Ep 51: Chemistry to Cybersecurity: Oakley Cox's Unique Journey | PrOTect IT All
HomeEpisodes › Episode 51
Episode 51
Episode 51 Interview

Chemistry to Cybersecurity: Oakley Cox's Unique Journey

Mar 31, 2025 00:52:07 with Oakley Cox
OT SecurityCritical InfrastructureAIIncident ResponseRisk Management

Watch This Episode

In this episode, host Aaron Crow dives deep into the world of OT cybersecurity alongside guest Oakley Cox, the director of product for Darktrace OT. They explore the unique journey of how Oakley transitioned from a chemistry background to cybersecurity, highlighting the role of AI and machine learning in evolving OT environments. 

With a focus on strategies for tackling cybersecurity challenges in critical infrastructure, the conversation covers the innovative ways AI is being used to enhance security measures and prepare for future threats. 

Tune in for insights on how Darktrace is redefining security through AI, and the importance of adapting and innovating in the ever-evolving landscape of OT and IT cybersecurity convergence.

Key Moments: 

05:49 Bridging IT and OT Skills

11:00 AI's Practical Use and Future Prospects

13:28 Rethinking Tabletop Exercises

16:39 Self-Learning AI for Network Security

21:37 "Security Vendor: Adapting to Cloud Risks"

26:22 OT Environment Change Awareness

35:28 Embracing Ambiguity in Data Analysis

38:52 AI-Assisted Unusual Activity Blocking

41:51 Enhancing Security with Smarter Tools

44:50 Power Utility Data Management Constraints

About the guest : 

Oakley Cox embarked on an academic journey in chemistry, completing an undergraduate degree which led to a PhD position. During their doctoral studies, Oakley discovered a passion not for the hands-on lab work typically associated with chemistry, but rather for the emerging field of machine learning and big data. Their PhD research focused on integrating these computational tools to streamline laboratory processes, thus bridging the gap between traditional chemistry and modern technology. Recognizing that his genuine interest lay in the computational aspects, Oakley shifted his career focus post-PhD, seeking opportunities that allowed them to apply machine learning and big data solutions outside of the chemistry lab.

How to connect Oakley Cox : https://www.linkedin.com/in/oakley-c-73aa27111/

Resources Mentioned:
The AI Arsenal (Darktrace White Paper): https://www.darktrace.com/resources/the-ai-arsenal

Comparing AI Approaches for anomaly based threat detection (Research Journal): https://hstalks.com/article/7177/anomaly-based-threat-detection-behavioural-fingerp/

 

Connect With Aaron Crow:

 

Learn more about PrOTect IT All:

 

To be a guest or suggest a guest/episode, please email us at [email protected]

 

Please leave us a review on Apple/Spotify Podcasts:

Apple   - https://podcasts.apple.com/us/podcast/protect-it-all/id1727211124

Spotify - https://open.spotify.com/show/1Vvi0euj3rE8xObK0yvYi4

Chapters

05:49Bridging IT and OT Skills
11:00AI's Practical Use and Future Prospects
13:28Rethinking Tabletop Exercises
16:39Self-Learning AI for Network Security
21:37Security Vendor: Adapting to Cloud Risks
26:22OT Environment Change Awareness
35:28Embracing Ambiguity in Data Analysis
38:52AI-Assisted Unusual Activity Blocking
41:51Enhancing Security with Smarter Tools
44:50Power Utility Data Management Constraints
Read the full transcript

Aaron Crow (0:1.600): Awesome. Hey, thank you for joining me on the protected all podcast. today I am, excited, to have this conversation. you and I met at S four a few weeks ago. I, have, I know your team and a, and a lot of the folks that you work with. So really excited to have this conversation. So why don't you introduce yourself, tell us about you and, your unique journey to get to where you are in this, in this, OT cybersecurity space.

Dr Oakley Cox (0:26.318): Yeah, good to see you again, Aaron. It's been busy couple of weeks since we saw each other, but yeah, I'm Oakley Cox. I am the Director of Product for Darktrace OT at Darktrace. So as you've probably already picked up, I am British. I'm joining from the United Kingdom. And yeah, I've been at Darktrace now for coming up to eight years, but prior to that, had nothing to do with cybersecurity, had nothing to do with OT.

Dr Oakley Cox (0:55.246): My background is actually in chemistry. So I did a doctorate at the University of Oxford, where that's where I first got introduced to machine learning, big data. And that's what led me through a windy route within Dart Trace to where am today.

Aaron Crow (1:10.180): So, man, that's awesome. We've talked a little bit before. Obviously, we talked in person and we talked before this started recording, but that's such a unique path to get here. And many of us have different unique paths. And my background, I've done everything from real estate and sales and kind of a mix of those things. And I think all of those skill sets have made me better at what I do now, whether it's talking on this podcast or it's selling stuff or really even the real estate side.

Aaron Crow (1:40.172): remodeling houses and all that kind of stuff. And even though it has absolutely nothing to with O2 cyber, it helps me ask questions and deal with ambiguity. And there's, all sorts of things like that. So, so how did you go from, you know, chemistry to AI and cyber security in OT of all things?

Dr Oakley Cox (1:57.390): Yeah, well, guess it's worth talking a little bit about the background, right? The chemistry part. I was a strange person. I really enjoyed chemistry. I enjoyed learning it. I know a lot of people got put off by it at some point during high school or university, but yeah, I just loved learning. kept doing it. I did it for my undergraduate and then was lucky enough to be offered a PhD position. But then this is the point where I started to realize it wasn't my thing because now I was having to do more stuff for the actual lab bench, the actual doing.

Dr Oakley Cox (2:25.902): So I like learning about it, but I didn't like doing it, which is a real limitation when you're spending all day, every day doing it. But at the time, this was the emergence of the big, well, the time was called big data, right? The emergence of the ML kind of machine learning stuff. So my PhD research was interfacing between these two fields. Like how can we make my job as a lab chemist easier by leveraging ML, big data.

Dr Oakley Cox (2:55.139): And so when I finished that and realized, you know, I didn't want to do chemistry, I was looking for other ways to other avenues to apply those, those more computational aspects of my research.

Aaron Crow (3:9.198): So how much, first of all, I was one of those people. I was really good at math. I loved physics, never liked chemistry. I don't know why. Like I could do physics all day long and calculus and all that kind of stuff. I loved those things. Chemistry to me was just like, I don't know if I was too stupid. I don't know what the problem was, but it did not click with me at all. So I am definitely one of those use cases. So talk about why those connections and how those connections, you know,

Aaron Crow (3:37.816): from chemistry and the large language models and all that kind of stuff, like how are those things aligned and connected when they seem completely irrelevant or unrelated to each other?

