PrOTect It All

PrOTect It All

Aaron Crow | Operational Technology & Cybersecurity Host
Maa Yhdysvallat
Kieli EN
Jaksot 123
Viimeisin 14.09.2026

PrOTect It All is hosted by Aaron Crow and focuses on cybersecurity and operational technology. Episodes cover emerging threats in industrial control systems, AI security, and IoT. The show explores enterprise risk management, manufacturing security, power grid security, and threat intelligence. It features conversations with security leaders and practitioners for those working in real-world IT/OT operations and critical infrastructure.

Jaksot

  • AI in OT: Why Humans Stay in the Loop and the Junior Problem with Jori VanAntwerp 14.09.2026 1t 5min
    Work with Aaron: https://protectitallpod.com/work/ The book: https://protectitallpod.com/book/ This episode: https://protectitallpod.com/ep123/ The OT Security Starter Kit: https://protectitallpod.com/starter-kit/ AI is a consensus engine, and consensus on the internet is frequently wrong. So what does that mean for the people defending power plants, water systems, and factories with it? In this episode of Protect It All, host Aaron Crow welcomes back Jori VanAntwerp, CEO and founder of EmberOT, for a completely unscripted conversation on AI in OT. Two practitioners who use AI aggressively every day make the case for restraint in exactly the places that matter. Jori explains why human in the loop is non-negotiable: AI shapes a junior's output to look senior without the understanding underneath, so you have to be able to interrogate it. Aaron walks through his own sandbox discipline, where AI gets a folder and not the keys, and nothing goes in that he would not publish on the internet. The conversation then turns to the OT reality behind AI-found vulnerabilities, why an attacker who can reach your HMI or PLC does not need your unpatched CVE, teaching AI your voice with markdown primers, the build-versus-buy MVP trap, the submarine principle for modular defense, and why an operator flipping to manual is still the save of last resort. Underneath all of it is the workforce math nobody is doing on air: if one person plus AI does the work of five, nobody is training juniors, and no juniors today means no seniors in ten years. OT's aging-out workforce is the preview. In this episode, you'll learn: Why AI is a consensus engine, and why that framing predicts where it fails Why human in the loop is not optional for anything that matters How to sandbox AI in real workflows: a folder, not the keys How to rank AI-found vulnerabilities against what an attacker in your OT network can actually do How primers teach AI your voice, brand, and rules The build versus buy trap: if a power company builds its own software, it is now a software company The submarine principle: compartments, modular tooling, and swapping tools without ripping out the estate Why analog fallbacks and operators keep saving critical infrastructure The junior pipeline problem: no juniors today means no seniors in ten years Why the entry-level job for OT cybersecurity is IT Tune in for the most honest AI conversation the show has had, from the people who actually run it in OT. About the guest: Jori VanAntwerp is a two-time cybersecurity founder and CEO who has spent over two decades helping industrial and IT/OT organizations reduce risk, strengthen compliance, and mature the way they defend critical infrastructure. He has held executive and leadership roles at McAfee, FireEye, CrowdStrike, Dragos, and Gravwell before stepping into the founder seat, first at SynSaber and now as the Founder and CEO at EmberOT. The result is a vantage point that runs from the boardroom to the packet capture, from silicon to the cloud. At EmberOT, he is focused on bringing visibility, security, and risk quantification to the critical infrastructure the rest of the world takes for granted. From EmberOT: Want to see what is really happening in your OT environment? EmberOT provides flow-first, passive OT visibility and threat detection without requiring proprietary hardware. Learn more about EmberOT...
  • Building the Cybersecurity Community: From 120 People to 3,000 at CYBR.SEC.CON 07.09.2026 46min
    Work with Aaron: https://protectitallpod.com/work/ The book: https://protectitallpod.com/book/ This episode: https://protectitallpod.com/ep122/ The OT Security Starter Kit: https://protectitallpod.com/starter-kit/ Get your tickets for CYBR.SEC.CON., a two-day cybersecurity conference, here: https://www.cybrseccon.com/ What started with 120 people and a homemade Word flyer has grown into a cybersecurity community of more than 3,000. So what does it take to build a community that can scale without losing its personal connection? In this episode of Protect It All, host Aaron Crow sits down with Michael Farnum, CEO and co-founder of CYBR.SEC.Community, and Sam Van Ryder, co-founder and an OT sales expert, to explore the story behind the growth of CYBR.SEC.CON and the community surrounding it. Michael and Sam share how they went from a grassroots cybersecurity gathering to a thriving community while keeping the relationships and sense of connection that made the event special in the first place. The conversation goes beyond conferences. Aaron, Michael, and Sam discuss the challenges facing people trying to break into cybersecurity and OT, why entry-level opportunities can be difficult to find, and what experienced professionals can do to help develop the next generation of cyber defenders. They also share their hands-on efforts to introduce young people to cybersecurity, including bringing 75 high school students into the community, with plans to reach 150. From hiring and firing lessons to career advice, community building, and the future of OT cybersecurity, this episode offers practical insight for anyone looking to grow their career, build meaningful connections, or help strengthen the cybersecurity workforce. In this episode, you'll learn: How CYBR.SEC.Community grew from 120 people to more than 3,000 What it takes to scale a cybersecurity community without losing its personal feel Why conferences can play an important role in cybersecurity careers How to break into OT and cybersecurity when you're just starting out The challenges surrounding entry-level cybersecurity jobs How community and mentorship can help develop the next generation of cyber professionals What CYBR.SEC.Community is doing to engage high school students in cybersecurity Coming September 15 and 16, 2026 CYBR.SEC.CON 2026 brings the cybersecurity community together again on September 15 and 16 at the George R. Brown Convention Center in Houston, Texas. If you're looking to connect with cybersecurity professionals, expand your network, learn from practitioners, discover career opportunities, and be part of a growing cyber community, CYBR.SEC.CON 2026 is an event worth checking out. Tune in to hear the story behind CYBR.SEC.CON, the people building the community, and why the future of cybersecurity depends on bringing more people into the conversation. About the guests: Michael Farnum is the CEO and co-founder of CYBR.SEC.Community and has worked in IT and cybersecurity since 1994. He founded HOU.SEC.CON. in 2010, which evolved into CYBR.SEC.CON., now attracting more than 3,000 cybersecurity professionals annually. Michael is passionate about cybersecurity community building, workforce development, education, and career development, and is a frequent speaker and podcaster on security leadership and industry trends....
