Ep 86: Legacy Tech, AI Hype & Cyber Risk: What IT and OT Leaders Must Get Right | PrOTect IT All
HomeEpisodes › Episode 86
Episode 86
Episode 86 Interview

Legacy Tech, AI Hype & Cyber Risk: What IT and OT Leaders Must Get Right

Dec 22, 2025 00:53:02 with Neil D. Morris
OT SecurityAIRisk ManagementRansomwareLeadership

Watch This Episode

AI promises transformation - but legacy technology, process gaps, and cyber risk often stand in the way.

In this episode of Protect It All, host Aaron Crow sits down with veteran IT and cybersecurity leader Neil D. Morris, who brings over 30 years of experience across aerospace, defense, and energy sectors. Together, they cut through the hype to explore what really matters when modernizing technology and managing cyber risk in complex, real-world environments.

Neil shares candid insights on why legacy systems still power critical operations, why replacing them isn’t as simple as it sounds, and how organizations can unlock real value from AI without increasing risk. The conversation dives into tech debt, regulation, ROI, and the often-overlooked role of process in successful transformation.

You’ll learn:

Whether you’re leading digital transformation, managing cyber risk, or advising the business on AI adoption, this episode delivers real talk and practical wisdom from the front lines of IT and OT leadership.

Tune in to learn how to modernize responsibly, manage risk intelligently, and separate AI reality from hype only on Protect It All.

Key Moments: 

00:00 "Legacy Tech in Modern Firms"

06:22 "Technology, Change, and Customer Focus"

09:51 "Challenges in Articulating Cybersecurity Value"

12:27 "Tech Solutions Must Drive Value"

15:43 Sell Ideas Beyond the Code

19:03 "Ransomware Risks in Acquisitions"

24:02 Government, Services, and Compliance Debate

25:35 Balancing AI, Cybersecurity, and Regulation

30:33 BlackBerry's Downfall: Ignored Innovation

32:06 "Evolution and Misuse of AI"

34:45 "Opportunity to Lead Change"

37:52 "AI Without Guidance Backfires"

41:07 "AI: Smart but Context-Lacking"

46:45 "AI Empowering Business Transformation"

50:30 "Effortless Tech-Fueled Imitation"

About the guest : 

Neil D. Morris is a senior enterprise technology leader with 25+ years of experience in digital transformation, cybersecurity, and AI at scale. He currently serves as Head of IT at Redaptive and previously held CIO roles at Ball Aerospace and Maxar Technologies. Neil is known for guiding organizations through complex modernization efforts while balancing security, risk, and business value.

How to connect Neil: https://www.linkedin.com/in/neildmorris/

Connect With Aaron Crow:

Learn more about PrOTect IT All:

To be a guest or suggest a guest/episode, please email us at [email protected]

Please leave us a review on Apple/Spotify Podcasts:

Apple   - https://podcasts.apple.com/us/podcast/protect-it-all/id1727211124

Spotify - https://open.spotify.com/show/1Vvi0euj3rE8xObK0yvYi4

Chapters

00:00Legacy Tech in Modern Firms
06:22Technology, Change, and Customer Focus
09:51Challenges in Articulating Cybersecurity Value
12:27Tech Solutions Must Drive Value
15:43Sell Ideas Beyond the Code
19:03Ransomware Risks in Acquisitions
24:02Government, Services, and Compliance Debate
25:35Balancing AI, Cybersecurity, and Regulation
30:33BlackBerry's Downfall: Ignored Innovation
32:06Evolution and Misuse of AI
34:45Opportunity to Lead Change
37:52AI Without Guidance Backfires
41:07AI: Smart but Context-Lacking
46:45AI Empowering Business Transformation
50:30Effortless Tech-Fueled Imitation
Read the full transcript

Aaron Crow: Thank you for joining me on another episode of the PrOTect IT All podcast. It's always fun to me to reach out to people I haven't engaged with before. A lot of the people I'm having conversations with, it's the first conversation we've had. Maybe we've gone back and forth on LinkedIn, but these are usually the first real conversations. I do that intentionally. I want these to be like you and I are sitting down having a coffee and you're explaining your experience over the last three decades. So Neil, thank you for taking the time. Why don't you introduce yourself and tell us about the past three decades.

