Moving at Risk: Securing the Software Behind Every Flight, Vessel, and Fleet

Your next transportation outage won’t originate in a hangar, airport, or a rail yard. It will come from a vendor’s build system.

Transportation is now a software business, and ransomware operators know it. A single
flawed update in 2024 disrupted over 5,000 flights globally and cost airlines hundreds of
millions of dollars in a matter of days. Ransomware on a single vendor’s dealer
management system took 15,000 auto dealerships offline for two weeks and cost the
industry more than a billion dollars. One breach at DP World paralyzed 40% of Australia’s
freight trade. Rail cyberattacks are up 220% over the past five years. It’s happening in every
mode, every geography, and every quarter.

For CISOs, this is a board-level exposure. For DevOps directors, it is operational. Every
mission-critical system now runs through the same CI/CD pipelines as any modern
application, and inherits every one of their vulnerabilities. For AppSec teams, it is an
unmanageable triage load: millions of CVEs across fleets that cannot be updated on a sprint
cadence.

This ebook covers what leading transportation operators are doing about it: closing the
third-party visibility gap, cutting through CVE noise at fleet scale, blocking malicious
packages at ingestion, verifying integrity from build to edge, and extending governance to
the AI models now running in cockpits, on bridges, and in dispatch centers.

Explore the JFrog Software Supply Chain Platform