Ep 64: How to Harness AI Without Breaking Security or Corporate Policies | PrOTect IT All
HomeEpisodes › Episode 64
Episode 64
Episode 64 Solo

How to Harness AI Without Breaking Security or Corporate Policies

Jun 30, 2025 00:15:46
AIRisk ManagementLeadershipSmall Business

Watch This Episode

In this episode, host Aaron Crow dives deep into the fast-evolving world of AI automation and its impact on cybersecurity. Aaron breaks down practical, real-world ways security professionals can leverage AI to streamline their workflows without breaking data loss prevention policies or putting proprietary information at risk. 

From drafting reports and playbooks to automating repetitive tasks and managing vulnerability data, Aaron offers actionable advice for using both public AI tools like ChatGPT and more advanced private AI models. He also addresses common fears CISOs and business leaders have about unsanctioned AI use in the workplace and shares tips for staying safe and compliant while taking advantage of AI’s efficiencies. 

Whether you’re in a large enterprise or a lean team with limited resources, you’ll come away with a fresh perspective on how to use AI responsibly to work smarter and protect your organization. Plus, Aaron invites listeners to share their own creative AI use cases and lessons learned. Let’s jump in and explore how to protect it all as AI advances.

Key Moments : 

01:20 AI's Rising Role in Media

03:22 Guidelines for Using AI Safely

07:06 "AI Integration and Automation Strategies"

10:03 Automating Windows Management Tasks

14:29 Exploring AI for Personal Tasks

Connect With Aaron Crow:

 

Learn more about PrOTect IT All:

 

To be a guest or suggest a guest/episode, please email us at [email protected]

 

Please leave us a review on Apple/Spotify Podcasts:

Apple   - https://podcasts.apple.com/us/podcast/protect-it-all/id1727211124

Spotify - https://open.spotify.com/show/1Vvi0euj3rE8xObK0yvYi4

Chapters

01:20AI's Rising Role in Media
03:22Guidelines for Using AI Safely
07:06AI Integration and Automation Strategies
10:03Automating Windows Management Tasks
14:29Exploring AI for Personal Tasks
Read the full transcript

Aaron Crow (0:1.388): Hey, what's up everybody? I want to do a little bit of a solo episode today. Talk about AI automation. You know, I talk about AI a lot on this podcast, but usually it's about AI in, you know, products and using it in an enterprise capacity. You know, kind of big picture. A lot of products that you see at, you know, RSA or the conferences. A lot of folks, everybody's an integrating AI. I just had a founder on the other day.

Aaron Crow (0:30.092): which has a AI focused OT product, like from the ground up, like it's designed using AI. So these things are coming. And those are things that you can definitely buy and you can, you know, integrate into your core systems and into your, your, you know, remediation plans and your program, things like that. But, that's just some of the use cases. So many of us are using AI. Obviously you've probably seen the AI, you know,

Aaron Crow (0:59.840): stuff that you've seen on like Instagram or Twitter or whatever. And it's the Yeti or the, you know, the babies talking and all that, right? So there's some really fun stuff that folks are doing. Creators are creating, you know, doing cool stuff with. I can absolutely see how, you know, people are gonna make TV shows and movies and things like that. That's really exciting. But from a cyber scrutiny perspective, as a...

Aaron Crow (1:27.744): An analyst or or you know whatever job is your manager your supervisor you're in cyber security maybe you have a I tools maybe you don't. I think there's ways that we can be using AI probably most people in technology are dabbling in it in some way but I was moving so fast things that I tried you know six months ago in AI and got really crappy results look at logos look at like heck now you can do video with audio and all the stuff to.

Aaron Crow (1:55.366): But AI is moving so fast that you can constantly be looking. There's all sorts of ways to utilize AI without breaking, you know, DLP rules, without breaking corporate policies, without copying, you know, proprietary information, things like that. So what are those things? Like, obviously, you can help create drafts of, you know, reports. Obviously, you wouldn't want to put customer data in those things. You would want just high level type things.

