Jason Cradit: Start with the use case and work backwards from there. I think if
you're trying to fight gravity, you've just failed, right? It is not going to work. And so
let's start with, what is it that we're trying to accomplish with AI? How do we protect
it? And then what are the guardrails around it? [ Music ]
Johnny Hand: Welcome to AI Security Brief, where we're unpacking emerging AI
threats, vulnerability research, and the strategic decisions that security leaders are
making right now. I'm Johnny Hand.
Dustin Childs: And I'm Dustin Childs. Today's guest is Jason Cradit, CTO and CISO
at Everline Technologies. Jason brings more than 25 years' experience across
pipelines, aerospace, and defense, and he's working right now in the IT/OT front
lines where a security decision can impact a pressure change on a pipeline and not
just a laptop getting quarantined. And this is critical infrastructure, we're talking
about, you know, the things that run the stoplights, the things that keep the AC cool
in the summer, and the gas keeping you warm in the winter.
Johnny Hand: Yeah, in this episode, we actually talk about the fact that, for years,
security leaders have been saying no to AI, right, we just don't want to implement
it. But Jason points out that no was never really the truth. Shadow AI is already in
your organization, arriving through both employees and the vendors and embedded
into the AI, into the product. So we know that whether you're intentional about it or
not, whether you put a policy in place or not, you have an AI culture today, and our
security leaders jobs are to make it intentional.
Dustin Childs: You know, Jason also talks about why an action that's routine in IT,
such as isolating the endpoints, can be catastrophic in OT, because you get a valve
you can't control, a rupture, and then an unintentionally flooded wetland. So agentic
AI making decisions on its own in this world right now is a non-starter. But the
reason this matters right now is that the adversaries are not waiting, and you
shouldn't either. So let's get into it.
[ Music ]
Johnny Hand: Well, Jason, welcome to AI Security Brief. This is the show where we
unpack emerging AI threats, vulnerability research, and the strategic decisions that
security leaders are making right now. We're very excited to have you with us.
Jason Cradit: I'm excited to be here, man. It should be fun.
Dustin Childs: Jason, I've got a question for you. So you've got more than 25
years of experience across energy pipeline, aerospace, and defense. And I'm sure
you've seen several adopt-it-now mandates land on regulated teams. How is the AI
whiplash different from earlier tech pressures that you've navigated?
Jason Cradit: You know, it's funny you say "whiplash." I totally agree, it is
whiplash, right? There's all of a sudden this like, hey, is this done yet? And it
happens all the time, right? I actually find it's very similar to like the cloud adoption
life cycle, or even like the network, I'm old enough to say like client server
architectures, and how those kind of things came to be. But it's different, and I think
it's different in one particular way for me. And that is the, in cloud, it started, this
idea of like, hey, everybody's moving to the cloud, you got to get on board, you got
to go for it, you got to change from CapEx, OpEx into those things. And at that time,
what happened was people were like, or CISOs and IT leaders who are like, anybody
in my organization can just go and swipe a credit card and then they have cloud
services and our data is somewhere else. The reason that story is interesting to me
is it is so much worse with AI. Because now it is like in -- it's not just your people
doing it, every product and service and vendor on the planet is trying to make their
AI your AI. And that becomes like a problem of like, there's not enough defense to
go solve this problem, right? And so the whiplash to me is the scale and size and
drive that AI is just hitting our organization from so many angles.
Dustin Childs: >> What does that whiplash look like on the ground? I mean, you
say, you know, you've never seen it before. And I get the cloud adoption analogy.
But when the board says make AI happen, that means a lot of different things. So
what does it on the ground typically look like?
Jason Cradit: Yeah. You know, for me, I mean -- and you're right, like board
leadership have been saying for a while, make AI happen. And it's funny, right? Like
we're all technologists here, we're all friends. And so to me, how I think about
articulating to the board and my leadership is that we have to be very clear on what
are we doing with it, what are the use cases that make sense, what are the use
cases that maybe don't? That's a training question. Like we don't necessarily want
to do that. That's incredibly important on our OT assets, our operational technology
assets that we support pipelines and energy infrastructure. Now, because we have
to be very clear, you know, as we entered 2020 -- midway through '25, maybe into
'26, the conversation was like AI, LLMs, everything. It's really transformed into
agentic AI and those sort of things and making -- robots making decisions and
actions for you. Absolutely, we should lean into those things. But to me, Dustin, it's
all about how do we take the use cases and drive solutions into them and tell the
stories about how AI impacted those specific use cases.