  • What Makes a Cybersecurity Startup Valuable in the AI Era? A VC's Perspective 31.08.2026 45min
    Work with Aaron: https://protectitallpod.com/work/ The book: https://protectitallpod.com/book/ This episode: https://protectitallpod.com/ep121/ The OT Security Starter Kit: https://protectitallpod.com/starter-kit/ AI has made it easier than ever to build a cybersecurity product. But has it also made it harder to build a valuable cybersecurity company? In this episode of Protect It All, host Aaron Crow sits down with Ken Elefant, Founding Managing Director of the venture group at Sorenson Capital, for a candid conversation about what really makes cybersecurity startups succeed. Ken shares a venture investor's perspective on the rapidly changing security market, including why simply wrapping a product around an LLM may not create lasting value, how AI is accelerating commoditization, and what founders need to do to build a meaningful competitive advantage. The conversation goes beyond technology to explore the often-overlooked role of people, process, market positioning, and execution. Aaron and Ken discuss the importance of finding the right "wedge" into enterprise security, solving real customer problems, differentiating in crowded markets, and building companies that can create lasting value rather than chasing the latest technology trend. They also draw on lessons from successful cybersecurity exits and the changing threat landscape to examine what investors are looking for as AI reshapes both cybersecurity products and the businesses behind them. Key Learning:  What venture investors look for in cybersecurity startups Why AI-powered security products can quickly become commoditized How founders can find a strong market wedge Why solving a real customer problem matters more than adding AI The role of people and process in building successful security companies How cybersecurity startups can differentiate in an increasingly crowded market What founders and operators can learn from successful security exits Where AI is creating genuine opportunity and where the hype may be ahead of the value Key Moments:  03:43 Using AI in podcasting 07:41 Trusting vendors and cybersecurity risks 10:59 Building Connections for Early Investments 15:19 Investing in emerging tech markets 17:45 Supporting AI-based startup growth 20:19 Building simple websites for businesses 26:03 Attracted to boring, overlooked markets 27:21 Building compliance products at Industrial Defender 30:16 Investing in defense tech startups 33:20 Experienced founders leveraging AI for products 38:32 Navigating fast-changing tech landscape 40:09 Importance of Building Trust in Business Whether you're a cybersecurity founder, investor, security practitioner, technology leader, or entrepreneur, this episode offers a behind-the-scenes look at how experienced investors evaluate innovation in one of the fastest-moving areas of technology. Tune in to hear what separates a promising cybersecurity idea from a company capable of creating lasting value. DISCLAIMER : "Any portfolio companies mentioned in this episode are investments of Sorenson Capital funds and do not represent all fund investments. A complete list of investments is available upon request. This podcast is for informational purposes only and does not constitute an offer to sell or solicitation to buy securities." About the guest : ...
  • Million-Dollar Buttons: How Offshore OT Is Embracing Containers and Modern Cybersecurity 24.08.2026 50min
    Work with Aaron: https://protectitallpod.com/work/ The book: https://protectitallpod.com/book/ This episode: https://protectitallpod.com/ep120/ The OT Security Starter Kit: https://protectitallpod.com/starter-kit/ Offshore oil and gas operations don't have the luxury of simply shutting everything down and starting over. In this episode of Protect It All, host Aaron Crow sits down with Josh Herr and Matt McLendon to explore the real-world challenges of modernizing cybersecurity and technology in offshore operational technology (OT) environments. From million-dollar equipment and aging control systems to virtualization, containers, and edge computing, this conversation reveals what it actually takes to keep critical industrial operations running when technology fails, hardware is difficult to replace, and downtime can come at an enormous cost. Aaron, Josh, and Matt share stories from the field, including the creative decisions operators sometimes have to make to keep one rig running when another goes down. They also explore the gradual shift from legacy Windows and Sun workstations toward Linux, containerization, and newer approaches to managing industrial systems. But this isn't simply a conversation about replacing old technology with new technology. It's about understanding the realities of OT cybersecurity, where reliability, availability, safety, cost, and security all have to work together. Key Learning:  Why offshore OT environments present unique cybersecurity challenges How legacy systems continue to influence modern industrial operations Why containers and virtualization are gaining ground in OT How operators balance cybersecurity with uptime and reliability The surprising realities of maintaining aging industrial hardware What the shift from Windows to Linux can mean for OT environments How creative problem-solving can keep critical operations running Where AI, containers, and modern infrastructure could take OT next Key Moments: 06:16 Frustrations with vendor costs and delays 09:34 Offshore connectivity and autonomy challenges 13:02 Managing power plants across Texas 16:19 Challenges with industrial HMIs and alarms 19:40 Vendor control and security policies 21:16 Component delays and industry characters 24:08 Final integration testing and safety factors 28:20 Vendor management challenges with outdated tech 34:02 Missing sysadmin skills in industry 35:59 Challenges with ARM architecture 41:09 Managing hardware life cycles 44:23 Concerns about AI and open source 45:43 Future of JavaScript and integration Whether you work in oil and gas, industrial cybersecurity, critical infrastructure, engineering, or OT operations, this episode offers an honest look at the gap between cybersecurity theory and what actually works in the field. Listen in for the war stories, lessons learned, and "art of the possible" approaches helping bring modern technology into some of the world's most challenging OT environments. About the guests:  Matt is a multidisciplinary team leader and technology practitioner with experience spanning electrical systems, controls, automation, data systems, and IS/IT. His background includes offshore oil and gas electronics, systems administration, and computer hardware, with a strong emphasis on troubleshooting and componen...
  • AI Agent Security: How to Stop Autonomous AI from Becoming Your Biggest Insider Threat 17.08.2026 57min
    Work with Aaron: https://protectitallpod.com/work/ The book: https://protectitallpod.com/book/ This episode: https://protectitallpod.com/ep119/ The OT Security Starter Kit: https://protectitallpod.com/starter-kit/ AI agents are becoming more autonomous - but are they becoming more secure? In this episode of Protect It All, host Aaron Crow welcomes David Girvin for a timely discussion about one of the fastest-growing challenges in cybersecurity: AI agent security and governance. From an unconventional career as a ship captain to building one of the first governance platforms for AI agents, David shares why organizations must begin treating AI agents as powerful digital coworkers with permissions, identities, and risks that require the same level of oversight as human employees. Together, Aaron and David explore how autonomous AI systems can unintentionally create business risk, why credential starvation, execution-layer security, and human-in-the-loop controls are becoming essential, and how organizations can safely adopt AI without sacrificing security. In this episode, you'll learn: Why AI agents should be treated like insider threats The biggest security risks of autonomous AI How guardrails prevent costly AI mistakes Why human oversight still matters in an AI-driven world What credential starvation means and why it's effective Practical governance strategies for enterprise AI adoption Key Moments:  05:31 Career paths and diverse experiences 06:24 Startup experiences and mentoring journey 09:30 Exploring a career shift to marketing 15:30 Building a Successful Career 18:20 Governance and AI risks 19:24 Early AI research and presentation 23:19 Just-in-time tokens discussion 27:52 Balancing work, family, and startup challenges 30:48 Transitioning from Operations to Events 35:18 Industry friendships and shared experiences 36:04 Work stress and job challenges 39:49 Securing AI systems and LLM inputs 43:46 Developing AI observability tools 47:56 Managing session risk and autonomy levels 51:14 Security and file management controls 55:34 Cybersecurity awareness chat Whether you're building AI applications, leading cybersecurity programs, or simply exploring how AI will change your business, this episode offers practical insights into securing the next generation of intelligent systems. Tune in to learn how organizations can embrace AI innovation while keeping people, data, and critical systems protected. About the guest : David Girvin is a cybersecurity leader, security architect, and Founder & CEO of Assury.ai, where he is building execution-level governance for AI agents. With leadership experience at companies including 1Password, Red Canary, and Sumo Logic, David has spent his career helping organizations strengthen security, architecture, and AI strategy. He specializes in making complex cybersecurity and AI concepts practical and accessible, helping businesses adopt emerging technologies securely and responsibly. Links to connect David:  LinkedIn: https://www.linkedin.com/in/david-a-girvin/  Website: https://assury.ai Learn more about PrOTect IT All: Work with Aaron:
