Welcome to another episode of Protect It All, where we dive deep into the world of IT and OT cybersecurity! In this episode, host Aaron Crow sits down with Patrick Gillespie, OT Practice Director at GuidePoint Security, for a candid conversation that's as insightful as it is relatable. Patrick, whose journey has taken him from working in manufacturing and building freight trains to leading OT security initiatives, shares real-world stories about the challenges and realities of protecting operational technology.
Together, Aaron and Patrick discuss the blurred lines between IT and OT, the importance of understanding business priorities in security, and why collaboration rather than heavy-handed mandates makes all the difference in securing critical infrastructure.
Whether you’re a seasoned professional or just getting started in cyber, you’ll come away with practical insights on risk management, building trust with operations teams, and the vital role of mentorship in developing the next generation of OT security experts.
Stay tuned for a grounded, actionable conversation that reminds us all: when it comes to securing the intersection of IT and OT, it’s about more than just technology -it’s about people, process, and the bigger business picture.
Key Moments:
05:53 IT and OT System Confusion
07:43 Implementing Fortigate and Managing Risks
11:21 Outdated Systems and Patch Challenges
15:43 Comprehensive Onsite Assessment Toolkit
17:56 AI or Traditional? Balancing Approaches
21:16 "Securing OT: Remote Access and Training"
25:47 Cybersecurity Skill Growth Forecast
26:38 "Mentorship in Cybersecurity Careers"
30:22 Understanding Your Network Setup
35:39 Balancing Security and Accessibility
36:09 Leveraging Operational Team Buy-In
39:27 IT Budget Prioritization for OT Needs
42:44 Challenges in OT Security Adoption
46:56 Tech Growth & Infrastructure Expansion
About the Guest :
Patrick Gillespie has spent over 15 years immersed in the world of cybersecurity, with the last three and a half years serving as the OT Practice Director at GuidePoint, a leading value-added reseller specializing in cybersecurity products.
At GuidePoint, Patrick leads a dedicated team of OT engineers focused on securing both operational technology (OT) environments and the rapidly growing array of IoT devices. Recognizing that clients often CISOs may not directly own OT assets or remediation processes, Patrick excels at bridging the gap between IT security leaders and their operational counterparts, such as plant managers and controls engineers.
Through his work, Patrick guides organizations to understand and address the unique challenges of OT security, helping them build collaboration across teams to strengthen their overall cyber defenses.
How to connect Patrick :
GuidePoint Security University: https://www.guidepointsecurity.com/gpsu/
MilMentor: https://www.milmentor.com/
Linkedin: https://www.linkedin.com/in/cpgillespie/
Connect With Aaron Crow:
Learn more about PrOTect IT All:
To be a guest or suggest a guest/episode, please email us at [email protected]
Please leave us a review on Apple/Spotify Podcasts:
Apple - https://podcasts.apple.com/us/podcast/protect-it-all/id1727211124
Spotify - https://open.spotify.com/show/1Vvi0euj3rE8xObK0yvYi4
Aaron Crow (0:0.844): Hey, thank you all for joining me on another episode of protected all podcast. I'm super excited today. Patrick is joining me. If you have been in a OT, you've been around the industry, you probably know this man and, and just all the things that he does, guide point does, et cetera. So thank you very much, Patrick, for joining me today, taking the time. And why don't you introduce yourself for anybody that doesn't know who you are and a little bit about your history and how you got here and all the fun we have in OT.
Patrick Gillespie (0:26.792): Yeah, for sure. Yeah, I appreciate you having me here. And yeah, definitely enjoy your podcast and see a lot of other familiar faces on it as well. So yeah, glad to be here. So yeah, name's Patrick Gillespie. If you can't tell by the accent, I live in Arkansas. So I've been here about 15, 16 years. I've been at GuidePoint for the last three and a half years. So I am the OT practice director at GuidePoint. So if you're not familiar with GuidePoint, we're essentially a VAR. We resell cybersecurity only products and my team of OT engineers
Patrick Gillespie (0:55.784): are hyper focused on securing OT environments and IoT. IoT devices are everywhere too. So, but we definitely are heavily, heavily focused on OT and helping our clients who are typically CISOs understand what they can even do in OT. You know, even though they don't own the assets or they don't own the remediation, you know, trying to get them to start working with their counterparts and engineering plant managers, controls engineers, you know, those kinds of things. So, yeah, I kind of, I guess go back.
Patrick Gillespie (1:25.672): to why I'm in OT. I didn't come to GuidePoint to do OT. Actually probably the exact opposite. I came on to manage the Threaten Attack Simulation Team for offensive security, doing penetration testing and red teaming for very secure networks, for a lot of large companies, those kind of things. But GuidePoint has a lot of clients that have OT.
Patrick Gillespie (1:53.256): And it's now starting to get attention, especially since COVID, all the remote access needs and things. So it got bounced around, I guess, about three years ago. At some point, somebody asked, hey, does anybody know Industrial Control Systems? And I my boss, I said, it came around a couple of times. Nobody responded. And I said, well, I'm not trying to volunteer for anything, I worked in manufacturing for 11 years. I don't mind meeting with them to see what they even want to do.
Aaron Crow (2:14.850): BUT
Patrick Gillespie (2:22.120): You know, said, because I was like, I had, I've been out of it for a while, but back when I was left OT and what we called OT now in 2016, I built freight transfer eight years. So I left, left the freight train rail manufacturing industry in 2016 and got into offensive security. But I do remember there's clear text protocols, no authentication, know, internet lines all over the place. So trying to figure out, Hey, what do y'all like, what do you want them to accomplish in this environment?
Patrick Gillespie (2:49.808): So just started meeting with them. We just kept getting asked more and more to where we just started building out OT services under that TAS team. So again, kept growing and growing until two summers ago, the Godpoint partners asked me if I would consider building out a nationwide practice for operational technology. And since then we've been doing that. You I don't do any real work anymore, of course. All my engineers do all that. I say I'm just a pretty face for OT. I'm either on Zoom or on the road, you know.
Patrick Gillespie (3:18.672): enjoyed hanging out with you in Vegas at Black Hat and seeing a lot of the community there. But yeah, so now we do the whole gamut. Everything that Godpoint's done for 15 years in IT, we now have built that in OT, essentially. But we also know that there are IT devices in OT, whether that's an HMI or historian, you got switches and routers and firewalls. So essentially, we've built joint services with all the firewall experts of Godpoint, the
Patrick Gillespie (3:48.040): know, network architecture, the identity team, the pin testing team. So we do a lot of OT pin testing, OT incident response, kinds of things. you know, trying to help our clients, you know, get started in OT security and, you know, kind of mature that program, right? And then also, since we've started this practice, GuidePoint has joined the OT Cyber Coalition in DC. So I represent GuidePoint there. We're actually pretty cool group.
Aaron Crow (4:9.390): Mm-hmm.
