
Sign up to save your podcasts
Or


Work with Aaron: https://protectitallpod.com/work/
In this episode, host Aaron Crow delves into IT OT convergence, a crucial yet often misunderstood topic. Listeners will gain insights into the distinct differences between IT and OT, the challenges of integrating these fields, and the reasons behind the historical mistrust between IT and OT teams.
Aaron discusses how technology might be similar, but the roles and impacts are starkly different—with IT focusing on corporate environments and OT handling mission-critical operations like power plants and manufacturing lines. He also shares real-world stories and strategies for building trust and fostering collaboration between these often siloed teams.
Tune in to learn how to overcome these hurdles to create a more secure and efficient organization. Whether you're an IT professional or an OT specialist, this episode offers valuable perspectives on navigating the complexities of IT OT convergence.
Key Moments:
00:10 Technology similarities, lack of understanding, a trust issue.
03:49 Corporate distrust causes technology outages and inefficiency.
07:21 Building trust and collaboration for buy-in.
11:20 Different games, but similar athletic requirements.
15:38 Team successful in providing technical support in Texas.
17:09 Connect with us at Black Hat, DEF CON.
Connect With Aaron Crow:
Learn more about PrOTect IT All:
Work with Aaron: https://protectitallpod.com/work/
To be a guest or suggest a guest or episode, email [email protected].
Please leave us a review on Apple or Spotify:
Work with Aaron: https://protectitallpod.com/work/
In this episode, Aaron Crow and special guest Joseph Perry dive deeply into the evolving landscape of cybersecurity. The episode explores the integration of commercial off-the-shelf systems into OT environments, highlighting how this transition brings similar security challenges from the IT sector into play. Throughout their discussion, Aaron and Joseph tackle the complex vulnerabilities, the resistance to adopting new technologies, and the critical necessity of tailored security measures. They also examine the pervasive buzzwords like "AI" in modern cybersecurity products.
Listeners will gain insights into the growing regulatory scrutiny from the SEC, the heightened responsibility of Chief Security Officers, and the anticipated evolution of cybersecurity professions into more rigorous, skilled trades. The conversation further touches on the chaotic state of threat intelligence, the impact of technological advancements such as AI on cyber-attacks, and the increasing industrialization of fraud. From understanding the hype cycles of AI to the practical challenges of explaining complex security solutions to non-technical stakeholders, this episode is packed with valuable information.
Aaron and Joseph also discuss the importance of learning from past IT mistakes when adopting new technologies and the unique challenges of protecting both cutting-edge and legacy systems within OT environments. As they address topics like social engineering attacks, ransomware, and the use of AI tools in cybersecurity, listeners will come away better equipped to navigate the intricate cybersecurity landscape. Tune in for a comprehensive exploration of these critical issues.
Key Moments:
05:36 Library catalog conversion led to career in cybersecurity.
15:02 AI useful in cybersecurity for structured data.
18:07 Questions remain about AI, and human intervention need.
25:39 Advanced fraud detection surpasses current AI capabilities.
28:37 AI contributes significantly to medicine, finance, and cybersecurity.
34:57 Powerful means test and audience testing revolutionized fraud.
37:58 Attacks getting shorter, focused on initial access.
47:52 Focus shifts to CPE, vulnerability, and attack.
48:53 Russian threat actors reassert, causing chaos. No rules.
54:43 IT challenges in dealing with construction clients.
59:56 Evolution of cyber security concerns and measures.
About the guest :
Joseph Perry is a seasoned cybersecurity expert currently leading incident response, threat intelligence, and purple teaming at MorganFranklin Cyber. With a background spanning the US Navy and the National Security Agency, Perry has built a robust expertise in emerging technology and cybersecurity. He specializes in critical infrastructure protection, threat intelligence, and the adoption of new technologies.
Perry is a prominent figure in the cybersecurity community, contributing his insights at major conferences like Black Hat and Defcon. He focuses on the practical applications of AI in cybersecurity, fraud detection, and the evolving threat landscape. Committed to advancing the field, Perry emphasizes continuous learning and domain expertise to help organizations combat cyber threats effectively
How to connect Joseph : https://www.linkedin.com/in/lousyhacker/
Connect With Aaron Crow:
Learn more about PrOTect IT All:
Work with Aaron: https://protectitallpod.com/work/
To be a guest or suggest a guest or episode, email [email protected].