Dr Oakley Cox (3:49.048): Yeah, I think it's the fundamentally the maths is the same or similar, right? So it's how do you take either structured or unstructured data and make sense of it to make your life easier? I've never seen AI as a replacement, so to speak, but more as an augmentation, a way to make my job or people like me, their jobs easier. So then when I was looking around for what other app

Dr Oakley Cox (4:17.798): What other things I could do I came across this what the time was relatively small UK startup called dark trace I'd never thought about IT had never thought about cyber security before but you know, they were applying AI As they called it then even back in 2017 Applying AI to the problem of cyber security. And so I thought that sounds like a great opportunity. So so went for it was lucky enough they they Hire so I went straight into the cyber analyst team

Dr Oakley Cox (4:46.070): They don't hire based on knowledge, so they don't look for certifications and degrees in cyber security. They hire based on skill sets. They look for a lot of people in those kind of science backgrounds, also language backgrounds, even things like international affairs, international relations. You get this real diversity of skills that then they then teach the knowledge once you're in.

Aaron Crow (5:7.246): Yeah, that's so forward thinking if you think about it, right? And it's really easy and we see this knowledge gap and this skills gap that we have in cybersecurity and we have all these positions that folks say that we need. But you look at the job requirements on those pages and it's like, well, it's an entry-level position but you have to have five years experience. That doesn't make sense, right?

Aaron Crow (5:33.656): So to your point, I've built a lot of teams and I looked for the underlying skill sets that I needed instead of a certification or years of experience or a title. Whereas, you know, I was taking people from, you know, IT working in desktop support, networking in an IT, in a law firm, things like that, and bringing them into my OT space, even though they had zero, they'd never been to a plant. They'd never under, they didn't know what OT was, but I was able to take those underlying skill sets that they had and

Dr Oakley Cox (5:33.768): Yeah.

Aaron Crow (6:2.636): teach them the OT side, but they had the underlying troubleshooting and networking and those other skill sets that I needed. And that built a really strong and powerful team. it's amazing to me that more companies don't do that, especially when they're needing these positions. And unfortunately, I think part of that is probably because HR is the one riding the job wrecks and they don't really truly understand what the need is. But as asset owners, as leadership, as management,

Aaron Crow (6:30.606): Like we need to work to better write those job racks and make sure that we really understand what we're looking for and know that there aren't very many people like me, like you, that has the current experience. So going and expecting that you can find one in the ether on LinkedIn that's A, looking for a job, B, has a skillset you're looking for, C, is willing to take a job in the pay range or the location and all of the things that you're talking about, you've just narrowed down the potential opportunities to nil.

Aaron Crow (7:0.088): to almost zero and then you wonder why you can't find anybody and then you hire somebody that's not, have any of skill sets but has a certification but then they don't do a good job. Anyways, I'll get off my soap box now and let's get.

Dr Oakley Cox (7:12.238): completely agree. mean, the other best plus side is it made it such a fun team to be a part of, We were all in the same boat together. The onboarding the first three, six months is really intense, but we've all come from kind of, you know, highly competitive universities. We've gone through school kind of doing that and we're coming into this new environment. We all love learning together. We're all learning from each other. And then by the time you're that,

Dr Oakley Cox (7:37.226): one, two years, three years down the line, you suddenly become the expert. But also, was only yesterday that you were in their shoes. So you get this kind of camaraderie. You still need the expert sprinkled around. So in our case, we were lucky enough to have a few former GCHQ MI5 types and the equivalent in for the US team. And I'm sure you did the same with OT experts for building your team. So you still need that sprinkle of real expert, real depth knowledge. But then below that, you get

Dr Oakley Cox (8:6.210): create this team that has a lot of camaraderie and fast learning, I think.

Aaron Crow (8:10.564): 100%. Yeah. So, so what are, what are some of the big, if you, if you kind of go back a little bit to, to in the beginning versus even now, even what is, what are some of the things that you guys were trying to attack again? Like you said, 2017, nobody's really talking about AI, especially in a cybersecurity lens, especially in an OT lens, we're still scared of AI, much less in an OT space. So what kind of things were you, were you guys trying to solve for back then?

Dr Oakley Cox (8:36.342): Yeah, so at the time, you know, we were a relatively new company, but had a few hundred, couple of thousand customers. And the underlying technology was this anomaly-based detection. So, you know, doing real-time threat detection based on mathematical anomalies. And then as the security analyst team, we were writing reports for our customers. So one of the first projects that the team I was in was involved with was actually

Dr Oakley Cox (9:3.512): how can we now apply a different form of AI ML to actually solve that repetitive problem of writing a report? So how do we investigate an incident such that we can then create a, do the hypothesis testing that human analysts would, but the repetitive part of that, and then create a full security incident. And so that was something we did in the first two, three years.

Dr Oakley Cox (9:29.730): We call it Cyber AI Analyst. We launched it in 2019 as part of the product. it allows that kind of correlation of disparate alerts, different devices. But beyond just correlation, also the investigation piece. What was this device done before? Does it represent some kind of... Does this unusual activity correspond to some kind of security incident? And then piecing that all together. that was very much that augmentation. It wasn't replacing the security analysis. It was making my job easier because...

Dr Oakley Cox (9:58.880): Now I didn't have to do the boring investigations. I could focus on what I enjoyed, which is the interesting in-depth investigations.

Aaron Crow (10:4.580): Sure. Well, and that's the key that I think most people need to understand because you hear all this, you know, the sky's falling, AI is going to replace all of your jobs. We're all going to be unemployed. You know, maybe at some point that is the case. I see it to more like what you just said. I see AI as a tool, just like a screwdriver or a hammer, like AI in and of itself is not going to go, it can't just replace a carpenter, right? But a carpenter can build better stuff.

