You Didn’t Adopt AI. It Adopted You.

You may have approved Copilot for your office, but who approved the AI already running your fleet?

Somewhere in your vendor stack, an AI feature got switched on that most likely nobody even knows about, let alone approved or wrote a governance policy for. It’s probably doing something helpful — like suggesting routes, flagging loads, or reading driver messages and summarizing them for your safety team. The problem is, it just showed up one day inside a tool you trust, and now it’s making decisions inside your operation with no real guardrails or oversight in place.


You Can’t Secure What You Don’t Know

This is a form of shadow AI — and if you run a company right now, you almost certainly have some.

Software vendors are racing to add AI features to everything, and most of them ship those features turned on by default. Think about your ELD platform, your maintenance system, your customer portal, your load-matching tool. NMFTA’s new Cybersecurity AI Governance Framework says the challenge isn’t whether AI becomes part of your operations. It’s whether you have the visibility and the controls to use it responsibly.

“The tools are already there. The governance usually isn’t.”
— Ben Wilkens, NMFTA Director of Cybersecurity

That’s exactly why the framework’s first real step isn’t a security control at all. It’s an inventory. Because you can’t govern what you haven’t found.


Risk Lives in the Gap

I’m not saying all AI is dangerous and you should ban it. AI can save real money through things like faster routing, fewer empty miles, and predictive maintenance that catches a failure before it strands a driver on the road.

Here’s the problem I keep running into as we evaluate the security of these technologies. Most of us don’t know where AI is already running in the tools we use in our operations every day.

The gap — between what you believe and what you’ve verified — is exactly where risk lives.

An AI feature you didn’t choose is a feature you can’t secure. If it makes a bad call and a load gets misrouted, who’s accountable? If it touches driver data and something leaks, whose problem is that? The danger is that it just starts working with no oversight and no secure use policy.

This isn’t just a compliance gap. It’s a real revenue risk.


Where to Start

You don’t need to overhaul all your technology this week. You need a clear answer to one question: which tools, technologies, and vendors are using AI in your business right now?

Start by writing down every vendor partner your company uses: dispatch, ELD, maintenance, customer service, back office. For each one, ask: does this have AI features — and did we ever actually review and approve it?

Once you know what’s there, you get to decide what stays, what gets an AI policy wrapped around it, and what gets a harder look. This isn’t a fear tactic. It’s clarity… and clarity is where true protection starts.

This month I’m walking through exactly what this looks like — from the AI readiness policy most companies haven’t written, to the incident response plan most aren’t practicing. If you’ve never done a real inventory of the AI already running in your operation, that’s where we’re starting.

Let me be clear: AI is a remarkable thought partner. But a thought partner still needs someone doing the actual thinking… and that’s still us. I’m excited about where we’re going. I just want us to get there with our eyes open, not our guard down.

What AI feature are you going to go check on first?


Contact us at ITArchiTeks.com to start the conversation.

Because hope is not a strategy… and proof is how you protect profit.


Written by Melanie Padron

Vice President of Strategic Growth · IT ArchiTeks
Risk Strategist · National Cybersecurity Speaker

Melanie Padron brings nearly three decades of risk management experience, spanning insurance and cybersecurity, to help trucking and logistics leaders validate security posture, strengthen resilience, and protect revenue before pressure reveals what preparation concealed.

She’s a nationally recognized cybersecurity keynote speaker and the creator of two acclaimed talks:

  • Surviving a Cyber Crisis: Real Stories. Real Lessons. Real Money.
  • Proof to Profit: How Leaders Protect Revenue in the Age of Ransomware and AI

To bring either conversation to your conference, association, or leadership team — visit ITArchiTeks.com or connect with Melanie directly on LinkedIn.

You Don’t Have to Wait for a Breach to Know You’re at Risk

You think you’re protected. Most companies do, right up until the moment systems go down.

I grew up watching trucks. My family owned a chain of convenience stores, and from the time I was old enough to work behind the counter, I watched a steady stream of 18-wheelers pulling in and out. Filling our tanks. Stocking our shelves. Keeping our community running.

My aunt and uncle were owner-operators. They drove across the country delivering all kinds of freight. I grew up hearing their stories about the long hauls, the breakdowns, the freedom and the pride. Those years gave me something I’ve carried throughout life — a deep respect for what it means to build something, to run something, to protect something that people depend on.

After close to three decades in risk management — first in insurance and now in cybersecurity — I shifted focus to what I care about most. Stopping those disasters before they happen. This shift changed everything about how I think about risk.


The Question I Ask Every Leader I Meet

What would it cost your business if your systems went down for just one day?

Because the companies I’ve seen hit hardest weren’t unprepared in the way most people imagine. They had IT support. They had security software. Some even had insurance. What they didn’t have was proof any of those things worked before the pressure hit. And by the time they found out, it was too late.

I’ve watched attacks erase in a single moment what took decades to build. I think about those companies a lot. About the employees who lost jobs. The owners who lost legacies. The leaders who told me some version of the same thing: “We thought we were protected enough.”

The companies who recover fastest aren’t the ones who never get hit. They’re the ones who prove their preparations work before the attack happens.


What “Proactive” Actually Looks Like

Proactive isn’t a buzzword. It’s a decision made before the crisis, not during it. It looks like:

  • Knowing who owns cybersecurity at your company — not just who manages your technology
  • Having your backups tested under real conditions, not just assumed to exist
  • An incident response plan that lives in your team’s muscle memory, not in a folder on a server that can also be encrypted
  • An independent set of eyes reviewing your environment before criminals do

I built my Proof to Profit framework around these disciplines because I kept seeing the same thing: companies that do the work of validating their security before the pressure hits recover in hours. The ones that don’t recover in months… some don’t recover at all.

