
Can you trust AI with critical infrastructure?
Jason Cradit: Start with the use case and work backwards from there. I think if you're trying to fight gravity, you've just failed, right? It is not going to work. And so let's start with, what is it that we're trying to accomplish with AI? How do we protect it? And then what are the guardrails around it? [ Music ]
Johnny Hand: Welcome to AI Security Brief, where we're unpacking emerging AI threats, vulnerability research, and the strategic decisions that security leaders are making right now. I'm Johnny Hand.
Dustin Childs: And I'm Dustin Childs. Today's guest is Jason Cradit, CTO and CISO at Everline Technologies. Jason brings more than 25 years' experience across pipelines, aerospace, and defense, and he's working right now in the IT/OT front lines where a security decision can impact a pressure change on a pipeline and not just a laptop getting quarantined. And this is critical infrastructure, we're talking about, you know, the things that run the stoplights, the things that keep the AC cool in the summer, and the gas keeping you warm in the winter.
Johnny Hand: Yeah, in this episode, we actually talk about the fact that, for years, security leaders have been saying no to AI, right, we just don't want to implement it. But Jason points out that no was never really the truth. Shadow AI is already in your organization, arriving through both employees and the vendors and embedded into the AI, into the product. So we know that whether you're intentional about it or not, whether you put a policy in place or not, you have an AI culture today, and our security leaders jobs are to make it intentional.
Dustin Childs: You know, Jason also talks about why an action that's routine in IT, such as isolating the endpoints, can be catastrophic in OT, because you get a valve you can't control, a rupture, and then an unintentionally flooded wetland. So agentic AI making decisions on its own in this world right now is a non-starter. But the reason this matters right now is that the adversaries are not waiting, and you shouldn't either. So let's get into it.
[ Music ]
Johnny Hand: Well, Jason, welcome to AI Security Brief. This is the show where we unpack emerging AI threats, vulnerability research, and the strategic decisions that security leaders are making right now. We're very excited to have you with us.
Jason Cradit: I'm excited to be here, man. It should be fun.
Dustin Childs: Jason, I've got a question for you. So you've got more than 25 years of experience across energy pipeline, aerospace, and defense. And I'm sure you've seen several adopt-it-now mandates land on regulated teams. How is the AI whiplash different from earlier tech pressures that you've navigated?
Jason Cradit: You know, it's funny you say "whiplash." I totally agree, it is whiplash, right? There's all of a sudden this like, hey, is this done yet? And it happens all the time, right? I actually find it's very similar to like the cloud adoption life cycle, or even like the network, I'm old enough to say like client server architectures, and how those kind of things came to be. But it's different, and I think it's different in one particular way for me. And that is the, in cloud, it started, this idea of like, hey, everybody's moving to the cloud, you got to get on board, you got to go for it, you got to change from CapEx, OpEx into those things. And at that time, what happened was people were like, or CISOs and IT leaders who are like, anybody in my organization can just go and swipe a credit card and then they have cloud services and our data is somewhere else. The reason that story is interesting to me is it is so much worse with AI. Because now it is like in -- it's not just your people doing it, every product and service and vendor on the planet is trying to make their AI your AI. And that becomes like a problem of like, there's not enough defense to go solve this problem, right? And so the whiplash to me is the scale and size and drive that AI is just hitting our organization from so many angles.
Dustin Childs: What does that whiplash look like on the ground? I mean, you say, you know, you've never seen it before. And I get the cloud adoption analogy. But when the board says make AI happen, that means a lot of different things. So what does it on the ground typically look like?
Jason Cradit: Yeah. You know, for me, I mean -- and you're right, like board leadership have been saying for a while, make AI happen. And it's funny, right? Like we're all technologists here, we're all friends. And so to me, how I think about articulating to the board and my leadership is that we have to be very clear on what are we doing with it, what are the use cases that make sense, what are the use cases that maybe don't? That's a training question. Like we don't necessarily want to do that. That's incredibly important on our OT assets, our operational technology assets that we support pipelines and energy infrastructure. Now, because we have to be very clear, you know, as we entered 2020 -- midway through '25, maybe into '26, the conversation was like AI, LLMs, everything. It's really transformed into agentic AI and those sort of things and making -- robots making decisions and actions for you. Absolutely, we should lean into those things. But to me, Dustin, it's all about how do we take the use cases and drive solutions into them and tell the stories about how AI impacted those specific use cases.
Johnny Hand: Yeah. I am appreciative that you brought up the kind of IT-OT comparison. Because I think one of the things that's interesting about your story is, for our listeners, is the fact that you do live in that intersection. And there's a very big difference in how you defend and really think about security around the OT and that critical infrastructure space. So when we look at the, I guess, if you will say the journey of, you know, from shadow AI and kind of being anti-AI as an industry into, you know, board recommendations on leaning into AI and those kind of things, what does that look like for you guys? How did you see AI, especially shadow AI, showing up in your organization first? And then how did you transform that culture to start to embrace and build a policy around that?
