123 episodes
AI in OT: Why Humans Stay in the Loop and the Junior Problem with Jori VanAntwerp
14/09/2026 | 1h 5 mins.Work with Aaron: https://protectitallpod.com/work/
The book: https://protectitallpod.com/book/
This episode: https://protectitallpod.com/ep123/
The OT Security Starter Kit: https://protectitallpod.com/starter-kit/
AI is a consensus engine, and consensus on the internet is frequently wrong. So what does that mean for the people defending power plants, water systems, and factories with it?
In this episode of Protect It All, host Aaron Crow welcomes back Jori VanAntwerp, CEO and founder of EmberOT, for a completely unscripted conversation on AI in OT. Two practitioners who use AI aggressively every day make the case for restraint in exactly the places that matter.
Jori explains why human in the loop is non-negotiable: AI shapes a junior's output to look senior without the understanding underneath, so you have to be able to interrogate it. Aaron walks through his own sandbox discipline, where AI gets a folder and not the keys, and nothing goes in that he would not publish on the internet.
The conversation then turns to the OT reality behind AI-found vulnerabilities, why an attacker who can reach your HMI or PLC does not need your unpatched CVE, teaching AI your voice with markdown primers, the build-versus-buy MVP trap, the submarine principle for modular defense, and why an operator flipping to manual is still the save of last resort.
Underneath all of it is the workforce math nobody is doing on air: if one person plus AI does the work of five, nobody is training juniors, and no juniors today means no seniors in ten years. OT's aging-out workforce is the preview.
In this episode, you'll learn:
Why AI is a consensus engine, and why that framing predicts where it fails
Why human in the loop is not optional for anything that matters
How to sandbox AI in real workflows: a folder, not the keys
How to rank AI-found vulnerabilities against what an attacker in your OT network can actually do
How primers teach AI your voice, brand, and rules
The build versus buy trap: if a power company builds its own software, it is now a software company
The submarine principle: compartments, modular tooling, and swapping tools without ripping out the estate
Why analog fallbacks and operators keep saving critical infrastructure
The junior pipeline problem: no juniors today means no seniors in ten years
Why the entry-level job for OT cybersecurity is IT
Tune in for the most honest AI conversation the show has had, from the people who actually run it in OT.
About the guest:
Jori VanAntwerp is a two-time cybersecurity founder and CEO who has spent over two decades helping industrial and IT/OT organizations reduce risk, strengthen compliance, and mature the way they defend critical infrastructure. He has held executive and leadership roles at McAfee, FireEye, CrowdStrike, Dragos, and Gravwell before stepping into the founder seat, first at SynSaber and now as the Founder and CEO at EmberOT. The result is a vantage point that runs from the boardroom to the packet capture, from silicon to the cloud. At EmberOT, he is focused on bringing visibility, security, and risk quantification to the critical infrastructure the rest of the world takes for granted.
From EmberOT:
Want to see what is really happening in your OT environment? EmberOT provides flow-first, passive OT visibility and threat detection without requiring proprietary hardware.
Learn more about EmberOT...- Work with Aaron: https://protectitallpod.com/work/
The book: https://protectitallpod.com/book/
This episode: https://protectitallpod.com/ep122/
The OT Security Starter Kit: https://protectitallpod.com/starter-kit/
Get your tickets for CYBR.SEC.CON., a two-day cybersecurity conference, here: https://www.cybrseccon.com/
What started with 120 people and a homemade Word flyer has grown into a cybersecurity community of more than 3,000. So what does it take to build a community that can scale without losing its personal connection?
In this episode of Protect It All, host Aaron Crow sits down with Michael Farnum, CEO and co-founder of CYBR.SEC.Community, and Sam Van Ryder, co-founder and an OT sales expert, to explore the story behind the growth of CYBR.SEC.CON and the community surrounding it.
Michael and Sam share how they went from a grassroots cybersecurity gathering to a thriving community while keeping the relationships and sense of connection that made the event special in the first place.
The conversation goes beyond conferences. Aaron, Michael, and Sam discuss the challenges facing people trying to break into cybersecurity and OT, why entry-level opportunities can be difficult to find, and what experienced professionals can do to help develop the next generation of cyber defenders.
They also share their hands-on efforts to introduce young people to cybersecurity, including bringing 75 high school students into the community, with plans to reach 150.
From hiring and firing lessons to career advice, community building, and the future of OT cybersecurity, this episode offers practical insight for anyone looking to grow their career, build meaningful connections, or help strengthen the cybersecurity workforce.
In this episode, you'll learn:
How CYBR.SEC.Community grew from 120 people to more than 3,000
What it takes to scale a cybersecurity community without losing its personal feel
Why conferences can play an important role in cybersecurity careers
How to break into OT and cybersecurity when you're just starting out
The challenges surrounding entry-level cybersecurity jobs
How community and mentorship can help develop the next generation of cyber professionals
What CYBR.SEC.Community is doing to engage high school students in cybersecurity
Coming September 15 and 16, 2026
CYBR.SEC.CON 2026 brings the cybersecurity community together again on September 15 and 16 at the George R. Brown Convention Center in Houston, Texas.