The difference isn’t budget or industry. It’s the decision to stop assuming and start proving.


Why I Do This Work

Cybersecurity isn’t something I talk about from a distance. I’ve watched what happens when a leader who’s poured everything into building a business finds out their protection wasn’t what they thought it was. I’ve watched people make impossible decisions under pressure that no one should have to face without a plan.

And I’ve also watched the other outcome. Companies that had done the work — completed their security upgrades, put the right tools in place, and practiced what to do before the pressure was real. When the attacks came, they were detected immediately. Systems isolated. Forensics engaged. Restoration in less than a day.

Zero encryption. Zero data loss. Zero ransom paid.

This outcome is available to every company willing to do the work before the crisis arrives. Because you don’t have to wait for a breach to know where you stand. You can find out right now, before anything goes wrong. And that conversation — that real look at where the gaps actually are — can change everything about what happens next.

You don’t have to wait for a breach to know you’re at risk. You just have to be willing to ask the question before you’re forced to.

The work I do is personal. The companies I fight for are personal. And the leaders I most want to reach are the ones who haven’t been hit yet — but are willing to find out the truth before they are. If that’s you, I’d love to start with a conversation.


Book a Free 20-Minute Strategy Session  |  Schedule an Independent Risk Audit  |  Book Melanie as a Speaker


Written by Melanie Padron

Vice President of Strategic Growth · IT ArchiTeks
Risk Strategist · National Cybersecurity Speaker

Melanie Padron brings nearly three decades of risk management experience, spanning insurance and cybersecurity, to help trucking and logistics leaders validate security posture, strengthen resilience, and protect revenue before pressure reveals what preparation concealed.

She’s a nationally recognized cybersecurity keynote speaker and the creator of two acclaimed talks:

  • Surviving a Cyber Crisis: Real Stories. Real Lessons. Real Money.
  • Proof to Profit: How Leaders Protect Revenue in the Age of Ransomware and AI

To bring either conversation to your conference, association, or leadership team — visit ITArchiTeks.com or connect with Melanie directly on LinkedIn.

The Two Things Every Business Needs. And Why One Without the Other Will Fail You.

Cyber insurance confuses most business owners. And honestly, that confusion is costing them everything.

Some have a Business Owner’s Policy with a cyber rider tucked inside and think they’re covered. Some have a standalone policy they bought two years ago and haven’t looked at since. And many have nothing at all, quietly hoping they’re too small to be a target.

Criminals don’t care about your size. They care about your vulnerability. Small and mid-sized businesses are among the most targeted organizations in the country. Not despite their size. Because of it.


Why a BOP Rider Is Not Enough

A cyber rider tacked on a Business Owners Policy is cheap. And it’s cheap for a reason: it strictly limits what the insurance company will actually pay.

Here’s what most business owners don’t realize until it’s too late. A single forensic IT investigation to find out how criminals got in can easily cost $25,000 to $50,000 on day one alone. If your rider’s entire limit is gone before the investigation is finished, there’s nothing left for customer notifications, credit monitoring, legal defense, or getting your systems back online.

And ransomware? Most general business policies either exclude it entirely or cap it at a minimal amount. A standalone cyber liability policy can start at $1 million to $5 million in aggregate coverage. It covers:

  • Ransom negotiations and payments
  • Data restoration
  • Business interruption
  • Social engineering losses like wire fraud
  • Immediate access to pre-vetted forensic and legal teams the moment something happens

With a rider, you’re on your own to find, hire, and manage those specialists yourself. During a crisis. With the clock running.

I spent two decades in the insurance industry, including holding my agent’s license. I’ve seen these gaps from both sides of the table. The leaders who understood their coverage before the incident recovered faster and paid less than the ones who found out what their policy actually covered while systems were down.

The time to read your cyber policy is not the morning your systems go down.


What Most Leaders Don’t Know About Qualifying for Coverage

You can’t buy a quality standalone cyber liability policy without demonstrating a baseline of cybersecurity first.

Insurers are underwriting your security posture. They want to know that MFA is deployed everywhere it needs to be: email, remote access, admin accounts, cloud environments. A partial deployment isn’t the same as a protected organization, and underwriters know the difference.

They also want to know whether your backups are tested, whether you have endpoint detection and response tools in place, whether your team has received security awareness training, and whether someone at the leadership level owns the risk. Every gap is a variable in how your policy is priced and what it will actually cover.

When you do the security work, you don’t just qualify for a policy. You qualify for the broadest coverage at the lowest rates. Security and insurance aren’t competing expenses. They’re compounding ones.


Security Is the Shield. Insurance Is the Safety Net.

No security stops every attack. Criminals are now using AI to generate phishing emails indistinguishable from the real thing. According to Chubb’s 2026 Cyber Claims Report, phishing was the number one entry point for ransomware in 2025. Not because teams aren’t careful. Because the attacks are built to defeat human judgment.

Layered security stops the vast majority of attacks. Insurance covers what slips through. It’s the financial backstop that lets a company survive what security couldn’t stop.

  • Security without insurance leaves you exposed to the attacks that get through.
  • Insurance without security leaves you unqualified for the coverage you need.

Security is the shield. Insurance is the safety net. Each one makes the other work better.


Three Questions Worth Answering Before You Move On

  1. Do you know the difference between what your current cyber coverage actually pays and what a real breach would cost?
  2. Does your security posture meet what your insurer expects — or do you have gaps that could affect your claim?
  3. Is someone at your leadership level responsible for making sure both pieces are in place and working together?

If any of those answers are unclear, that’s your starting point. Not a technology conversation. A business conversation.

Data referenced: Chubb 2026 Cyber Claims Report.