  • AI & Cybersecurity: Why People, Accountability & Resilience Still Matter 10.08.2026 51min
    Work with Aaron: https://protectitallpod.com/work/ The book: https://protectitallpod.com/book/ This episode: https://protectitallpod.com/ep118/ The OT Security Starter Kit: https://protectitallpod.com/starter-kit/ AI is changing cybersecurity at an incredible pace. But are organizations prepared for the risks that come with it? In this episode of Protect It All, host Aaron Crow sits down with Brian Schleifer, an industry veteran with decades of experience spanning the military, technology, consulting, defense, and critical infrastructure. Aaron and Brian explore what it really takes to adopt AI responsibly across IT and OT cybersecurity. Beyond the technology itself, they examine the human side of security, including communication, collaboration, accountability, and the skills needed to make new technologies work in the real world. The conversation also tackles the growing challenges of AI governance, shadow AI, continuous monitoring, and cyber-physical resilience. Rather than treating AI as a magic solution, Brian offers a practical perspective on how organizations can be intentional about where and how they use AI while preparing for the disruptions it may create. Key Learnings:  How organizations can approach AI adoption in IT and OT cybersecurity Why communication and collaboration are critical to successful security programs The growing risks of shadow AI and AI governance Why human accountability remains essential as AI becomes more capable How continuous monitoring can strengthen cyber-physical security Why organizations need to think beyond prevention and prepare for resilience and business continuity How people, process, and technology must work together in an AI-driven environment Key Moments:  05:22 Working in tech and cybersecurity 07:23 Importance of people skills in business 10:20 Importance of Listening First 14:31 Implementing Machine Learning Thoughtfully 16:44 Importance of Human Oversight in AI 20:21 Discussing security and human accountability 24:24 Publishing a book with AI tools 27:47 Future of computing technology 31:39 Focusing on disaster recovery strategies 35:27 Budgeting Challenges with Emerging Tech 38:00 Focus on proactive security planning 40:40 Evaluating cybersecurity effectiveness 45:49 Challenges in incident response logistics 47:33 Talking about Security Week events Whether you're a cybersecurity leader, OT professional, technology executive, or simply trying to understand what AI means for the future of security, this episode offers practical perspectives on navigating the change without losing sight of what matters most. Listen to the latest episode of Protect It All and discover how organizations can embrace AI while building the trust, accountability, and resilience needed to protect what matters. About the Guest :  Brian "SchleiF" Schleifer is a retired United States Air Force veteran, cybersecurity professional, content leader, and owner of PAVE Consulting LLC, which provides digital content creation and cybersecurity consulting. Through PAVE Consulting, he currently supports SecurityWeek as Director of Content and Events, helping lead conferences, podcasts, webinars, and executive-level cybersecurity programming. Brian previously served in senior cybersecurity engineering and leadership roles at Modern Technology Solutions Inc. His exper...
  • OT Pen Testing: Why Trust, Culture & Hands-On Experience Matter Most 03.08.2026 1t 10min
    Work with Aaron: https://protectitallpod.com/work/ The book: https://protectitallpod.com/book/ This episode: https://protectitallpod.com/ep117/ The OT Security Starter Kit: https://protectitallpod.com/starter-kit/ Effective OT penetration testing isn't just about finding vulnerabilities, it's about building trust. In this episode of Protect It All, host Aaron Crow is joined by Oren Niskin and Reynaldo Gonzalez for an engaging discussion on the evolving role of penetration testing in operational technology (OT) environments. Drawing from years of experience in industrial operations, IT, and OT cybersecurity, Oren and Reynaldo explain why successful OT security assessments require far more than technical expertise. They explore how trust, communication, and collaboration help bridge the gap between security teams and operations, making penetration testing a valuable business tool rather than something to fear. The conversation also highlights the importance of diverse career paths, hands-on learning, and mentoring the next generation of cybersecurity professionals. From network segmentation and risk communication to creating realistic lab environments, this episode offers practical lessons for anyone responsible for securing critical infrastructure. Key Learnings:  Why trust is essential for successful OT penetration testing How IT and operational experience strengthen OT security teams The value of network segmentation in reducing cyber risk Why "doing nothing" is no longer an acceptable cybersecurity strategy How organizations can bridge the gap between safety, operations, and security Practical ways to develop the next generation of OT cybersecurity professionals Key Moments:  07:00 Oren's technology and security approach 15:04 Discussing network security measures 19:16 Building Trust in Business Relationships 26:17 Understanding and planning security architecture 30:16 Network management and rule assessment 33:39 Managing and Assessing Tool Overload 38:39 Analyzing tool overlap and complementarity 48:41 Building a trusting team culture 49:48 Encouraging Open Communication 56:34 Getting into cybersecurity without IT experience 01:04:56 Entry-level ICS training courses Whether you're an OT engineer, penetration tester, security leader, or just beginning your cybersecurity journey, this episode delivers practical insights into protecting industrial environments while building stronger relationships across teams. Tune in to discover why the most successful OT penetration tests don't just identify vulnerabilities they build trust, strengthen teams, and improve security for the long term. About the guests:  Oren Niskin is Principal OT Security Engineer at GuidePoint Security. His 20-year arc runs from the US Navy as a Nuclear Electrician's Mate, to Electronics Technician on offshore drilling rigs, to office OT/IT management, to OT cybersecurity consulting at EY, and now into OT cyber engineering at GuidePoint. He also runs Packets Or It Didn't Happen, a YouTube livestream where he builds a factory-realistic PLC and HMI training kit on camera (the open-source PLC Trainer Kit), aimed at helping newcomers get hands-on with OT for under $500. Link to connect Oren Niskin: LinkedIn: https://www.linkedin.com/in/orenniskin/ YouTube:
  • Cybersecurity Leadership: Why People Matter More Than Technology 27.07.2026 51min
    Work with Aaron: https://protectitallpod.com/work/ The book: https://protectitallpod.com/book/ This episode: https://protectitallpod.com/ep116/ The OT Security Starter Kit: https://protectitallpod.com/starter-kit/ The biggest cybersecurity challenge isn't technology - it's people. In this episode of Protect It All, host Aaron Crow welcomes Swapnil Kachave for an insightful conversation about what it really takes to build high-performing cybersecurity teams in an era of AI, automation, and increasing cyber threats. Having built and led Security Operations Center (SOC) teams across five industries, Swapnil shares why successful cybersecurity programs are driven by leadership, communication, and continuous learning - not just the latest tools. Together, Aaron and Swapnil explore the growing impact of alert fatigue, burnout, workforce development, and the changing role of AI in modern security operations. They also discuss why "people debt" can become just as dangerous as technical debt and how organizations can create resilient teams prepared for the future. Key Moments:  Why cybersecurity leadership is fundamentally about people How to reduce alert fatigue and improve SOC performance The importance of mentoring, training, and career development How AI is changing security operations - and the skills teams need next Why communication and empathy make better security leaders How organizations can prepare teams for emerging technologies like AI and quantum computing Whether you're leading a SOC, managing cybersecurity programs, or just beginning your security career, this episode delivers practical leadership lessons that extend far beyond technology. Key Moments:  06:04 Dealing with alert fatigue 07:55 Navigating SOC career growth 13:54 From network admin to new opportunities 14:41 Diverse career path overview 21:02 Translating tech issues for executives 23:41 Importance of Soft Skills in Tech 25:50 Prioritizing practical knowledge over trends 31:03 Prototyping and learning new skills 35:26 Using AI to validate ideas 37:57 Human awareness vs. tech evolution 41:32 Quality assurance in AI responses 42:40 Discussing AI system reliability 46:05 Accelerating processes with AI tools Tune in to discover why investing in people is still the most effective cybersecurity strategy - only on Protect It All. About the guest :  Swapnil Kachave is a cybersecurity operations leader with extensive experience building and leading Security Operations Center (SOC) teams across five industries. Passionate about developing people as much as technology, Swapnil specializes in security operations, incident response, and leadership development. They focus on helping organizations build resilient cybersecurity teams by balancing technical excellence with communication, mentorship, and continuous learning in an increasingly AI-driven world. How to connect Swapnil:  LinkedIn: https://www.linkedin.com/in/swapniilkachave/ Website: https://www.optiv.com/= Learn more about PrOTect IT All: Work with Aaron: https://protectitallpod.com/work/ The book: https://protectitallpod.com/book/ This e...