Aaron Crow (10:34.212): if he has better tools, right? A carpenter, you know, 300 years ago using all manual tools. Yes, they could create amazingly beautiful, gorgeous things. We've seen examples of that, you know, Sistine Chapel and all of these things, whether it's a carpenter or a painting or sculptures or all this kind of stuff, they did amazing things with their hand. But how much better and more accurate can they be when they're using these different tools? Look at 3D printing, look at, you know, power tools and all of the things that we have today. It's amazing how much

Aaron Crow (11:2.978): faster, better, more accurate, efficiently that we can do these things. And you can have one master and all of these, you know, lower skilled type people that can, can deliver these amazing things because of the toolkits they have. And that's the way I see AI is, you know, every, all the vendors are wanting to bolt AI onto their thing for obvious reasons. To your point, how can I make it more efficient? How can I make some of those reports? How can I take some of the responsibility and some of the, and usually it's the lower level things that I start with.

Aaron Crow (11:31.950): Like that's the entry into AI is like, want to start with how do I make this report? Even if I know it's going to be a draft and I'm going to have to have a human to manipulate it and make it look better. How do I at least just take raw data and put it into a draft report that saves me six hours of somebody copying and pasting from 12 different sources into this one file, right? That's an easy thing that AI can do. It doesn't take much intelligence. It's just copy paste, you know, put it in here, blah, blah. You can, you can very easily do that. So.

Aaron Crow (12:0.662): So knowing that, what are some of the more advanced things that you guys are looking to do, either even in current state or even future casting, and especially in OTCyber where everybody's so terrified of, you know, the AI robots crashing my system or taking over and me not being able to control it and all that kind of stuff that folks are fearful of from maybe watching too many movies or whatever the reason may be.

Dr Oakley Cox (12:24.910): Yeah. But I think one of the more recent interesting things we've added, particularly from an OT perspective, is in instant response preparedness and training, know, the readiness and recovery. There's a lot of hype around generative AI, your chat GPT AI. And, you know, the chatbot type application of that, I don't think has a good application in cybersecurity or in particularly in OT cybersecurity, but you need that kind of trust and reliability.

Dr Oakley Cox (12:55.114): the ability to scrutinize the data at really high level. So we were thinking of different ways of applying that type of thing. And one of the things we came up with was tabletop exercises. So taking your real data, combining that with templates of what an attack looks like, and then being able to play out a simulated, not, you don't perform the attack, you simulate the attack within the UI. This is what an attack would look like in real time based on your devices, your data.

Dr Oakley Cox (13:24.302): And then that allows you to drill your teams, right? Which is useful for cybersecurity teams in general, but in critical infrastructure where, you you're getting requirements, you have to do tight tabletops every six months, you know, the ability to do it in a safe and secure way, remove that paperwork part of a traditional tabletop, we've seen it a really popular use case that people in OT teams seem to love.

Aaron Crow (13:48.142): Yeah, I you know, I've had this conversation with a lot of folks and the traditional tabletop where, you you do it with the executives once a year, you hire a big four consulting firm to come in, you know, a lot of pomp and circumstance around it. But what's the value add? are you including the right people? Are you having the right conversation? Are you just checking a box? And unfortunately, I feel that a lot of folks are just checking a box. Whereas I see tabletops as more like training.

Aaron Crow (14:18.722): because it's just like anything, the more times I go, like the first, why do we do, you know, fire drills and, and, know, high rises, right? We go through it because when, the alarm goes off for real and there's smoke, you don't want people to go like, I don't know what to do. Where do I go? Where's the fire escape? Like, should I take the elevator? Should I jump out the window? Like they should, we, shouldn't be the first time that we've thought through this, right? We, we practice, we go back to the place of, our, of our, you know, what we've done and what we've practiced. It's like with,

Dr Oakley Cox (14:41.122): Yeah.

Aaron Crow (14:48.034): with martial arts or with shooting or with anything, if you've trained something over and over and over again, it just becomes natural, right? So if you look at tabletops in that way, in that I've done this before, I've gone through this scenario, I know what my first step is. Saving seconds of time can be exponentially impactful in an incident. Like how quickly can I make sure it's not spreading? How quickly can I shut it down and isolate it? Like whatever the scenario is for the attack, but

Aaron Crow (15:16.992): If it's the first time somebody's seen it or they don't even recognize it until it's weeks or months away, those are all things that we know, especially in OT, because most people are, know, when you're locking in an OT environment, most of the time it's operators, it's engineers, it's chemists, right? There's chemistry folks at power plants and they're not thinking cybersecurity. They're thinking the water, you know, the chemistry in the water and other, are there bad things in there and how do I purify it and get it to the levels that I'm looking for, right? They're not thinking about.

Dr Oakley Cox (15:33.346): Yeah.

Aaron Crow (15:45.592): when the chemistry is off, they're not necessarily even considering, is it really off or is that analyst, is the device incorrect for some reason? And even if they are, they're thinking physically calibrated. They're not necessarily thinking somebody's tampering with it or there's a software glitch, whether it's a bad actor or anything. So all of these things are so powerful to train our people and tools like AI are huge in that. Let's take a step back real quick. Why don't you tell us,

Aaron Crow (16:14.892): What is Darktrace? What is your focus in the marketplace in OT? Because what I love about y'all story is so many vendors, and I'm talking a lot, I'm sorry. I'm very passionate about this if you can't tell, but Darktrace is very unique in the space in that there's not very many vendors in the OT cyberspace that started as OT. Most of the vendors started as an IT company.

Aaron Crow (16:41.036): and they kind of shifted or they added a capability or they adjusted and kind of form fit into OT instead of you guys started out as an OT. Like that was the intention when you started up, it was to attack and look at OT cybersecurity. So that's a unique use case. So give us the elevator pitch or the kind of what you guys do and what your focus is and what makes you guys different from a product perspective at least.

Dr Oakley Cox (17:7.470): Yeah. So when, when the, uh, the founders were developing this technology back in 2013, 2014, they were taking unstructured network data to train what they called a self-learning AI, right? To understand what, what is normal, pattern of life for that network. And it didn't really matter where that network traffic came from. And so they, the, the, the first place they went was those operational systems where the network traffic is, you know, it's still unstructured, but it's more predictable. And so that the first customer doctor has had as you.

Dr Oakley Cox (17:36.622): we've already said was an OT customer, Drax Power Station, is a big, well, at the time it was a coal power station. It's now, they burn wood pellets in the North of England. And so, you know, the intention was to learn what is normal for that network and then perform anomaly based detection, but not in a way of, there's a really key difference between what a lot of vendors are doing out there, which is baselining, where they will take a, you know, a two week baseline.