Book a Free 20-Minute Strategy Session  |  Schedule an Independent Risk Audit  |  Book Melanie as a Speaker


Written by Melanie Padron

Vice President of Strategic Growth · IT ArchiTeks
Risk Strategist · National Cybersecurity Speaker

Melanie Padron brings nearly three decades of risk management experience, spanning insurance and cybersecurity, to help trucking and logistics leaders validate security posture, strengthen resilience, and protect revenue before pressure reveals what preparation concealed.

She’s a nationally recognized cybersecurity keynote speaker and the creator of two acclaimed talks:

  • Surviving a Cyber Crisis: Real Stories. Real Lessons. Real Money.
  • Proof to Profit: How Leaders Protect Revenue in the Age of Ransomware and AI

To bring either conversation to your conference, association, or leadership team — visit ITArchiTeks.com or connect with Melanie directly on LinkedIn.

The Ransom Note Is Not the Attack. It’s the Bill.

Ninety-five years in business. Survived the Great Depression, a World War, deregulation, a global pandemic, and recessions that swallowed companies whole.

Then one night, criminals found an open door. They didn’t kick it in. They slipped in quietly, the way criminals always do, and they stayed. Watching. Mapping. Studying exactly how the operation ran and exactly how much it would cost to bring it to its knees. For months, nobody knew they were there.

Then they dropped the payload. By morning, every computer had the same message:

“Your files have been stolen and encrypted. All you need to do is pay.”

No incident response plan. No tested backups. No defined ownership of risk at the leadership level. When the crisis hit, no one knew what to do or who was in charge. We worked around the clock for weeks that turned into months. We got critical systems back up. But the damage — layered on top of existing financial pressure — became too much.

Sadly, they closed their doors permanently. Ninety-five years. Gone.

And here is the part I can’t stop thinking about: they thought they were protected enough.


The Most Expensive Gap in Business Has Nothing to Do With Technology

The ransom note is never where the story starts. The attack happened months earlier. Sometimes over a year earlier. A convincing email that looked like it came from a trusted vendor. A contractor with credentials nobody revoked. An alert firing into a folder nobody was monitoring. Criminals walked quietly through an open door, and nobody knew until the bill arrived.

The gap that destroys companies is not the gap in their firewall. It’s the gap between what leaders believe about their security and what they can actually prove. That gap looks like confidence. It feels like preparedness. It sounds like “we’ve got it covered.”

Until the morning systems go down.

The ransom note is not the attack. It’s the bill. The attack happened months ago.


What Full Recovery Actually Requires

A different company gets hit with a ransomware attack through a business email compromise — the same entry point criminals use constantly. By every measure, this should have been catastrophic. Here’s where the story changes.

Months earlier, this company had made a decision. Independent audit completed. Vulnerabilities identified and closed. Ownership defined at the leadership level. Incident response plan documented and practiced. Backups tested under real conditions, not just assumed to exist.

When the attack hit, it was detected immediately. Systems were contained. Forensics was engaged. After a five-day investigation to confirm the environment was clean, restoration began. Eighteen hours. Data restored to within fifteen minutes of the attempted attack.

Zero encryption. Zero data loss. Zero ransom paid. Still in business and thriving today.

That’s not luck. That’s what happens when a leader stops asking “are we protected” and starts asking “can we prove it.”


The Five Disciplines That Separate Those Two Outcomes

The difference between those two companies is not budget, industry, or the sophistication of the attack. It’s discipline. Practiced before the pressure was real.

I built a framework around five disciplines. I call it Proof to Profit. Every company I’ve seen recover fast — with minimal damage and zero ransom paid — had those disciplines in place before the crisis hit. Not after. Before.

The framework is something I walk leaders through in detail when we work together, and it’s the foundation of the keynote I deliver to executive teams. But the principle behind it is simple enough to say here:

Real protection isn’t assumed. It’s validated. It’s practiced. And it’s owned at the top.

If your security has never been tested by someone outside your organization, it has never truly been tested.


Five Questions Every Leader Needs to Answer

Not for your IT team. For you.

  1. Who owns cybersecurity at your company right now — and do they have the authority and resources to act?
  2. When was your last independent audit, by someone with no conflict of interest in the outcome?
  3. When did you last practice your incident response plan under simulated pressure?
  4. Who has active credentials in your systems — and when were those credentials last reviewed?
  5. When did you last restore from your backups under real conditions, with the clock running?

If any of those answers are “I don’t know,” that is your starting point.

The companies that survive aren’t the ones that never get hit. They’re the ones that prepared, proved, practiced, and protected before the pressure was real. That work starts with a clear look at where the gaps actually are.


Book a Free 20-Minute Strategy Session  |  Schedule an Independent Risk Audit  |  Book Melanie as a Speaker


Written by Melanie Padron

Vice President of Strategic Growth · IT ArchiTeks
Risk Strategist · National Cybersecurity Speaker

Melanie Padron brings nearly three decades of risk management experience, spanning insurance and cybersecurity, to help trucking and logistics leaders validate security posture, strengthen resilience, and protect revenue before pressure reveals what preparation concealed.

She’s a nationally recognized cybersecurity keynote speaker and the creator of two acclaimed talks:

  • Surviving a Cyber Crisis: Real Stories. Real Lessons. Real Money.
  • Proof to Profit: How Leaders Protect Revenue in the Age of Ransomware and AI

To bring either conversation to your conference, association, or leadership team — visit ITArchiTeks.com or connect with Melanie directly on LinkedIn.

What the World’s Top CEOs Are Worried About Right Now (And Why It Should Stop You Cold)

The most dangerous phishing email hitting inboxes today doesn’t look dangerous.

It’s AI-generated. It sounds like your CFO. It looks like your most trusted vendor. It arrives at exactly the right moment.