Patrick Gillespie (4:14.376): I think there's like 15 members. It's a nonprofit that essentially we advise Congress, Capitol Hill, the House, the senators, White House, all that for securing critical infrastructure. Since my background was manufacturing, I actually started out as a CNC programmer building elevators a long time ago. Around the time I was in the Army National Guard as an intelligence analyst, I got into manufacturing that way and then ended up, like I said,
Patrick Gillespie (4:43.718): doing, working for a company from the 1800s. know, trains have been built, I think since around 1812 was like the first locomotive somewhere around there. So a little bit before the internet, of course. So the culture of a company from the 1800s was poor for IT, much less for security. was no appetite for security whatsoever. I was responsible for building automated
Patrick Gillespie (5:10.524): the infrastructure for automated facilities to build parts for trains. And then of course, the freight trains themselves and the systems that supported all of that. And then all the repair facilities. So again, my career, you know, wanted to go more cyber. So I went offensive security. So I didn't touch OT from 2016 till 2022. And now love it. Like we didn't have cool tools 20 years ago. I had, I had Wireshark and PRTG and I was actually talking to somebody the other day that
Patrick Gillespie (5:39.078): They still use PRTG. so yeah, it was the only way I could get any kind of visibility on the wind side, wind links. And so yeah, I wish we'd have had all these cool tools 20 years ago for sure. I might not have left manufacturing, but it would have been a little more fun during incidents instead of watching Warshark for two hours. So that's kind of, I know that was a very long intro there, but yeah, it's kind of how I got into OT and why I'm doing what I'm doing. I didn't say not yet, I guess.
Aaron Crow (6:1.270): No, it's great.
Aaron Crow (6:8.910): Yeah, well, and you said, you you raised your hand and that's that's the number one rule that you're not supposed to do, right? If you don't want to volunteer, you can't raise your hand, which is why no one else did. I'm probably I'm sure so, you know, it's it's it's so funny hearing I've had so many people like you sit in that seat and have this conversation and so many of us didn't like I came from an IT background and and my dad was in power utility for 45 years and.
Patrick Gillespie (6:14.499): Yep. Never.
Patrick Gillespie (6:18.578): person.
Aaron Crow (6:34.434): So I grew up around power plants and all that kind of stuff, but I wasn't really working in it. wanted to do my goal. I wanted to go work at Microsoft and Google and all that kind of stuff. And it wasn't until I really got back into power, cause I had some early part of my career. I got out of it for a while and then I got back in. And to your point, like, you know, I've loved it ever since and I've dove in. I still dabble in the IT thing and work because, you know, you and I were talking before we recorded this morning.
Patrick Gillespie (6:42.536): a little bit faster.
Patrick Gillespie (6:59.336): you
Aaron Crow (7:1.458): You go on an assessment, you go on a site and a client needs help. And a lot of times if they don't have a mature environment, there isn't a clear delineation of where is OT and IT. Is this system an IT system or an OT system? Is this an OT firewall or an IT firewall? Is this Windows machine, is this IT or OT? It's sitting on the manufacturing floor, but it's plugged in the IT network because they need to be able to connect to their ERP system and they need to scan barcodes and they're printing to a Zebra printer.
Patrick Gillespie (7:6.140): want it.
Patrick Gillespie (7:22.600): Yep.
Aaron Crow (7:29.464): but it also has a serial connection in the PLC that they're running, you know, the skid on or the lathe or whatever the thing is that it's controlling. So it's this hybrid, right? And so we're having these conversations with IT and with OT and it's being able, and for me, I think it's that superpower of being able to really say there is no clear line of delineation. There is no, this is always an OT device. This is always an IT device. Most of the time it's black and white and it really just depends on its use case.
Patrick Gillespie (7:30.536): So that's the of the PMC.
Patrick Gillespie (7:38.184): Yeah.
Aaron Crow (7:59.225): But also, it really almost doesn't matter. It's like, how can I do this securely to make sure that they can do their work? Because it's very easy to come in from an IT perspective and say, I'm gonna lock this down, I'm gonna kick this off the network, I'm gonna put a firewall around it. But at the end of the day, they need to make those widgets, whatever they're making. And if you make it so hard they can't do it, they're gonna find a workaround anyways. And then the business shuts down, they're not profitable, the business closes. So we have to keep this in mind. And that's not a mindset we have on the IT side.
Patrick Gillespie (8:12.094): So.
Patrick Gillespie (8:18.792): So I think that's it.
Patrick Gillespie (8:24.754): Yeah.
Aaron Crow (8:28.706): But on the OT side, we have to have that. And that's one of the bigger things I see from my perspective, walking into an OT space, trying to help. I can't just walk in with a hammer and hit people over the head with security tools and expect them to respond well.
Patrick Gillespie (8:32.154): see.
Patrick Gillespie (8:42.013): Exactly. Yeah, because it's definitely different priorities because you know even like when I was going around I did a lot of projects in those manufacturing and repair facilities So we would you know, if I replaced a I actually replaced all my Cisco switches with Forti gates This was like 15 years ago. They were the support for Cisco They wouldn't I couldn't even get budget to approve support for the switches at each site or routers Cisco routers
Patrick Gillespie (9:7.401): So I did get approval to put a FortiGate in because then I was able to do SD-WIM, multiple links and all that stuff. did that. So each time I did a project, I did it at all the sites, but I would find cable modems in OT. And it's not that they were being malicious, right? Because most attacks that are successful and detrimental, especially manufacturing, are accidental or a developer. Our incidents in American Real Car were more
Patrick Gillespie (9:35.174): developers accidentally wiping out the Unix server from root because they had root access and wipe accidentally, you know use the asterisk or whatever So wiped out to complete ERP systems, which took things down for days What's called, you know, then that's millions and millions of dollars All that fun stuff. But again, you know when I found those things it wasn't like like you said I can't go bashing the plant manager in the head for that because their intent is to save the company money Keep the plant running
Patrick Gillespie (10:4.486): because some of the automated facilities that we built, we had vendors from all over the world. We worked with probably Google primarily on the automation side. We had a lot of Siemens, we had some Rockwell, but it primarily Siemens back when I did a lot of that. But we had people from all over the world. We had heat treat furnaces that come from Canada. We had a huge forge that built out the double axle for trains and that came from Austria.
Patrick Gillespie (10:33.820): when they're doing these things, plugging a internet connection into a POC cabinet to a device that has a port that does not require authentication, has no encryption. So now literally clear text protocols, no authentication, public IP. So like, know, for security, that's the worst of the worst of the worst, right? But for them, it's now they don't have to wait for somebody to fly for two days to come fix something.
Patrick Gillespie (11:1.832): They're keeping the business running. They're saving the money, saving money. They're increasing profitability. So again, it's not like they're doing, yes, from a security perspective, that's bad, but their behavior was not ill intent whatsoever. So yeah, you definitely got to have a different look on it. And I've seen a lot of tools get sold or clients I'll talk to, CISOs I'll talk to that, hey, we've had this XOT tool for three years, five years, seven years. We haven't got one actionable alert.
Patrick Gillespie (11:32.060): We haven't changed anything because of this visibility. So that's where we come in and really try to help make sure they're getting visibility. Most of the time it's just never got fully deployed typically. And then showing them how to use it and all that fun stuff. definitely. But yeah, definitely great point on that because it's definitely all about availability because it can be the most secure business in the world. But if the power shuts off for a week,
Patrick Gillespie (12:2.463): It doesn't matter, you know.