  • Conficker Still Exists? The Hidden OT Malware Threat Putting Critical Infrastructure at Risk 20.07.2026 45min
    Work with Aaron: https://protectitallpod.com/work/ The book: https://protectitallpod.com/book/ This episode: https://protectitallpod.com/ep115/ The OT Security Starter Kit: https://protectitallpod.com/starter-kit/ Some of the biggest cybersecurity threats to critical infrastructure aren't new - they've simply never gone away. In this episode of Protect It All, host Aaron Crow welcomes back Lesley Carhart for a fascinating conversation about why decades-old malware like Conficker continues to infect operational technology (OT) environments around the world. Drawing on nearly two decades of industrial incident response experience, they share real-world stories from the front lines of critical infrastructure, explaining why legacy systems, operational constraints, and workforce shortages continue to make remediation incredibly challenging. The discussion goes far beyond "just patch it," exploring the difficult risk decisions organizations face when uptime, safety, and cybersecurity all compete for priority. Aaron and Lesley also examine one of the industry's most pressing issues: the growing shortage of OT cybersecurity talent and the need to rebuild foundational technical skills for the next generation of defenders.  Key Learnings:  Why malware like Conficker still exists in modern OT environments The unique challenges of removing malware from industrial control systems Why patching isn't always possible in operational technology How legacy infrastructure creates long-term cybersecurity risk The growing OT cybersecurity skills gap - and how the industry can address it Practical lessons from real-world industrial incident response Key Moments:  05:47 Challenges with Old Industrial Systems 06:58 Struggles with malware cleanup 11:02 Challenges in Cyber Security Careers 16:19 Dealing with malware spread 17:53 Managing infection risk long-term 23:04 Challenges with nuclear hardware upgrades 27:05 Training the Next Tech Generation 29:33 Importance of Computer Basics 34:04 Discovering hidden technical issues 37:01 Troubleshooting in industrial environments 39:10 Malware and botnets era 42:20 Developing low-touch security solutions Whether you're responsible for manufacturing, utilities, energy, transportation, or any critical infrastructure environment, this episode provides practical insight into one of OT cybersecurity's longest-running challenges. Tune in to discover why yesterday's malware is still creating today's biggest industrial cybersecurity problems - and what organizations can do about it. About the guest :  Lesley Carhart is a Principal Industrial Incident Responder at Dragos and a recognized expert in OT and industrial cybersecurity. With nearly two decades of experience in incident response, digital forensics, and threat hunting, they help organizations defend critical infrastructure from cyber threats targeting industrial control systems. Lesley is also a respected speaker, instructor, and advocate for cybersecurity education, regularly sharing their expertise with industry professionals and the next generation of defenders. How to connect Lesley:  LinkedIn: https://www.linkedin.com/in/lcarhart/ Youtube: https://www.youtube.com/user/hacks4...
  • OT Cybersecurity: Why Trust Beats Technology | Jacob McCune | Ep 114 13.07.2026 47min
    Work with Aaron: https://protectitallpod.com/work/ The book: https://protectitallpod.com/book/ This episode: https://protectitallpod.com/ep114/ The OT Security Starter Kit: https://protectitallpod.com/starter-kit/ The biggest challenge in OT cybersecurity isn't technology - it's earning trust. In this episode of Protect It All, host Aaron Crow sits down with Jacob McCune, a cybersecurity architect with more than 20 years of hands-on experience across both IT and OT environments. Jacob shares his unconventional journey from the help desk to securing critical infrastructure, highlighting the lessons that only real-world experience can teach. Together, Aaron and Jacob explore why communication, collaboration, and trust are often the deciding factors between successful cybersecurity programs and failed initiatives. The conversation also dives into the future of OT security, examining how AI, cloud technologies, and evolving architectures are changing industrial environments and why organizations need to rethink traditional approaches while keeping operational realities front and center. Key Learning:  Why trust is the foundation of successful OT cybersecurity programs How practical experience shapes better cybersecurity decisions The importance of communication between IT, OT, and leadership teams Why compliance alone doesn't guarantee security How AI and cloud technologies are reshaping OT environments What the future may look like beyond traditional industrial architectures Key Moments:  05:18 Building a Power Plant Team 09:06 Balancing cybersecurity with business needs 11:01 Avoiding project delays during downtime 16:04 Importance of Broad Experience 17:59 A mentor's lesson on teamwork 23:41 Challenges with job postings and requirements 26:27 Managing risk and resource challenges 29:59 Helping Your Compliance Team 33:12 Dad's long career and expertise 36:44 Discussing cybersecurity risk management 39:44 Cloud resources and AI discussions 41:08 Exploring future solutions and technologies Whether you're building an OT security program, managing critical infrastructure, or looking to grow your cybersecurity career, this episode delivers practical lessons from years of real-world experience. Tune in to discover why people, trust, and communication remain the most valuable assets in modern cybersecurity only on Protect It All. About the guest:  Jacob McCune is a cybersecurity architect with more than 20 years of experience across IT and OT environments, helping organizations secure critical infrastructure through practical, real-world security strategies. From starting his career on the help desk to designing enterprise security architectures, Jacob has built a reputation for bridging the gap between IT and OT through collaboration, communication, and trust. He is passionate about helping organizations move beyond compliance to build resilient cybersecurity programs that protect both people and operations. Links to connect Jacob :  LinkedIn: https://www.linkedin.com/in/jake-mccune-33a08984/  CornCon Cybersecurity Conference : https://corncon.net/ Learn more about PrOTect IT All: Work with Aaron: https://p...