Dr Oakley Cox (18:6.466): to understand what is normal and then switch it to detect mode and then all of their detections from then on are referenced from the baseline. Now this is, you know, it's massive to have a baseline, right? That's a huge upgrade for a huge number of organizations. But firstly, you're baking in bad because you are assuming that your two week training period, four week training period is good. And secondly, even OT networks are not static, right? They are constantly evolving and changing. So

Dr Oakley Cox (18:35.150): You are then having to spend all of that detection time fighting false positives and saying, know, re-baselining it, saying, accept this, I put it in, and then you've got all the risks of human error of saying, yes, no, you know. Does a security analyst who actually happens to do this all day every day going to thoroughly check that SSH connection is expected or not, for example? So this was, this approach was different. was real time. That's the self-learning aspect, right? It evolves over time. Now, since then,

Dr Oakley Cox (19:3.566): we've applied it across all sorts of parts, digital data. So we do it across cloud, email, identity, things like Office 365, and of course, OT. So now we kind of have a broad platform, but its strength is it unifies all of it. So things like IT OT convergence is a massive use case for us because we can treat those different realms. And as OT moves to the cloud, right? As OT moves to the cloud.

Dr Oakley Cox (19:30.862): treat those different digital realms but keep them in a single pane of glass from a security perspective.

Aaron Crow (19:36.484): Right. Yeah. And that's, that's, I can't tell you how many people have, uh, I've been around this long enough that, 20 years ago, you know, we were not, we were, everything was, was, was, you know, uh, 420 milliamp. It was hard connected. They weren't using IP as things started changing over, you know,

Aaron Crow (19:55.704): they didn't want to use firewalls or routers or things like that. They wanted isolated air gap networks and everything was proprietary. And then they started bringing in commercially off the shelf equipment with switches and firewalls and windows servers. And then, you know, they resisted on virtualization and, and of course now everything uses virtualization and VMware and, and all the things. And cloud is another one of those cloud and AI, obviously, you know, cloud is another one that's like, we'll never do OT in the cloud. People are already doing OT in the cloud, right?

Aaron Crow (20:25.676): Now a power plant is probably not gonna put their control room in the cloud, but cloud is such a interesting term because a cloud can just mean, it doesn't have to mean that I'm going to Amazon. It can mean I have a cloud in my data center, right? It can mean a lot of things. So cloud is a generic term, but it's really just hosted resources.

Aaron Crow (20:54.564): in some place. And it's a little bit different than, you know, physical iron servers that this is a dedicated email server, and this is a physical box that's my file server, and this is my network attached storage device. that's really the bigger differences of those things. And how do I use that processing and GPUs and all that kind of stuff. And as we get into AI, we see more and more of that as well. And I think it's a matter of making sure that we're thinking through. And what I love about what all that you've just shared, right, is

Aaron Crow (21:23.350): as you guys were forward thinking, bringing in people, looking at problems differently with, cause a lot of times we get a lot of the, we could never do that. We've done this for 40 years and we've never done that. And there's the resistance to change people inherently, you know, you've probably read the book, who moved my cheese. People hate change. Like it's, it's funny. It's a little bitty book, but it's very powerful. If you haven't read who moved my cheese, I highly recommend it. takes 20 minutes to read the book.

Dr Oakley Cox (21:46.337): Yeah.

Aaron Crow (21:52.172): But it's very powerful to understand people's perspective and understand why people are resistant to change in all things. It has nothing to do with cybersecurity and everything you do with mindset and how people look at changing things. But this goes to the ultimate reasoning behind resistance to put in things that have AI or cloud or anything like that in our OT spaces, even if maybe they provide better security and reliability and availability than the physical ones that we have today.

Dr Oakley Cox (22:21.944): Yeah, I completely agree. I think it's security vendor as well. It's not for us to decide what, it's the risk profile is based on the customer. Like you say, there's going be nuclear power plants that are never going to go, you know, to the cloud. But there are plenty of OT organizations starting in manufacturing and even things like renewable energy that are going to increasingly put workloads in the cloud or private cloud or whatever it may look like. And so for us as a vendor, that's where we need to be ahead of the curve to make sure we can manage that transition.

Dr Oakley Cox (22:52.020): as best as possible, manage their risks, that risk management piece, understanding, you know, if the business is going to introduce this from a efficiency saving perspective, can we also understand what risk that's going to introduce and then therefore mitigate against it? yeah, and I think that's an exciting place to be, to be kind of, you know, you're constantly thinking ahead, looking ahead. Yeah, it's good.

Aaron Crow (23:20.482): What are some of the exciting use cases that you've seen come across? And it doesn't have to be OT or IT, but just, you know, what are some of the things that y'all are excited about that you've seen that you've been able to use it that hasn't been used before or, you know, that kind of thing, right?

Dr Oakley Cox (23:37.326): Well, I think actually this is actually a slightly older story, but it's what got me into the OT space in the first place, once at Dart Trace. We had an attack, was with APT that we detected, but it was specifically targeting critical infrastructure. That's what I find fascinating about OT, is the risk profile is so completely different.

Dr Oakley Cox (24:4.578): the impacts are so completely different. is impacting people's lives in a way that the vast majority of IT does not necessarily do. Your email server going down for half a day is a break from work, whereas you can't say the same about the electric grid. So yeah, it was an incident in 2018 around the time that Triton, or Trisis, whatever you want to call it, that attack was going on. And it was actually a very similar attack

Dr Oakley Cox (24:33.486): called Shamoon, which also targeted oil and gas. The difference with Shamoon was that it didn't specifically target the control systems. It was more of an IT attack, but used a lot of the similar techniques. we had a customer that was hit by Shamoon. And we were able to see every step. Now, at the time, it was just detection only. We weren't doing any response, so the attacker was able to progress. And

Dr Oakley Cox (25:0.322): So it was really interesting seeing this like never seen before attack being undertaken by what was clearly an advanced persistent threat, some kind of nation state or nation state aligned. And there's that kind of realization moment of how powerful the adversaries are, but also how powerful our solution was to help overcome that challenge. We could actually pick out the most sophisticated threat actors. So we've got a blog.

Dr Oakley Cox (25:30.648): from 2018, so an old blog that kind of talks through that. since then, you know, that's carried on. continue finding that kind of thing. Zero days, insider threats, the kind of things that traditionally get around those static rules and tools because there is no rule or playbook for how do you detect vault typhoon? How do you detect that rogue insider who is using their legitimate access in order to steal data?

Dr Oakley Cox (26:0.022): Yeah, that's what gets me excited is solving those really difficult challenges.