Aaron Crow (12:3.597): Nope, it doesn't. how I've had this conversation so many times. I know it sounds like a broken record for you, but it's listening to this podcast. Like these are problems that we have an OT and it's not going like we're not going to wave a magic wand and replace all of the equipment in an OT manufacturing facility or power plant or something like that and be on the bleeding edge. And honestly,
Aaron Crow (12:24.333): That would probably make things less reliable. Like how many times do we, you know, patch a Windows machine in at blue screen of deaths, right? You know, we don't want that in an OT environment. We'd rather just leave it over in the corner and don't look at it and protect around it instead of having to patch it. Like patching is just not something you want to do. So how are you having these conversations? How have you been successful and kind of flipping that script in the conversation that you're having with these CISOs and how they look at risk differently in OT and IT.
Patrick Gillespie (12:33.351): Yep.
Patrick Gillespie (12:53.773): Yeah, it really just depends on the location so working with companies and I met with a company in Dallas this week that Was I think founded in like the 1850s? It was not even not even manufacturing but again, so they have a lot of very old facilities But they also have new facilities you have new data centers being built new automated distribution Facilities with robots in self-driven forklifts, and they're really cool
Patrick Gillespie (13:19.464): And but that's very different than supporting a manufacturing plant that has all Windows 98, right? Because those legacy ones where it is too expensive to replace every HMI and you know, every machine just to replace the HMI. And a lot of times those software and hardware vendors from the 90s and 2000s are out of business or people who wrote them are retired, you know, no longer working those kind of things. So so patch management. You know, if it's a brand new facility and
Patrick Gillespie (13:48.744): the devices are supported. If you come in, Windows 11 or Linux, whatever operating system it is, and you have supported Rockwell, Siemens, equipment, then that would make sense to prioritize patch management alongside segmentation and micro-segmentation. But for these older facilities, may, less than 10 % of the devices may even have patches.
Patrick Gillespie (14:15.846): Right? So it's, you know, that's like you said, that's where the mitigating strategies come into play. You know that. Cause it is just so easy patch, patch, patch every day or whatever. Even if, even if there were patches and OT, like you said, you can't just shut down the facility to do something that may or may not ever even be needed, you know, you know, depending on the situation. yes, definitely, definitely much different strategies in our, and we have to help our CISOs understand that.
Patrick Gillespie (14:45.384): Because if they come in saying, hey, you we're going to lock down this firewall. We're going to add encryption in OT. We're going to add authentication. When there's a down, if there's an outage, even if it was a year ago when you did this, the first thing they're going to do is shut off all security, get it back running because they're going to blame that. 20 years ago, the network was always the blame, you know, always got blamed for everything. Even if didn't matter if it was a database application, whatever. But now it's definitely security that gets, you know, kind of blamed for.
Aaron Crow (15:0.483): Yep. Yep.
Patrick Gillespie (15:15.604): anything extra latency which can hurt OT systems especially you know legacy things so there's just so many things that it's like it just you just got to have different controls you got to have a different look on it so yeah
Aaron Crow (15:19.033): Yeah.
Aaron Crow (15:29.699): I feel like a paramedic or a first responder showing up to an accident and you're having to triage. They've got a broken arm, their nose is bleeding, their clothes are ripped off, but the car's on fire and they're in the middle of traffic and there's more cars coming at them. You have to be able to look around because there's always going to be, anytime you walk into some place,
Aaron Crow (15:57.431): And obviously maybe it's more glaring in an O.T. space and an I.T. space, at least the way that we're talking about it. But there's always going to be things that you can find. But it's about, you know, not fear selling and not the sky's not falling. Sometimes it is. Sometimes the sky's falling. But, you know, sometimes it's just a matter of, OK, calm down, deep breath. You're here. You've been running this way for 10 years, 20 years, 30 years, 40 years. So, you know, just because we see it today, it was there yesterday and you were fine. Right. So.
Patrick Gillespie (16:6.118): yeah. Yeah.
Patrick Gillespie (16:20.230): Yeah.
Aaron Crow (16:25.461): let's figure out a plan and let's prioritize and say if I have five minutes to spend on something, this is what you should focus on. And then after you get that thing done, then this is the next thing. And then this is the next thing. Cause you're not gonna, you can't boil the ocean. You're not gonna solve all the problems overnight. Like prioritize the things in order. And that prioritization I think is the biggest difference between IT and OT of where I focus my time and energy.
Patrick Gillespie (16:41.096): Yeah.
Patrick Gillespie (16:48.553): Exactly, because yeah, if the sky is burning or yes, guys burn if fire is falling from the sky and there is an incident and ot is shut down if the power facility is not distributing power the water wastewater treatment facility is not cleaning water if the nuclear facility core is going unstable you get ot operational You unplug any internet connections you let ransomware run inside you you let any malware
Aaron Crow (16:52.995): That too.
Patrick Gillespie (17:15.868): go, you get it running, then you stop the malware, you stop the ransomware and then recover from there. Like you said, it's you got to prioritize the availability over that confidentiality for sure. because the data in OT, like it's one thing for data in IT where proprietary information or sensitive information, PII, all that fun stuff, credit card information. So that's data that needs to be protected for a long time.
Aaron Crow (17:35.668): PII, yeah.
Patrick Gillespie (17:44.124): But data in OT is real time. the temperature of that heat treat furnace, it matters right now. It didn't matter what it was two seconds ago. What is it right now? What water level is that cooling stack at? know, all that. it's used differently, but that's also, think it's called now cyber physical because the data there, changed improperly, you know, up or down, left or right, whatever, could hurt somebody.
Patrick Gillespie (18:13.276): could physically hurt somebody, kill somebody. Accidents happen all the time and especially large operational facilities and things. So yeah, you definitely don't want things turning on when they shouldn't be or turning off when they shouldn't be, those kinds of things. yeah, prioritization is it because when we hook up a visibility tool, we often find, hey, this device has this virus. like you said, it's probably been there for 10 years or unpatched.
Patrick Gillespie (18:42.824): Firewall for 10 whatever you know they're just because I see behind me a lot of my My backer I'll be a manufacturer you know some of that PLC equipment me very old like SLC 500 and we got Windows 98 back there because we have a lot of clients still running Windows 98 so Yes, just it's very much a different different strategy and but like you said when you get to the wreck or the OT environment like I Want to equip my team my engineers or you know paramedics in that situation?
Patrick Gillespie (19:12.680): to go in and be able to quickly assess the damage and then have the tools in their kit, flyway kit, assessment kit, whatever you want to call it, have an array of tools that no matter what they see, they have it. They don't have to ask for an internet connection to the cloud. If all they're on-prem, they can help resolve if there's malware running around or provide that visibility or...
Patrick Gillespie (19:41.704): start integrating things. There's a lot of great data even sometimes about OT in a lot of the IT systems like a CMDB for example, things that somebody had to purchase these things and they may be in the purchasing system. So thankfully a lot of the OT tools now have integrations with these tools to help pull a lot of that asset data and start doing traditional things like asset management. Because it's hard to secure.
Patrick Gillespie (20:10.281): If you don't know it's there, you can't secure it properly.
Aaron Crow (20:13.549): Right. Yeah. mean, many times when I'm walking into these places all the way back to, you know, I was CTO of industrial defender and we talked about that stuff, you know, working at EY, working at all these places, even when I was an asset owner and a power utility, right? That was one of the main things that we focused on was I have to understand what's in my network and then I can start defending it, right? It's hard to defend what I don't know is there. I know about these things, but what about the stuff that is over in the corner that nobody told me about? Right. How do I, and those are
Patrick Gillespie (20:31.836): So, yep.