And the leaders running some of the largest companies in the world are finally putting it on the record.

I’ve studied the data, the research and the field reports that are shaping how global executives think about cyber risk right now. What I found wasn’t surprising. It was confirming. Because the patterns showing up in boardrooms across every industry are the same ones I see when I get called in after a company has already been hit.

Same blind spots. Same gap between what leaders believed about their security and what was actually true.


The Threat They Were Preparing For Last Year Is Not the One Coming Now

In 2025, ransomware was the number one concern for CEOs worldwide.

In 2026, it dropped.

Cyber-enabled fraud and phishing took the top spot. AI vulnerabilities moved to second place. That shift doesn’t mean ransomware protection stopped mattering. It means the entry point changed, and most companies are still defending the door that already got closed instead of the one that’s actually open.

That shift matters more than most leaders realize. Because the most dangerous version of an attack today doesn’t announce itself. It’s personalized. It’s timed. And it’s increasingly built by AI to get past the defenses you already have.

Nearly three out of four executives surveyed said they or someone in their professional network had been personally affected by cyber-enabled fraud in the past year alone.

That’s not a niche threat. That’s nearly everyone in the room!

“The gap between what you believe about your security and what you can actually prove is where criminals live.”


94% Agree AI Changes Everything. But Most Companies Haven’t Changed Anything.

Ninety-four percent of executives surveyed identified AI as the most significant driver of change in cybersecurity right now.

Ninety-four!

And yet, roughly one-third of organizations still have no formal process to assess the security of their own AI tools before deploying them. Even fewer have built real AI threat detection into how they monitor those tools day to day.

I’ve stood in the aftermath of enough attacks to tell you what that gap costs. The companies that called on IT ArchiTeks after a breach knew cybercrime was a risk. They heard the warnings. They believed they were prepared.

What they couldn’t do was prove it.

The gap between belief and proof is one of the most expensive gaps in business today.


This Is Not a Technology Problem. It Never Was.

The research draws a sharp line between organizations with high cyber resilience and those without.

The single biggest differentiator? Leadership.

Among highly resilient organizations, 99% reported board-level involvement in cybersecurity. Regular updates. Active engagement. Defined roles.

Among organizations that described their resilience as insufficient, board engagement was nearly absent.

Cybersecurity isn’t an IT discussion. It’s a business continuity decision. It’s a margin protection strategy. It belongs at the same table as revenue, operations and risk.

“What isn’t owned isn’t prioritized. And what isn’t prioritized becomes exposed.”


The Blind Spots Haven’t Changed. Most Companies Haven’t Either.

The top barriers to cyber resilience: a rapidly evolving threat landscape, third-party and supply chain vulnerabilities and cybersecurity skills shortages.

I’ve been documenting those same gaps in the field for years.

I see backups never tested under real conditions, cybersecurity monitoring that exists on paper but not in practice, vendor credentials nobody revoked, flat networks with no segmentation, cloud environments assumed to be someone else’s responsibility. And people, still the most targeted entry point of all, with little to no insider threat detection in place to catch the moment someone inside the building becomes the risk.

None of these require a sophisticated attacker. They are simply the doors criminals find before you do.

And here’s what makes them so dangerous: they don’t look like problems. They look like confidence. They feel like preparedness. They sound like “we’ve got it covered.”

Until the day you find out they weren’t.

The research has confirmed what I see every day. The patterns are documented. The risk is named.

The question is whether you’ll act before you’re forced to, with managed cybersecurity services that catch what your team can’t see on its own, or after.

Book a free 20-minute strategy session  |
Schedule an independent risk audit  |
Book Melanie as a speaker

Data referenced throughout: WEF Global Cybersecurity Outlook 2026, published January 2026 in collaboration with Accenture.

This Is What Proof Looks Like. 18 Hours. Zero Ransom. Zero Data Loss.

I want to tell you about one of the best days of my cyber career.

I’m sitting in a conference room with a transportation client. A few months earlier we had completed a comprehensive risk assessment and uncovered some significant vulnerabilities. Since then we’d been in a holding pattern while they decided how they wanted to respond to what we found.

This was decision day.

I walked through the findings one more time. The gaps. The risks. What was at stake. Then I asked the question: how do you want to manage your risk?

They said yes. All of it. Our full cybersecurity stack.

I won’t pretend I wasn’t relieved. This is exactly the moment this work is for.

Over the next several months we onboarded them completely. Everything was running exactly as it should. Then at the end of December, just before the holidays, a ransomware attack launched from Russia hit their network through a business email compromise.

Our monitoring tools detected it immediately. Our team isolated the affected systems and engaged a forensics team within hours. The investigation took five days to ensure no residual threats remained.

Once forensics cleared the environment and gave us the green light, we had their systems back online within 18 hours. And because of a well-designed, tested backup and data recovery plan, their data was restored to within 15 minutes of the initial attack.

Zero data encryption. Zero data loss. Zero ransom paid. Business continuity maintained without interruption.

Chalk that one up as a win for the good guys.

That company is still in business today because they recognized the risks, made a decision, and gave us the time to build something proven before they needed it.

That is what proof looks like.


Why This Outcome Is Rare

I wish I could tell you this is the typical result. It isn’t.

Most of the companies we help recover after a ransomware attack are calling us after the fact. After the encryption. After the ransom demand. After the data is already gone or compromised. After dispatch is dark and drivers are sitting idle and customers are calling with nowhere to turn.

The difference between that company and the ones who don’t make it isn’t luck. It isn’t budget. It isn’t the size of the fleet or the sophistication of the criminals who targeted them.

It’s preparation. Specifically, preparation that was built, tested, and proven before anyone needed it.

