Couverture de PrOTect It All

PrOTect It All

PrOTect It All

De : Aaron Crow | Operational Technology & Cybersecurity Host
Écouter gratuitement

Offres de saison | 0,99 € par mois pendant les 3 premiers mois

5,99 €/mois par la suite. Des conditions s’appliquent. Annulation mensuelle possible.
PrOTect IT All with Aaron Crow delivers weekly episodes focused on cybersecurity and operational technology, tackling emerging threats across industrial control systems, AI security, and IoT threats. The show emphasizes enterprise risk management, manufacturing security, power grid security, and threat intelligence, providing listeners with authentic conversations from security leaders and practitioners. It’s a resource for those committed to real-world IT operations security and understanding AI risks in critical infrastructures.© 2024 Economie
Épisodes
  • AI Is the New Shadow IT: Why Blocking It Never Worked with Jack Smith
    Oct 5 2026

    Work with Aaron: https://protectitallpod.com/work/
    The book: https://protectitallpod.com/book/
    This episode: https://protectitallpod.com/ep126/
    The OT Security Starter Kit: https://protectitallpod.com/starter-kit/

    Shadow IT used to be a server in a closet. Today it is Linda from sales uploading confidential quotes to whatever AI tool she found first, and your corporate data leaving with it.

    Jack Smith has spent more than 25 years in enterprise IT, across infrastructure, networks, datacenters, cloud and incident management, and he hosts the IT Horror Stories podcast. His argument is that AI is not a new problem, it is the latest version of an old one, and that the reflex to block it at the firewall has never worked and will not work now.

    Aaron and Jack get into where AI genuinely helps, where it quietly does not, and the question of what happens when a system that gives a different answer every time is asked to make a decision that has to be the same every time.

    What you will take away
    • Why blocking AI tools fails the same way blocking USB sticks and webmail failed
    • The difference between a tool that optimises your work and a tool you hand your work to
    • Why analytics and diagnosis are the strong case for AI, and treatment is not
    • The training gap: staff get GDPR training and security training, and no AI training at all
    • A one question test anyone can apply before pasting company data anywhere
    In this episode
    • 1:19 Twenty five years, from floppy disks to AI
    • 10:45 Shadow IT used to be a box in a closet
    • 12:31 Why blocking it never works
    • 19:53 You cannot throw people in the deep end
    • 21:48 When a wrong answer can kill someone
    • 25:40 The answer everybody hates: training
    • 27:54 Never give AI your production environment
    • 41:20 Ask who owns your AI policy
    • 44:38 Who actually gets rich
    • 47:08 The Times Square test
    About the guest

    Jack Smith has spent more than 25 years working in enterprise IT across infrastructure, networks, datacenters, cloud and incident management. He hosts IT Horror Stories, a weekly podcast about real-world IT incidents, what went wrong, how they were fixed, and what we can learn from them.

    • IT Horror Stories podcast: https://ithorrorstories.eu/
    • "AI Is The New Shadow IT": https://ithorrorstories.eu/#rant07
    • Jack on LinkedIn: https://www.linkedin.com/in/franky/

    Learn more about PrOTect IT All:

    Work with Aaron: https://protectitallpod.com/work/
    The book: https://protectitallpod.com/book/
    This episode: https://protectitallpod.com/ep126/
    The OT Security Starter Kit: https://protectitallpod.com/starter-kit/
    YouTube: https://www.youtube.com/@PrOTectITAll
    Email: info@protectitall.co
    X: https://twitter.com/protectitall
    Facebook: https://facebook.com/protectitallpodcast

    To be a guest or suggest a...

    Afficher plus Afficher moins
    56 min
  • Own Your Industrial Airspace: Wireless, Vendors, and the Parking Lot Crane Hack with Scott McNeil
    Sep 28 2026

    Work with Aaron: https://protectitallpod.com/work/
    The book: https://protectitallpod.com/book/
    This episode: https://protectitallpod.com/ep125/
    The OT Security Starter Kit: https://protectitallpod.com/starter-kit/

    A wireless engineer sat in a parking lot, connected to a plant's crane anti-collision network, and had everything he needed to stop the cranes inside 20 minutes. Nobody inside the fence ever knew he was there.

    In this episode of Protect It All, host Aaron Crow talks with Scott McNeil, Industrial Network and Security Architect II at Global Process Automation (GPA), about the part of the OT network most plants never look at: the airspace. Scott has spent more than 20 years in networking and wireless, the last ten of them entirely in OT, and he sits in the integrator's seat, working across every manufacturer's gear without a product to sell.

    The conversation starts where most plants actually are: one flat network, off the shelf gear on the floor, and no budget. Scott's argument is that the low hanging fruit costs time and effort, not money, and that a stable network is the foundation for everything security asks for later: segmentation, inventory, monitoring, then a firewall between OT and IT. He walks through war driving your own plant, why a hidden SSID is not security, the wild west of industrial wireless protocols, wireless that was abandoned in power plants years ago and is still on the air, and where wireless earns its place.