Aaron Crow (2:23.788): You can work through scenarios. I know we're working with a company, Brett Jinn, that does AI-focused auto tabletops. I've talked about that here, right? But those, again, are very specific tool sets that you're using. But what are some of the bigger ways? CISOs and leaders, business owners, are looking at this and they're terrified. They're scared because of a couple of things, right? They're scared because they don't know what's coming and they don't want their employees

Aaron Crow (2:52.590): looking to use tools and doing them unsafely, uncontrolled, unsanctioned use. So, know, are many, many organizations just block, you know, just flat out block all of these sites, which, you know, may be the right policy for you. But if that is not the case and you're allowed to use that on your corporate environments, you know, there are some ways that you can do it. Now, obviously, you need to be really intentional. You should...

Aaron Crow (3:19.106): highly recommend that you run this by up the food chain, that type of thing. But you know, as long as you're not copying proprietary information, you're not connecting your corporate email, you know, you're not copying and pasting things that don't need to be in there. There's a lot of high level things that you can do that can help you creating presentations. Obviously, again, you're not going to put proprietary information in there because anything I've said it a thousand times, but anything you're going to put into chat GPT or any of these public AI models.

Aaron Crow (3:46.464): I wouldn't put anything into those models that I'm not willing to post on Facebook because you can just assume that that data is available. So obviously you got to be really careful with that. But I also still believe that there are a lot of great use cases for using AI and just the generic AI models that are out there. Obviously, if you're more advanced and more technically capable, you can spin up a VM. You can have, you know, a llama running in your on your own personal environment. And then that data is not going anywhere. So

Aaron Crow (4:15.714): I'm not talking about that because obviously you can take that a lot further. But even with that, you're still taking data off of the corporate environment and putting it in your environment. So still there's there's, you know, DLP data, data policies that go into that. But let's look at this at a high level. You could be looking at threat Intel, things that are obvious already available on the Internet. And you could be taking vulnerability data that comes out, news reports, things like that, and saying, hey, what

Aaron Crow (4:41.772): this new vulnerability on this asset or this Microsoft update, et cetera. You can be digesting all of this data. You can automate reports and summaries, alert triage. Again, publicly information, publicly available information. This stuff is already out there. It's coming across your LinkedIn, your newsfeed. You can clean that stuff up. You can set up agents to be searching for certain things. Google Alerts is a great example. It's not AI. Well, it wasn't.

Aaron Crow (5:8.898): But it was something you could set up keyword alerts and anytime a new alert came up, it would send you a notification. Well, you can set up automation to do, hey, if you see this come in, then take care of this, right? You can draft policies, could draft job descriptions, you can help draft emails. Again, none of these things are proprietary. If I'm gonna send an email to my boss and I'm struggling with exactly the right way to say it, you can tell ChatGPT that and say, hey, this is what I'm trying to communicate, this is the thing I'm trying to get across.

Aaron Crow (5:38.048): And again, none of the information, I would not tell it anything that again, I'm not willing to put on Facebook. So, you know, don't put any proprietary information from the company, any financial information, anything like that. But you can help it with wording, help it with making it sound better, come across better. These are all things that will help to help you with communication. I see chat GPT is just like anything. It's like your cell phone. It's like, you know, back in the day having a calculator in math.

Aaron Crow (6:7.180): You still have to understand how to do it, but that can help you. It's spell check on a word processor. It's, know, the grammar, grammarly, you know, all of these have been tools that we've added on and we've used them to subsidize and make us faster and more efficient in the jobs that we're doing, right? So I really see AI in these spaces, even as a cybersecurity professional, being integrated and integral into

Aaron Crow (6:36.406): how you do your job on a daily basis. You can build playbooks, you can build tabletop scenarios, okay? You don't wanna put proprietary information. I keep saying that, but I wanna hammer that home in that you don't wanna put that stuff in there, but you could still build playbooks. Build me a generic playbook for a pharmaceutical company that has five manufacturing facilities and has one outage a year and is doing...