Please leave us a review on Apple or Spotify:
Work with Aaron: https://protectitallpod.com/work/
In this episode, our host, Aaron Crow, explores the intriguing world of OT cybersecurity products.
This episode explores the key differences between IT and OT, the challenges faced in OT environments, and how some IT products can actually be adapted for OT use.
Aaron explains why availability and safety take precedence in OT settings, from power plants to manufacturing lines, and how traditional IT cybersecurity measures need to be tailored for these unique environments. He also discusses the importance of understanding protocols, implementing multi-layered defenses, and leveraging advancements in cybersecurity tools.
Tune in as we unravel the distinct intricacies of protecting our critical infrastructures and discover how IT and OT worlds continue to converge.
Key Moments:
00:10 Adapting IT products for OT cybersecurity challenges.
06:33 IT products integrating OT capabilities, impacting uptime.
10:33 Windows XP boxes in production pose risk.
14:00 Access device remotely to avoid travel time.
17:45 Complex network setup required for risk reduction.
20:06 Multiple vendors complicate technology and support solutions.
24:14 Plan for OT challenges by engaging IT.
26:21 OT and IT overlap, and industry devices evolve.
Connect With Aaron Crow:
Learn more about PrOTect IT All:
Work with Aaron: https://protectitallpod.com/work/
To be a guest or suggest a guest or episode, email [email protected].
Please leave us a review on Apple or Spotify:
Work with Aaron: https://protectitallpod.com/work/
Welcome to Episode 13 of Protect It All! This episode features Philip Huff, a professor at UA Little Rock and a cybersecurity expert. He explores the promise of AI in education, especially for robotics and automation, while cautioning against the erosion of educational rigor.
Philip and host Aaron Crow discuss the importance of hands-on learning and real-world experience in aligning educational standards with industry needs. They delve into the role of industry partnerships, the necessity of embedding cybersecurity education at the community college level, and the growing skills gap in technology due to retiring experts.
The conversation also covers the advantages of competency-based education and flexible training programs in enhancing social mobility. Throughout, they stress the critical role of human involvement in AI and cybersecurity and the need for innovative, resilient systems.
Tune in for an engaging discussion on the future of education and workforce development in the tech and cybersecurity sectors.
Key Moments:
00:10 Early career challenges prepare for real-world demands.
04:35 Degree's purpose is knowledge and skill acquisition.
08:17 Promoting cyber-informed engineering principles in community colleges.
11:32 Small private school in Texas prioritizes practical engineering.
14:48 Trade skills in high demand, apprenticeships offered.
17:33 Community colleges offer efficient curriculum changes for workforce.
23:12 Team's success attributed to aligning schedules with peers.
26:57 Company and employee benefit from long-term commitment.
28:46 Aligning learning outcomes with career competencies is crucial.
31:44 Retooling professionals for new careers and skills.
36:13 Value education based on future job prospects.
37:35 Integration of AI in education needs balancing.
42:52 Transforming education to align with real learning.
46:28 Transforming classroom for positive shared learning experiences.
49:57 Unused industrial equipment turned into educational tools.
52:10 Learn troubleshooting, not just following instructions.
56:07 Excitement and fear about accessible AI advancements.
59:12 Developing cyber engineering education standards at Idaho National Labs.
About the guest :
Philip Huff is an Associate Professor of Cybersecurity at the University of Arkansas in Little Rock and serves as the Director of Cybersecurity Research in the Emerging Analytics Center. Dr. Huff is also chief scientist and co-founder of Bastazo, a company specializing in cybersecurity solutions for industrial technology. He leads the National Cyber Teaching Academy, the Department of Energy’s Emerging Threat Information Sharing and Analysis Center, and the Cybersecurity Consortium for Innovation which all focus on driving work-force development and innovation for cybersecurity in the region. He is also a CISSP.
How to connect with Philip: https://www.linkedin.com/in/philip-huff-65012621/
Connect With Aaron Crow:
Learn more about PrOTect IT All:
Work with Aaron: https://protectitallpod.com/work/
To be a guest or suggest a guest or episode, email [email protected].
