Thank you for Subscribing to Transportation Review Weekly Brief

Leveraging Data for Security Decision-Making


Pete Statia is a seasoned technology leader specializing in information security at Saia Inc., based in the Atlanta Metropolitan Area. As the Director of Information Security and Compliance, Pete champions innovative solutions that support business growth while ensuring robust security practices are upheld. With a strong commitment to aligning technology solutions with business goals, he possesses extensive experience in developing and implementing strategic initiatives that enhance operational efficiency and foster a customer-centric corporate culture.
Through this article, Statia highlights the importance of data analytics in information security decision-making and emphasizes that without data to measure and improve processes, security controls can stagnate or disappear entirely. Professional Journey in Information Security I began my career as a traditional IT engineer with a passion for network security. When HIPAA Security regulations were being drafted in the late 1990s, the large healthcare organization I worked for decided to form a dedicated Information Security team to comply with the upcoming rules. The existing IT director and I established this new department. Later, I moved to another healthcare organization to build an information security program from scratch. The cybersecurity capability maturity score was just above 1 when I started, and by the time I left, it was approaching an average of 4. After nearly six years there, I sought a change and joined the “Great Resignation” during the COVID pandemic. This led me to Saia LTL Freight, a national, publicly traded transportation and logistics company eager to rapidly mature its cybersecurity capabilities. Three years later, we are still making significant strides in our cyber journey. “Understanding the business needs and providing a balanced, non-hyperbolic security risk analysis to business leadership is key to achieving both cybersecurity maturity and operational efficiency.” Balancing security measures and operational efficiency Organizations face more than just cyber risks; they also encounter daily legal and financial risks. Businesses make decisions to accept, mitigate, or transfer these other risks regularly. I do not differentiate these from the risks I aim to minimize. Understanding the business needs and providing a balanced, non-hyperbolic security risk analysis to business leadership is key to achieving both cybersecurity maturity and operational efficiency. The real challenge arises when security leaders’ understanding of business priorities is not aligned with the business itself. Data Analytics in Information Security Decision-Making Establishing a successful information security program involves setting up processes and continuously improving them over time. Early in my career, I didn’t prioritize this, and I learned that without data analytics to measure them, initially established processes quickly fell apart. At best, unmeasured security controls stagnate and fail to improve; at worst, they disappear entirely, and this can happen rapidly. Making decisions without data analytics is like target practice with a blindfold. Staying Updated I belong to several peer groups that provide valuable support. Additionally, I have a few trusted vendor relationships that specialize in decision support services. Impact of Emerging Technologies on Information Security I have always been a strong advocate for behavior analysis to detect abnormalities. AI and ML are significantly reducing the time it takes to identify these out-of-normal behaviors, enabling faster response times. However, we are also witnessing attackers leveraging AI and ML to identify targets and launch attacks. It’s not far-fetched to imagine them widely adopting AI and ML to evade detection or even turn an organization’s AI and ML tools against them. Advice for Information Security Leaders The best advice I can offer is to establish rock-solid trust with management. Without it, no matter what the data says, you won’t succeed. If you break trust with your organization or its leaders, you lose the ability to influence anything.