Aaron Crow (7:3.438): vulnerability updates and blah, blah. Like you can walk through the scenario and it'll help you build it. You can have recommendations for different types of legacy data. can build custom GPTs for your specific use cases. Even creating document management processes, there's just really the sky is the limit on what you can use. Look at your workflow, look at a daily basis on the things that you're doing.

Aaron Crow (7:32.622): Are there things that you're repeating on a daily basis, the repetitive things, the monotonous things, the things that take a lot of time to do and to go through and could be trained or outsourced to a third party? I look at LLM or AI as could I train an intern to do it? If I could train an intern to do it, could I train an AI to do it? Obviously, we'll want to use local private LLMs for sensitive data.

Aaron Crow (8:2.382): But you could integrate AI into SOAR platforms. You could start building things internally. That's the other piece of this is, you know, you're not going to want to put things in chat GPT, but have you had a conversation? What is your company's policy on? Do you have an internal, you know, LLM? Can you do it on site? Can you do it on a company server? Can you start building out AI integrations? know, N8n is a great free tool that you can do and download and run in a local container. You can run that in a container and all

Aaron Crow (8:32.180): N8n does, the letter N, the number eight, the letter N, it runs, it's basically Zapier for a free integration and it's really designed for this automation. So you can have it tie into with API calls, it can do web hooks, can do all, you know, it can log into email and all this stuff. Again, be careful with that in a corporate environment, but you could do a lot of things with this. You can build a lot of automations.

Aaron Crow (8:58.380): When somebody drops a file into this folder, I want it to read it. I want it to dump it to a local model. I want it to summarize it. And I want to send me an email or I want to drop out a report from that in this other folder. Right. There's all sorts of little tools and and and capabilities that you can start building and looking at both as a team. You know, whether you're a sock analyst, whether you're an OT guy or gal, your whatever your your job description is.

Aaron Crow (9:27.168): start looking around and thinking outside of the box. Go through the right approvals. Don't do anything that's risky or dangerous to your organization, but start thinking about AI is coming, y'all. It is coming, it's not going away. More and more is going to be done with this. So start thinking now, how can I do this safely? How can I do this without risking my environment, without risking my job? And think about what is the value that I can bring to my organization

Aaron Crow (9:56.546): by automating things. We've been doing automation forever. I've spent multiple projects where we were automating things by doing scripts, building scripts, these long, know, crazy scripts that we would go out to go grab data off of Windows machines and summarize the data and consolidate data across, you know, these 50 or a thousand devices into a single report, just using scripts. All of these tools now, it makes it so much easier. You don't have to be a

Aaron Crow (10:25.442): you know, excellent JSON script or you don't have to be great with PowerShell. AI can help you create the scripts. That's the other piece to this. I can create a script in my chat GPTs, in my Claude, in a lot of these platforms. And then I can scrub it, make sure that it's clean, make sure it's okay. So again, there's no proprietary information in there. I'm saying, I need to connect to a Windows machine. Well, Windows machines are everywhere. I need to connect to a Cisco switch on SSH using this port. I need to connect.

Aaron Crow (10:53.950): You're not gonna give it credentials. You're not gonna give it the names of your IP addresses of your devices, but you can say, hey, I want to create a script that can connect to Windows machines, grab all the Windows information, pulls out the installed applications, pulls out the, know, whatever the types of devices and information that you're looking for, goes through the logs and looks for these keywords, whatever the thing may be, you could start.

Aaron Crow (11:20.386): telling this stuff to ChatGPT, to Claude, to all these chat agents and start helping you build these scripts, helping you build these customizations, these automations and really up level the work that you're doing. I see this hugely beneficial at smaller organizations. Think about the wastewater places, right? The places that have low, limited budget, limited resources. How can you empower your staff to do more with less? I can't necessarily go buy that new product.

