True stories from the people defending critical infrastructure
Real conversations about OT security, ICS protection, SCADA systems, IT challenges, AI, compliance, and the human side of keeping critical infrastructure running. 108+ episodes and counting.
Help us keep this going
Subscribe wherever you listen
Hit subscribe on your podcast app and the YouTube channel. It costs you nothing and it tells the algorithm someone cares. That is how independent shows like this one stay alive.
Tell us who to talk to
Got a guest you want to hear from? A topic worth covering? A question you want answered on the show? Drop it below. We read every one.
OT & ICS Security
Protecting power plants, water utilities, manufacturing, and transportation. Grounded in NIST 800-82 and the Purdue Model.
IT-OT Convergence
Bridging the gap between IT and OT teams, technologies, and mindsets.
AI & Emerging Tech
AI, cloud, quantum, and automation in industrial environments.
Compliance & Risk
NERC CIP, SANS Five ICS Critical Controls, risk-based approaches beyond checkbox audits.
Leadership
Building trust between teams, developing talent, navigating organizational dynamics.
Incident Response
Real breach stories, tabletop exercises, lessons from the front lines.
Interested in sponsoring? See the audience and packages or email sponsorship@protectitallpod.com
Interested in starting your own podcast or need help with production? Check out BlackOrchid for editing, hosting, and launch support.
PrOTect IT All is built on real conversations with people who have something valuable to share. We cover the full spectrum: people, process, and technology across IT, OT, cloud, enterprise, AI, and everything in between.
You don't need to be a 20-year veteran. Some of our best episodes have come from practitioners early in their careers who bring fresh perspectives, real case studies, and hard-won lessons learned. If you've done the work, you have something worth sharing.
Aaron Crow
30 years in technology across both IT and OT roles. From supporting 40+ power plants at a Texas utility to building out consulting practices and leading large-scale security programs for critical infrastructure. Currently at Arcova, bringing the practitioner's perspective to every conversation.
Full Bio →
30 years in technology across both IT and OT roles. Husband. Dad. Texan. Rucker. Car guy. Someone who believes all business is a people business, and that the best conversations happen face to face, not behind a screen.
The Career
I grew up around critical infrastructure before we called it that. My dad was a controls engineer for 40+ years, so power plants, substations, and control rooms were just part of the landscape. I got into technology early, building a coax network through cinder block walls in college and messing around with a Tandy TRS-80 and Apple IIe as a kid.
Over 30 years I've worked across both IT and OT, from large enterprises to critical infrastructure operators, consulting, and product companies. I started in IT, then found my way into the OT world when I joined a Texas utility supporting 40+ power plants across the state: fossil gas, coal, renewable, and nuclear. That's where everything clicked. Since then I've held roles across consulting, utilities, and cybersecurity product companies, always focused on the intersection of IT and OT and the real-world challenges of securing critical infrastructure. I'm currently at Arcova, bringing the practitioner's perspective to everything we do.
The podcast started while I was CTO at Industrial Defender and rebranded from "PrOTect OT Cybersecurity Podcast" to "PrOTect IT All" because I've always believed OT security cannot be understood in isolation from IT. The whole picture matters.
The Family
Married to Kary Crow since 2008. She's the one who keeps everything running when I'm on the road for conferences, assessments, or recording sessions. We have three kids: Charlie, Sydney, and Tyler. They've heard more about firewalls and network segmentation at the dinner table than any kids probably should, but that's the deal when your dad can't stop talking about protecting the things that matter.
Born and Raised in Texas
I'm a native Texan and proud of it. Born and raised here, and this is home. Texas is a big state. If you haven't been here or seen it on a map, some of those power plants I supported were six hours from headquarters. You learn a lot about yourself on those long drives through the middle of nowhere.
Conferences like RSA, DEFCON, and ICS Village events in Las Vegas and Singapore have taken me to some incredible places. But at the end of the day, Texas is where the boots come off.
Rucking
If you don't know what rucking is, it's simple: you load up a backpack with weight and walk. That's it. No gym membership, no fancy equipment, just a good ruck and the road.
I ruck approximately 3 miles a day carrying as much as 65 pounds. It's not about going fast. It's about putting in the work, building mental toughness, and getting outside. I've also become a collector of GoRuck rucks. If you know, you know. Some people run. I ruck.
Outside the Screen
When I'm not talking cybersecurity or hauling weight on my back, you'll find me working on cars, out at the range, hiking, hunting, fishing, or just being outside. I'm a technology guy by trade, but I recharge in the outdoors.
I also train jiu-jitsu, though not as often as I'd like. There's something humbling about stepping on the mat and getting submitted by someone half your size. The kids train too, and watching them grow through it has been one of the best parts.
Lone Star Cyber Shootout
Events I host that bring together CISOs, security leaders, and sponsors for real conversations in a setting that's anything but a typical conference. The best relationships in this industry aren't built in a conference hall. They're built over shared experiences.
No sales pitches. No scripted panels. Just real people having real conversations about the things that matter.
Core Philosophy
- OT depends on ITSiloed OT-only thinking is insufficient. The industry needs a big-picture, end-to-end perspective.
- Fundamentals over hypeThe SANS Five ICS Critical Controls are the recurring defensive framework. Basic hygiene prevents most attacks.
- Compliance is not securityCompliance is a baseline and budget justification tool, not comprehensive protection. "99.999% compliant is not actually compliant."
- OT is different, not harderA core framing principle for positioning OT security to both technical and business audiences.
- All business is a people businessIT/OT team trust is an incident response asset. We do business at the speed of trust.
Subscribe to PrOTect IT All
Available everywhere you listen.
Want to be a guest?
We are always looking for practitioners, leaders, and builders with real stories to share.
[email protected]