Fleet Cybersecurity 101: What You Need from Your Technology Vendors
From identity management to third-party certifications, the right technology partner should make security easier to manage. Here are the three building blocks that fleet managers need to stay in control as connected systems scale.

“A compliance failure, an unplanned outage, or a data breach isn't just a security problem. It's an operational disruption that costs time and money.” -Sean Herron
Automotive Fleet
- Effective identity management is essential for simplifying cybersecurity management for fleet managers.
- Technology vendors must possess third-party certifications to ensure security and reliability.
- Fleet managers require strategic building blocks to maintain control as connected systems expand.
*Summarized by AI
The modern car is no longer a standalone asset, but a rolling digital network. By 2030, 95% of all vehicles sold will be connected, underscoring the need for active cybersecurity planning.
We spoke with Sean Herron, chief information security officer at Samsara, to learn how fleet managers can prepare for a cyber threat before one hits.
Begin With Identity Management
As fleet technology continues to advance, it also introduces new blind spots that fleet managers have never dealt with before. A common weak point is identity management.
“Shared credentials, password-based logins on shared devices, API tokens that were never revoked after a vendor relationship ended — these are the kinds of things that create real exposure. And a lack of audit logging creates hidden exposures that overstretched IT teams often miss until a breach occurs,” explained Herron.
Fleet managers need to actively manage users on all connected vehicle systems to reduce risk and any potential access points. Organizations often scale their systems without scaling their governance, and that increases their vulnerability to a cybersecurity breach.
For cost-constrained fleets, Herron recommends prioritizing dual-value investments, such as automated user lifecycle management via SCIM provisioning and comprehensive audit logging.
Dual value investments are strategic investments meant to support AI- adoption and broader data-driven decision-making. Examples include process and product integration, and data infrastructure and governance.
“Don't build for security in a vacuum. Start with the controls that drive efficiency, then expand,” he added.
As with much of the world of fleet, the key, as Herron puts it, is in the partnership between the vendor and your fleet IT team. The vendors provide the digital infrastructure, and the IT team actively configures and monitors those controls.
Herron notes that when IT teams treat vendor platforms as a “set and forget” solution, it increases risk. The infrastructure only works if the IT team actively utilizes it.
How Do I Identify a Breach?
To identify a disruption in a system, you will first need real-time system health monitoring.
This visibility allows you to respond to threats as they arise, rather than after the fact.
“The real value lies in pairing health data with activity log analysis,” he added. If a disruption is accompanied by unusual configuration changes, unexpected permission modifications, or access patterns that don't fit normal behavior, those are signals that point toward a security issue rather than a simple technical failure.”
He also notes that a legitimate platform-wide outage looks different from a localized anomaly, so being familiar with how your system looks under normal conditions is central to identifying unusual occurrences.
Three Non-Negotiables
Herron has three non-negotiables for safeguarding connected fleets:
- Access Governance. SSO with SAML or OAuth, role-based permissions, and automated user lifecycle management to ensure users are provisioned and deprovisioned correctly. Without this, every new integration or new user is an unmanaged risk.
- Data Security. Encryption is only the starting point. You must govern data egress: knowing exactly what leaves the platform, where it goes, and who has access to it. Clear data retention policies and export governance controls are vital for maintaining ownership of your data.
- Auditability. You need to be able to answer "who did what, when, and what changed” not just for compliance, but for your own operational awareness. If you can't trace configuration changes with before-and-after detail, you're flying blind during an incident.
Heron recommends asking vendors for proof of security. You want to see independent third-party validation. SOC 2 Type II and ISO 27001 are the baseline standards for data security in telematics and connected systems.
As AI becomes a global standard, you want to ensure the vendor also uses the ISO 42001 framework for AI governance.
ISO 42001 is the world’s first AI management system standard, providing valuable guidance for this rapidly changing field of technology. It addresses the unique challenges AI poses, such as ethical considerations, transparency, and continuous learning.
Aside from that, Herron recommends that fleet managers scrutinize their access management systems, keeping the non-negotiables in mind.
"A platform that makes governance hard will become a liability regardless of how good its uptime is," he added.
Quick Answers
Identity management is crucial for fleet cybersecurity because it helps ensure that only authorized users have access to critical systems, reducing the risk of data breaches and unauthorized actions.
*Summarized by AI
More Safety

Turning Connected Vehicle Data Into Decisions That Matter
Fleet leaders have more data than ever, but turning that data into clear, actionable decisions remains a challenge. This white paper shows how leading organizations are using connected vehicle data to improve safety, reduce costs, and optimize fleet performance. Learn how to turn insight into action across your fleet.
Read More →
Cameras, Safety and Insurance: From Reactive Claims to Real-time Prevention
Commercial auto remains one of the most challenging and costly lines of coverage for fleet operators and insurers alike. Learn more about how to effectively address these issues from Onur Aksan, Enterprise Business Development Executive, Geotab.
Read More →
NAFA Fleet Safety Symposium to Collocate With 2026 Fleet Forward Conference
The daylong certificate program will precede the Fleet Forward Conference at the Gaylord National Harbor in Maryland.
Read More →
The Distractions You Can’t Turn Off: What Drivers Face Outside the Vehicle
Fleet drivers face constant visual, cognitive, and environmental interruptions the moment they hit the road. From roadside chaos to mental fatigue and digital overload, today’s biggest driving risks often come from outside the vehicle itself.
Read More →
FLASH Weather AI Launches First Deep-Learning Hail Prediction Model With High-Resolution Forecasting
FLASH Weather AI has launched a first-of-its-kind hail prediction model capable of forecasting hail size and arrival time at 1-kilometer resolution up to 55 minutes ahead, giving fleets and insurers critical time to prepare for severe storms.
Read More →
How Coca-Cola United Protects Its Fleet from Growing Legal Risk
As litigation risk rises, vehicles are increasingly targeted. This Coca-Cola bottler shares how it’s reducing exposure through driver training, technology, and a proactive risk management approach.
Read More →
How to Speak the Same Language on Fleet Safety
Drivers, supervisors, and data often speak different safety “languages.” Getting on the same page will drive better results.
Read More →
Reducing Risk by Eliminating Phone Use Behind the Wheel
Distracted driving remains one of the most persistent risks in fleet operations. New approaches focus on removing mobile device use entirely while adding real-time safety support.
Read More →
Distracted Driving in the Age of Smart Tech – Part 2
As distraction risks evolve, fleets are turning to smarter, more connected technologies to better understand what’s happening behind the wheel. Part 2 explores how these tools are helping identify risky behaviors and improve visibility across operations.
Read More →
Data Rights, Risks, and Responsibilities After a Crash
What fleets capture to improve safety can also expose them in litigation, forcing leaders to rethink how data is managed, stored, and shared.
Read More →