Aaron Crow (11:49.516): I don't really have the skill set to do it in-house. My team doesn't. I can't afford to send them to training. How can I do this in a safe way that enables them to do more with what they have, the tools they have, with the skill sets that they have, and be able to use these tools to lean on and up-level exactly what you're doing. How to stake a client. I know I continue to go back on this, but what data are you sharing? Is it classified? Is it private or is it public? Build a list. Here's what's safe to automate. Be really intentional about this. Talk with your team about

Aaron Crow (12:19.096): talk with your leadership about it. Hey, this is what I want to do. This is the type of data that we would be putting in there, making sure to put no company data in there. Use company approved tools with AI integrations. If you have Microsoft tenant, you have Copilot and that is in your space. So there's another example of a way that you can do it. Again, though, you need to consider and talk with your company's policies, your leadership, et cetera, make sure that your

Aaron Crow (12:49.154): following the path that is approved for your organization. Document your usage, really document it, right? That's really the CYA when somebody says, how did you create this? Where did it go? What data did you copy and paste there, right? So really keep those logs so that you understand and you can show the evidence, the receipts of the things that you did, how you did it, and the information, where you put it, all that type of stuff, right? There's all sorts of tools.

Aaron Crow (13:17.154): The other piece to this on the flip side of this is almost every tool now because they all have AI, you've got to be really intentional about which tools you use. Notion has AI, Microsoft Co-Pilot, Google now has AI. Like all of these things have AI integrated and if it's not turned off, so you may have been using something on your own, Gmail, any number of things that has that AI integrated and you need to make sure that you're not putting things in places that doesn't need to be.

Aaron Crow (13:45.336): I don't think AI is going to replace you. I don't think that it's there yet, but it's going to replace people who waste time and aren't doing it. Organizations that don't adopt AI and figure out how to use it to fast track and to improve is going to get left behind. Cyber security is evolving. Don't get left behind. You are at a place in time.

Aaron Crow (14:8.994): where having cybersecurity is great and having that skillset is great, but you're going to have to also use AI. You're gonna have to integrate that into processes. I don't care if you're accounting, I don't care if you're in the business finance group, I don't care if you're engineering, we are all going to be utilizing AI, because it's gonna help us work faster, more efficiently and better. If I assign an analyst,

Aaron Crow (14:33.634): to look through logs and manually hunt for a certain word, he's not gonna be, he or she is not gonna be as good as me training a computer to look for that same word. It's just impossible. So there's, we know that AI is going to be able to help us and make us go faster. It's just about where can you do it as an individual contributor in my own space and do it in a way that A, it's not gonna get you trouble and B, it helps your organization, helps you, helps you be more efficient. We're not trying to avoid work.

Aaron Crow (15:3.256): We're trying to do it faster and do it better so you can focus on the things that matter. A lot of the times we're focused on and we end up having to spend time doing things that take a lot of time, they're monotonous. Think about an expense report. I hate doing expense reports. I despise them. But imagine if I had an environment where I took my expense report or I took all my expenses, I scanned all those receipts and I made a summary of them into report. And then even if I have to then manually enter that into my expense system,

Aaron Crow (15:32.394): At least I can keep track of so I don't forget about things. I'm very bad about keeping my receipts. I scan all of them now. I use, but that's my data. It's not a company information issue. That's all on my phone. I take pictures of receipts, all that kind of stuff. But I still sometimes struggle to keep track of, I forgot to do this receipt. You can set up systems to help you remember to do certain things like that.

Aaron Crow (16:1.398): Anyways, all this to say guys, definitely think about how can you use, I'd love to hear some feedback from you guys on what are you using AI for outside the box thinking, are you using public systems like ChatGPT, Claude, Grok, et cetera? Are you using local LLMs? What are you using for, what are the use cases? Did you get approval? Have you been in trouble?

Aaron Crow (16:23.786): Like where have you struggled? Where are you wanting to do? Are you working to build out any AI automation type stuff? So love to hear more about it. Definitely post, comment, let us know. Share ideas, guys. This is how we grow and how we get better and faster.

Transcript lightly edited for readability.

Want your brand in front of OT, IT, AI, and cloud security decision-makers?
PrOTect IT All listeners are the practitioners and leaders making security buying decisions across critical infrastructure.
See Sponsorship Packages →

Never Miss an Episode

Subscribe to PrOTect IT All and stay ahead of the threats targeting critical infrastructure.