Please leave us a review on Apple or Spotify:
Work with Aaron: https://protectitallpod.com/work/
In this episode, our host Aaron Crow, sits down with Dr. Anmol Agarwal, a distinguished security professional at Nokia and adjunct professor specializing in machine learning. Together, they dive deep into machine learning, AI, and cutting-edge telecommunications technologies.
They uncover how vast amounts of data are crucial for training machine learning models to detect anomalies and prevent cyber threats, particularly in the telecommunications industry. Dr. Agarwal also sheds light on the transformative impacts of 5G and future 6G networks, from enhancing communication speed to revolutionizing smart manufacturing and industrial networks.
Explore the fascinating world of digital twins, AI-powered anomaly detection, and the complexities of transitioning from 4G to 5G. Aaron and Dr. Agarwal also discuss the global efforts required to standardize these technologies and emphasize the importance of diversity and passion in the tech industry.
Tune in as they tackle the current challenges and future possibilities in AI and telecommunications, and discover how these innovations are shaping the security landscape. Plus, take advantage of Dr. Agarwal's valuable insights and upcoming research on AI-based solutions to prevent DDoS attacks. Let's dive in!
Key Moments:
00:10 Old technology, like dial-up, latency is important.
04:08 Latency in IT and OT processes. Excitement for 5G.
08:40 Machine learning for anomaly detection, digital twins, network sensing for 6G.
12:54 5G as secure media pipe for communication.
15:43 Training machine learning models requires ample data.
18:14 AI benefits outweigh fear of job loss.
22:06 AI creates and replaces jobs, imperfect but beneficial.
25:34 AI adapts dynamically, opens limitless possibilities.
27:31 Live stream with CEO playing themed tabletop.
32:06 5G signal has shorter coverage than 4G.
36:42 Diversity in cyber is crucial for innovation.
40:37 Diverse backgrounds bring fresh perspectives to cybersecurity.
43:04 AI creating deepfakes raises concerns about misinformation.
45:01 Concerned about deep fake potential and solutions.
About the guest :
Dr. Anmol Agarwal is a security expert at Nokia, dedicated to securing advanced communication technologies such as 5G and upcoming 6G networks. Her critical work ensures that the data transmitted through your cell phone calls and text messages remains confidential and protected from hacking. Additionally, Dr. Agarwal imparts her extensive artificial intelligence knowledge as a part-time adjunct professor teaching machine learning. Her expertise not only safeguards our digital communications but also enhances their speed and efficiency through the innovative application of AI.
How to connect with Dr. Anmol :
LinkedIn: https://www.linkedin.com/in/anmolsagarwal/
X: https://twitter.com/anmolspeaker
Connect With Aaron Crow:
Learn more about PrOTect IT All:
Work with Aaron: https://protectitallpod.com/work/
To be a guest or suggest a guest or episode, email [email protected].
Please leave us a review on Apple or Spotify:
Work with Aaron: https://protectitallpod.com/work/
In this episode, host Aaron Crow interviews Kevin Walter, an expert in vehicle security, about the growing cybersecurity and safety risks in modern vehicles. Kevin, with a master’s degree in cybersecurity and extensive experience in vehicle systems like the CAN bus, shares his insights into the hidden vulnerabilities within today's cars.
The discussion covers key topics such as the challenges automakers face in updating vehicle software, the real-world implications of vehicle hacking—including the notorious 2014 Jeep hack—and the emerging threats from autonomous vehicles and AI systems. Kevin and Aaron explore how hackers can exploit architectural weaknesses and what measures can be taken to protect against these threats, from simple solutions like Faraday bags to advanced strategies like kill switches.
Whether you’re a cybersecurity enthusiast, a vehicle owner, or just intrigued by the intersection of technology and safety, this episode offers valuable insights into keeping modern vehicles secure. Join Aaron and Kevin for an engaging dive into automotive cybersecurity. Let’s get started!
Key Moments:
00:10 Vehicle network, OBD 2 standard, vehicle diagnostics.
07:22 Incident leads to upgrading car engine.
08:06 Programmed car transmission to work with engine.
13:34 Cars now require computer skills for repair.
14:25 Shop had to enable new battery in car.
18:50 Tire sensor vulnerabilities lead to serious risks.