Aaron Crow (26:7.308): Well, and that's, that's the biggest use case for tools like this, right? Is, is we, we've all been around long enough. Most of my listeners probably as well, even, even if you're new, you've used antivirus and what is antivirus, right? It is a blacklist. These are known bad things. If any of the, if you see any of these things happen, file types, whatever block it. but as we know, we get new signatures and definitions for those, those antiviruses weekly, daily, hourly, sometimes.

Aaron Crow (26:36.888): and so if, if somebody releases a new attack that is not in the blacklist and applies it before the antivirus finds out a system or provider finds out about it, adds it to their signature list and sends it to you, then, then it's going to get by. It doesn't matter. Right. And, and by very definition, a zero day is something that somebody didn't know existed before it happened. Right. It's the very first time something like that happens. Right. And those are the types of things that.

Aaron Crow (27:4.644): tools like this can see now obviously a human if they were super capable and understood everything about the network and was looking at everything and all that kind of stuff like yeah sure maybe they could find it but how long would it take them to find it etc and especially in ot we don't have dedicated resources that are that are looking at glass 24 7 at this particular facility right so

Aaron Crow (27:27.938): So it's unlikely that an analyst in and of itself would be able to find that without tools to be able to highlight and bring those, this looks different. Like there's something about this. I don't know that it's a bad thing necessarily, but it's different enough. And to your point, things do change in an OT environment, but things don't change as frequently or as often as they do in an IT environment. So I say this a lot, know, Sun Tzu art of war.

Aaron Crow (27:53.368): you know, use my strength as weaknesses and my weaknesses as strengths. Because I'm not patching, I'm not going to the internet, I'm not doing a lot of these things all the time, when something changes, it should be pretty obvious that like it's the green thumb, it's a flashing light. Like, why did that change? Is that expected? You know, especially as I do this more and more and more, and I'm getting more and more data, especially about a particular environment and facility. I've had examples in case studies where, you know, vendor brings in an application whitelisting

Aaron Crow (28:23.342): product, right? They're locking down workstations. These are the only thing that are allowed to do. And they go through that learning process you talked about. Like we ran it, we let it run for six weeks, right? And then we lock it down. A, what am I locking down that was really bad, but I just said is good. I don't go to that level of detail to know that, but even worse in the experiences that we've had is there's a process that runs once a year during a certain scenario.

Dr Oakley Cox (28:48.716): Mm-hmm.

Aaron Crow (28:50.210): And it didn't happen during my time. So when they go to kick that process off, because it wasn't approved in the white list, it didn't work. And now the plant doesn't work because that process didn't kick off and something failed. And now everybody's all up in arms about it because I broke something instead of, you know, truly understanding the full process. And that gets that back down to nobody really understands enough of the process.

Aaron Crow (29:13.368): to be able to do that type of thing, which is why we need tools like AI that can kind of learn them a fly and grow. So yeah, that's super exciting and the future is coming with that. And also the flip side of that is we know that the nation state actors are using it. We know they're using these tools against us. So if we're not gonna use them, then they're just gonna exponentially outpace us and we'll never keep up because they can throw things at AI that we can't respond to individually as humans.

Dr Oakley Cox (29:18.541): Yeah.

Dr Oakley Cox (29:43.599): I really like your point about, in theory, a human could do this job. The beauty of this method of detection is, of what the attacker, brand new idea the attacker comes up with, they have to do something unusual. And you're right. If you know your network inside out and your network's 10 devices so that you can know it inside out, you could detect unusual events. That's perfectly reasonable.

Aaron Crow (30:7.746): Right. Sure.

Dr Oakley Cox (30:10.774): The point we're trying to do is, how can we augment that? How can we actually help you find the unusual much, much quicker by kind of understanding that unstructured data? And yeah, so you get these, you know, mathematical unusual events. And then I, you know, I frequently get questions, well, what if the attacker just learns what's normal and then, and then blends in with it? Well, I mean, firstly, if they do, fair play to the attacker. But secondly, if you think about the whole kill chain of attack, not just

Dr Oakley Cox (30:40.322): the stealing the data at the end or the initial compromise. have to go through multiple steps to achieve their goal. There is no way they could blend in completely normally to achieve that. You talk about like man in the middle attacks where they're just listening. Well, they've got to exfiltrate the data somewhere. That's going to look unusual. So, you know, even these low and slow attacks have an unusual element to it. And that's, that's what we're there to kind of find and shine a light on and contextualize as quickly as possible for the security teams and for the engineers.

Aaron Crow (31:9.240): Well, know, and to you, that example you just gave, right? It's no different than if I'm going to infiltrate something and I dress up as a janitor and I've got a mop and I start mopping the floors and all that kind of thing. I look, I look the part, I've got the badge, I'm wearing the right uniform. I'm actually cleaning the floors. All that's normal until I start doing it. But if I'm just going to clean floors, then I just got a job. I'm not a bad actor, right? I'm just, I'm just doing what they're paying me to do. The point is, is I'm going to do that until I want to do something else.

Aaron Crow (31:38.764): until I want to steal something, until I want to break something, whatever that thing is. And that's the difference, right? At some point, they have to do something different because they want a different outcome. They want to steal data, they want to turn off a machine, they want to ramp it up, they want to damage it, whatever their goal is. Obviously every attacker or a nation state or whatever is different. But at some point, they have to deviate from normal because normal is not to run the...

Aaron Crow (32:7.198): the turbine until it breaks. That's not normal.

Dr Oakley Cox (32:9.742): Yeah, yeah. You'd hope so anyway.

Dr Oakley Cox (32:16.174): you

Aaron Crow (32:20.034): Yep, it's alright. You there? Yep.

Dr Oakley Cox (32:20.654): Are you back? Yeah. We lost each other mid-laugh, I think. OK.

Aaron Crow (32:25.444): Yeah, that's OK. This is edited so we can cut that out so we could just kind of get back into it. No worries. That's why I love this product.

Dr Oakley Cox (32:32.205): Makes it easy to do the other the other thing I wanted to pick up on is the your point about the like the once once a year maintenance cycle right and and those those infrequent events that still do recur Because I get asked about that a lot as well as I had you know, it's usually framed through the false positive question and and So a couple years ago, I think it's three years ago now some myself and some of three of my colleagues published a

Dr Oakley Cox (33:1.454): a research paper, which we can link with the podcast in which we explored that comparison of this base lining approach that you've just described, and then this self-learning AI approach that we use, is difficult to find because it's multiple algorithms, but we package it as self-learning AI. And we took those, so we used three different scenarios. One of the obvious one, if there's something already bad.