  • AI for OT Cybersecurity: Real-World Strategies to Protect Critical Infrastructure 06.07.2026 1t 12min
    Work with Aaron: https://protectitallpod.com/work/ The book: https://protectitallpod.com/book/ This episode: https://protectitallpod.com/ep113/ The OT Security Starter Kit: https://protectitallpod.com/starter-kit/ AI is changing OT cybersecurity - but success still depends on understanding your operations. In this episode of Protect It All, host Aaron Crow welcomes Vivek Ponnada for a practical conversation about how artificial intelligence is transforming the way organizations defend critical infrastructure. With decades of experience in industrial automation and OT security, Vivek shares firsthand insights into the realities of protecting legacy control systems while preparing for a future increasingly shaped by AI, automation, and digital transformation. Together, Aaron and Vivek discuss how organizations can use AI to improve visibility, accelerate threat detection, prioritize vulnerabilities, and strengthen operational resilience, without losing sight of the fundamentals that keep industrial environments safe. Key Learning:  How AI is transforming OT cybersecurity and industrial operations Practical AI use cases for protecting critical infrastructure Why legacy systems remain one of the biggest OT security challenges How AI can improve vulnerability management and incident response The role of digital twins in strengthening cyber resilience Why trust, collaboration, and operational knowledge remain essential in OT security Whether you're responsible for manufacturing, utilities, energy, water, or other critical infrastructure, this episode provides practical insights into balancing innovation with operational reliability. Tune in to discover how AI can strengthen OT cybersecurity while helping organizations protect the systems that keep the world running. Key Moments:  06:43 AI and cloud adoption in OT 13:27 Controller logic changes and safety steps 21:24 Discussing Digital Twins for Security Use 26:51 Managing vulnerabilities at scale 32:41 Understanding Power Plant Limitations 37:17 Keeping up with plant changes 41:43 Automating infrastructure and maintenance 49:08 Rising importance of cybersecurity investment 52:16 Early days in cybersecurity and OT 01:00:03 Ransomware impacts on industries 01:01:53 Using GPUs for security and OT About the guest :  Vivek Ponnada is an Operational Technology (OT) Security practitioner with global experience and currently serves as the SVP of Growth & Strategy at Frenos, the world's first Simulated OT Pentesting Platform. Having started his career in Industrial Control Systems (ICS) as a Technician, Vivek became a Controls Engineer and commissioned Gas Turbines in Europe, Middle-East, Africa and South-East Asia. Post MBA, Vivek held multiple roles in Sales, Marketing & Business Development and Services covering ICS and OT Security solutions for Critical Infrastructure industries (Power, Oil & Gas etc.) at GE, XenonCyber Dynamics and Nozomi Networks. He was a co-lead for the Top 20 Secure PLC Coding Practices Project and regularly speaks at Information Security Conferences. Vivek has a C.Eng. from IEI, MBA from McCombs (UT Austin) and holds the ISA/IEC 62443 Cybersecurity Expert & GICSP certifications. He is a member of the ISA, ISACA, Public Safety Canada ICS Security Symposium Advisory Committee and is a CS2AI Fellow. How to connect Vivek:...
  • OT Cybersecurity That Works: Defense in Depth, AI Risks & Protecting Critical Infrastructure 29.06.2026 44min
    Work with Aaron: https://protectitallpod.com/work/ The book: https://protectitallpod.com/book/ This episode: https://protectitallpod.com/ep112/ The OT Security Starter Kit: https://protectitallpod.com/starter-kit/ When it comes to OT cybersecurity, the fundamentals still matter - even in the age of AI. In this episode of Protect It All, host Aaron Crow sits down with Caleb Davis for a practical discussion on securing industrial environments where uptime, safety, and resilience are non-negotiable. From legacy control systems and tight budgets to AI-powered threats and open-source security tools, Aaron and Caleb explore the real challenges organizations face every day - and the strategies that deliver meaningful protection without requiring massive investments. A major focus of the conversation is defense in depth: building multiple layers of protection, fostering trust between IT and OT teams, and strengthening foundational cybersecurity practices before chasing the latest technology. You'll learn: Why defense in depth remains the cornerstone of OT cybersecurity How to improve security in legacy industrial environments Practical ways to strengthen OT security - even with limited budgets Why asset inventory, segmentation, and basic cyber hygiene still matter most How AI is changing both offensive and defensive cybersecurity The importance of trust and collaboration between IT, engineering, and operations Whether you're responsible for manufacturing, utilities, water treatment, energy, or any critical infrastructure environment, this episode delivers practical strategies you can apply immediately. Tune in to learn how layered defenses, strong relationships, and proven fundamentals create resilient OT security programs - only on Protect It All. Key Moments:  05:41 PLCs and network security challenges 07:24 Challenges in Updating OT Systems 11:33 Impact of Downtime on Security 16:03 Using affordable cybersecurity tools 19:14 Building Trust in Business Deals 23:01 Security challenges in medical devices 25:49 Trust and IT implementation risks 28:35 Using AI for safer software updates 31:05 Cybersecurity best practices for plants 33:40 Balancing Security Costs and Business Needs 37:50 Nurturing OT like raising kids 41:20 AI and cybersecurity concerns About the guest : Caleb Davis is a founding member of SolaSec, a cybersecurity consulting firm specializing in advanced penetration testing for embedded and connected systems. Based in Dallas/Fort Worth, he holds a degree in Electrical Engineering from the University of Texas at Tyler and is a patent-holding expert with vast experience in hardware and firmware security. Caleb leads deep technical assessments across a range of high-impact industries, including medical devices, automotive, industrial control systems, ATMs and financial terminals, aerospace components, and consumer electronics. His work focuses on secure design, trusted boot processes, cryptographic implementations, and threat modeling, helping organizations integrate security throughout the development lifecycle and align with industry and regulatory standards. How to connect Celeb : SolaSec: https://solasec.io  LinkedIn: https://www.li...