Neil Morris: Thanks, Aaron. Neil Morris, I'm out in Denver. Currently the Head of IT for Redaptive, an energy and sustainability company. Been doing IT and cybersecurity for three-ish decades. Formerly CIO and CISO for Ball Aerospace, a highly regulated aerospace and defense company. Before that, Maxar Technologies, now going by Vantor, doing intelligence and satellite imagery. Long background in enterprise architecture, cybersecurity, going back to education and IBM and a number of different organizations. Currently leading IT for Redaptive, having fun, been doing that for about the last 14-15 months.

Aaron Crow: It's funny thinking back on my career. Starting out as a desktop administrator, the little network admin working nights and weekends upgrading from token ring to ethernet. Sometimes I have to look back at my resume to remember where I was. It's been such a trajectory from crawling around in the dirt to having conversations like this.

Neil Morris: I got right out of high school and did a seven-month trade school program, which is what first got me into tech. Old X.25 networking on the back of Cisco 2600s for what today would be described as a SaaS platform. We were doing terminal emulators into an AS/400 for a little regional airline. Our authentication was Novell 3.12 because Active Directory hadn't won the war yet. There were still conversations about whether it was going to be TCP/IP or SPX/IPX. All those wars in the late nineties.

Aaron Crow: I was doing the same thing at power plants, rolling out SNA servers to connect back to the green screen so operators could log in and do their operations. We took this big stack of servers just to be able to connect back to a green screen on their desk.

Neil Morris: I was flying around California, Vegas, Reno, for a regional airline putting terminal emulators on old Windows 95 machines to access a decentralized AS/400 running booking reservations and aircraft maintenance.

Aaron Crow: The irony is so much of that has not changed as much as you would imagine. A lot of it is not that different today.

Neil Morris: I've been in conversations even the last few months where IBM is still making P Series, I Series. Talking to big banks, hospital institutions, the larger the company, the more legacy tech. They have cutting-edge stuff too because they have the budgets, but trying to move off of Z or some of these old programming languages is not easy when you have hundreds of thousands to millions of customers. I still know organizations using tech where someone put a shiny UX on top of it to make it look modern, but the heart of that organization is still tech from 30-plus years ago.

Aaron Crow: That's why none of this is easy. The underlying concept is you have to make it work for customers and the use case. AI is not going to fix those problems. Maybe they can slap a new UI on it, but the underlying capabilities are still embedded unless they do that heart transplant, which is a big deal.

Neil Morris: Big deal, big change, massive risk. That's one of the reasons companies don't do it. You see knowledge attrition, people moving on, retiring. You thought you had good documentation, but it's scattered. The time, effort, energy, and investment to reverse engineer some of those where the documentation is close but not quite there is heart surgery or brain surgery. You might not need a surgeon's steady hand behind a keyboard, but everything else is pretty similar.

Aaron Crow: Talk about this: it's easy as a technologist to play with technology all the time. But at the end of the day, it's the risk to the business. Is the ROI big enough that it's worth the risk to rip out what's there? My dad always said, "If it ain't broke, don't fix it." Is it that much better considering cost, risk, training, upkeep? It's not just the tech, it's all the people and process that goes with it.

Neil Morris: IT people, cybersecurity people, in general we're not really good at articulating value to our customers. If you're in banking or healthcare, they're coming to you for some sort of result. Translating that new feature into "is it going to penetrate the market or help our customers?" is really hard. That's why you see new businesses come into markets and really disrupt them, because they come in with new tech and new ways of doing things. But even when traditional banks gobble those up or try to add those services, they never really go back and fix the debt. They just bolt more things on, which almost makes the problem worse.

Aaron Crow: If you are a technologist and not partnering up with somebody and learning the business and putting all your language around the business, you're missing out. One of my mentors told me all business is a people business. You're basically a salesperson even if you're a technologist. You have to sell your ideas to your teammates, your manager, up the chain. We have to learn skill sets that may not come naturally.