Dr Oakley Cox (33:30.594): how do you detect it? And we, we detect pre-existing bad using our clustering. So essentially each device is clustered into peer groups. If a device is in a peer group and one of them is doing something out of the ordinary from that peer group, then it triggers an alert. And that's how you find pre-existing infections, right? Because of this peer grouping. Scenario number two was the situation you described, right? Where something happens infrequently.

Dr Oakley Cox (34:1.026): But so therefore, it looks new the first time you see it. But then if it happens three months, it looks less unusual six months, even less. And so how the baseline approach suffers, as you've described, with the self-learning AI slowly. It might give an alert the first couple of times. That might be described as a false positive, potentially. But it doesn't require manual interference.

Dr Oakley Cox (34:27.055): And I've completely forgotten the third example, but it's there in the paper. So that gives you a reason to go read it.

Aaron Crow (34:33.255): Sure. No, that's awesome. And that's the point, right, is to look at these things from different perspectives, which, know, one of the buzzwords, and today, and again, I'm not trying to get political at all, but one of the buzzwords that we hear in everything that's going on with politics and everything else is diversity, right? And diversity is so important, right? And I'm not talking about, you know, where you went to school or what religion you are or how you look or, you know, anything about your personal...

Aaron Crow (35:1.996): anything. It's really about how do you look at a problem and you and I are going to look at problems differently because of my experiences, because of some inherent assumptions that I make based on my knowledge and things that have happened in the past and you're going to have a different one. It doesn't make mine right or wrong. It just means that when you and I are team together and we're looking at that problem, you may see something that I just take as a normal because I've seen it a hundred times and I assume it's always good and you look at it as

Aaron Crow (35:32.438): should we assume that's always good? And that's where we get this differing of ideas and perspectives. And that's where the difference comes, right? And our attackers are coming from those perspectives as well, right? So that's where the diversity of thought and perspective, and that's where AI can really help us because it doesn't have any of those inherent assumptions or anything like that. It's really just looking at the facts, right? And it's assuming nothing.

Aaron Crow (36:2.640): other than what we tell it to. that's where we've got to be careful in what we tell it. It's just like the baselining. We keep going back to that, but it's why Blacklist is kind of a thing of the past and baselining is troublesome because I don't know that I didn't baseline something that was bad or I forgot to baseline something that was good and it'll always be that way. And there's really no way to fix that other than have other things that are not doing it in that older

Aaron Crow (36:31.862): older way, right?

Dr Oakley Cox (36:33.624): I love the phrase diversity of thought. mean, it touches back to what we spoke about at beginning with building teams, right? And having people with different backgrounds in terms of their education and the way they solve problems. But also the, so one of the challenges we sometimes find with, know, with customers with very rigid security teams that have built up their particular playbooks.

Dr Oakley Cox (36:57.600): Often SOC teams are built around the idea that it's like a playbook where it's very binary. Is it good? Is it bad? And they kind of work their way through the work chart. When you're investigating unusual activity, it doesn't really work like that. You're acting more like an intelligence officer where you're having to go, okay, well, this is my starting point. And depending on the nature of the alert, it could be a really strong starting point. It could be a really vague, like something's unusual. And then you have to pull the string. And then that's where you firstly...

Dr Oakley Cox (37:26.278): You have to edit your playbooks because you're now looking more investigative, but your diversity of thought, people investigate that different ways. They have a different perspective on what that unusual activity may represent. And then you build up the, you have this opportunity to create those wider breadth teams and remove yourself from that silo of I need someone with a cybersecurity background and training.

Aaron Crow (37:51.108): That I've never heard it spoken about like that, right? But that's a very good point. Like the word analyst, if you think about when you're thinking about from an intelligence gathering perspective, whether you're, know, MI5 or CIA or, you know, whatever, they're really looking at data and there isn't a known, you know, most of the time it's very gray. It's like, is this good? Is this bad? Like you're pulling that string and it takes a lot of time and a lot of data and a lot of sources.

Aaron Crow (38:20.836): and a lot of, a lot of effort to figure out if it's good or bad, right? And the same thing to your point, I think a lot of socks and a lot of cyber policies, they try to make it so rigid in that, Hey, we know all of these things are bad and all of these things are good. And there's no gray, right? There's they, we've got to be able to put that in to say, you know, what happens if you're going through like a workflow.

Aaron Crow (38:47.618): and I get to a place and it's not either going to be yes or no. Sometimes it's going to be, is it yes? Is it no? Or is it question mark? Like that should be an avenue that we, we allow them to pursue. Otherwise you're going to end up categorizing things inherently as good or bad, which may not be either of those things. Or at least you don't know yet if they're good or bad. And that, if you force people to say, you know, that binary yes or no, good or bad, you know,

Aaron Crow (39:16.878): block or don't block, allow or unallow, like a firewall, not everything is that black and white. Now maybe, you know, in an IT world, they probably lean towards block, you know, inherently, you know, deny all. And they're probably more aggressive on that side. And the OT side is probably leans more on the opposite side of allow it through because I need it to work. And if I block things, I break stuff. And that's where I think

Aaron Crow (39:45.078): AI and tools like what you guys do is so powerful, especially in these OT spaces, because I can't just block. Like I can't just kick an XP machine out of my environment. I can't just, you know, stop a process mid thing because I think maybe it's, it's fail or it's not right because that can have downstream impacts physically to hurt people, damage equipment, bring down the grid.

Aaron Crow (40:8.748): And those things are, you my response from an analyst perspective in an OT world is usually pick up the phone and call Bob, the operator at the plant, as opposed to kick it off the network, block it, you know, send the troops, all that type of stuff, right? It's a completely different response plan. And we need to allow that flexibility in our process of procedure. And this is where I hone in so many times on when we're talking about these. There is no silver bullet at any product. Like I was a product owner.

Aaron Crow (40:38.390): I was a CTO at a product company. I've been a consultant for a long time, so I sell services and all that kind of stuff, but it's people, process, and technology. If your run books aren't good enough, it doesn't matter how great your tools are, right? They're gonna fall on their face because you broke the process and you didn't train your people. All those things, it takes the whole thing to really make it work and efficient.

Dr Oakley Cox (40:59.974): I agree. did touch on one of those topics within O2 security that really divides the room, the response part. How and when do you take action? yeah, you're completely right. The risk profile is completely different. You would rather allow wait and confirm than deny and then cause an explosion. But that's something we take into consideration.