    The second half is about vendors and access. Do not take the vendor's word for it, ask the questions before the gear ships, and treat every third party connection as your own exposure. Scott's rule for remote access is simple: this is my house, vendors connect on my terms, every session logged, with an approve or deny button before anyone gets in. Aaron adds the zip tie in the fan story, a backup switch that had silently failed months earlier and nobody knew until monitoring went on, and the two close on shrinking the wireless footprint that leaves your site and on Scott's podcast, The Industrial Wi-Fi Shop.

    In this episode, you'll learn:
    • Why a stable network comes before any security project, and what to fix first
    • How to war drive your own plant and what a passive scan of your airspace tells an attacker
    • Why hiding the SSID and relying on obscurity is not a control
    • Which industrial wireless protocols are standards based and which are proprietary risk
    • The questions to ask a wireless vendor before you sign
    • How to run vendor remote access on your terms: logged sessions, approve or deny, no standing tunnels
    • Why monitoring finds failures you did not know you had

    Tune in to hear why your industrial airspace deserves the same design, monitoring, and ownership as any wired connection.

    About the guest:

    Scott McNeil is an Industrial Network and Security Architect II at Global Process Automation (GPA), where he helps manufacturers design, secure, and modernize the OT networks that keep critical processes running: architecture, IT/OT convergence, segmentation, resilient connectivity, and industrial wireless. A longtime wireless engineer, he created and co-hosts The Industrial WiFi Shop Podcast with Jeremy Baker, speaks regularly at OT and industrial cybersecurity events, holds a bachelor's degree in Industrial Technology from East Carolina University with multiple wireless and network certifications, and serves on the UNC Wilmington Cybersecurity Advisory Board.

    Important Links:
    • LinkedIn of Scott McNeil:
    Afficher plus Afficher moins
    1 h et 6 min
  • Regulation Is the Budget Unlock OT Has Been Waiting For: NIS2, the CRA, and Getting the Basics Right with Tobias Nitzsche
    Sep 21 2026

    Work with Aaron: https://protectitallpod.com/work/
    The book: https://protectitallpod.com/book/
    This episode: https://protectitallpod.com/ep124/
    The OT Security Starter Kit: https://protectitallpod.com/starter-kit/

    NIS2, the EU Cyber Resilience Act, and CIRCIA are converging between now and 2027, and for the first time the law is pushing cybersecurity requirements upstream into product design and supply chain. What does that actually change on the plant floor?

    In this episode of Protect It All, host Aaron Crow talks with Tobias Nitzsche, Head of Legislation and Technology for Cybersecurity at ABB Energy Industries, about the shift regulation is driving in OT: responsibility moving from the server rooms into the boardrooms, and from the operator to the manufacturer.

    Tobias makes the case that what gets regulated are fundamentally the basics: risk assessment, asset inventory, cyber hygiene, and detection. The industry has preached these for a decade. Now the law demands them, which makes compliance the business case that finally unlocks long-overdue modernization budget. His advice: do not treat legislation as a paper exercise. Treat it as a utility.

    The second half is about recovery, the foundation most plants skip. Aaron and Tobias dig into the vendor-install backup that has never been tested, recovery targets that ignore how long a plant really takes to come back, retain values operators tuned for years that live nowhere else, redundant controllers that are not cyber resilience, and vendor SLAs that send a system engineer when you needed a cyber expert. Tobias's practical pattern: keep a replica of your critical systems, restore into the bubble, and be as intrusive as you like there, scanners and all, without touching production.

    Also in this one: NIS2 Article 20 and personal liability for executives, why a cyber incident does not need a nation state (bad firmware counts), where AI belongs in the Purdue model and where it does not, AI as the daily brief for the one-person water utility, Aaron's Exchange 5.5 story about the week the executives lost their email, borrowing the safety engineers' hazard studies as risk input, and why you should never fire up a wireless pineapple on an airplane.

    In this episode, you'll learn:
    • How NIS2, the Cyber Resilience Act, and CIRCIA move accountability to executives and manufacturers
    • Why 24-hour incident reporting starts with detection, and why you can't wing it
    • How to reframe your next modernization budget ask around compliance
    • What a real recovery plan needs: tested backups, plant-realistic RPO and RTO, and captured retain values
    • Why redundant controllers protect against failure, not compromise
    • How to test restores and run scanners safely in a replica instead of production
    • Where AI helps an understaffed operator and where it should never take control

    Tune in to hear how the biggest regulatory wave in industrial cybersecurity history can become the budget unlock OT has been waiting for.

    About the guest:

    Tobias Nitzsche is Head of Legislation and Technology for Cybersecurity at ABB Energy Industries, where he translates the fast-moving regulatory landscape, including NIS2, the EU Cyber Resilience Act, and CIRCIA, into how products are designed and projects are delivered for critical infrastructure. Before this role he was ABB's Global Cyber Security Practice Lead, capping more than 20 years across IT and OT security. Having sat on both sides of the table, first delivering cybersecurity services to critical infrastructure operators and now shaping...

    Afficher plus Afficher moins
    47 min
adbl_web_anon_alc_button_suppression_t1
Aucun commentaire pour le moment