Johnny Hand: >> Yeah. I am appreciative that you brought up the kind of IT-OT
comparison. Because I think one of the things that's interesting about your story is,
for our listeners, is the fact that you do live in that intersection. And there's a very
big difference in how you defend and really think about security around the OT and
that critical infrastructure space. So when we look at the, I guess, if you will say the
journey of, you know, from shadow AI and kind of being anti-AI as an industry into,
you know, board recommendations on leaning into AI and those kind of things, what
does that look like for you guys? How did you see AI, especially shadow AI, showing
up in your organization first? And then how did you transform that culture to start to
embrace and build a policy around that?
Jason Cradit: Yeah. So it did, shadow AI, it kind of comes into your organization or
came into our organization largely through -- on the OT side, it came through
vendors, saying like, hey, it's embedded now in your SCADA software or those sort
of things. Like it's just embedded, it's part of the conversation. And then on the IT
side, it really comes from, you know, the board and others saying, I could use, you
know, whatever LLM and whatever frontier model to go augment my work. I can
respond to emails faster or more articulate or I could write this documentation or do
this development. And so looking at those kind of competing things, right, like on
the one hand on IT, we can go and we could use LLMs relatively sophisticated. We
really get worried about the gray area in between, where we say, yeah, but we can't
put like BCSI information in that or SSI. Like we can't -- we've got to be very careful
about what information we put in there. And that's a training and testing issue and
making sure that's true. But then like, if we wanted to go create agents that would,
or agentic AI inside there that would like go do something for us -- like one example
for us right now is in like contracts management, to help us like, who's got the ball?
Like it's a very easy, obvious agentic AI workflow. Who's got the ball? What are they
doing with it? And just kind of tracking those things. But on the OT side, agentic AI is
really scary. And it's one of those things we have to be very careful with. The
example of an AI inside OT would be in like anomaly detection for like -- we've done
this forever in IoT, right? Like is that vibration something I should care about? Or is
this heat sensor something I should care about? Or are those things together
something I should care about? Those are really good AI things, where a human
watching those things may not see the anomaly as early as an AI would. They just
see it differently. The difference comes in the empowering of the AI to make a
decision and do something about it. Because maybe just maybe, the AI doesn't --
we haven't given it all the context to make a proper decision. But then also, we just
don't trust it. The regulatory framework inside of, especially like NERC CIP would
just say like, nah, we don't, we don't need AI to make decisions for us.
Johnny Hand: >> For our listeners, because I know in technology, we love to do
lots of acronyms, could you explain a little bit about that NERC CIP and how does
that play into critical infrastructure? Yeah. Well, CIP, C-I-P, to your point, is critical
infrastructure, yeah, critical infrastructure protection. And it's the idea of like a set
of standards that NERC, the National, what is it, Energy Resource Consortium, like
said, like here's how to think about securing critical infrastructure. On that side of
the fence, that's more like electric, the electric transmission distribution or battery
or solar wind, those sort of things. On the other side with critical infrastructure like
oil and gas pipelines, that's all regulated through the TSA. The same people who are
like, you can't come through at the airport. The same people are saying like, here's
how you should secure pipeline infrastructure, oil and gas pipeline infrastructure.
And so the impact or lack of resilience or lack of availability of those things, that's
where the real regulations for NERC CIP or for the TSA security directive really hit is
focused on safety and availability of the asset.
Jason Cradit: Yeah, that's definitely a different level of criticality. I think that -- I
know for being in South Georgia for many years like I have been, air conditioning is
a very useful tool that we don't want to lose when the power goes out. I want to go
back a little bit, because you kind of mentioned, we were talking about how shadow
AI kind of seeps into the organization. And I know that there's, you know, a really
big difference between that critical infrastructure and that kind of OT environment,
but also the, I guess, the, you know, kind of corporate and company policies and
also culture that you mentioned, right? That even if you haven't defined a culture,
that you have culture. But how did that compete with the existing culture, which
was kind of anti-AI? And how did you turn that leaf to start bringing AI more into the
organization? It starts with just that first step of just embracing it and saying, yeah,
we do have it. And so we should enable people to go use it, but we should create
the policy guardrails for them or should help them. So that like we could say, from a
policy perspective, instead of saying no AI, say you can use it, but don't put certain
information in it. And so by saying we're going to help be a part of the solution to
work together and collaborate on it, instead of just say no, which inevitably leads
people to their personal devices or browser windows that are now costing us money
as a company to try to control things rather than embracing it and going with
people, that policy and that attitude change, I think, is what enables us to start
moving faster. Like we want to support MCP connections. But by default, an MCP
connection means I'm giving the LLM access to other data. And so we should be
mindful about what is it. And so if you've got access to Claude co-work -- Claude
Code, sorry, Code, but you've said no MCP connections, you could easily go tell
Claude Code like, just if you're savvy enough, I expect you are, Dustin, to say like,
well, I know this server, even though my IT and security leadership doesn't allow me
an MCP connection, I know they have an API connection. And so write me a quick
API that goes and connects and gets this data for me. Now we're talking about
prompt questions, and how do I control what we're actually asking or allowing our
people to prompt? Well, dang it. Did I solve anything by blocking the MCP
connection? I would argue, no, right? Like they just -- again, there's another way to
solve the problem.
