Ep 77: OT Cybersecurity Wake-Up Call: How Airports and Power Grids Expose the Gaps We Can’t Ignore | PrOTect IT All
HomeEpisodes › Episode 77
Episode 77
Episode 77 Solo

OT Cybersecurity Wake-Up Call: How Airports and Power Grids Expose the Gaps We Can’t Ignore

Oct 20, 2025 00:22:46
OT SecurityCritical InfrastructureRisk ManagementNetwork SecurityEnergy

Watch This Episode

In this solo episode of Protect It All, host Aaron Crow delivers a straight-talk reality check on the widening IT–OT cybersecurity gap and what it really takes to protect the systems that keep the world running. With decades of experience defending critical infrastructure, Aaron exposes why many OT environments are still years behind in resilience and visibility - and how we can finally fix that.

You’ll learn:

This episode isn’t about fear - it’s about preparation. If your work touches energy, transportation, manufacturing, or utilities, this one’s your wake-up call to act before disaster hits.

Listen now and learn how to protect what truly keeps our world moving - only on Protect It All.

Key Moments:

05:06 "Real Risks of Critical Disruptions"

06:16 Redefining OT System Boundaries

11:42 Troubleshooting Unknown System Issues

14:09 "Secure Remote Access Best Practices"

18:28 "Planning for Worst-Case Scenarios"

19:36 Critical Infrastructure Under Cyber Threat

 

Connect With Aaron Crow:

 

Learn more about PrOTect IT All:

 

To be a guest or suggest a guest/episode, please email us at [email protected]

 

Please leave us a review on Apple/Spotify Podcasts:

Apple   - https://podcasts.apple.com/us/podcast/protect-it-all/id1727211124

Spotify - https://open.spotify.com/show/1Vvi0euj3rE8xObK0yvYi4

 

Chapters

05:06Real Risks of Critical Disruptions
06:16Redefining OT System Boundaries
11:42Troubleshooting Unknown System Issues
14:09Secure Remote Access Best Practices
18:28Planning for Worst-Case Scenarios
19:36Critical Infrastructure Under Cyber Threat
Read the full transcript

Aaron Crow (0:1.890): Hey everybody. Welcome to another episode of the Protect It All podcast. In the last few weeks, we've seen cyber incidents disrupt airports, power systems, critical services across the globe. Some of those were criminal or state sponsored potentially. Maybe they were activist driven, but the results are the same, right? The systems we rely on on a day-to-day basis are being pushed, right? They're being challenged. They're being tested.

Aaron Crow (0:31.078): and we've known, and we've talked about in this podcast multiple times, we talk about it at conferences, people stand on stage and talk about the risky part. know, most of our OT operational technology and industrial control systems, they actually run in these environments or older. They're running on, you know, antiquated systems, older, non-published or non, know, updated, supported systems. and they're breaking down.

Aaron Crow (0:59.602): Even even if you put in a brand new system, it's not it's not really going to stop it. But a lot of the things that we're seeing in these spaces is there. There there risk. You look at airports, you know, CrowdStrike again, not an OT cyber attack, but you look at the way an airport is is is distributed and you've got multiple gates. And most of us have been to an airport. You've got you've got land side and you've got air side.

Aaron Crow (1:27.914): on on land side. You've got check in. You've got baggage check in. You've got, you know, the kiosks and you've got, you know, printing out boarding passes and and all of that. And then you get you've got the TSA. You've got the check throughs. And once you get on the other side, there's there's everything all the gates and there's baggage handling and there's just systems and integrations throughout that. And then you've got different airlines and you know, maybe this gate is is a airline specific. This was only American Airlines or this was only Southwest or this is Emirates or whatever it is.

Aaron Crow (1:57.268): or their multi-use. They can log in as an American Airlines one, or they can log in as a Southwest, they can log in as Delta, they can log in as United. These are all intricacies that are very hard to manage and secure from a geographical perspective, just the amount of having clearance and having security clearance to get through, and I don't mean like government security clearance, like Top Secret, anything like that, but...

Aaron Crow (2:25.154): getting through into these spaces, working them in nuclear power, right? You I had to be white badge to be able to get in even to just enter the building, not even the secure building, not even the where the reaction was. It's just to have that security. So, and if you don't have enough escorts to escort people, again, let's say a system goes down and you have to support it. You don't have enough hands. Again, going back to the CrowdStrike incident, right? You don't have enough hands to...