If you're looking to connect with cybersecurity professionals, expand your network, learn from practitioners, discover career opportunities, and be part of a growing cyber community, CYBR.SEC.CON 2026 is an event worth checking out.
Tune in to hear the story behind CYBR.SEC.CON, the people building the community, and why the future of cybersecurity depends on bringing more people into the conversation.
About the guests:
Michael Farnum is the CEO and co-founder of CYBR.SEC.Community and has worked in IT and cybersecurity since 1994. He founded HOU.SEC.CON. in 2010, which evolved into CYBR.SEC.CON., now attracting more than 3,000 cybersecurity professionals annually. Michael is passionate about cybersecurity community building, workforce development, education, and career development, and is a frequent speaker and podcaster on security leadership and industry trends.... - Work with Aaron: https://protectitallpod.com/work/
The book: https://protectitallpod.com/book/
This episode: https://protectitallpod.com/ep121/
The OT Security Starter Kit: https://protectitallpod.com/starter-kit/
AI has made it easier than ever to build a cybersecurity product. But has it also made it harder to build a valuable cybersecurity company?
In this episode of Protect It All, host Aaron Crow sits down with Ken Elefant, Founding Managing Director of the venture group at Sorenson Capital, for a candid conversation about what really makes cybersecurity startups succeed.
Ken shares a venture investor's perspective on the rapidly changing security market, including why simply wrapping a product around an LLM may not create lasting value, how AI is accelerating commoditization, and what founders need to do to build a meaningful competitive advantage.
The conversation goes beyond technology to explore the often-overlooked role of people, process, market positioning, and execution. Aaron and Ken discuss the importance of finding the right "wedge" into enterprise security, solving real customer problems, differentiating in crowded markets, and building companies that can create lasting value rather than chasing the latest technology trend.
They also draw on lessons from successful cybersecurity exits and the changing threat landscape to examine what investors are looking for as AI reshapes both cybersecurity products and the businesses behind them.
Key Learning:
What venture investors look for in cybersecurity startups
Why AI-powered security products can quickly become commoditized
How founders can find a strong market wedge
Why solving a real customer problem matters more than adding AI
The role of people and process in building successful security companies
How cybersecurity startups can differentiate in an increasingly crowded market
What founders and operators can learn from successful security exits
Where AI is creating genuine opportunity and where the hype may be ahead of the value
Key Moments:
03:43 Using AI in podcasting
07:41 Trusting vendors and cybersecurity risks
10:59 Building Connections for Early Investments
15:19 Investing in emerging tech markets
17:45 Supporting AI-based startup growth
20:19 Building simple websites for businesses
26:03 Attracted to boring, overlooked markets
27:21 Building compliance products at Industrial Defender
30:16 Investing in defense tech startups
33:20 Experienced founders leveraging AI for products
38:32 Navigating fast-changing tech landscape
40:09 Importance of Building Trust in Business
Whether you're a cybersecurity founder, investor, security practitioner, technology leader, or entrepreneur, this episode offers a behind-the-scenes look at how experienced investors evaluate innovation in one of the fastest-moving areas of technology.
Tune in to hear what separates a promising cybersecurity idea from a company capable of creating lasting value.
DISCLAIMER : "Any portfolio companies mentioned in this episode are investments of Sorenson Capital funds and do not represent all fund investments. A complete list of investments is available upon request. This podcast is for informational purposes only and does not constitute an offer to sell or solicitation to buy securities."
About the guest :
... Million-Dollar Buttons: How Offshore OT Is Embracing Containers and Modern Cybersecurity
24/08/2026 | 50 mins.Work with Aaron: https://protectitallpod.com/work/
The book: https://protectitallpod.com/book/
This episode: https://protectitallpod.com/ep120/
The OT Security Starter Kit: https://protectitallpod.com/starter-kit/
Offshore oil and gas operations don't have the luxury of simply shutting everything down and starting over.
In this episode of Protect It All, host Aaron Crow sits down with Josh Herr and Matt McLendon to explore the real-world challenges of modernizing cybersecurity and technology in offshore operational technology (OT) environments.
From million-dollar equipment and aging control systems to virtualization, containers, and edge computing, this conversation reveals what it actually takes to keep critical industrial operations running when technology fails, hardware is difficult to replace, and downtime can come at an enormous cost.
Aaron, Josh, and Matt share stories from the field, including the creative decisions operators sometimes have to make to keep one rig running when another goes down. They also explore the gradual shift from legacy Windows and Sun workstations toward Linux, containerization, and newer approaches to managing industrial systems.
But this isn't simply a conversation about replacing old technology with new technology. It's about understanding the realities of OT cybersecurity, where reliability, availability, safety, cost, and security all have to work together.