The NMFTA Cybersecurity Best Practices Guidebook calls this out across multiple tiers: documented incident response plans, regular assessments, tested backups, disaster recovery planning, and business continuity protocols. These aren’t bureaucratic checkboxes. They’re the infrastructure that determines whether your company survives the hour everything goes wrong.


The Five Pillars That Made It Possible

When I look back at what made that recovery possible, it maps directly to the Proof to Profit framework I teach in my keynote presentations.

Prepare.
They completed a comprehensive risk assessment before the attack. They knew where their gaps were. They made informed decisions about how to address them.

Prove.
They didn’t assume their systems worked. They tested them. They validated their backup and recovery plan under realistic conditions before they ever needed it.

Practice.
Their team knew the protocols before the incident required it. When the attack hit, nobody was figuring out roles in real time. The response was practiced, not improvised.

Protect.
The right tools were in place and monitored around the clock. When the attack came through a business email compromise, the monitoring detected it immediately. Not days later. Not weeks later. Immediately.

Profit.
They’re still in business. Still moving freight. Still serving their customers. That is the profit. Not a financial metric. Survival. Continuity. The ability to keep operating when criminals tried to take that away.


What This Means for Your Company

The company in this story isn’t extraordinary. They’re a transportation company that made a decision. They recognized the risks, invested in the right framework, and gave us the time to build something solid before they needed it.

That decision is available to every trucking leader reading this.

Cybersecurity isn’t an IT problem with a technology solution. It’s a leadership problem that requires a leadership response. The trucking leaders who understand that are the ones who get to tell the success story instead of becoming the cautionary tale.

You don’t rise to the occasion in a cyber crisis. You fall to the level of your preparation.

The question isn’t whether an attack is coming. The question is whether you’ll be ready when it does.


Three Questions Worth Asking

  1. Do you have a documented, tested incident response plan that your leadership team has actually practiced?
  2. Has your backup and data recovery plan been tested under realistic conditions, against a clock, in the last twelve months?
  3. If an attack hit tonight, would your team execute a practiced response — or improvise one?

If those questions don’t have confident, documented answers, you know where to start.


Contact us at ITArchiTeks.com to start the conversation.

Because hope is not a strategy… and proof is how you protect profit.


Written by Melanie Padron

Vice President of Strategic Growth · IT ArchiTeks
Risk Strategist · National Cybersecurity Speaker

Melanie Padron brings nearly three decades of risk management experience, spanning insurance and cybersecurity, to help trucking and logistics leaders validate security posture, strengthen resilience, and protect revenue before pressure reveals what preparation concealed.

She’s a nationally recognized cybersecurity keynote speaker and the creator of two acclaimed talks:

  • Surviving a Cyber Crisis: Real Stories. Real Lessons. Real Money.
  • Proof to Profit: How Leaders Protect Revenue in the Age of Ransomware and AI

To bring either conversation to your conference, association, or leadership team — visit ITArchiTeks.com or connect with Melanie directly on LinkedIn.

You Believe You’re Protected. Can You Actually Prove It?

Imagine building something for 95 years.

Three generations. Hundreds of employees. 75 terminals across the country. A name in the industry that meant something. A company your grandfather started, your father grew, and you were supposed to carry forward.

Then one night, everything goes dark.

Dispatch offline. Drivers unable to log trips. The call center silent. 800 computers encrypted. Ransom paid. Weeks of around-the-clock recovery work that still couldn’t save what had already been lost. The attack was the final nail in the coffin for a company already under financial strain.

A year later, they closed permanently.

What haunts me about this story isn’t just the loss. It’s that it was preventable. They had IT support. They had systems in place. What they didn’t have was a cybersecurity framework, independent verification that their systems actually worked, or any way to prove they were protected when it mattered most.

They believed they were. They couldn’t prove it.

That gap — between belief and proof — is what this post is about.


Three Gaps That Turn Belief Into a Liability

When I look back at situations like this one, the same three vulnerabilities show up every time. None of them are hard to fix. And most trucking companies I work with have at least one — often all three.

Gap 1: The Cloud Created a False Sense of Security

When a company moves to Microsoft 365, a cloud-based TMS, or any hosted platform, there’s often a collective exhale. Someone else is managing the infrastructure. The assumption — rarely stated but almost always present — is that security came along for the ride.

It didn’t.

Your vendor secures the underlying cloud infrastructure. Securing your data, your user access, your permissions, your configurations? That remains entirely your responsibility. It’s all spelled out in the fine print that nobody reads.

Just because you outsource your technology does not mean you outsource your risk.

Most trucking companies aren’t even having this conversation with their vendors. Many don’t have an inventory list of who their vendors are, let alone what security standards those vendors meet. At minimum, maintain a vendor list and send the NMFTA’s vendor vetting questions to each one. It starts a conversation most companies have never had.

Gap 2: The Network Had No Locked Doors

The NMFTA Cybersecurity Best Practices Guidebook lists internal network segmentation as a Tier Two control. The concept means dividing your network into separate sections so that if criminals get into one area, they can’t move freely into everything else.

Think of it like a warehouse with no locked doors between departments. Someone gets through the front entrance and suddenly they have access to the loading dock, the offices, the safe, and the server room.

Improper segmentation — or no segmentation at all — is one of the most common gaps we find in our fleet security audits. When ransomware enters a flat network it doesn’t stay where it landed. It moves fast and takes everything it can reach.

Gap 3: Nobody Had Independent Eyes on It

This is the one that connects everything back to that 95-year-old company.

Their IT partners were reporting that things were fine. Nobody had ever brought in an independent set of eyes to verify whether what they had actually worked. Your IT team and your MSP can’t assess their own work. Even the most well-intentioned internal team has blind spots they genuinely cannot see because they’re too close to the environment they built.