Neil Morris: Getting good enough at understanding finance, sales, HR, marketing, and being able to communicate in their language goes a long way. Removing that language burden by talking their language, that's an area I certainly did not focus on for the first two decades of my career. Once it smacked me in the head and I stopped being a tech person and started talking in their language, things got a lot better.

Aaron Crow: I was a CTO of a software company, a vendor selling into organizations. I'm also a consultant selling services. It's surprising more sales organizations are not putting their marketing language around business value. It's easy to sell the new feature to the firewall administrator, but how do you convince the CFO?

Neil Morris: That's where you switch to risk avoidance and maintaining company valuation. When smaller businesses get acquired, there's a point in time where they're a major target. Someone pops these little companies, 10 million, 50 million, 100 million in revenue. They get acquired by big PE, and two weeks later they lock it down because now they've got someone with much deeper pockets to go after. The risk of acquisition, the valuation of the company could be directly impacted by security posture. CFOs and CEOs will look at that.

Aaron Crow: You came from highly regulated environments where regulations exist to ensure a bare minimum. NERC CIP and the power industry are further ahead because they don't have a choice. There are fines. Compare a power plant's security maturity to a city municipal water district, and they're not the same. A lot of that budget and funding has been forced down into regulated entities. What are your thoughts on pushing regulation?

Neil Morris: I have this internal monologue because fundamentally I'm a small-government guy, but I want to provide services. In aerospace and defense, the talk now is CMMC. If you don't comply, you're not going to bid on new government contracts. But it drove culture. My personal opinion is we need even a little more regulation. I hate to ask because I hate what I might get. But on a macroeconomic scale, if companies don't get better at cybersecurity, we're going to see a lot of companies get owned, we're going to see trust in technology erode. We've got to get the bar low enough where it's palatable. Like putting a key in your door. We've got to get cybersecurity technology to a point where it's so easy that people can meet those requirements of basic locks and guards and training.

Aaron Crow: It's that catch-22. But on the flip side, in regulated environments the budget never goes dry. That money is there for people, process, and technology. It pushes the envelope.

Neil Morris: We need to make sure industry has enough voice at the table. The pace of change is so fast. There are regulations on the books that talk about specific technologies that haven't existed in 20 years. How do you write regulations that are adaptable enough and flexible enough?

Aaron Crow: We're already seeing impacts from AI and there's always a risk anytime we put in a new capability. But there's also a risk to sitting still. The thing that came to mind was BlackBerry. They owned the market. They were so egotistical to think they were too big, they'd never be replaced. Then the iPhone came along and within a few years, nobody wanted a BlackBerry. They were too late. They let the momentum get too far. That very large company, because they didn't see it and weren't willing to take the risk.

Neil Morris: It drives me a little crazy. The fundamentals of AI have existed for 70 years. When I was doing early networking, configuring algorithms to find the next best hop and building auto-failover, that was AI. In aerospace and defense doing computer vision writing algorithms to detect planes, trains, and automobiles from imagery, that's AI. So you can say the toaster's AI because it determines it should pop up in 35 seconds based on bread thickness. By calling everything AI, nothing is actually useful. But if my toaster ever talked back to me, I might put it in the trash.

Aaron Crow: The hard part is if it's hard for us as technologists, imagine the CEO reading the Wall Street Journal who sees this new AI thing and comes back asking "shouldn't we have this?" Then you have to put it in terms they understand.

Neil Morris: I think we have a unique moment in time as technologists to get in front of that. If we can talk the language of the business and go educate those leaders, help them understand our strategy, where we will and won't leverage AI, now we have strategic alignment. Then we figure out where to implement it. Do we want to be risk-forward and put AI in front of customers? Or leverage intelligent process automation and make back offices more efficient? We can make that pivot from technologists to business executives in a way I don't think we've ever been able to before.

Aaron Crow: AI can do amazing things but it's not magic. If you don't understand your process, you can't expect AI to fix it. If you can train an intern to do it, you can train an AI. But if you're immature in your business processes, AI is not going to save you. It's probably going to make it worse. It's like telling your 10-year-old to go clean your office without instructions.