Patrick Gillespie (20:40.530): Exactly.
Aaron Crow (20:41.951): A chain's only strong is its weakest link. We're throwing out all sorts of puns today, right? But it's so true. if I have protections, and that doesn't mean that I have to remove the Windows 98 thing, it just means I need to know about it so I know what vulnerabilities it has so that I can protect it. And that doesn't mean patching. can't patch Windows 98. But I could put it in a segmented environment. I can put firewall rules on it. I can make sure that I disable USB ports and things like that that make it risky. I can reduce that risk. It's never zero, but I can reduce it.
Patrick Gillespie (20:45.663): Yeah.
Patrick Gillespie (20:53.288): Thank
Patrick Gillespie (21:0.178): Thank you.
Patrick Gillespie (21:10.866): Yeah.
Aaron Crow (21:11.693): I know I'm not going to plug that Windows 98 machine in the Internet like that's a that's a definite no. You can I don't recommend it though.
Patrick Gillespie (21:17.512): Yeah, well, you can, you know, you don't want to exactly. yeah, it's yeah. But again, like to me, this stuff's fun. Like it's, you you're dealing with retro. So Godpoint has a lot of crazy smart people and we're cyber security only like 1100 employees. And when I go to his Godpoint conference or any other conference where Godpoints at a lot of times it's the huge thing right now is AI. AI, do we use AI for our business? Do we?
Patrick Gillespie (21:46.920): Do we block all the AI? Does AI protect our AI and defend our other AI? And then I'd jump in and it's like, we're gonna go a little retro here and I'm not gonna talk about AI. it's just, I don't know. And I don't know if I'm definitely older now than all the younger folks, more traditional command line than pre-cloud services, definitely traditional Active Directory Windows.
Patrick Gillespie (22:16.904): servers all over the place and got a couple rack servers back there too. But yeah, so that's kind of how we help a lot of the CISOs is just understanding how to talk with the asset owners. And we have to keep it simple. When we started building this out, you know, two or three years ago, we used a lot of things like 62443 Cisco Plantwise Converged Ethernet and of course all the guidance that all the different government agencies put out. FDA, Food and Drug Administration puts out cyber guidance for medical devices.
Patrick Gillespie (22:45.178): EPA, water, wastewater, NERC SIP for power. got TSA for an FAA for air, TSA for rail. know, cruise ships are in their own international waters, are whole different beast. But so, you know, we made it so complex, like it was so, so much information that like it was 100 plus pages per site for these assessments. You hand that to a CISO who doesn't own any of the assets remediation.
Patrick Gillespie (23:13.672): You hand that to a plant manager. was like, here you go. This is all the things you need to do. Go find your priorities. know, it's nothing happened. Like nothing. Like we would then meet with the clients a few months later. It's like, Hey, how's this going? It's like, well, we never did anything. It's just, it's just, we don't know where to start. So we dumbed it down. I don't say dumb it down. We simplified it to essentially the SANS five critical controls for industrial control systems. So we've grouped our vendor partners, our OT and our OT vendor partners into
Aaron Crow (23:20.228): Good luck.
Patrick Gillespie (23:42.844): four of the categories that you need technologies for. And we grouped all of our services into each of the five categories. So now when we do an assessment, we give them a crawl, walk, run roadmap based on those five controls. So if you don't have an OTAsset inventory, a lot of times CISO doesn't, especially a full one for hardware, software, you're not even crawling. To crawl, we're gonna build you an OTAsset inventory. Then you can do your policies and procedures and asset management and so on and so forth.
Patrick Gillespie (24:11.974): You know, if do even have an O.T. specific hour plan? Because if not, if if if you put in a visibility tool, doesn't matter which one it is, you're monitoring the span traffic. The SOC gets an alert that it's on an O.T. subnet. It could be a Windows box. It might be Windows X. Even if it's Windows 11, that SOC person or whoever is responding to that incident cannot SSH to the O.T. switch and shut that port off, even if it's a modern IT OS inside O.T.
Aaron Crow (24:37.423): Correct.
Patrick Gillespie (24:41.276): your playbook has to be different. Again, we're talking about physical safety here. That trumps everything else from data. So if you don't have those separate playbooks, you're going to have outages. So again, our plan, like already brought up, like defensible architecture, it's got to be heavy micro-segmentation. And I'll also include OT secure mode access and defensible architecture because of the quickest way to reduce so much risk is by
Aaron Crow (25:2.009): Yep.
Patrick Gillespie (25:10.386): treating your IT network like it's the freaking internet. If you're in OT, you want to treat IT, I know they zero trust, we'll fill that one out there too, but you don't want to trust anything coming from IT. But you can't just shut all that off. You have to have visibility and know what's communicating, what should be communicating. Is that business critical? Is that engineer remoting into a PLC over VNC with no password?
Patrick Gillespie (25:39.592): Is it a ERP system pulling data from a historian and then going over to billing? know, once you figure out, these are legit things that need to happen, you do them the right way. You set up OT remote access for your engineers to get into the OT HMIs or workstations, whatever. And you do the same thing for your third party vendors. You set up industrial DMZ and then you shut off all the IT to OT connections, right? Because now you should know what's connecting the two. So now when that
Aaron Crow (25:59.096): Mm-hmm.
Patrick Gillespie (26:8.186): Accounting I pick on accountants a lot in my talks, but clicks that link in that phishing email That and ransomware, know, hopefully is gets stopped pretty quickly in IT It's not gonna spread over to OT right that open SMB share that an engineer Decided to hey this be easier for me instead of walking out to the plant and sticking a USB drive in I'm just gonna share a folder With no password, right? So that happens a ton So and then to the
Aaron Crow (26:31.823): Hmm?
Aaron Crow (26:34.905): It does.
Patrick Gillespie (26:37.844): So we do a lot of Like our team my engineers do a lot of mentoring like you mentioned entry level. So guide point has a guide point security university And a lot of us help other people in the community, right? t-security is very niche a lot smaller than the whole cyber security or IT umbrella so for those that are entry level, you know, lot of people say well, you can't be entry level in OT it's like
Patrick Gillespie (27:4.815): You can know how to secure something. It's the same thing when like offensive security and pin testing was new like 15 years ago. You're like you can't be an entry-level pin tester. Well, you can figure out what routers have a vulnerability and know how to exploit it without knowing how to configure the router. You know, it's there's different things. There are always things if you go into a add a visibility tool and they get a million assets, you can't pay a senior engineer.
Aaron Crow (27:10.351): Mm-hmm.
Patrick Gillespie (27:31.676): to go classify every one of those, you have to have people learning OT and you got to prioritize the younger generation. If not, you know, when we're all put to pasture, then, you know, there's these to be people behind us ready to take the helm and keep this stuff running. You know, so, so from an entry level perspective, if you're entry level, entry level means, you know, let's say you're inexperienced doing OT security. You've never done OT security.
Patrick Gillespie (27:59.496): You may have been in IT for 10 years, you may have been in the military the last 10 years, doesn't matter. You may have just graduated college. So if you're doing IT, help desk, network admin, system admin, cloud, whatever, talk to the people who are running OT. Don't do what I did when I started. So I learned a bit the hard way on that OT is sensitive to things like port scanning. when I did the first OSCP course,
Patrick Gillespie (28:28.370): This was in backtrack Linux. anybody remembers that this is before Cali Linux ever existed. So I did it with backtrack Linux and open boss was kind of the tool to use then. So of course I had my IT computer on the IT network and also managed these physically separated. It was just a plant network. It was one or two, I to say dot one. Everything was on that. And then
Aaron Crow (28:32.399): before Cali. Yep.