You cannot fix what you cannot see. And you cannot see what you’ve never had someone qualified look for.

If your IT provider resists independent scrutiny, ask yourself why. The answer matters more than the explanation.


Belief and Proof Are Not the Same Thing

I’m not writing this to frighten anyone. I’m writing it because I’ve sat across from too many trucking leaders who had every reason to believe they were protected — and discovered too late that they couldn’t prove it.

Your IT team may be excellent. Your MSP may be responsive. Your cloud vendor may be reputable. None of that is proof that your specific environment is actually secure.

Proof comes from independent eyes. From a framework built for your industry. From testing that happens before criminals do it for you.

Age and legacy are not safeguards against modern threats. The most expensive hour in your business is the one you assumed would never happen.


Three Questions Worth Asking

  1. Do you have a complete vendor list — and have you asked each vendor what they are responsible for securing versus what you are?
  2. Who outside of your internal IT team or MSP has independently assessed your security posture, and when?
  3. If ransomware entered your network today, what would stop it from reaching every system you operate?

If those questions don’t have clear documented answers, you have your starting point.


Contact us at ITArchiTeks.com to start the conversation.

Because hope is not a strategy… and proof is how you protect profit.


Written by Melanie Padron

Vice President of Strategic Growth · IT ArchiTeks
Risk Strategist · National Cybersecurity Speaker

Melanie Padron brings nearly three decades of risk management experience, spanning insurance and cybersecurity, to help trucking and logistics leaders validate security posture, strengthen resilience, and protect revenue before pressure reveals what preparation concealed.

She’s a nationally recognized cybersecurity keynote speaker and the creator of two acclaimed talks:

  • Surviving a Cyber Crisis: Real Stories. Real Lessons. Real Money.
  • Proof to Profit: How Leaders Protect Revenue in the Age of Ransomware and AI

To bring either conversation to your conference, association, or leadership team — visit ITArchiTeks.com or connect with Melanie directly on LinkedIn.

Your People Are the Most Targeted Asset in Your Company. They Could Also Be the Most Powerful One.

Every cybersecurity conversation eventually lands on the same uncomfortable truth: most attacks don’t start with a sophisticated technical exploit. They start with a person. A click. A reply. A wire transfer that seemed completely legitimate until it wasn’t.

That gets framed as a human failure. I want to reframe it.

Your people aren’t being targeted because they’re careless or uninformed. They’re being targeted because criminals are sophisticated, patient, and specifically trained to exploit the way humans naturally communicate and trust each other. There’s a difference between a vulnerability and a character flaw. Your team most likely has the first, not the second.

But here’s the other side of that truth. Properly trained, aware, and empowered people are also your strongest line of defense. The same asset criminals target most is the one that stops them when it’s developed correctly.

Right now, most trucking companies have the risk. Very few have developed the defense.


What the NMFTA Says About the Human Layer

The NMFTA Cybersecurity Best Practices Guidebook for Mid-Sized Fleets lists basic cybersecurity awareness training as a Tier One prerequisite. Not a nice to have… or something to get to eventually. A foundational control that must be in place before anything else is built on top.

The guidebook also calls out alert monitoring and least privilege access as critical controls. Because the human layer isn’t just about training people not to click bad links. It’s about building systems that limit the damage when someone inevitably does.

All three of those controls show up consistently in our fleet security audits as gaps. Not because nobody thought they mattered. Because nobody was specifically hired to own them.


How Criminals Actually Get In

Let me walk you through two scenarios we see repeatedly in the trucking industry.

The fake invoice. A criminal researches your company, identifies a vendor you work with regularly, and sends an invoice that looks exactly like the real thing. Same logo. Similar email domain. Accurate freight details pulled from publicly available information or a previous data breach. Someone in accounting processes it. The money moves before anyone realizes the vendor’s email was off by one letter.

Vendor compromise. A third party you trust — a software provider, a logistics partner, an MSP — gets breached. Criminals use that trusted relationship as a bridge into your network. You didn’t click anything suspicious. You didn’t make a mistake. You trusted someone you had every reason to trust, and that trust became the attack vector.

Neither of these requires a technical genius. Both work because they’re designed around human behavior, not technical vulnerabilities.

And it’s escalating. Industry intelligence and peer conversations at conferences are surfacing a growing threat: AI-generated attacks that can impersonate your CFO’s writing style, replicate vendor invoice formats with perfect accuracy, and craft phishing emails written specifically for your organization. Companies that look exactly like yours are already encountering this.


The Alert Nobody Saw

One of the most painful patterns we uncover in post-attack investigations is the alert that was there all along.

In one case we responded to, security alerts had been coming in for months, going to a folder nobody was actively reviewing. The IT team wasn’t equipped to recognize what those alerts meant from a security standpoint. By the time the attack was visible, criminals had been inside the network for over a year.

The NMFTA guidebook is explicit: alerts are only useful if they’re configured correctly and watched in real time. That requires either dedicated internal resources or a security partner whose specific job is to monitor threats around the clock.

A generalist IT team managing day-to-day operations cannot reliably do this. That’s not a criticism. It’s a staffing reality.


Too Many People Have the Keys

The third piece of this — one that compounds every other vulnerability — is excessive access.

Imagine if every driver in your fleet had access to your company bank account. That’s essentially what excessive admin privileges look like inside a network. If a criminal gets access to one admin account, they have the keys to everything that account can reach.

The principle of least privilege is simple: people get access to what they need to do their job, and nothing more. The NMFTA lists this as a Tier One control. We find it misconfigured in many of the fleet security audits we conduct.


Real Talk: This Is Not a Training Problem Alone

Companies respond to human risk by scheduling annual cybersecurity awareness training. Watch a video. Pass a quiz. Check the box. That training has value. The NMFTA recommends it for good reason.