20:55 Relying on sensors, lacking basic driving skills.
26:05 Greenberg upset about engine shutdown on highway. The jeep's brakes disabled in parking lot. Demonstrated vehicle vulnerability in 2014.
27:40 Potential security risk shutting down connected vehicles.
32:16 Harley dealership charged $100 to enable Spotify.
36:12 OBD2 standard needed for vehicle safety.
39:32 Tesla's automated driver assist misinterprets speed limit.
41:43 Keyless cars vulnerable to theft via tech.
46:13 Interconnected systems may lead to car hacking.
49:19 Balancing innovation with cybersecurity is crucial.
About the guest :
Kevin Walter is an experienced professional in the field of vehicle network and computer systems. He possesses a deep understanding of the more than 50 electronic control units typically found in these networks. Kevin is well-versed in the use of onboard diagnostics tools, specifically the OBD 2 standard, which has been a universal feature in vehicles since 1996. This standard is crucial for mechanics to diagnose and troubleshoot vehicle issues effectively. Kevin’s extensive background includes work as an independent transportation contractor, further solidifying his expertise in the automotive industry.
How to connect Kevin :
https://www.linkedin.com/in/kevin-w-942416211/
Watch a key fob replay attack video Kevin made with his vehicle.:
https://drive.proton.me/urls/3FJXK72NVG#lr_dL45TIogs
Connect With Aaron Crow:
Learn more about PrOTect IT All:
Work with Aaron: https://protectitallpod.com/work/
To be a guest or suggest a guest or episode, email [email protected].
Please leave us a review on Apple or Spotify:
Work with Aaron: https://protectitallpod.com/work/
In Episode 10 of Protect It All, titled "Tools and Techniques for Better Network Visibility and Vulnerability Management with Kylie McClanahan," host Aaron Crow and guest Kylie McClanahan dive into the critical elements of enhancing cybersecurity through advanced tools and strategies. Kylie, CTO of a company specializing in this field, shares her insights on overcoming the challenges of consistent naming conventions, accurate vendor data, and breaking down silos for effective communication across teams.
They explore the utility of tools like Spartan and Network Perception in visualizing network vulnerabilities, mapping asset inventories, and planning effective patch management. They emphasize the importance of correlating vulnerabilities with business priorities rather than just CVSS scores and the need for a layered security approach.
The episode also discusses cybersecurity risks to non-technical stakeholders, highlighting the business implications. The duo discusses the evolving landscape in the power utility sector, the dual nature of physical and cyber threats, and the ever-present need for continuous adaptation.
Kylie shares her excitement about machine learning and graph neural networks for grid state estimation while expressing caution about AI tools' accuracy. Aaron and Kylie stress the importance of reliable data, automated processes, and vendor security advisories in maintaining effective asset management.
Key Moments:
03:47 Discussion focused on improving cybersecurity classifications and communication.
08:48 Compliance sometimes leads to minimum effort for benefit.
11:17 Vendor security advisories prioritize patch tracking.
14:46 Testing for security vulnerabilities and potential exploits.
17:20 Understanding and communicating cybersecurity risk to non-professionals.
20:50 Disagreement on consistent product naming causes confusion.
25:46 NVD website publishes overwhelming recent vulnerabilities.
27:07 Understanding the importance of asset management.
32:13 Challenges of tracking change management in organizations.
33:33 People, process, and technology are crucial investments.
37:34 Spartan takes any scan, offers change management.
39:55 Vision of the future: a dynamic ecosystem.
43:19 Vendors acknowledge changes in control systems effectiveness.
48:09 Equations useful, AI for optimization, caution with models.
49:28 Questioning truthfulness of AI in HR replacement.
53:01 Toyota and Lexus prioritize reliable, tested technology.
About the guest :
Kylie McClanahan is the Chief Technology Officer of Bastazo, Inc and a doctoral candidate in Computer Science at the University of Arkansas. She has nearly a decade of experience with cybersecurity in the electric industry, including both professional experience and frequent collaborations with industry as a graduate researcher. Her research explores the automation of vulnerability analysis and remediation using natural language processing and machine learning. She holds a GCIP certification from GIAC and speaks frequently about cybersecurity in industrial control systems.