Key Learning:
Why offshore OT environments present unique cybersecurity challenges
How legacy systems continue to influence modern industrial operations
Why containers and virtualization are gaining ground in OT
How operators balance cybersecurity with uptime and reliability
The surprising realities of maintaining aging industrial hardware
What the shift from Windows to Linux can mean for OT environments
How creative problem-solving can keep critical operations running
Where AI, containers, and modern infrastructure could take OT next
Key Moments:
06:16 Frustrations with vendor costs and delays
09:34 Offshore connectivity and autonomy challenges
13:02 Managing power plants across Texas
16:19 Challenges with industrial HMIs and alarms
19:40 Vendor control and security policies
21:16 Component delays and industry characters
24:08 Final integration testing and safety factors
28:20 Vendor management challenges with outdated tech
34:02 Missing sysadmin skills in industry
35:59 Challenges with ARM architecture
41:09 Managing hardware life cycles
44:23 Concerns about AI and open source
45:43 Future of JavaScript and integration
Whether you work in oil and gas, industrial cybersecurity, critical infrastructure, engineering, or OT operations, this episode offers an honest look at the gap between cybersecurity theory and what actually works in the field.
Listen in for the war stories, lessons learned, and "art of the possible" approaches helping bring modern technology into some of the world's most challenging OT environments.
About the guests:
Matt is a multidisciplinary team leader and technology practitioner with experience spanning electrical systems, controls, automation, data systems, and IS/IT. His background includes offshore oil and gas electronics, systems administration, and computer hardware, with a strong emphasis on troubleshooting and componen...AI Agent Security: How to Stop Autonomous AI from Becoming Your Biggest Insider Threat
17/08/2026 | 57 mins.Work with Aaron: https://protectitallpod.com/work/
The book: https://protectitallpod.com/book/
This episode: https://protectitallpod.com/ep119/
The OT Security Starter Kit: https://protectitallpod.com/starter-kit/
AI agents are becoming more autonomous - but are they becoming more secure?
In this episode of Protect It All, host Aaron Crow welcomes David Girvin for a timely discussion about one of the fastest-growing challenges in cybersecurity: AI agent security and governance.
From an unconventional career as a ship captain to building one of the first governance platforms for AI agents, David shares why organizations must begin treating AI agents as powerful digital coworkers with permissions, identities, and risks that require the same level of oversight as human employees.
Together, Aaron and David explore how autonomous AI systems can unintentionally create business risk, why credential starvation, execution-layer security, and human-in-the-loop controls are becoming essential, and how organizations can safely adopt AI without sacrificing security.
In this episode, you'll learn:
Why AI agents should be treated like insider threats
The biggest security risks of autonomous AI
How guardrails prevent costly AI mistakes
Why human oversight still matters in an AI-driven world
What credential starvation means and why it's effective
Practical governance strategies for enterprise AI adoption
Key Moments:
05:31 Career paths and diverse experiences
06:24 Startup experiences and mentoring journey
09:30 Exploring a career shift to marketing
15:30 Building a Successful Career
18:20 Governance and AI risks
19:24 Early AI research and presentation
23:19 Just-in-time tokens discussion
27:52 Balancing work, family, and startup challenges
30:48 Transitioning from Operations to Events
35:18 Industry friendships and shared experiences
36:04 Work stress and job challenges
39:49 Securing AI systems and LLM inputs
43:46 Developing AI observability tools
47:56 Managing session risk and autonomy levels
51:14 Security and file management controls
55:34 Cybersecurity awareness chat
Whether you're building AI applications, leading cybersecurity programs, or simply exploring how AI will change your business, this episode offers practical insights into securing the next generation of intelligent systems.
Tune in to learn how organizations can embrace AI innovation while keeping people, data, and critical systems protected.
About the guest :
David Girvin is a cybersecurity leader, security architect, and Founder & CEO of Assury.ai, where he is building execution-level governance for AI agents. With leadership experience at companies including 1Password, Red Canary, and Sumo Logic, David has spent his career helping organizations strengthen security, architecture, and AI strategy. He specializes in making complex cybersecurity and AI concepts practical and accessible, helping businesses adopt emerging technologies securely and responsibly.
Links to connect David:
LinkedIn: https://www.linkedin.com/in/david-a-girvin/
Website: https://assury.ai
Learn more about PrOTect IT All:
Work with Aaron:
More Business podcasts
Trending Business podcasts
About PrOTect It All
PrOTect IT All with Aaron Crow delivers weekly episodes focused on cybersecurity and operational technology, tackling emerging threats across industrial control systems, AI security, and IoT threats. The show emphasizes enterprise risk management, manufacturing security, power grid security, and threat intelligence, providing listeners with authentic conversations from security leaders and practitioners. It’s a resource for those committed to real-world IT operations security and understanding AI risks in critical infrastructures.
Podcast websiteListen to PrOTect It All, A Bit of Optimism and many other podcasts from around the world with the radio.net app

Get the free radio.net app
- Stations and podcasts to bookmark
- Stream via Wi-Fi or Bluetooth
- Supports Carplay & Android Auto
- Many other app features
Get the free radio.net app
- Stations and podcasts to bookmark
- Stream via Wi-Fi or Bluetooth
- Supports Carplay & Android Auto
- Many other app features


PrOTect It All
Scan code,
download the app,
start listening.
download the app,
start listening.



