Aaron Crow (2:52.366): to actually be able to put hands on everything to get it back up and going potentially. There's a lot of implications with that, right? So how do you have enough escorts? How do you have enough, you know, people that understand the systems that are there? So a lot of times, maybe the first step is a cyber thing and the rest of the steps is operation. The rest of the step is supporting. It's just getting the things back up and going so that normal operations can happen. You're getting it back to a status of zero.

Aaron Crow (3:20.760): You're not improving it. You're not necessarily, you know, when you're doing an incident response, you're not necessarily re-architecting and designing or even fixing the hole. Sometimes just getting it back up online, even just as bad or maybe even in a worse scenario than it was before it started. Right. So, you know, really the reality check is cyber attacks on airports, transportation, utilities, they're, they're no longer rare headlines. Like we're seeing these things happen. And again, when I say

Aaron Crow (3:49.358): It doesn't even have to be a cyber attack. It could just be something that's bringing down the system. Again, the CrowdStrike incident, right? That wasn't a cyber attack. Colonial pipeline, I've had multiple people argue with me and not like it that, you know, that wasn't an OT attack. Okay, you're right. They didn't actually attack an OT system, but the OT system was brought offline. Well, they did that intentionally. The company chose to do that, you're right. But they chose to do that not because they just wanted to, they did it because they had to.

Aaron Crow (4:17.870): So it really comes down to what used to be theoretical. The sky is falling, cyber theatrics, or I've seen a lot of people posting about, nothing's really happened, why do we need all this stuff? And these are prominent people that cloud these things on LinkedIn and all these places. I don't believe that this is theory.

Aaron Crow (4:43.098): I don't believe I think there's more than enough evidence. I've seen them firsthand. I can't talk about all of them, and there's a lot of coworkers and friends and people that I know that have been on these things too. And just because it's not in the news, just because it's not. Publicly available information does not mean they're not happening. I mean, just because they're not necessarily public doesn't mean that we shouldn't just do something right. What used to be theoretical? Like I said, what if someone shuts down a power plant? What if somebody?

Aaron Crow (5:12.492): takes off a an airport so it can't you know, passengers can't get through what happens if they shut down a train? What happens if they turn off a water filtration or water providing for us a city? These things are real world disruptions. You know, we've we've seen incidents or examples of this from you know, national disasters, right? You see natural disasters, you see.

Aaron Crow (5:37.519): you know, a hurricane come through an environment and now water's turned off, electricity's turned off, like the whole city shuts down and it becomes a third world country really fast. These types of things, they really show how a connected and OT system is and how that exposure has grown faster than the potential defense if there is any there.

Aaron Crow (6:4.738): To be clear, when I say an OT system, I don't just necessarily mean the PLC, the controller that is talking to a turbine or a valve or that kind of stuff. Yes, that is part of the OT system. But an OT system to me is anything that is supporting that endpoint. So again, I go back to Colonial Pipeline. The OT system in one person's definition was not impacted because the HMI or the PLC wasn't directly, directly

Aaron Crow (6:34.318): you know, ransomware, but it doesn't matter in my perspective because the bigger what really in my perspective, what is the OT system is anything that can impact control. If you look at NERC SIP, NERC SIP defines it as any single shared cyber asset that can impact, you know, well for NERC SIP medium, any single shared cyber asset that can impact more than 1500 megawatts in 15 minutes. It doesn't say it has to be a PLC. It can be an email server. could be Shikrim Road access, be active directory.

Aaron Crow (7:4.012): is active directory and OT system. I know I sound like a broken record with these things, but I've seen so many things come across. Some of them I could talk about, some of them I cannot, that it's just, it's frustrating that we still have people that are arguing that there aren't really OT incidents that are happening and that we don't need to spend as much money on cybersecurity and we don't need to be doing all these tools and detection and monitoring and all these types of things. And I just, I think that's just a really bad message to be sending out.

Aaron Crow (7:34.337): OT has been behind the eight ball or 20 years or some people claim that we're probably 20 years behind IT. I think some are 403040 years behind where traditional IT environments would be like we would never allow a Windows XP machine on any IT system in the world. Ever it just wouldn't work like you would just buy new system doesn't work like that in OT so we have to know that but we just because it has to be there doesn't mean we need to allow it to.

Aaron Crow (8:4.120): touch the internet. We don't need to allow VNC or remote access to it directly, right? We should have visibility. We should be monitoring those things. But these are the basic things that we're not doing, right? It doesn't have to be expensive. It doesn't have to be, I don't have to completely redesign your entire network, but I need to, we as a collective need to understand where you're at so that we can put protections around it. Okay. You have that XP box. Perfect.