Patrick Gillespie (28:57.288): Of it was like a slash 16 and they just kept adding more stuff to it. But so of course I plugged a second Nick into that network. So now I got a dual home Nick. Hey, I can play with this older stuff. So I run open boss on the OT network and, and of course weird stuff happens, but the, the, the craziest thing help desk calls me. It's like, Hey, there's a, the, there's a lady in shipping freaking out.
Aaron Crow (29:13.057): and scan the network.
Patrick Gillespie (29:26.376): Her printer won't stop printing the message. Are you dead? So So open boss, that's like one of the messages like it's seen so like it sent this message I guess instead of peeing it was like are you dead? I don't know why you wouldn't do are you alive? She thought somebody was like like stalking her or something like she was freaking so I had to go there and Apollo profusely apologize But but then I learned like you can't really do you know, these things are not the same
Aaron Crow (29:33.764): Yeah.
Aaron Crow (29:40.825): Hahaha
Aaron Crow (29:55.065): Yeah. Yeah.
Patrick Gillespie (29:55.066): Right. So don't do that. So if you go meet your OTE asset owners, people who help with the network, because again, they have firewalls out there. They got switches and routers. They're not firewall experts. I wouldn't even call my OTE engineers here that are cyber security focused firewall experts. That's where we bring in a firewall expert along with an OTE engineer and together they make sure that's working properly. When we do an OTE pen test, there's always IT. There's oftentimes active directory and
Patrick Gillespie (30:24.584): OT. So we have to do it very differently. We don't even send broadcast traffic whatsoever, but it's it's somebody from TAS or it's like simulation who's an active directory expert and all their misconfigurations or weaknesses. There's somebody with Windows, Privilege, Privilege Escalation expertise because nobody can know all of this. It has to take both sides working together to have a valuable pin test. And I don't even recommend our CISOs do an OT pin test until they have an inventory.
Patrick Gillespie (30:54.024): visibility because I can tell you 10 findings right now without charging you a dime that you have in OTE. So it's like, some, a lot of times that's what it takes to get leadership buy-in is a tabletop exercise, a pen test, whatever. so start getting to know the people who run your OTE assets just to start learning terminology. And there's great training now, like Mike Holcomb, his whole YouTube, I mean, great in the tube training is you TILSEC channel on YouTube.
Aaron Crow (30:58.404): Right.
Patrick Gillespie (31:22.456): There's CompTIA is putting out, I think, don't know what they're calling it, industrial controls, OT, whatever plus, whatever they're calling it. And then of course, SANS, I know SANS is expensive, but there's a ton of great training out there. But continue to improve your IT security skills while also learning OT because I think that the career growth is going to be great for the next three, five, years.
Aaron Crow (31:27.854): Yeah.
Aaron Crow (31:48.887): I agree.
Patrick Gillespie (31:50.280): because as legislation happens, I think it was 45 states enacted like 75 cybersecurity bills. A lot of the states, a lot of the administration in DC are now focusing on critical infrastructure, power, water, roads, commercial facilities, all these things that our country relies on, airplanes, how much media attention do they get when a system is down?
Aaron Crow (32:20.036): All right.
Patrick Gillespie (32:20.168): you know, for a plane or for for traffic or air traffic control. Like now you got hundreds or thousands of people in a miserable state. It's different when it's rail. You know, rail goes to a passenger rail car. You can go pick them up on a bus. It's usually not that far. But for planes, it's a much different scenario. yeah, just start and start reaching out to other people in the community, you know, because I always tell people I mentor a lot of veterans in the military to get into cyber jobs, I.T. and O.T.
Aaron Crow (32:24.237): Mm-hmm.
Patrick Gillespie (32:50.024): And like you need to have a mentor to, you know, progress yourself, you know, find somebody that is doing or has done the role that you want or you think you want. Cause to be honest, before COVID, I started meeting with mentors because I thought being a CISO was the logical path for me to become in the C-suite, you know? So when I started meeting with CISOs, I was like, I don't want to do that. So one of them, one of them suggested to start mentoring veterans.
Aaron Crow (33:15.502): Yeah.
Patrick Gillespie (33:19.708): to get into cyber from a technical perspective. So I started doing that with several of the veteran mentoring platforms. And like, that's really when my career really took off from a leadership perspective is helping other people, you know, have a mentor, but also be a mentor. There's always somebody behind you as well. Even if you just finished college, you got four years of college students behind you. You know, if you just, if you've been help desk or sock for a year, you got people who've never done that. So.
Patrick Gillespie (33:48.454): Be open to helping others and be kind of course, because not everybody's going to know as much as you on where you're at. I know a lot of times in cybersecurity, can be pretty hard to ask questions because you feel like you're dumb. But yeah, definitely need to ask questions to learn.
Aaron Crow (34:9.827): Yeah. Put, put the ego down, be willing to ask the questions, you know, and I also think that's one of the big things with, with OT, to double click on that you talked about there, you know, there's a lot of things. And so I've been doing this since, 2010, when I started building teams and, and, and power utility. And I had, you know, a team of OT people and my team, had six employees and another 10 contractors that worked for me or something like that. I don't remember the exact numbers, but around those numbers.
Aaron Crow (34:38.071): We supported 45 power plants across the state of Texas, including, including mines that associated mines and, you know, other stuff that kind of went left that. But the main thing was, you know, the, the, the, the, the actual power generation. We had some overlap into the substations, but substations were kind of ring fenced off with Encore and in the state of Texas. And they weren't really my responsibility, but with all of that, again, especially back then.
Aaron Crow (35:2.733): There was no such thing as OT. We didn't have that term yet. Like we just, was controls and automation and, and INC and PNC protection and control, instrumentation and control, DCS, like all that type of stuff. But I needed a team of people that had cyber skill sets, but I also needed people that had the, the understanding of the systems. So I would bring in people that had never been in a power plant. They'd never even heard of OT. They'd, they'd been in law firms and, and
Patrick Gillespie (35:3.430): Yeah.
Patrick Gillespie (35:9.800): plane.
Patrick Gillespie (35:23.580): Yes.
Aaron Crow (35:31.247): you know, data centers and places like that, but they had networking capabilities. But then I would get one of the guys that worked for me had been in a control engineer at a power plant for 30 years at this company. Right. So I brought him out of the INC group into my group because it was amazing how much putting him with a, with a, you know, an IT, you know, backgrounded person.
Patrick Gillespie (35:45.156): up.
Aaron Crow (35:54.703): and how much they could understand and find a solution because the IT guy's like, oh, we'll just patch it. Oh, we'll just reboot it. Oh, we'll just lock them out. And he would be like, the hell you are. And this is why you're not going to do that. And this is why they'll kick you out of the plant. But it was amazing how much authority and ability for us to walk into these places with his credibility. Because when we walked in, he was able to credentialize us even if they didn't know us because he'd been there for 30 years.
Patrick Gillespie (36:6.823): now.
Patrick Gillespie (36:9.682): is in coverage.
Patrick Gillespie (36:22.376): Thank you.