Dr Oakley Cox (41:29.752): Part of the solution, DartTrace OT, has what we call autonomous response, which is a terrible name if you're an OT engineer. But the point is, is when you find something unusual, you specifically block the unusual. Now, you can do that autonomously, but the vast majority of our customers in OT who use it are using it in human confirmation mode. So they are able to specifically see, this is normal, this is the unusual.

Dr Oakley Cox (41:58.102): connection or connections that are unusual. Can I block those? How do I block those? This is what the AI is recommending. And then they can go out and kind of do whatever investigations is required before they then confirm that and block it. Because ultimately, even when you find out, you do your investigation, you find out what it is, it's not always that easy to do your response, right? So being able to be targeted, allow that machine to do normal so that you're really restricting any possible

Dr Oakley Cox (42:26.562): downstream effects, unwanted downstream effects. Yeah, I think there's still, we're still working out how, where this looks in terms of the risk profile. And again, it's going to vary by organization, by customer. But I think having some form of autonomous response in your arsenal is really important in OT security. We just need to be able to get to grips with that as end users.

Dr Oakley Cox (42:55.500): and then work out where it looks in our risk profile. We all have fire extinguishers. It doesn't mean we go around spraying fire extinguishers everywhere. It needs to be there. Now let's work out what and how when we use it.

Aaron Crow (43:2.252): Exactly.

Aaron Crow (43:9.730): Well, and one of the other common problems I see in OT is, in IT, everything is standardized, right? I've got these standard servers. They're usually very similar versions and patch levels and what applications I can install and what devices they can talk to. I'm very mature in knowing my email server doesn't need to talk to my file server.

Aaron Crow (43:37.774): database server doesn't need to talk to my whatever, All of those things, it's very, very documented and it's pretty much the same at every IT organization. There are some exceptions, but the back office stuff, we always know exchange and active directory and all the things that go into these spaces, right? I don't want to put my exchange server or my file server directly on the internet, like all that type of stuff. In an OT world though, it's so different.

Aaron Crow (44:3.460): Right? Even in a space, if I'm at company A and they're a manufacturing facility and they've got 10 manufacturing facilities around the world, each one of those manufacturing facilities are different. Even if they were built on the same plan at the same time and they had the same hardware when they started, they're all different. Right? So that adds another level of complexity when I'm looking at how do I look at what's good and bad because every facility is different.

Aaron Crow (44:30.936): And even in, you know, I'll look at a power generation facility and they may have multiple units. So I've got generating unit one, generating unit two, generating unit three in between one, two and three, there's going to be differences of equipment, of software, of hardware, like all sorts of differences. And, and yes, there are people on site that understand those differences, but a sock analyst at corporate is not going to know that unit one is different than unit two in these exact ways.

Aaron Crow (45:0.484): because they've got 48 sites or 300 sites or 3000 sites. It's impossible for one person to know all of those things, right? And that's where tools like this can really up level us to get us better and understand because at the end of the day, I know we say this a lot, but at the end of the day, a bad actor only has to be right once. We have to protect this stuff all the time. And some people don't align with that or don't agree with that. But I mean, that's the way I look at this, right? Is we have to start looking, we have to be smarter.

Aaron Crow (45:29.004): and more efficient with our tools and what we're doing and where we're focusing our efforts. That doesn't mean we don't need firewalls. It doesn't mean we don't need, you know, all these other things. Absolutely. We need segmentation. We need firewalls, zero trust, all that kind of stuff. But how do we start monitoring and looking at these things when we know there's so much diversity in my architecture and my tools and all that kind of stuff? And AI is a huge level up for our teams to be able to have that efficiency.

Dr Oakley Cox (45:54.848): Yeah, 100%. And I do also recognize the hesitancy with AI adoption, right? Like, is this new buzzword, it's become a marketing term, you know, there's a lot of like, well, what actually is it? How are you actually applying it? And I think that's a really important part of the puzzle, right? Is the AI transparency part. We've been in this space for 10 years, and we spent eight years

Dr Oakley Cox (46:19.830): shouting AI and nobody listening to us because they thought it was too futuristic and then two years shouting it and nobody listening us because everyone else is saying it, right? But it has allowed us to kind of peel back the bonnet a little bit, so to speak, whereas before people weren't interested in looking at the bonnet. Now people are, you know, they want to go, okay, well, let's learn a little bit more about your algorithms. They don't necessarily have to be math spoffins, but just give a little bit of an understanding as to how you're applying this. So, you know, we recently published a new

Dr Oakley Cox (46:48.812): white paper called the AI Arsenal, which just talks a little bit about different how AI is being applied across cybersecurity in general. And then more specifically, the algorithms, the Bayesian statistics that are being underpinned in the self-learning AI. just to give people that information, that transparency, right? So that they can build trust with the tool. It's not, we need to adopt it because that's the direction it's going. It's, let's adopt it in the right way and understand how it's actually helping my use case.

Dr Oakley Cox (47:18.906): One of our big strengths we see is the fact that our AI can be applied on-prem. So it can sit on a physical server, learns only from that organization's data. That's what makes it so applicable in OT. There's a lot of AI out there, but that can't be done, right? It has to go to the cloud. It has to be compared with third-party data. And so just little differences like that, not all AI is the same, right? You can apply it in different ways. Really important to understand as you kind of adopt it for the different challenges you've got.

Aaron Crow (47:46.946): And that's huge. So first of all, let's, let's say for our American people, when he said bonnet, he means hood, like under the hood.

Dr Oakley Cox (47:54.706): Thanks for the translation.

Aaron Crow (47:58.116): But that's so true, right? And again, going back to a lot of my time has been in power utility and power utility is not going to allow data to go to the cloud. So a lot of these tools that are coming out, especially from a, and this goes back to the original thing I said, where we've got IT tools that are trying to get into the OT space and they don't always really understand where and when they can use it. Some organizations look at large manufacturing facilities, things like that, that may not have a regulatory reason to do it.