Aaron Crow (8:31.234): Let's make sure that we're blocking it from the internet. Nothing can get to it. And I want to monitor it. I have to know what those, I know what the vulnerabilities are on it because it's been published forever. Let's monitor for those things. If anybody tries to do this, this, this, and this, we should monitor and alert on those things. These are not difficult problems to solve, but you have to be intentional about them. You know, flat network, shared credentials again.

Aaron Crow (8:54.838): you walk through a secure environment and yeah, you set passwords on things and every terminal you walk up to has got the password printed on it. It's sitting on the terminal. It's underneath the keyboard. It's on the whiteboard behind it. It's anywhere, right? It doesn't do any good. Unmonitor, they're sharing credentials. You're sitting in a room and they're sharing, hey Bob, what's your login? I'm trying to get in this machine and they're sharing their credentials back and forth. It happens so often. Vendors coming in unannounced.

Aaron Crow (9:23.574): whether it's physically or virtually. It's even worse in my opinion when they're virtually doing it and you don't know what changes they made. You don't know what they're doing. Did they install something? Did they make a change?

Aaron Crow (9:35.491): And then there's this belief in OT. it ain't broke, don't fix it. And although I agree with it, because making those changes can break stuff, it's also how you get to be in massive technical debt. Because you never come back and fix the things, the temporary band-aids that you needed to get it working at three o'clock in the morning on a Saturday because the system was down. But then Monday morning when the full team comes back on, you don't allow them to touch it. So then it just stays there and it becomes the way.

Aaron Crow (10:5.058): That's just unacceptable. Like we've got to get to a place where we know that was a temporary fix. Now let's bring it down to the next available opportunity and let's fix that thing. Let's make it right. Let's not keep the D-Link wireless. Let's not keep the system doing the things that their temporary band-aids are doing. Let's find a way.

Aaron Crow (10:31.096): to fix those things, come back to them, find some budget, find some capabilities around those things.

Aaron Crow (10:39.958): What else? Mark this so come cut this part out. Show Vic. So what what can organizations do now? Again, I've said this 1000 times. I guess I'll just continue to say it and I'll get it put on a T shirt and wear it to conferences and it really starts with visibility right in.

Aaron Crow (11:7.840): Everybody says, you can protect things you don't understand. Cause I know that the vendors are saying, Hey, you've got to, you've got to be able to see what to be able to protect it. And I've seen again, the same people that are saying there's no OTC systems. Well, I can protect things. I don't know where they are all the time. I could do it all the time. Yeah. Again, let's walk through a hypothetical. Incident response. Something happens at a facility, whatever facility you name it, a bus depot, a power plant, manufacturing facility, airport, whatever it is.

Aaron Crow (11:38.393): How many systems do you have? If you had to replace them or you had to go check and see if they were all impacted. Do you know where they all are? Does everybody know where they all are? Cause it doesn't matter if one guy knows they all need to be able to know where they are. They properly documented. Do know what systems they are? What do they look like? What are they labeled as? Do they all have labels? What version are they running? Like these are questions. They seem super basic, but they don't in reality exist. There is a

Aaron Crow (12:4.584): lack of knowledge at the right level. There's some people that know the answers, but not everyone. Again, I've been on an incident response. I've been on these outages, these response times where, I hate to say the word incident, when you're doing an upgrade, when you're doing a control system upgrade, or you're there troubleshooting something with the vendor, and they're trying to find all the things that are broken, making sure that we can fix all those things before we leave.

Aaron Crow (12:33.442): but we don't know where they all are because we didn't install the system and the guy that didn't that installed the system isn't there anymore. And this guy knows where some of the stuff is, but he's not exactly sure where all of them are. So we're missing 10 of them. So we aimlessly walk around this environment. And if you've ever walked around a power plant or manufacturing facility or an airport or some of these places, there's these little cubbies that you don't have a clue. If you don't know they're there, you would never find them. Not never, but it'd take you a long time. Right? So little things like that can, can really hurt you.

Aaron Crow (13:1.176): So start with visibility, build a complete asset inventory beyond just I have 5000 devices in a spreadsheet that these are my systems. Like know every PLC, every HMI, every sensor tools like Ember OT and the Zomi and Dragos and etc. Tinnable. And there's lots of tools that do it. I'm not trying to pitch a tool. I'm trying to say you need something to be able to do this and then segment aggressively.