  • Quantum Readiness: The Cybersecurity Threat Most Organizations Aren’t Prepared For 22.06.2026 41min
    Work with Aaron: https://protectitallpod.com/work/ The book: https://protectitallpod.com/book/ This episode: https://protectitallpod.com/ep111/ The OT Security Starter Kit: https://protectitallpod.com/starter-kit/ Quantum computing isn't a future problem - it's a cybersecurity challenge organizations need to start preparing for today. In this episode of Protect It All, host Aaron Crow welcomes Jim Sortino for a timely discussion on quantum readiness, cryptographic risk, and the future of cybersecurity. As organizations continue accumulating technical debt and relying on aging cryptographic systems, the arrival of quantum computing threatens to disrupt the very foundations of digital trust. Jim explains why leaders need to think beyond today's threats and begin preparing for a future where current encryption standards may no longer provide adequate protection. Together, Aaron and Jim explore the practical realities of quantum risk, how organizations can identify vulnerable systems, and why crypto agility is becoming one of the most important cybersecurity priorities of the next decade. You'll learn: What quantum computing means for modern cybersecurity Why cryptographic technical debt creates long-term business risk How to assess your organization's quantum readiness The importance of crypto agility and encryption modernization Practical steps security leaders can take today Why IT and OT environments must prepare for the same emerging threats Whether you're a cybersecurity professional, technology leader, board member, or simply curious about the future of digital security, this episode provides actionable insights to help you prepare before quantum disruption arrives. Tune in to learn why the organizations that start preparing today will be the ones best positioned to protect tomorrow. Key Moments:  06:02 Challenges with product maintenance and AI integration 08:42 Importance of Software in Everything 12:30 Addressing cybersecurity risks 16:00 Authentication and trust challenges 18:13 Preparing for technological changes 20:56 Planning and Implementing Projects 25:38 Budget planning for cybersecurity risks 28:54 Challenges for Small Financial Institutions 31:27 Importance of regulations in business 33:37 Legacy security systems and protocols 36:38 Quantum readiness and future risks About the guest :  Jim Sortino is the Chief Revenue Officer and a Board Member at Isera Corporation, where he helps organizations address emerging cybersecurity challenges through innovative identity and cryptographic security solutions. With decades of experience working with global enterprises, Jim specializes in helping leaders navigate complex technology risks, from technical debt and encryption modernization to quantum readiness. He is a passionate advocate for proactive cybersecurity strategies that prepare organizations for the next generation of digital threats. How to connect Jim Sortino : https://www.linkedin.com/in/jamessortino/ Learn more about PrOTect IT All: Work with Aaron: https://protectitallpod.com/work/ The book: https://protectitallpod.com/book/ This episode: https:...
  • Cybersecurity vs Resilience: What Business Leaders Need to Know About Managing Risk 15.06.2026 44min
    Work with Aaron: https://protectitallpod.com/work/ The book: https://protectitallpod.com/book/ This episode: https://protectitallpod.com/ep110/ The OT Security Starter Kit: https://protectitallpod.com/starter-kit/ Cybersecurity isn't the goal. Business resilience is. In this episode of Protect It All, host Aaron Crow sits down with Lee Ward to explore why organizations need to move beyond compliance checklists and start focusing on what really matters: the ability to withstand, recover from, and adapt to disruption. Drawing on more than two decades of experience spanning the UK civil service, logistics, supply chain operations, and governance, risk, and compliance (GRC), Lee shares practical insights on helping boards and executives understand cyber risk in business terms. Together, Aaron and Lee discuss the realities of risk acceptance, operational technology challenges, patching constraints, and why resilience not perfection should be the ultimate objective of any cybersecurity program. You'll learn: Why resilience is a better business objective than security alone How to communicate cyber risk to boards and executive leadership The difference between compliance and meaningful risk reduction Practical approaches to OT security, patching, and operational constraints Why risk acceptance is a critical leadership responsibility How logistics and supply chain organizations approach resilience planning Whether you're a security leader, executive, risk manager, or OT practitioner, this episode provides practical guidance for building organizations that can continue operating when disruptions inevitably occur. Tune in to learn why resilience not just security is becoming the defining metric of successful organizations. Key Moments:  03:59 Understanding Cyber Risks for Leaders 07:16 Discussing non-cyber risks to services 11:12 Understanding business impact of cyber risk 15:45 Evaluating Cybersecurity Risks 19:37 Understanding installation complexities 21:15 Global risks affecting business resilience 24:27 Discussing regulation impacts on business 29:30 People's drive to make good choices 31:27 Industrial control systems demo at DEFCON 34:43 Limitations of technical security 38:06 The future of AI and education About the guest : Lee Ward is a Governance, Risk Management, and Compliance (GRC) leader with more than 20 years of experience spanning the UK civil service, logistics, supply chain operations, and cybersecurity. Specializing in business resilience, risk governance, and operational technology security, Lee helps organizations translate complex cyber risks into meaningful business decisions. He is passionate about moving beyond compliance-driven security programs and helping leaders build resilient organizations that can adapt, recover, and thrive in an increasingly uncertain world. How to connect Lee:  https://www.linkedin.com/in/lee-ward-882a54244/ Learn more about PrOTect IT All: Work with Aaron: https://protectitallpod.com/work/ The book: https://protectitallpod.com/book/ This episode: https://protectitallpod.com/ep110/ The OT Security Starter Kit:
  • Continuous Trust in Cybersecurity : Why Identity Is the New Security Perimeter 08.06.2026 44min
    Work with Aaron: https://protectitallpod.com/work/ The book: https://protectitallpod.com/book/ This episode: https://protectitallpod.com/ep109/ The OT Security Starter Kit: https://protectitallpod.com/starter-kit/ What if trust wasn't something you granted once - but something you continuously verified? In this episode of Protect It All, host Aaron Crow sits down with Frank Goodman to explore one of the most important challenges in modern cybersecurity: establishing trust in an increasingly connected world. As organizations expand across cloud, OT, AI, APIs, and distributed workloads, traditional approaches based on static credentials, API keys, and long-lived tokens are struggling to keep up with modern threats. Frank shares his vision for continuous trust, where cryptographic source identity and automated policy enforcement work together to verify every interaction in real time. Together, Aaron and Frank discuss how organizations can move beyond traditional security models and build architectures capable of responding to threats at machine speed. You'll learn: Why static keys and tokens remain a major cybersecurity weakness How continuous trust differs from traditional Zero Trust approaches The growing importance of source identity across IT, OT, cloud, and AI environments How automated policy enforcement improves visibility and response times Why supply chain and API-based attacks continue to challenge organizations What the future of cybersecurity looks like when trust becomes dynamic and continuous Whether you're responsible for enterprise security, critical infrastructure, cloud operations, or emerging AI systems, this episode offers a practical look at the next evolution of cyber defense. Tune in to discover why identity, trust, and automation are becoming the foundation of modern cybersecurity - only on Protect It All. Key Moments:  03:56 Importance of cryptographic source identity 08:52 Securing software supply chains 11:31 Current gaps in network security solutions 16:51 Improving cybersecurity through source identity 17:50 Trust thresholds and security priorities 23:51 Monitoring and securing backend systems 24:51 Managing security with SaaS providers 30:35 Enterprise security and infrastructure challenges 32:23 Adapting to new technologies 36:08 Improving cybersecurity tool integration 40:38 Innovative tech solutions discussion About the guest :  Frank Goodman is a cybersecurity entrepreneur with 25+ years of experience in enterprise infrastructure and security. After leadership roles at Gigamon, NetScout, and VSS Monitoring, he founded Onoratio to tackle what he sees as a fundamental cybersecurity challenge: building continuous trust and verifiable source identity into the infrastructure itself. How to connect Frank : https://www.linkedin.com/in/frankgoodman/ Learn more about PrOTect IT All: Work with Aaron: https://protectitallpod.com/work/ The book: https://protectitallpod.com/book/ This episode: https://protectitallpod.com/ep109/ The OT Security Starter Kit:
  • Breaking Into Cybersecurity: Soft Skills, Networking & Standing Out in a Crowded Market 01.06.2026 1t 2min
    Work with Aaron: https://protectitallpod.com/work/ The book: https://protectitallpod.com/book/ This episode: https://protectitallpod.com/ep108/ The OT Security Starter Kit: https://protectitallpod.com/starter-kit/ Technical skills might get your attention - but soft skills build cybersecurity careers. In this episode of Protect It All, host Aaron Crow sits down with technology leader and mentor Robert Whetstine for a candid conversation about what it really takes to succeed in today’s cybersecurity job market. As AI reshapes hiring, the market becomes more crowded, and professionals struggle to stand out, Aaron and Robert explore the overlooked factors that often determine long-term success: adaptability, networking, authenticity, and communication. This episode goes beyond résumés and certifications to focus on the human side of career growth. You’ll learn: Why soft skills matter as much as technical ability in cybersecurity How networking and community create real career opportunities The impact of AI and oversaturation on the cybersecurity job market How to stand out without relying only on certifications Why adaptability and continuous learning are critical for long-term success Lessons on leadership, resilience, and professional growth from decades in tech Whether you’re breaking into cybersecurity, navigating a career transition, or trying to stay relevant in a fast-changing industry, this episode delivers practical advice and honest insights for building a sustainable and rewarding career. Tune in to learn why relationships, mindset, and adaptability are becoming the true differentiators in cybersecurity - only on Protect It All. Key Moments:  07:31 Developing essential soft skills 11:44 Embracing leadership and failure 16:14 Evaluating candidates for fit 22:00 Building a career through networking 31:16 Taking risks and finding support 35:16 The importance of empathetic leadership 38:34 Networking for job opportunities 47:28 Discussing layoffs for AI investment 50:07 Concerns about infrastructure cost 53:40 Entering the tech industry About the guest :  Rob Whetstine (#BowTieSecurityGuy) has been in the technology and Cyber Security space for the last two decades. Known for the Mentoring, Making and of course his nerdy bowties. Born with an obsession for problem-solving, Rob's journey into the world of technology began at a young age, where he spent countless hours tinkering with computers found in the trash. When he was laid off a year ago from Disney after almost 20 years of service. He made it his mission to help people anyway he could. Those who were struggling in this job market and people new to Cyber. He started sharing videos on LinkedIn about his journey and sharing leadership stories. He has now started a podcast and mentors people all over the world. How to connect Rob : LinkedIn https://www.linkedin.com/in/bowtiesecurityguy/ Youtube: https://www.youtube.com/@bowtiesecurityguy Connect With Aaron Crow: Website: www.corvosec.com  LinkedIn: https://www.linkedin.com/in/aaronccrow Learn m...
  • AI, Cybersecurity & Career Growth: Why Curiosity Matters More Than Credentials 25.05.2026 52min
    Work with Aaron: https://protectitallpod.com/work/ The book: https://protectitallpod.com/book/ This episode: https://protectitallpod.com/ep107/ The OT Security Starter Kit: https://protectitallpod.com/starter-kit/ The future of cybersecurity belongs to people who can adapt - not just those with the longest list of certifications. In this episode of Protect It All, host Aaron Crow sits down with Peter Schawacker for a candid conversation about the evolving intersection of AI, cybersecurity, talent, and career growth. With nearly 30 years of experience in cybersecurity and technology leadership, Peter shares real-world insights on what organizations are getting wrong about hiring, why curiosity often matters more than credentials, and how AI is reshaping both technical work and the future of security teams. Together, Aaron and Peter unpack the changing role of CISOs, the dangers of checkbox-driven hiring, and why nontraditional talent may hold the key to solving the industry’s growing skills gap. You’ll learn: Why soft skills and curiosity are becoming critical cybersecurity assets How AI is transforming cybersecurity recruiting and technical roles The growing challenges around technical debt and workforce readiness Why traditional credentials don’t always predict success How CISOs and leaders should think differently about talent and culture Practical career advice for cybersecurity professionals navigating rapid change Whether you’re building a cyber team, hiring talent, or planning your next career move, this episode delivers honest insights into what it really takes to thrive in the AI-driven future of cybersecurity. Tune in to learn why adaptability, curiosity, and human ingenuity still matter most - only on Protect It All.. Key Moments:  04:08 The role of security in business 09:24 Managing Aramis online security 11:22 Hiring mindset for troubleshooting skills 13:55 Evaluating AI talent challenges 16:26 Discussing vulnerabilities in software 22:24 Early days of hacking and tech 25:55 Realizing the power of soft skills 28:15 Browsing eclectic book collections 32:13 Recent grads and AI opportunities 33:24 Getting into cybersecurity careers 37:22 Unexpected paths into security careers 40:41 Importance of critical thinking 44:35 Explaining tech's evolution over time About the Guest : Peter Schawacker is the Founder & CEO of Nearshore Cyber and a cybersecurity executive with more than 25 years of experience across multiple industries. A former CISO in four sectors, Peter specializes in cyber risk, AI governance, and workforce development. He is the creator of ARAMIS Insight, an AI-powered cybersecurity workforce competency platform aligned to the NIST NICE framework, and author of Governing AI at the Edge: An Operating Model for Citizen Development in the Enterprise. How to connect Peter:  LinkedIn: https://www.linkedin.com/in/schawacker  Nearshore Cyber: https://nearshorecyber.com.mx | ARAMIS Insight: https://project-aramis.com/insight  Email: [email protected] Phone: +1 (760) 880-4258
  • AI in OT Cybersecurity: Real-World Risks, Smarter Defenses & the Future of Critical Infrastructure 18.05.2026 49min
