tied to logistics jumped 61%, climbing from 132 cases to 213. Hackers are moving away from hitting individual companies and instead going after shared transportation networks, where a single breach can ripple across thousands of businesses.
Supply Chain 24/7
Cyberattacks on Logistics Are Set to Double in 2026
January 2026·Supply Chain 24/7
In minutes, 56,000 devices were encrypted, operations halted, and global trade felt the shockwave — $10 billion in losses, including $350 million for Maersk alone.
Global Logistics analysis
On the 2017 NotPetya attack on Maersk
2025
What is now required

TSA Act 2025 and expanded CIRMP scope are now live

The Transport Security Amendment Act 2025 (Royal Assent 27 March 2025) brings aviation and maritime transport security into an "all-hazards" framework including cyber. Business-critical data and secondary data storage systems came into SOCI CIRMP scope from 4 April 2025. The Enhanced CIRMP Rules — including an ML2-equivalent cyber uplift for designated asset classes — have been in force since June 2026.

The SOCI Act designates transport as one of 11 critical infrastructure sectors. Within transport, the CIRMP obligations directly capture critical freight infrastructure and critical freight services assets — while critical aviation and critical port assets sit under the separate all-hazards regimes of the Aviation Transport Security Act 2004 and the Maritime Transport and Offshore Facilities Security Act 2003, not Part 2A of the SOCI Act. For entities in CIRMP scope, Section 8 of the CIRMP Rules requires compliance with one of five specified cyber security frameworks — the Essential Eight, AESCSF, NIST CSF, ISO/IEC 27001, or the US DOE C2M2. The Transport Security Amendment (Security of Australia's Transport Sector) Act 2025 (Royal Assent 27 March 2025) amends ATSA and MTOFSA to add an "all-hazards" framework explicitly including cyber — the mechanism by which cyber obligations are being layered onto aviation and maritime security. For Australian-flagged and Australian-calling ships, IMO Resolution MSC.428(98) and the ISM Code require cyber risk management to be integrated into the Safety Management System. The Cyber Security Act 2024 applies in parallel. Port operators are explicitly advised to align ISPS Code physical-security plans with CIRMP to avoid duplication. The Enhanced CIRMP Rules 2026 lift the cyber framework baseline to ML2-equivalent for designated asset classes, phasing in over 24 months to June 2028.

Source: Cyber and Infrastructure Security Centre
Legislation
SOCI Act — Critical Infrastructure Risk Management Program

Applies to SOCI CIRMP-regulated transport entities — critical freight infrastructure and critical freight services assets. (Critical aviation and port assets are covered by the separate Aviation and Maritime Transport Security Acts.) Section 8 of the CIRMP Rules requires compliance with a specified framework plus demonstrable risk minimisation and mitigation.

Your chosen CIRMP cyber frameworkSelect one
Also in effect

A cascade of new obligations

Multiple new regulatory requirements are hitting simultaneously — each increasing the compliance burden and the consequences of failure.

SOCI CIRMP Rules — 2025 Measures No. 1 Rules

4 Apr 2025

From 4 April 2025, business-critical data and secondary data storage systems came into CIRMP scope. Responsible entities must establish and maintain processes that minimise or eliminate the material risk of a cyber hazard occurring, and mitigate its relevant impact. Failing to adopt or maintain a CIRMP carries civil penalties of up to 1,000 penalty units for a body corporate, per contravention.

Source: Cyber and Infrastructure Security Centre

Transport Security Amendment (Security of Australia's Transport Sector) Act 2025

27 Mar 2025

Royal Assent 27 March 2025. Amends ATSA and MTOFSA to introduce an "all-hazards" security framework explicitly including cyber threats, supply chain dependencies, insider threats, and third-party vulnerabilities. Aviation and maritime entities previously regulated only under ATSA/MTOFSA now face SOCI-adjacent risk management expectations.

Source: Aviation and Maritime Transport Security Reforms Impact Analysis

TSA Act 2025 — all-hazards cyber for aviation

27 Mar 2025

Critical aviation assets remain regulated under ATSA rather than the SOCI CIRMP. The Transport Security Amendment (Security of Australia's Transport Sector) Act 2025 layers an all-hazards framework — explicitly including cyber — into that regime, with subordinate regulations to follow.

Source: Cyber and Infrastructure Security Centre

Cyber Security Act 2024 — mandatory ransomware reporting

30 May 2025

Mandatory 72-hour reporting of ransomware payments to ASD for entities over $3M turnover — captures essentially every tier of the sector above sole-operator level. Stacks with SOCI: a ransomware event at a SOCI-regulated port or freight operator triggers both the SOCI 12/72-hour notification and the Cyber Security Act 72-hour payment report.

Source: Cyber Security Act 2024

Enhanced CIRMP Rules 2026 (FOCI + ML2 uplift)

In force June 2026

The Enhanced CIRMP Rules 2026 (registered 9 June 2026) deliver the consulted enhancements — foreign ownership, control and influence obligations and a cyber framework uplift to ML2-equivalent for designated asset classes including critical freight, phasing in over 24 months to June 2028.

Source: Federal Register of Legislation — LIN 26/075
Beyond the platform

NodeZero produces the continuous evidence. Drochaid helps you bridge to the full CIRMP and TSA Act programme.

CIRMP obligations extend well beyond cyber testing — they cover governance, supply chain, personnel, physical, and business continuity. NodeZero directly validates the cyber hazard obligations under Section 8. Drochaid helps you bridge from NodeZero's testing evidence to the full annual CIRMP report, Board approval package, and TSA Act 2025 subordinate regulation preparedness.

CIRMP Section 8 evidence
Findings mapped to your chosen cyber framework (Essential Eight, NIST CSF, ISO 27001, AESCSF, or equivalent) — structured for the Board approval and CISC submission process.
TSA Act 2025 readiness
Cyber component of the all-hazards framework for aviation and maritime — validated ahead of the subordinate regulations taking effect.
Third-party and supply chain testing
Port agents, customs brokers, freight platforms, and EDI partners validated at scale — evidence of cyber hazard mitigation across the supply chain obligations CIRMP increasingly expects.
Platform credentials

The only autonomous pentesting platform that is:

SOCI / CIRMP
Control-by-control
Board attestation
Essential Eight
Mapped ML1–3
ASD baseline
Gartner Peer Insights
4.7 / 5
Customers' Choice (Oct 2025)
310,332
Pentests run
7,013 orgs
Trusted by 7,013 organisations worldwide
Powers the NSA's CAPT program310,332 pentests4.7 Gartner

See your CIRMP and TSA Act 2025 cyber posture before your CISC assessor does

Book a baseline mapped to your chosen CIRMP framework and the all-hazards cyber component