Aaron Crow (36:24.301): the you know, he'd done the control system upgrades and so would I, but the rest of the team hadn't, right? So, so there's a lot more to learn in OT than just firewalls and networking and asset discovery and threat protection. You have to know those things too, but you also like to really a great, I think the difference between a good and a great and an OT person is somebody that understands the functionality. When I walked in, I told you was doing an assessment. I do them all the time.
Patrick Gillespie (36:29.480): at super school.
Patrick Gillespie (36:41.490): So, ready?
Aaron Crow (36:53.411): whether it's a power plant, manufacturer facility, it doesn't really matter. I'm more focused on understanding why this equipment exists and why they have this thing connect. I'm not like, my God, you have this connected to the internet? Like I'm not doing that. I'm just like, what are you trying to do? Why do you have an SMB to this up to your corporate network? What is the job? What is the business function you're trying to get? And obviously the reason you set that up is because you had a pain and this was the only way you could solve that pain.
Patrick Gillespie (37:9.661): Yeah.
Patrick Gillespie (37:16.104): Yep.
Aaron Crow (37:22.541): Let me understand how it is before I just go in and write, you know, the letter that has all the red markings on it because your essay was awful, right? You know, it's the hundred page report you talked about. That doesn't help anyone. It's better to come back and say, hey, here's a better way that you can do that. Not that you can't do it. Not that the answer is to patch and upgrade and, you know, have Fort Knox around the thing. That's not reasonable. What is a better way that they can do this? But you have to be able to listen.
Patrick Gillespie (37:28.199): Yeah.
Patrick Gillespie (37:34.834): Yeah, exactly.
Patrick Gillespie (37:46.674): Yeah.
Aaron Crow (37:51.545): to what the operator, what the engineer, what the plant manager is telling you, understand the business process, and then come up with a compromise, a better solution that helps improve security, but it also keeps them able to do their job. Because if you make it so secure they can't do their job, to your point, they're just gonna unplug it as soon as you leave and go back to the way they were doing it before. Because they have to do their job.
Patrick Gillespie (38:5.789): Yeah.
Patrick Gillespie (38:14.259): Exactly. Yeah, because and to the IT folks and you know traditional IT and security folks a lot of times It's easy to think of your business as a technology business. So like even when you know, I was an IT doing rail car like Nobody in our IT department made a dime for that business. We were supporting the people that were making the trains
Patrick Gillespie (38:38.522): and making money. if it comes down to, you know, the CISO telling the CEO, you got all these SMB shares, we need to shut them off to the plant manager who's making millions for the thing, who's going to win? It's like, it's going to be that plant manager every in time. Like it won't even matter. Like you're never going to win that battle. So don't go in there and call them dumb because they plugged in internet lines and got all this stuff everywhere.
Aaron Crow (38:53.593): Yep. Every time, without a question.
Patrick Gillespie (39:6.438): Right, like you said, they have pain points. You have new pain points now that you've opened your eyes to all this stuff in OT. So yeah, you have to have a good plan and a good relationship with them. They need to trust you. And oftentimes they don't trust people in suits and ties or from the corporate office, know, you know, you know, get still to boost, get you a hard hat, like go out there. Like a lot of IT people want to sit at their desk and remote in to wherever they want to do. They don't want to get out.
Patrick Gillespie (39:36.326): out of their cubicle or out of their office, like go out there. Like, you know, it's, it's really cool stuff. Like seeing an automated facility, like, you know, if there's 16 critical infrastructure industries, my favorite is transportation. I like things that move planes and trains and cars, like all these automated cars now and cruise ships. it's, they're just really cool. They're like cities to themselves, you know, especially the cruise ship side of things. And, but you know, there's other things, if you don't, if you could care less about that, like, yeah.
Aaron Crow (39:50.083): Yeah. Yeah.
Patrick Gillespie (40:5.798): do it, know, go to power generator and power. Electricity is cool, too. Just don't touch it. You know, so there's a lot of really awesome things. Our mining, we have a lot of mining class. I love our mining class like mines are cool. And they're not really they're not even listed as one of the they're more like manufacturing, split manufacturing, split, you know, several different critical infrastructure industries. And they're thousands of feet below the ground, which is crazy to me. So very much safety.
Aaron Crow (40:17.327): Mm-hmm.
Aaron Crow (40:26.553): Mm-hmm.
Aaron Crow (40:30.733): Yeah. Yeah.
Patrick Gillespie (40:35.078): You know, it wouldn't, it doesn't take much at all to create a very hazardous situation down in the mine. So, so yeah, it's good, good stuff.
Aaron Crow (40:43.907): Yeah, so if you're interested in getting into OT, like these are great things to think about. Or if you're already in OT, if you're the CISO that's newly responsible, or you find yourself in a place you don't know where to begin, like it's very easy to, and I've been the consultant that's done that, right? And it sounds like you have too, Patrick, where we beat them over the head with 100 pages of evidence of how smart we are and how bad they've done their job. And that doesn't help anyone, right? You know, I remember walking into a facility and they had,
Patrick Gillespie (40:48.162): So thank you for your party.
Patrick Gillespie (40:59.592): it's different.
Patrick Gillespie (41:5.765): Yeah. Yeah. Yeah.
Aaron Crow (41:14.703): 80,000 endpoints that were out of date patching. And they were like, there's no way we can keep up with patching on this. What do we do? Right. You know, so just saying that you have to patch all this stuff, it's impossible. Impossible. So how can I prioritize that? Right. And that's the conversation we need to have. And you walk into, have this conversation with your IT people, you know, you, that you have, you know, windows 98 and you're never patching and you have SMB and you know, you have remote access and like all of these problems.
Patrick Gillespie (41:20.776): Yeah. Yeah. Oh, yeah.
Aaron Crow (41:43.317): their heads explode because they just don't they can't imagine doing that in an IT world and the right. But the flip side of that, know, Sun Tzu art of war user weaknesses and strikes the straightness is strikes as weaknesses, right? Things don't change very often in the world. So if you do it correctly, if you can monitor, you add monitoring, you have an asset inventory, you begin monitoring your environment, you should be able to notice differences. These devices don't just randomly talk to things. They talk to the one the HMI talks to the PLC and usually nothing else.
Patrick Gillespie (41:52.429): This is short.
Aaron Crow (42:12.461): And if it starts trying to talk to something else, that should be a red flag because it's not like it just randomly. It's not trying to go the Internet. It's not connected to Starbucks Wi-Fi. Nobody's installing anything on it. And any time those things happen, it should be an obvious red flag that says, hey, something's going on. Look over here. So that's the way that you can start protecting these environments is you just have to look at it from a different mindset than you do on the IT. You're in the same tool sets. You just look at it from a different lens, understanding that I can't just go change everything.
Patrick Gillespie (42:29.403): Yeah.
Aaron Crow (42:41.955): But that also means that, you know, this, a lot of these systems haven't been updated. Hell, many of haven't been rebooted in three years, right? And not touch, not change, just normal operations and just sits there and does it right. It's slow, but it does its job. And as long as that old saying, again, coming, my dad live and work in power utility. If it ain't broke, don't fix it. Right? Literally that's the mantra of OT. I'm not going to just replace an HMI because you have a new one. This one does everything I need it to do. Why would I replace it? There's
Patrick Gillespie (42:48.849): I
Patrick Gillespie (42:53.320): you.
Patrick Gillespie (43:4.658): Yeah.