How to connect Kylie:
https://www.linkedin.com/in/kyliemcclanahan/
https://www.bastazo.com
https://www.cisa.gov/stakeholder-specific-vulnerability-categorization-ssvc
Connect With Aaron Crow:
Learn more about PrOTect IT All:
Work with Aaron: https://protectitallpod.com/work/
To be a guest or suggest a guest or episode, email [email protected].
Please leave us a review on Apple or Spotify:
Work with Aaron: https://protectitallpod.com/work/
The conversation covers various topics related to cybersecurity, including offensive security, IoT devices, hidden threats in cables, advanced hacking devices, privacy concerns with smart devices, cyber hygiene, securing personal data, risks of social media platforms, importance of cybersecurity education, government regulations, and trends in cybersecurity for 2024. The conversation explores the prevalence of social engineering attacks and the effectiveness of generative AI in social engineering. It discusses the challenges of detecting phishing emails generated by AI and the difficulty of defending against AI-powered attacks. The role of password managers and firewalls in defense is highlighted, as well as the importance of recognizing the limitations of human perception. The conversation emphasizes the need for cyber defense measures in organizations and the vulnerability of the weakest link in the chain. It also addresses the risks associated with third-party vendors and the impact of cyber attacks on critical infrastructure. The importance of cyber-informed engineering and designing with security in mind is discussed, along with the challenges of securing outdated OT systems. This conversation covers various topics related to securing OT networks, including the challenges of upgrading OT systems, the complexity of OT networks, and the use of OT firewalls. The discussion also explores the importance of understanding OT protocols and the security risks of unencrypted OT protocols. Additionally, the conversation delves into the impact of Active Directory issues and the role of AI in cybersecurity. The future of AI and quantum computing in cybersecurity is also discussed.
Hosted by: Aaron Crow
Guest: Duane Laflotte
Audio production by NMP. We hear you loud and clear.
Learn more about PrOTect IT All:
Work with Aaron: https://protectitallpod.com/work/
To be a guest or suggest a guest or episode, email [email protected].
Please leave us a review on Apple or Spotify:
Work with Aaron: https://protectitallpod.com/work/
Hosted by: Aaron Crow
Guest: Luther 'Chip' Harris
Audio production by NMP. We hear you loud and clear.
Learn more about PrOTect IT All:
Work with Aaron: https://protectitallpod.com/work/
To be a guest or suggest a guest or episode, email [email protected].
Please leave us a review on Apple or Spotify:
Work with Aaron: https://protectitallpod.com/work/
In this conversation, Bryson Bort discusses his background and the creation of Scythe, an offensive security platform. He also talks about the ICS Village and the Vulnerability Management Pavilion, as well as his collaboration with the Department of Energy on a vulnerability management research project. Bryson emphasizes the importance of prioritizing vulnerabilities in operational technology (OT) and understanding the risks in power plants. He also highlights the need to build trust with asset owners and gain leadership buy-in for cybersecurity initiatives. Finally, he discusses the importance of connecting technical expertise to business priorities. The conversation explores the importance of building trust and collaboration in the field of cybersecurity, particularly in the context of power utilities. It emphasizes the need for security professionals to be partners rather than adversaries, and highlights the role of organizations like the ICS Village in fostering collaboration and education. The conversation also delves into the concept of purple team exercises and the importance of starting small and growing in cybersecurity initiatives. Additionally, it discusses the significance of conversations with policymakers and the need for more cybersecurity professionals in the industry.
Hosted by: Aaron Crow
Guest: Sevak Avakians
Show notes by NMP.
Audio production by NMP. We hear you loud and clear.
Learn more about PrOTect IT All:
Work with Aaron: https://protectitallpod.com/work/
To be a guest or suggest a guest or episode, email [email protected].
Please leave us a review on Apple or Spotify:
From the publisher's feed

227,519 Listeners

1,028 Listeners

8,058 Listeners
![Talkin' Bout [Infosec] News by Black Hills Information Security](/_next/image?url=https%3A%2F%2Fpodcast-api-images.s3.amazonaws.com%2Fcorona%2Fshow%2F516141%2Flogo_300x300.jpeg&w=640&q=75)
93 Listeners

138 Listeners

25 Listeners