Aaron Crow (13:29.614): And the reason I say segment aggressively is because some people think that a VLAN is segmentation. In my perspective, it is not. VLAN is great, but VLAN alone, if it's going into the same interface on a firewall, is not really segmentation. It's not going to restrict things the way that you're looking for. So segment them, really segment corporate away from IT, away from the plant network. Segment systems within the OT environment. So if I've got, again, going to a power plant or

Aaron Crow (13:59.799): Use power plant for first. If I have a turbo control system, I'm going to segment and power utility does this already. But if I've got a manufacturer, so you know, segment line one from line two, segment a sub component painting or or assembly or whatever those those environments are, segment those things off. That doesn't mean they can't talk. You just have them segmented so that if something happens, I can stop it. I can change a firewall rule.

Aaron Crow (14:29.090): to stop a spread. can monitor, hey, I'm gonna see that traffic coming through the, ooh, there's something different there. Why is that? I can see all of those things. When it's just one big flat network, I can't see those things. East-West communication is harder to track unless I have spans going down, I've got sensors, I've got taps, and I'm looking at all those things. But even that, I can't stop it. I can see it, I can monitor it, but I can't stop it. It's a lot, not can't, it's a lot harder to stop it if I have no segmentation.

Aaron Crow (14:59.106): So segment aggressively, secure mode access for obvious reasons. I see way too many times we're giving RDP and VNC access directly to an OT system from the internet. But beyond that, is you wanna be able to understand what's going on in these spaces. So if a vendor's coming in to make changes, you should be recording that session. You should know exactly what was changed. So you can document it, so you can understand what was changed.

Aaron Crow (15:25.198): So if something happens, if something breaks, if, there's anything good, bad, or ugly that happens that you have a trace of it and who did it and why, at what time, all the things. And then zero trust, right? Is every verify every user, every connection, you know, add DLP, all these things are not going to be available for every scenario. Well, Aaron, I can't put, uh, in point protection on my POC. You're right. But can you on your HMI? You probably can cause it's probably just a windows machine. So let's do it there.

Aaron Crow (15:55.759): Obviously you can't do it on a POC. Obviously you can't do it on a control processor. Obviously you can't do it on an RTU, know, things like that. Of course, but where you can do it.

Aaron Crow (16:8.078): Next is expansion on visibility, especially when we start talking about tools, but really seeing trouble before it starts, right? If you are monitoring, especially, you know, since you are the war in OT, things don't change that often. We're not patching. We're not going on the internet. We shouldn't be going on the internet. We shouldn't be installing things all the time. You know, changes don't really happen that frequently in an OT space, which means

Aaron Crow (16:37.198): that I should notice a change because there aren't that many of them. If I look for changes in the IT environment, everybody installs something or gets a patch or an update or reboots or plugs into a different network or brings on new hardware and plugs in new stuff. Man, that's a lot because everybody's plugging in their plugging their phones in. They're plugging in new Bluetooth headsets and new keyboards and they're going to the Internet. They're going to new web spaces. They're installing things. All this stuff happens all the time and OT doesn't happen that often. Right. So be monitoring for those things.

Aaron Crow (17:5.326): But you can also monitor for dark web and threatened forums and social media channels about things that are going on in the spaces. There's entire services that can do this for you. Pair that with external intelligence, anomaly detection in your OT environment. Those are things in monitoring for unusual activity. You can scan the traffic. You don't have to scan OTM points, but you could be looking at that traffic and understand, hey, what?

Aaron Crow (17:33.454): Are there spikes? there things going on? Earlier warning gives you the availability to prepare, isolate, et cetera. Especially if you're monitoring and something happens at site A, I can turn it off or make sure I'm monitoring and making sure it doesn't happen at site B, C, D, E, F, blah, blah, blah, through Z.

Aaron Crow (17:53.251): This again should go without explanation, but we should be protecting the edge. We have to lock down these systems. And to me, the edge of an OT system is not the corporate boundary. The edge of an OT system is at the OT system. IT to me is considered bad.

Aaron Crow (18:19.758): There should be a segmentation. There should be a clear line of blocking between IT and OT. There should be an edge for OT. Does that mean I have to be complex? doesn't have to be a huge, expensive, capable firewall. It can be a firewall. I think it should be a firewall, but it doesn't have to be the same level and capacity of your corporate edge firewall. Of course, there's not as much traffic going through it. There shouldn't be that much stuff going. That doesn't mean it's not important.