Patrick Gillespie (43:11.462): Microsoft would love for you. Yeah, Microsoft wants you to every two years. Yep. You don't have to, yeah.
Aaron Crow (43:11.978): zero reason.
Aaron Crow (43:15.509): Exactly. But you don't have to like, you know, there there's so many ways around that. And there's so much value to understanding because at the end of the day, there's so much equipment. No, T, there's so much out there that we have to be able to protect it and know when you walk in, you're going to find old stuff and you're going to find things that are crazy. You can't imagine, you know, things directly the Internet, any any rules, you know, direct access, no passwords.
Patrick Gillespie (43:35.774): yeah.
Aaron Crow (43:44.269): or if there is a password, it's literally written on the desk or on the monitor, you know, all that type of stuff. But that's okay. It's not okay and it's okay at the same time. It's definitely something we need to continue to improve, but having conversations like this and helping you understand those things, when you walk into these places, you're looking at it from a, can I solve this problem in a way that the OT team, the plant manager, the operations guys would be on board with? Because if you can get their buy-in,
Patrick Gillespie (44:10.472): around.
Aaron Crow (44:12.429): And the other piece to this really quick, and I want to get your feedback on this is if you know that going in and you know that the plant manager, they own the budget, they own rights. And a lot of times I hear, well, we don't have budget in IT, they won't approve anything. If you can find something that makes the plant manager or the operations people's jobs better, it makes the environment more reliable or easier to troubleshoot or easier to onboard or whatever those things are. If you can make their lives easier, they have the budget.
Patrick Gillespie (44:21.586): Yep.
Patrick Gillespie (44:37.179): Thank
Patrick Gillespie (44:41.074): yeah, yeah.
Aaron Crow (44:41.399): and then they'll pay for it and you get to have segmentation, you get to have secure remote access, you have to sell it as a value to them as an ROI because if it's just cyber, nobody wants cyber, nobody wants a firewall, they just want the outcome.
Patrick Gillespie (44:46.503): Yep.
Patrick Gillespie (44:52.983): yeah, I could care less. Yeah. Exactly. So that's where like God, you know, we've been selling to the CISOs for just the beginning of Godpoint. And that's where, you know, we're having to kind of teach ourselves teams that, you know, if it's an OTS owner that wants this, because a lot of these OT tools not just provide the visibility and where risk is, but those anomalies like you talked about, like why is this ITIP now downloading PLC files? Like that's
Patrick Gillespie (45:20.454): just not normal behavior. So that tells you the anomalies and helps you if a third party vendor is doing stuff outside of the change window or causing issues and they're saying, no, we never touched it type stuff. the shared goal, if you're on the IT side or security side, whatever your shared goal with OT is to reduce risk. Patch management is a tool that you can use to reduce risk. It's just not as much of a priority in OT and it shouldn't be.
Patrick Gillespie (45:49.414): You know, again, you have other tools you can use. You just gotta, you know, learn what those are.
Aaron Crow (45:55.245): What's the craziest thing that you've seen or the thing that surprised you the most when you walked into one of these places and saw something, the way it was configured or a perspective of someone, whether it's IT or OT, anything come to mind?
Patrick Gillespie (46:11.009): Man just all the internet connections like you know I would I did an pin test when I was a pen tester a long time ago and saw Traffic I don't even remember going to what it was going to but essentially I saw stuff coming from from IPs in Africa through To multiple endpoints inside the network like like
Patrick Gillespie (46:37.554): I don't know if they had any any allowed or what, I, but I saw a failed authentication attempts directly to a domain controller from Africa and directly to something. I don't remember what it was in OT, but like communication, like they were talking SNMP with public or private, whatever two devices in OT and, and that internet line came through it. It was that part. Wasn't even configured appropriate. Like you said, the any any stuff it's so easy to misconfigure a firewall.
Patrick Gillespie (47:7.590): But even in IT, you're never 100 % secure. You never have zero risk. Like there's always gonna be risk. Yeah, it may be, you know, seen worse when you get into OT, but it's all about making, getting started somewhere. You can plan for 10 years on how to secure OT and never do anything. You get started, pick your highest priority site. Typically it's close to your headquarters. If it's not at your headquarters, pick your highest party system there that's making the most money.
Aaron Crow (47:25.337): Yep.
Patrick Gillespie (47:36.122): or will cause the most damages from a financial perspective, your CFO knows what system this is, if you need to ask. So you learn what you need to do to secure that. And then you follow the rest of your priorities, right? Follow the money. Like if you're on a patch, a PC that gets used once a quarter, because it's running Windows 10 and it has patches, but you're ignoring the 30 year old stuff and you're not segmenting, like, you know, that's where
Patrick Gillespie (48:5.832): You know, you're going to be spending a lot of time and money on something that's not valuable. you the budget, you so that's where we've had to teach our sales teams to if OT wants it, they can get it from IT. They can get it from maintenance. I got most of the budget for plants for the maintenance manager because I'd go to these switches that were out in the environment. They'd be caked of dust. The fans wasn't running. But as soon as they rebooted or, you know, we try to patch them, they never booted back up.
Patrick Gillespie (48:35.280): So like we need new switches or we need new wireless access points so they can use Motorola scan guns to log in, know, time clocks or whatever. So, you know, so yeah, definitely if you can get an OT person, they will always get budget because they're again, they're making the money. You know, it's not like, you know, being CISO and I don't even remember what accountants call like IT and security teams, but they're definitely not like revenue generating, you know, functions at all.
Aaron Crow (49:3.435): No, usually cyber is a cost center, not a value add. Yeah. And, but, but when you can find those OT problems and help them solve those, they have the money, right? Most of the time, right? If it's a healthy business, they're going to have the money to fix it, especially if it makes them more efficient, especially if it makes them, you know, if it saves them five minutes, that makes them more productive. It makes their ROI better and they'll find a way, especially, you know, if you're looking at safety systems, if you're looking at, you know, availability, you know,
Patrick Gillespie (49:5.915): Coliseum, yeah, exactly.
Patrick Gillespie (49:26.024): safety systems.
Aaron Crow (49:29.081): that you talked about it earlier, the CIA triad, it's flipped upside down, Availability is key. Nobody cares about confidentiality because there's no confidential information in it. For the most part, in most scenarios, obviously that's something, know, the secret recipe of Coca-Cola is secret, right? But most places, at a power plant, the steam temperature coming out of the boiler doesn't really matter, right? It doesn't matter. It's the same at every steam turbine everywhere. So it doesn't matter.
Patrick Gillespie (49:38.130): Rock. Yeah. Yeah.
Patrick Gillespie (49:50.650): Exactly.
Patrick Gillespie (49:56.360): Yeah.
Aaron Crow (49:56.417): Awesome, man. So I always ask this question to everybody. I kind of tee it up to everybody, but next five to 10 years, what's one thing you see come up over the rise and that may be concerning and maybe one thing that's exciting from your perspective?
Patrick Gillespie (50:11.605): concerning is just probably just, you know, continue to get awareness. Like I seem like there's a ton more awareness in the last five years, and especially in my Stuxnet was like 15 years ago now. like concerning to me is are we ever, you know, going to get heavy investment in securing OT, right? Or, you know, our business is going to realize, hey, lot of private industries own critical infrastructure.
Aaron Crow (50:22.532): Yeah.