Dustin Childs: >> Right. It's a good first step, but not the last step.
Jason Cradit: Correct.
Johnny Hand: Walk us through when -- you know, shifting from the organizational
side over through that critical infrastructure and the OT kind of control room, it's got
to be very different than maybe what I grew up on, the traditional IT and SOC
environments and looking at security through that lens. So how does that look like
for you, especially with AI?
Jason Cradit: Especially with AI, right? And I think on the IT side, the example I
hear a lot, like looking at SOCs -- or SOC software or SIMs and those sort of things
that like say they have AI. On the IT side of the fence, what we see a lot is a great
example of, well, the EDR says this. And we see this in the network traffic from east
to west. So we can -- so we -- the SIM can now say, I see this, I should take an
action. And in this case, I think you can see, like EDR is saying we have malware, we
can see that's trying to propagate east to west around the network. And so then
what would any AI SOC say? Well, isolate the endpoint, right? Like, of course it will.
And it just makes sense. And we would empower -- every IT professional on the
planet would be like, totally, just isolate it. And in an OT world, that's a non-starter.
And so trying to sell SOC and SIM AI services into an OT system, you can't do that.
Because then all of a sudden, if you were to decide to isolate a controller's
workstation, they may not have control over the asset. That means pressure change
could happen and there could be a rupture. Or it could mean that we can't turn off a
pump and now we've flooded or polluted a wetland area. Like these are real-world
lifelong problems that this organization or any organization would have. And so the
criticality of the impact matters a whole lot. And so we can't just go isolate those
things. But what we can do is start to think about, like, knowing what we know, how
should we respond? And build our incident response plans around better
intelligence that AI can provide to us and better response plans than AI. We just
don't have the comfort level to say, yeah, go isolate those machines based on that
type of attack vector, right? And I think AI helps drive better responses, just not
automatic yet. Because it's just too critical of infrastructure to go say, yes, you're
approved, go make these changes. We wouldn't trust many people with making
those changes either, right? So we certainly wouldn't trust an AI quite yet. >> Yeah,
I know historically a lot of OT systems still rely on the air-gapped model or the
Purdue model as if they were sufficient protection. And I always laugh at air-gapped
because yeah, there's, well, a long history of getting around air-gapped. Why is that
misconception worth correcting head on? Air-gapped right now means that it's just
another network than somebody else's. To me, it means an ownership question. It's
like, who manages that network versus that? It's just an ownership question. And
that ownership is gray. Because, like, for example, one use case inside of an OT
network is a historian. And a historian collects what happened over -- it's a long
history of what happened over a course of time. That's really useful information.
And so that happens inside the OT network. What happens then is people want to
ask questions about that information. They want to know because pressure in an oil
and gas or how much product moved through the pipeline is directly attributed to
revenue. And so it's a leading indicator of revenue. Well, who wants that? Might be
the CFO, right? He might care. She might care, right? And so if those people care,
how do they get access to that information? They get access through, we poke a
hole into this air-gapped environment to allow that information to be extracted. It's
a one-way hole. It'll be fine. It'll be secure, Dustin, don't worry. But that, to your
point, is one simple example of how air gap's not really real.
Dustin Childs: Yeah, we've been talking about resilience and availability a lot.
Now, you sit on Secure World's Advisory Board. What shift in how peers talk to you
about AI gives you the most hope or worries you the most?
Jason Cradit: Oh, my goodness. All right, I have a lot of hope in AI, and I think that
comes from my peers and the people I'm lucky enough to work with showing
incredible value in what we can do and insights to what we can do. One example of
that is, I'm working with an industry group, a very forward-looking industry group in
the Northeast, and they're gas operators, right? That should be enough hint without
saying their name directly. But in that, I've got to work with some really good
professional technologists who focus on what can we glean from information we
know, like what lessons can we learn, and then how do we communicate that to the
network or to everybody around this area? And that gives me so much optimism to
see really smart people focused on how do we increase the velocity of how we
communicate lessons learned and safety measures across the industry? On the
other hand, what's scary to me is that there is some technology debt inside of OT.