    Work with Aaron: https://protectitallpod.com/work/ The book: https://protectitallpod.com/book/ This episode: https://protectitallpod.com/ep106/ The OT Security Starter Kit: https://protectitallpod.com/starter-kit/ AI is rapidly transforming cybersecurity but are critical infrastructure environments ready for what comes next? In this episode of Protect It All, host Aaron Crow sits down with longtime colleague and cybersecurity expert Clark Liu to explore how artificial intelligence is reshaping both IT and OT security operations. From incident response and compliance frameworks to workforce shifts and operational resilience, Aaron and Clark unpack the real-world opportunities and very real risks of integrating AI into industrial environments. Together, they tackle the evolving role of frameworks like NERC CIP and NIST, the challenges of balancing compliance with actual security outcomes, and how organizations can responsibly adopt AI without increasing exposure. You’ll learn: How AI is changing OT and IT cybersecurity operations The role of AI in incident response, documentation, and monitoring Why compliance frameworks alone don’t guarantee resilience The risks of adopting AI without strong operational foundations How organizations can prepare for AI-powered threats and workforce changes Practical insights for balancing innovation, budgets, and security priorities Whether you’re leading OT security, managing critical infrastructure, or evaluating AI adoption in your organization, this episode delivers practical guidance for navigating cybersecurity’s next major shift. Tune in to learn how AI is transforming cyber defense and what organizations must do to stay resilient only on Protect It All. Key Moments;  05:33 Understanding cybersecurity compliance frameworks 07:11 Overlooked vulnerabilities in systems 09:59 Balancing multiple firewall vendors 15:17 Delegating tasks to AI 19:11 Importance of documenting commits 21:51 Hospital system shutdown crisis 25:11 AI uncovering software vulnerabilities 26:37 Engineers implementing AI in automation 31:26 AI tools and personal security 32:55 Password security practices 36:46 Using AI for basic tasks 39:38 Transition to off-the-shelf software 42:29 Going back to basics with appliances 47:02 Excitement About Future AI Capabilities Guest Profile :  Clark Liu is a veteran OT cybersecurity expert and one of the original contributors to the NERC CIP standards. With nearly two decades in energy and critical infrastructure security - including leadership roles at EY and GALLO - Clark specializes in OT risk management, compliance strategy, and securing industrial operations from the plant floor to the cloud. How to connect Clark:  LinkedIn :  https://www.linkedin.com/in/clarkliu/ Connect With Aaron Crow: Website: www.corvosec.com  LinkedIn: https://www.linkedin.com/in/aaronccrow Learn more about PrOTect IT All: Work with Aaron: https://protectitallpod.com/work/ The book:
  • AI Agents & Cybersecurity: Identity, Compliance, and the New Risks Facing IT and OT 11.05.2026 1t 6min
    Work with Aaron: https://protectitallpod.com/work/ The book: https://protectitallpod.com/book/ This episode: https://protectitallpod.com/ep105/ The OT Security Starter Kit: https://protectitallpod.com/starter-kit/ AI agents are changing cybersecurity faster than most organizations can adapt. In this episode of Protect It All, host Aaron Crow welcomes back cybersecurity veteran Ken Foster for a deep dive into how AI is reshaping risk, identity, and resilience across IT and OT environments. With more than 30 years of experience spanning the Navy, manufacturing, fintech, government programs, and startups, Ken brings a grounded, real-world perspective on what organizations are getting right and dangerously wrong about AI adoption. Together, Aaron and Ken explore the growing challenges around AI agents, identity governance, shadow AI, compliance, and attribution in highly regulated industries. As AI tools become embedded into workflows and decision-making, organizations must rethink how they manage access, monitor activity, and maintain resilience against rapidly evolving threats. You’ll learn: Why AI agents introduce new identity and governance risks The dangers of shadow AI inside enterprise environments How AI impacts compliance, attribution, and accountability Why foundational practices like patching, segmentation, and documentation still matter The role of continuous monitoring in AI-driven environments How organizations can balance innovation with resilience and control Whether you’re leading cybersecurity strategy, managing critical infrastructure, or navigating AI adoption inside regulated environments, this episode delivers practical insights for securing the next generation of digital operations. Tune in to learn how AI is transforming cybersecurity - and what leaders must do to stay ahead - only on Protect It All. Key Moments:  07:47 AI guardrails discussion 12:02 Patching and network segmentation 20:44 AI changing job roles 24:24 FISMA and FedRAMP concerns 29:18 Emergency response planning 35:36 Choosing the right tech team 37:14 Discussing accountability and risk 46:31 Developer access problems 51:50 AI Dependence Risks 57:36 AI in pen testing 58:55 AI in risk prevention About the guest : Ken Foster is a veteran cybersecurity leader with 25+ years of experience in enterprise security, risk governance, and global infrastructure strategy. Currently Head of Global Architecture at Adient, Ken has previously led cybersecurity and compliance programs at Fleetcor and Fiserv, specializing in IAM, cloud security, regulatory compliance, and risk-based cybersecurity strategy. He is known for helping organizations balance innovation, resilience, and operational execution in highly regulated environments. How to connect Ken: http://linkedin.com/in/kennethfoster/ Connect With Aaron Crow: Website: www.corvosec.com  LinkedIn: https://www.linkedin.com/in/aaronccrow Learn more about PrOTect IT All: Work with Aaron: https://p...
  • From NFL to OT Cybersecurity Why Trust and Teamwork Matter More Than Tools | Aaron Crow 04.05.2026 48min
    Work with Aaron: https://protectitallpod.com/work/ The book: https://protectitallpod.com/book/ This episode: https://protectitallpod.com/ep104/ The OT Security Starter Kit: https://protectitallpod.com/starter-kit/ Cybersecurity isn’t just about technology - it’s about people. In this episode of Protect It All, host Aaron Crow sits down with Sean Tufts for a conversation that goes far beyond tools and tactics. From the locker room to control rooms, Sean shares how his journey from professional football to OT cybersecurity shaped his approach to trust, teamwork, and leadership. Together, they unpack one of the biggest challenges in OT environments: building trust between IT and OT teams. Because without trust, even the best tools fail. You’ll learn: Why trust is the foundation of OT cybersecurity success How to bridge the gap between IT teams and engineers The role of communication and empathy in security programs Real-world lessons from segmentation failures and hidden network risks Why diversity and teamwork drive stronger security outcomes How leadership mindset shapes resilience in high-stakes environments Whether you’re leading cybersecurity, working in OT environments, or building cross-functional teams, this episode delivers practical insights on the human side of security—where real progress happens. Tune in to learn why the strongest cybersecurity programs are built on people, not just platforms only on Protect It All. Key Moments:  05:11 Importance of communication in tech 06:58 Learning from early career mistakes 11:40 Implementing network scanning in OT environments 15:50 Debating project priorities in cybersecurity 18:24 Improving system reliability and ROI 20:28 Convincing plants to self-fund projects 26:21 Creating layered RACI charts 26:57 Discussing people, process, and technology 31:15 Easy validations and big risks 34:35 Operators' productivity challenges 37:21 Network security in hospitals 42:25 Creating a safe network environment 43:10 Addressing network configuration issues 46:55 Different types of AI users About the guest :  Sean Tufts is Field CTO at Claroty and a cybersecurity leader with deep expertise in industrial environments. With leadership roles at GE and Optiv, he has helped asset-intensive industries navigate the intersection of OT, IT, and cyber risk. Before cybersecurity, Sean was a standout linebacker and team captain at the University of Colorado and went on to play in the NFL with the Carolina Panthers bringing the same discipline, teamwork, and leadership mindset to securing critical infrastructure today. How to connect Sean :  LinkedIn: https://www.linkedin.com/in/sean-tufts-36b4909/ Website: https://claroty.com/ Connect With Aaron Crow: Website: www.corvosec.com  LinkedIn: https://www.linkedin.com/in/aaronccrow Learn more about PrOTect IT All: Work with Aaron: https://protectitallpod.com/work/ The book:

Suosittu maassa

Tämä podcast esiintyy myös näiden maiden podcast-listoilla.