Patrick Gillespie (50:38.536): So that's definitely a concern. And another concern is, know, CISA and NIST, you know, all these controls put out great things, but they don't always apply to OT or not all of them. There's always pieces that apply to OT, like, you know, like secure by design, for example, that if they wanted clients to buy or get their manufacturers to add security, add encryption, add authentication, like basic things. But even if you could get Rockwell Emerson Delta V
Patrick Gillespie (51:8.700): Johnson Controls, all of them to 100 % have secure devices. They're still going to be vulnerable firmware. You know, there's going to be vulnerabilities, but you have 20, 30, 40 years of legacy risk behind you. Like you can't just, you know, move forward and then, you know, hope, you know, there's nothing behind you. Right. So, so yeah, it's great to, to do these, you know, great things to, you know, but that really never happened. I think there's now it's secure by something else. I don't even remember what it is now, but
Aaron Crow (51:38.231): Yeah. I just talked about this other day. It's Idaho national lab, CIE, cyber informed engineering.
Patrick Gillespie (51:40.228): yeah.
Patrick Gillespie (51:46.972): Yeah. So yeah, it's so there's so many things like that, that like the government is great about planning these things and creating these things and research that resmoder and Idaho national, all these labs like do these great things. And then it never really gets picked up by industry, you know? So those are concerns. Great things is there's a lot of interest in people wanting to get into OCE security. I mean, we see, so I had a couple of senior level jobs I posted a few weeks ago.
Patrick Gillespie (52:16.144): And over about three or four days, we had about 110 people apply. think we interviewed like five, maybe, you know, cause a lot of them were not really OT or more GRC, whatever. and we were needing more engineering folks. And, then I posted it OT security analyst role, like more entry level somebody, but I hire people that are prior electricians, prior mechanical engineers, prior military. So it's entry level in that they don't have OT experience or that maybe they don't even know network architecture or security. That's what we want to teach them is those things.
Patrick Gillespie (52:46.056): 1100 people applied first day. So it's like, it's like, dang, so like had no idea. if, if, if you follow me on LinkedIn and I didn't reply to your message, I got a thousand messages that day and connection requests. So I used to be good at replying on LinkedIn, but I just, it's crazy. It's very overwhelming. It's like, man, I think it's like, maybe I, you know, I get some sleep every night, but not have to sacrifice what I did get if I started replying to all that. So, so yeah, there is, there seems to be a very heavy interest in
Aaron Crow (53:1.165): That's overwhelming.
Aaron Crow (53:9.836): Exactly.
Patrick Gillespie (53:15.206): Because if there wasn't that, nobody would want to go secure this. And then when the people who are running it retire or pass away sadly, like there's nobody to run it. So then that's where like industries or nations start crumbling for the infrastructure, especially like Rome had some great things and things just fall apart.
Aaron Crow (53:39.919): Yeah, yeah, we have, we have to continue to maintain them. That's so very true. So what, what's a, how do people find out more? See, obviously follow you on LinkedIn. If maybe they've got a job coming up and wanting to get into OT, reach out to you. sounds like you, if you're a veteran and you're looking to get in this space, definitely reach out. Patrick has some, connections there. Um, you know, that definitely the, the one of the, one of the things I love about the OT space is, you know, technically Patrick and I are competitors. I'm, I'm a.
Patrick Gillespie (53:49.329): Thank you.
Patrick Gillespie (53:54.088): Yeah.
Aaron Crow (54:6.699): OT cybersecurity consultant. He's an OT cybersecurity consultant. I don't care. I see there's there's more than enough needs in this industry that needs good people, needs good companies that have ethics and integrity and capabilities. And I don't see us as I don't see us as truly competitors. Yes, if we're going on the same proposal, sure, we're a competitor. The rest of the time we just happen to be in the same industry. And what I love about this industry is it's a very small niche industry and there's a lot of really amazing people in
Patrick Gillespie (54:11.388): Yeah.
Patrick Gillespie (54:28.648): Yeah.
Aaron Crow (54:36.311): Right. And there's a lot of people that are willing to answer those questions and mentor and help and advise and guide. It's why I love doing it's why I do the podcast. Why I enjoy having conversations like this today with you, Patrick. So thank you so much for your time. How can people reach out, find more, anything you want them to know about with guide pointing yourself.
Patrick Gillespie (54:37.027): yeah.
Patrick Gillespie (54:46.768): Thank you
Patrick Gillespie (54:54.796): Yeah, yeah LinkedIn definitely the best you don't reach out to others on my team and then guidepointsecurity.com of course for our company But Godpoint also has a university GPSU. So if you're active duty military, you're looking at skill bridge Look, you know, you can Google guidepointsecurity.com slash GPSU learn more about skill bridge It's a great way to transition transitioning from the military to civilian life is very hard. Don't do it alone
Patrick Gillespie (55:22.696): And I do a lot of the things I do to prevent or try to help prevent veteran suicide. the high sorry to put in this on a kind of a downer, but the highest risk of veteran suicide is the first 60 days when you get out of the military. So whether you're transitioning from careers, even if it's not the military, like don't do it alone. Like it's it's it if you apply for a hundred dollars and you don't get one phone call like that's like it's it's demeaning. Like it's painful to go through that. So.
Aaron Crow (55:32.206): Not at all.
Patrick Gillespie (55:50.076): have mentors, don't be afraid to ask a mentor for help, review a resume, be a reference, don't do it alone. And then yeah, so yeah, reach out to GPSU and then also if you're in college or recently college grad, we have paid internships. Like I have a paid intern starting next week, actually two, I got two OT security interns starting Tuesday. So that want to...
Patrick Gillespie (56:16.198): do OT, know, military, or once prior college, once prior military. you know, kind of grow up that force of people that know how to do this, you know, so.
Aaron Crow (56:24.761): Yeah, absolutely. That's awesome, man. I appreciate you doing that. I've got a big heart for veterans and definitely want to pay that back. One of my best friends, gunnery sergeant in the Marine Corps, and he does very similar things in data center industry. So there's a lot of great organizations. There's a company here called Overwatch that does data center manufacturing and works in that industry and they do similar types of things. So there's a lot of skills bridge type environments to get into and you
Patrick Gillespie (56:44.229): Anyways.
Aaron Crow (56:51.535): the state of Texas is expected to increase the capacity of generation by 50 % by 2030. So that's a huge growth in a very short, mean, it's 2025, halfway through 2025. So there's four and a half years to spin up more than 50 % capacity than what we currently have. So that means a lot of generation being created. And most of that is because of all the data centers that are coming in, because of AI, because of all of the cloud and all the things that are coming. So thank you so much for your time, Patrick. Thank you for.
Patrick Gillespie (56:52.456): Thank
Patrick Gillespie (56:57.821): Wow.
Patrick Gillespie (57:3.996): How I am.
Patrick Gillespie (57:8.968): Wow.
Patrick Gillespie (57:13.692): Yeah.
Patrick Gillespie (57:18.952): We'll you then.
Aaron Crow (57:19.693): giving back and all the guide point does. And if there's anything I could ever do for you brother, just don't hesitate to reach out. I appreciate your time,
Patrick Gillespie (57:26.064): Yeah, thanks brother. Yeah, it's great to be here.
Transcript lightly edited for readability.
Subscribe to PrOTect IT All and stay ahead of the threats targeting critical infrastructure.