Aaron Crow (18:49.174): doesn't mean that you don't need something there to monitor. Right? You should treat, you should treat in my perspective, you should treat corporate IT as the internet from an OT perspective. And then you should treat these endpoints as you know, the OT systems as you know, anything that's in in in between as high risk, you don't trust zero trust. Again, I don't trust my own corporate environment.

Aaron Crow (19:17.718): I can't in an OT space where you can encryption. Encryption doesn't always make sense in OT. but anything that I'm going through up and down and crypt communications, you know, disable unused ports. you know, deploy, obviously we talked about this a little bit ago, but deploy passive monitoring solutions, again, Amber OT, Nizomi, et cetera, et cetera, to establish, you know, behavioral baselines and, the goal isn't just prevention, right?

Aaron Crow (19:46.627): I think we've seen in the news, it's just like with anything given enough time and opportunity, something's going to happen when it does happen. What can, how can, how quickly can you respond? That's the bigger piece to this. We're looking at response and incident response. We're not just trying to stop a bad actor from getting in. Assume they can get in. Then what are you planning for the worst case scenario? All of your systems are down. You run an airport and all of your systems are inaccessible. What are you going to do?

Aaron Crow (20:16.172): You run a power plant and all of your HMIs go offline. What are you going to do? Like these are the things. How quickly can you recover? Do you have a process for that? If you had to replace your machines, if they got locked out and you had to replace them to get them back up and running, how would you do that? Do you have a team? Is there security, physical security that you would need to escort people? If you got contractors in, how are you going to do that? Like all of these things need to be gone through and tabletop and thinking about what would you do in these scenarios and making sure you have plans.

Aaron Crow (20:46.818): Because if we all depend on the same incident response team to come in and fix the problem and a really big, bad thing happens from a nation state level perspective, those same incident response players are going to be responding to there's going to be more places they would need to respond than they can abs, can possibly respond. So the attacks we're seeing, whether they're at airports and the power grid cross manufacturing are all symptoms really of the same issue.

Aaron Crow (21:13.934): We've connected these critical systems many times before we secured them. Now we're racing to close that gap and trying to find the gaps and the holes in the chink in the armor. But we've got, you know, activists and cyber criminals and nation states that are all going after these targets of opportunity because they know that visibility is low. They know consequences are high.

Aaron Crow (21:44.035): They know if they get to a power plant or an airport or a wastewater treatment facility, they're going to hit the news. There's going to be payout that, you know, they're all of the consequences are huge. They're big. So if you run a critical infrastructure organization, if you work for one, if you're embedded in one, if you're supporting one hell, if you're in a city that has support by one, which is every one of us, because we all live in places that depend on these systems.

Aaron Crow (22:13.984): Now's the time to build resilience, make these conversations, start having these hard discussions, asking these questions. Because cyber and cybersecurity and OT is not about perfection. It's not going to be fancy. We're not talking AI. We're not talking any of those things. It's about survival, right? It's about getting these things back up and running as fast as possible in a safe way, right? Before people get injured, get hurt.

Aaron Crow (22:42.754): get, you know, there there's an impact that is beyond what we want to accept. So I, I appreciate you listening to this. if this episode hits home, someone on your network is responsible for industrial or critical infrastructure. Definitely share this. if you have ideas, if you've seen some examples of these types of things, hit me up. Love to have a conversation about answer response or.

Aaron Crow (23:11.388): you know, some things that you've seen in the space that worked or maybe you've struggled with et cetera. but definitely, you know, if we want to stay ahead of the next cyber threats, like we've got to be, on the same page, we've got to be willing to have these colored conversations and also not attack people. I get really tired of people, coming after someone because, you know, they, they say there's an incident and they don't think it is an incident or that wasn't an OT thing. Like we're all on the same page. We're all in the same team. We're trying for the same thing.

Aaron Crow (23:38.838): Right? I do this podcast because I enjoy it, because I have these conversations with people and I think it's important. I think it's extremely important to do this and do more and push the envelope because I still see way too many risks and not enough resolutions being done. So that's all. Thank you. Until next time.

Transcript lightly edited for readability.

Want your brand in front of OT, IT, AI, and cloud security decision-makers?
PrOTect IT All listeners are the practitioners and leaders making security buying decisions across critical infrastructure.
See Sponsorship Packages →

Never Miss an Episode

Subscribe to PrOTect IT All and stay ahead of the threats targeting critical infrastructure.