But training alone doesn’t stop a perfectly crafted fake invoice from a spoofed vendor domain. It doesn’t catch an alert sitting unread in a security folder. It doesn’t limit the damage when one compromised account has access to everything.

The human layer requires more than education. It requires systems, monitoring, and access controls that assume someone will eventually be fooled — because they will — and limit the blast radius when it happens.

Your people aren’t the problem. The absence of systems designed to protect them is.


Three Questions Worth Asking

  1. Are security alerts monitored around the clock, in real time?
  2. How many people in our organization have administrative access — and when was that list last reviewed?
  3. Has our team not just received but completed and passed cybersecurity awareness training in the last twelve months? Is someone monitoring your Employee Security Score to ensure staff is actually consuming and understanding it, not just clicking through?

If the answers are uncertain or overdue, you know where to start.


Contact us at ITArchiTeks.com to start the conversation.

Because hope is not a strategy… and proof is how you protect profit.


Written by Melanie Padron

Vice President of Strategic Growth · IT ArchiTeks
Risk Strategist · National Cybersecurity Speaker

Melanie Padron brings nearly three decades of risk management experience, spanning insurance and cybersecurity, to help trucking and logistics leaders validate security posture, strengthen resilience, and protect revenue before pressure reveals what preparation concealed.

She’s a nationally recognized cybersecurity keynote speaker and the creator of two acclaimed talks:

  • Surviving a Cyber Crisis: Real Stories. Real Lessons. Real Money.
  • Proof to Profit: How Leaders Protect Revenue in the Age of Ransomware and AI

To bring either conversation to your conference, association, or leadership team — visit ITArchiTeks.com or connect with Melanie directly on LinkedIn.

The Ransomware Wasn’t the Problem. Trusting the Wrong People With the Wrong Job Was.

Most of the trucking companies we help recover after a ransomware attack weren’t careless. They had people handling cybersecurity. They had systems in place. They thought they were covered.

They weren’t.

Not because they failed to act. Because the people they trusted to act weren’t equipped for the job.

There’s a critical difference between IT and cybersecurity. Between a Managed Service Provider who keeps your systems running and a cybersecurity partner who keeps your systems protected. Most trucking companies have the first. Almost none have the second.


The NMFTA Built a Roadmap. Most Fleets Don’t Know It Exists.

The NMFTA Cybersecurity Best Practices Guidebook for Mid-Sized Fleets lays out four tiers of cybersecurity maturity. Tier One isn’t advanced. It isn’t optional. The guidebook calls it prerequisites — the foundational controls every fleet must have before anything else is built on top.

Tier One includes tested backups, MFA on every account, updated software, endpoint detection, secured wireless networks, and least privilege access. That’s the starting line. Not the finish line.

When we conduct a comprehensive fleet security audit, we look for everything — basic through advanced. And what we find, almost every single time, is that the starting line controls — the ones that should’ve been locked in years ago — have gaps nobody knew were there.


How It Happens to Smart, Well-Run Companies

A trucking company hires an IT team or contracts with an MSP. Those people are good at what they do. They keep the network running, manage updates when they can, and handle day-to-day technical issues. Leadership trusts them. Why wouldn’t they?

But IT isn’t cybersecurity. An MSP focused on uptime and helpdesk tickets isn’t a cybersecurity partner. The skill sets are related — but they’re not the same.

Cybersecurity requires a threat-first mindset. Someone who thinks like an attacker, not just like an administrator. Most IT teams and generalist MSPs were never trained that way — and were never hired to think that way.

So the backups get configured. But nobody tests whether they can actually be restored under pressure. MFA gets turned on for some accounts. But not all of them. Software updates get applied when convenient. But the end-of-life systems that haven’t been touched in years? Those sit quietly in the corner — and criminals find them before anyone else does.

Nobody skipped anything on purpose. The fundamentals just never got done properly because the people doing them didn’t know what properly looked like from a security standpoint.


The Three Tier One Failures We Find Most Often

01 · Backups That Have Never Been Tested

The NMFTA guidebook is explicit: testing backups is an equally important and often overlooked requirement. Not just running them — testing them. Restoring from them. Timing the process. Confirming the data is complete, uncorrupted, and accessible when everything else has gone dark.

We’ve helped companies recover after an attack only to discover the backup existed but couldn’t be used — corrupted files, incomplete data, backups stored on the same network ransomware just encrypted, companies that couldn’t locate their own decryption key.

Think of it like a spare tire. Owning one isn’t enough. You need to know it’s inflated, you can get to it, and someone on your team has actually changed a tire before.

02 · MFA That Isn’t Everywhere

Multi-Factor Authentication is one of the most effective and affordable controls available. The NMFTA lists it as a Tier One prerequisite. Yet we consistently find it turned on for some systems and completely absent from others — email accounts, remote access, administrative accounts.

Criminals don’t hack into networks. They log in. A stolen password with no MFA behind it is an open door.

03 · Unpatched and End-of-Life Systems

Running unpatched software is like driving on bald tires. Trucking operations run specialized software that doesn’t always get updated — maintenance diagnostic tools, TMS platforms, legacy systems running since before anyone thought to ask whether they were still supported.

Criminals scan the internet for these vulnerabilities the way a predator scans for the weakest animal in the herd. If you’re behind on patches, you’re the easy target.


The Conversation Nobody Prepares You For

When we sit down with a company and walk through what we found, the reaction varies. Some leaders lean in immediately. They want to know everything. They’re relieved someone finally looked closely enough to find it. Healthy teams with healthy cultures respond that way.

But sometimes there’s defensiveness. If your IT person has been managing cybersecurity for years, our findings can feel like a grade on their work. That’s a hard thing to receive in front of leadership, and we respect that.