Aaron Crow (48:27.756): and they're more open to it. But a power utility is never gonna be able to do that from regulatory restrictions around those. So being able to have it on-prem, only my data, like all those types of things makes you, opening the door. It's harder as an asset owner to manage that type of stuff, but there's real benefit and value in those things because I don't want my data going to the cloud for obvious reasons, because I don't want it mixing with anybody else's. I don't want to lose access to it

Aaron Crow (48:57.764): it needs to be all, all those things are very well defined and understood. But that doesn't mean it's not still valuable. There are ways to do it. Like you said on on prem. Yes, you buy more hardware and when you're dealing with AI, it's different than your exchange server, right? It's going to be a little bit more expensive because you need different different resources and capabilities than an exchange server. But

Aaron Crow (49:20.676): but that doesn't mean you can't do it, right? And again, you can also do it in the cloud. You can have your own cloud. You could do it in the cloud. Like there's all sorts of ways that you can look at this, but it's looking at these problems and concerning it. So all this to say in the next five to 10 years, are you excited about coming over the horizon in this space and maybe something that's a little concerning.

Dr Oakley Cox (49:44.332): Great question. Well, I'm excited about how AI can transform cybersecurity in general. think OT is a massive part of that. OT has been kept so siloed and separate for so long. I don't think that can last forever. We have to respect its differences. It's never going to be treated exactly the same. all of these challenges that we face in OT cybersecurity have been the same for

Dr Oakley Cox (50:13.870): well, at least as long as I've been in, which is seven, eight years, but, but speaking to other people, it's been 10, 15 years. It's the same problems. How do we manage our densities? How do we, how do we talk between IT and OT teams? How do we ensure availability? How do we detect stuff? Like how do we make sure we patch all of these things are the same old problems. I am an AI optimist in the sense that I believe that the right AI for the right challenge can completely transform cybersecurity.

Aaron Crow (50:21.742): It is.

Dr Oakley Cox (50:43.726): Because it should be just a business function that's not seen, a business enabler. And at the moment, when you see the number of incidents that are happening and the knock-on impacts it has, it's not happening. It's not fit for purpose for too many organizations.

Dr Oakley Cox (51:0.290): The second part of question was, what am I worried about? And I guess it would be the flip side. Could the attackers stop that transformation from happening? Because they have the ability to adopt much quicker. They can afford to make mistakes as they learn and evolve and adapt, and therefore potentially adopt it quicker.

Aaron Crow (51:3.886): Yeah.

Dr Oakley Cox (51:27.498): Ultimately, that's just a logical extension of what's already been happening. Attackers like to stay ahead of the curve. So I'm not a doomsday about it, but ultimately, that's the biggest challenge is the threat landscape. How is that going to evolve at a pace and a scale that we haven't seen up to this date?

Aaron Crow (51:48.056): Yeah. I mean, ultimately they, they, they have no restrictions. their gloves are off. They, they can test and if it fails, they go to the next, the next victim and they try it again and they improve and they get better and they go to the next place and they try it again and do it better. Like there's no, there's no limitation on them trying and failing. Like they don't care. and,

Dr Oakley Cox (52:4.782): Yeah, the accountability is really hard, right? Like they can fail and nobody, half the time you don't even know who they are. Even if you don't know, do know who they are, there's not a lot you can do about it. yeah, they can really afford to make some big mess ups and get away with it and just learn from it, which helps them get better quicker, right?

Aaron Crow (52:22.594): Right. Yeah. I mean, we all know that we, learn more from failure than we do from success. So every one of their failures, they're getting better. They're getting faster. They're getting stronger. They're getting smarter. and they're, they're not going to, well they caught me here or this didn't work because of this. Okay. Well, let's adjust that and do it, do it better. And they're using these tools to do it faster. So yeah, for sure. So, so what's, what, what's call to action? How do people find out more about AI? Obviously we'll, we'll link to all of the

Aaron Crow (52:49.582): the white papers, cetera, that you mentioned, any others that you want, how can people learn more about OT and AI in the space and what you guys are doing?

Dr Oakley Cox (53:0.632): So yeah, we've recently released a whole package of different documents and kind of education, but videos, white papers around AI in cybersecurity. We don't split it by coverage area. So it kind of covers cloud ITOT altogether, because as I've already said, that's how we envisage the future, right? everything needs to be treated in a similar way, not exactly the same way, but a similar way. So yeah, check it out.

Dr Oakley Cox (53:29.954): darktrace.com, you can find all of the resources there. The AI arsenal is the white paper that I mentioned earlier. But also check out our blogs for examples of these threat finds, these APTs, zero days that we detect in our customer environments. And yeah, and then reach out if you want to learn more specifically.

Aaron Crow (53:51.268): You can talk about what's under the bonnet.

Dr Oakley Cox (53:54.134): Under the bonnet. Under the hood. Under the hood sounds like a little Red Riding Hood story.

Aaron Crow (53:55.564): I love it.

Aaron Crow (53:59.320): Hahaha!

Aaron Crow (54:2.756): Well, also sir, hey, was great to have the conversation. It was great to meet you in person. My entire intent with this podcast is to grow and have people have different, challenge the status quo, right? And how do we get better, faster, stronger as a community? And how do we learn and look at things from different perspectives? Which is why I love having diverse opinions and ideas and perspectives on the podcast to talk about things. I'm not always gonna 100 % agree or align with everything, but that's the point, right? Is to have conversations and

Aaron Crow (54:32.534): and have dialogue and we can still go have a beer even if you and I don't agree on something, right? And that's okay. But obviously on this, we didn't really disagree on many things because I think the problems are there and the future is going to be using AI and cloud and all those things to our benefit. It's just a matter of how and when, like how do we push the button? How do we accelerate and do those things? Because to your point, the bad actors are already using it and they're already trying it. we've got to start using, we got to be smart and not...

Aaron Crow (55:0.854): avoid tools just because we're scared of them. Obviously we need to be careful because I don't want to bring down my power plant, but I also just can't say, well, I'm never going to do that because that's just going to end up hurting me, inviting me in the backside because of that. So.

Dr Oakley Cox (55:14.530): Yeah, completely agree. Thanks, Aaron. It's been an absolute pleasure. Really enjoyed the conversation.

Aaron Crow (55:18.904): Yeah, man, I appreciate your time and thank you for for dedicating it with me and continue doing what you guys do. And I look forward to seeing you again at another conference coming up soon. Amen. Thank you.

Dr Oakley Cox (55:28.608): Yeah, we'll do. Thanks, Bye bye.

Transcript lightly edited for readability.

Want your brand in front of OT, IT, AI, and cloud security decision-makers?
PrOTect IT All listeners are the practitioners and leaders making security buying decisions across critical infrastructure.
See Sponsorship Packages →

Never Miss an Episode

Subscribe to PrOTect IT All and stay ahead of the threats targeting critical infrastructure.