Neil Morris: It's like an intern that comes in with 12 PhDs and access to a bunch of information and has absolutely zero common sense, or more importantly, your own business sense. Without understanding the context and what good looks like, you're just accelerating the bad. And on the flip side, if we're just talking cybersecurity, hackers and cyber criminals know exactly how they're going to go after people. They've got good processes and they're throwing that accelerant on it now to infiltrate with better phishing, spear-phishing, not only for the top 1% but for everybody.

Aaron Crow: Most of the time when I'm done with an assessment, most of my recommendations are super simple. Don't have an any-any rule in your firewall. Segment your networks. Lock the front door. Have a backup. Have it offsite. Little things we've been doing for 30, 40, 70 years. These are not new technologies. I'm not brilliant. I've had a backup fail where the backup server was sitting in the same rack as the server it was backing up and the whole thing caught on fire.

Neil Morris: At this point, 30-plus years into a technical career, three, four, five different waves of technology. The basics just never change. Basic hygiene is probably 80 if not 90% of the solution. Everything else is the sexy shiny stuff on top. Don't put your password on a sticky note. Lock the front door. Give the neighbor a spare key so you have a backup in case of ransomware. Have basic cameras and actually look at the logs. Test those tapes every once in a while and don't store them in the battery room.

Aaron Crow: If most organizations would just take care of the basic stuff, that's not super expensive. It doesn't take a big team. You've got a big percentage there. Can you do a basic recovery? Are you doing the basics right? A firewall, backup, disaster recovery plan, monitoring logs. Those things are not sexy. They don't take a lot of technology. But if you do those things well, your organization is going to be a lot lower risk.

Aaron Crow: So what do you see coming over the horizon? Give me one thing exciting and maybe something concerning.

Neil Morris: Exciting: I do think technologists have the opportunity over the next couple of years to help lead the business, help them understand AI, put that accelerant on really good defined processes, and really add organizational value. That can switch us from being the guys in the closet managing the firewall with the hoodie up to actually having a legitimate seat on how we drive organizations forward. It's IT's time to shine.

The threats: if you haven't looked into the economics of cyber threats, adversarial countries, these little businesses all over the planet where five people with very defined processes hack companies. If they get one a year, they're making a really good living. AI is going to accelerate their processes too. I don't think people appreciate the economics of cyber warfare, whether at nation-state or individual organizational level. They do it because there's really good money in it, and it's going to continue to get worse with AI.

Aaron Crow: We see it with phishing attacks, how much better they've gotten. The logos are right, the language is right, they're using the same marketing copy. I've been almost hit with a couple of attacks. I'm a practitioner looking for it, and they still got me a few steps down the road. My spidey senses went off, but it was close.

Neil Morris: Organizational safe words are going to become a thing. I had one the other day, someone showed me a deepfake taken off of a YouTube video of a senior leader talking in their voice from a presentation they did. Damn, that's good.

Aaron Crow: I've got hundreds of hours of me talking on video, seeing my facial expressions, the language I use, the inflections. It's very easy for somebody even with today's technology. Imagine what it looks like in a year or five years.

Neil Morris: That's the part that makes me quiver. The basic port-scanning attacks, that's not where the money's going to be. Cyber criminals are going to move on and try to stay one step ahead. If we're all looking at shiny objects, it's like we're looking out the front window and the back door is unlocked.

Aaron Crow: Well Neil, I appreciate your time today. How do people find out about you?

Neil Morris: Always happy to chat. I love these conversations. I consult with different boards and executive groups on AI and cyber. Best way to find me is on LinkedIn, Neil D. Morris. Reach out. I'm always open to have a conversation. I'm just a geek at heart that enjoys nerding out on this stuff.

Aaron Crow: Thank you again for your time. Everybody check out his LinkedIn. Until next time.

Transcript lightly edited for readability.

Want your brand in front of OT, IT, AI, and cloud security decision-makers?
PrOTect IT All listeners are the practitioners and leaders making security buying decisions across critical infrastructure.
See Sponsorship Packages →

Never Miss an Episode

Subscribe to PrOTect IT All and stay ahead of the threats targeting critical infrastructure.