We’re not here to replace your IT team or expose them. We’re here to fill the gaps they were never trained or hired to fill. Our goal is to be their security extension — to stand them up and make them look like heroes.

Cybersecurity is a specialty. Expecting a generalist IT team to cover it completely is like expecting your dispatcher to also handle your DOT compliance audits. Related world. Different expertise.


This Is a Leadership Conversation, Not an IT Conversation

Cybersecurity isn’t an IT problem you can hand off and stop thinking about. It’s a business risk that requires leadership to ask hard questions, demand proof not assumptions, and understand the difference between a team that keeps the lights on and a team that keeps the criminals out.

The question worth sitting with isn’t whether you have someone handling cybersecurity. It’s whether you’ve ever asked them to prove it.


Three Questions Worth Asking

  1. When did we last restore from backup under realistic conditions — and how long did it take?
  2. Which accounts in our organization don’t have MFA enabled right now?
  3. What systems are we running that are no longer supported by the manufacturer?

If those questions get answered quickly with documented proof, that’s a good sign. If they’re met with hesitation or vague reassurances — you now know where to focus.


Contact us at ITArchiTeks.com to start the conversation.


Written by Melanie Padron

Vice President of Strategic Growth · IT ArchiTeks
Risk Strategist · National Cybersecurity Speaker

Melanie Padron brings nearly three decades of risk management experience, spanning insurance and cybersecurity, to help trucking and logistics leaders validate security posture, strengthen resilience, and protect revenue before pressure reveals what preparation concealed.

She’s a nationally recognized cybersecurity keynote speaker and the creator of two acclaimed talks:

  • Surviving a Cyber Crisis: Real Stories. Real Lessons. Real Money.
  • Proof to Profit: How Leaders Protect Revenue in the Age of Ransomware and AI

To bring either conversation to your conference, association, or leadership team — visit ITArchiTeks.com or connect with Melanie directly on LinkedIn.

You Have an Incident Response Plan. Has Anyone Actually Practiced It?

Most trucking companies have an incident response plan. Almost none have practiced it under pressure. The NMFTA framework and ransomware data agree: a plan no one has rehearsed is not a plan. It’s paperwork.


The ransomware hit at 6:12 a.m.

Dispatch went dark. TMS was inaccessible. Drivers were calling. Customers were calling. And the executive team was staring at each other asking a question no one had ever actually answered before:

Who is in charge right now?

Not “who is technically responsible for IT.” Who makes the decision to shut systems down? Who calls legal? Who calls the insurance carrier? Who authorizes the forensics firm? Who communicates with drivers? Who notifies customers?

If your team would have to answer those questions for the first time during an active incident, your incident response plan has never been practiced.

A plan no one has practiced is not a plan. It’s paperwork.


The NMFTA Framework Is Explicit About This

The NMFTA Cargo Crime Framework requires a documented incident response plan that is regularly tested and kept up to date — not written once and filed. Tested. Meaning someone ran a scenario, people made real decisions, gaps were exposed, and those gaps were corrected before the real incident revealed them.


What the Ransomware Data Tells Us

  • 64% of closed claims in 2025 were resolved with no out-of-pocket loss — the direct result of rapid, practiced response (Coalition 2026)
  • 65% average reduction in ransom demands via negotiation — but negotiation requires time, legal authority, and a coordinated team that knows their roles (Coalition 2026)
  • The gap between a breach and the first class-action filing has shrunk to days (Chubb 2026)

If your team is making decisions for the first time during the incident, you are not responding. You are improvising. And improvisation under pressure is how recoverable situations become catastrophic ones.


The Five Decisions That Must Be Pre-Made

  • Containment authority — who can take systems offline right now, without a committee?
  • Legal notification — who calls counsel, and when? Breach notification laws may require action within 72 hours.
  • Insurance activation — who calls the carrier, and do they have the policy number memorized?
  • Forensics authorization — who engages a forensics firm, and do you have one on retainer?
  • Communication authority — who speaks to drivers, customers, and media?

These decisions need to be made before the crisis. Written down. Distributed. Practiced until they are muscle memory.


What a Tabletop Exercise Actually Looks Like

A tabletop exercise is not a presentation about cybersecurity. It is a structured simulation in which your leadership team walks through a realistic scenario and makes real decisions in real time.

It exposes who hesitates when they should move, who moves when they should escalate, and where your documented plan breaks down against reality. Then those gaps get fixed — before the real incident.


The Proof to Profit Argument

You don’t rise to the occasion. You fall to the level of your preparation.

And preparation that has never been practiced is not preparation. It’s intention.

At the NMFTA Convention this year, Proof to Profit is my answer to that question. It’s a leadership framework built on five disciplines: Prepare. Prove. Practice. Protect. Profit.

Criminals have practiced. They’ve rehearsed this. They know what they’re doing when they hit your systems.

The question is whether you do.

Book a Tabletop Exercise with IT ArchiTeks  |  Register for NMFTA Convention 2026


Written by Melanie Padron

Vice President of Strategic Growth · IT ArchiTeks
Risk Strategist · National Cybersecurity Speaker

Melanie Padron brings nearly three decades of risk management experience, spanning insurance and cybersecurity, to help trucking and logistics leaders validate security posture, strengthen resilience, and protect revenue before pressure reveals what preparation concealed.

She’s a nationally recognized cybersecurity keynote speaker and the creator of two acclaimed talks:

  • Surviving a Cyber Crisis: Real Stories. Real Lessons. Real Money.
  • Proof to Profit: How Leaders Protect Revenue in the Age of Ransomware and AI

To bring either conversation to your conference, association, or leadership team — visit ITArchiTeks.com or connect with Melanie directly on LinkedIn.