And then there's a lot of energy organizations who have said no to AI. And I think
what we saw with Mythos and what we've seen in the industry is that we as an
organization or any of our organizations in the energy and critical infrastructure can
say no thanks to AI. We totally can. But you know who's not? The bad guys, right?
The bad guys are absolutely empowered to go use whatever means necessary. And
if we can't keep up the velocity of the bad guys with our ability to protect ourselves
against it, then we will just fail as an industry. We will lose because of our own
stubbornness to adopt technology.
Johnny Hand: In your spirit of collaboration that you talked about earlier with your
industry, what are three key takeaways or maybe next steps for those security
leaders that are in critical infrastructure? What should they consider when they're
wanting to close that gap from not allowing or zero AI to being secure and
responsible with their AI adoption?
Jason Cradit: Yeah, I think my kind of three takeaways would be, you know, we
started this conversation with, don't assume AI is not there, because it is. And so if
it is there, you should embrace it and figure out how to use it safely. Which really is
my second bullet, right? How do you think about using it safely? Just draw paths,
work with people, not at people, focus on use cases and how you support them. And
then I think finally, you know, start with every conversation -- this is old news, right?
But start with the why, right? Start with the use case and work backwards from
there. I think if you're trying to fight gravity, you've just failed, right? It is not going
to work. And so let's start with, what is it that we're trying to accomplish with AI?
How do we protect it? And then what are the guardrails around it? You know, where
are we comfortable or we're not comfortable? Specifically more around agentic AI. If
we can do those kind of three things, I think we're setting ourselves up for better
conversations but also better outcomes to support organizations.
Dustin Childs: Yeah, I agree. We can't ignore it. We must move forward. Let's just
do it smartly. Crawl, walk, run.
Johnny Hand: Well, Jason, thank you for a great conversation today. We really do
appreciate you sharing your insights and also helping just secure AI in the critical
infrastructure world, which is an interesting world. So we can't wait to have you on
the show again and look forward to talking.
Jason Cradit: Yeah, I appreciate it, guys. It's been a pleasure. And yeah, we're all
in this together. So I appreciate the insights.
[ Music ]
Johnny Hand: Dustin, what a great episode. Jason lives in such an interesting
world. He's in critical infrastructure. He's focused on availability and safety and not
necessarily confidentiality, which is something that I've always had to work in. But
he also has to deal with a lot of regulations. He's dealing with NERC, CIP, TSA
security directives, and they're all built to really protect the organization. But the
one thing is true is AI is inevitable. Jason makes that point. But our job as security
leaders is to make it intentional inside the organization. Was there something that
really stuck out to you?
Dustin Childs: Yeah, I was surprised to learn TSA was involved. I had no idea they
were asking pipelines to take off their shoes. But what really worked for me is that
department of no doesn't work and that people just route around it to personal
devices. And security leaders have to work with people and not at them to enable
safe use, to set guardrails, and to decide together and move forward with AI. So
security has flipped from the group of no to saying the group of we have to. If
defenders don't match the velocity of attackers who are already using AI, the risk
isn't missing an opportunity, it's becoming the switchboard operators who get
displaced.
Johnny Hand: Yeah. And I think we know now that OT is such a different
environment. It's not about traditional firewall rules or just blocking base MCP
connections. That's not enough anymore.
Dustin Childs: Yeah, OT runs older by nature and the downtime for patching or
hardware swaps is incredibly costly. I mean, they expect hardware to last for
decades in some cases. So virtual patching and segmentation as practical moves for
legacy OT doesn't become just a nice to have, it becomes an absolute necessity
when you just can't take a controller down every second Tuesday of the month.
Johnny Hand: And I love Jason's optimism for how the industry can actually move
forward. So thanks to Jason for sharing his insights today. For more information on
how to connect directly with Jason and to learn more about AI security and critical
infrastructure, please see our Show Notes. >> And that does it for another episode
of AI Security Brief. We want to thank you for joining us. Our goal is to host
conversations that get you thinking differently about security. And if it does,
consider subscribing so you don't miss what's next. >> AI Security Brief is mixed
and produced by Elliott Peltzman, with original music by Amneajynx. Our executive
producer is Jennifer Eiben, with content strategy by Ma'ayan Plaut and Melany
Gallant. Additional production help by Liz Stokes. Video editing by Sarelle Joppy and
Bridgitte Criqui-Wild. >> Thank you so much for joining us, and we'll see you next
time on the AI Security Brief. [ Music ]