Jason Cradit: Yeah. So it did, shadow AI, it kind of comes into your organization or came into our organization largely through -- on the OT side, it came through vendors, saying like, hey, it's embedded now in your SCADA software or those sort of things. Like it's just embedded, it's part of the conversation. And then on the IT side, it really comes from, you know, the board and others saying, I could use, you know, whatever LLM and whatever frontier model to go augment my work. I can respond to emails faster or more articulate or I could write this documentation or do this development. And so looking at those kind of competing things, right, like on the one hand on IT, we can go and we could use LLMs relatively sophisticated. We really get worried about the gray area in between, where we say, yeah, but we can't put like BCSI information in that or SSI. Like we can't -- we've got to be very careful about what information we put in there. And that's a training and testing issue and making sure that's true. But then like, if we wanted to go create agents that would, or agentic AI inside there that would like go do something for us -- like one example for us right now is in like contracts management, to help us like, who's got the ball? Like it's a very easy, obvious agentic AI workflow. Who's got the ball? What are they doing with it? And just kind of tracking those things. But on the OT side, agentic AI is really scary. And it's one of those things we have to be very careful with. The example of an AI inside OT would be in like anomaly detection for like -- we've done this forever in IoT, right? Like is that vibration something I should care about? Or is this heat sensor something I should care about? Or are those things together something I should care about? Those are really good AI things, where a human watching those things may not see the anomaly as early as an AI would. They just see it differently. The difference comes in the empowering of the AI to make a decision and do something about it. Because maybe just maybe, the AI doesn't -- we haven't given it all the context to make a proper decision. But then also, we just don't trust it. The regulatory framework inside of, especially like NERC CIP would just say like, nah, we don't, we don't need AI to make decisions for us.
Johnny Hand: For our listeners, because I know in technology, we love to do lots of acronyms, could you explain a little bit about that NERC CIP and how does that play into critical infrastructure? Yeah. Well, CIP, C-I-P, to your point, is critical infrastructure, yeah, critical infrastructure protection. And it's the idea of like a set of standards that NERC, the National, what is it, Energy Resource Consortium, like said, like here's how to think about securing critical infrastructure. On that side of the fence, that's more like electric, the electric transmission distribution or battery or solar wind, those sort of things. On the other side with critical infrastructure like oil and gas pipelines, that's all regulated through the TSA. The same people who are like, you can't come through at the airport. The same people are saying like, here's how you should secure pipeline infrastructure, oil and gas pipeline infrastructure. And so the impact or lack of resilience or lack of availability of those things, that's where the real regulations for NERC CIP or for the TSA security directive really hit is focused on safety and availability of the asset.
Jason Cradit: Yeah, that's definitely a different level of criticality. I think that -- I know for being in South Georgia for many years like I have been, air conditioning is a very useful tool that we don't want to lose when the power goes out. I want to go back a little bit, because you kind of mentioned, we were talking about how shadow AI kind of seeps into the organization. And I know that there's, you know, a really big difference between that critical infrastructure and that kind of OT environment, but also the, I guess, the, you know, kind of corporate and company policies and also culture that you mentioned, right? That even if you haven't defined a culture, that you have culture. But how did that compete with the existing culture, which was kind of anti-AI? And how did you turn that leaf to start bringing AI more into the organization? It starts with just that first step of just embracing it and saying, yeah, we do have it. And so we should enable people to go use it, but we should create the policy guardrails for them or should help them. So that like we could say, from a policy perspective, instead of saying no AI, say you can use it, but don't put certain information in it. And so by saying we're going to help be a part of the solution to work together and collaborate on it, instead of just say no, which inevitably leads people to their personal devices or browser windows that are now costing us money as a company to try to control things rather than embracing it and going with people, that policy and that attitude change, I think, is what enables us to start moving faster. Like we want to support MCP connections. But by default, an MCP connection means I'm giving the LLM access to other data. And so we should be mindful about what is it. And so if you've got access to Claude co-work -- Claude Code, sorry, Code, but you've said no MCP connections, you could easily go tell Claude Code like, just if you're savvy enough, I expect you are, Dustin, to say like, well, I know this server, even though my IT and security leadership doesn't allow me an MCP connection, I know they have an API connection. And so write me a quick API that goes and connects and gets this data for me. Now we're talking about prompt questions, and how do I control what we're actually asking or allowing our people to prompt? Well, dang it. Did I solve anything by blocking the MCP connection? I would argue, no, right? Like they just -- again, there's another way to solve the problem.
Dustin Childs: Right. It's a good first step, but not the last step.
Jason Cradit: Correct.
Johnny Hand: Walk us through when -- you know, shifting from the organizational side over through that critical infrastructure and the OT kind of control room, it's got to be very different than maybe what I grew up on, the traditional IT and SOC environments and looking at security through that lens. So how does that look like for you, especially with AI?
Jason Cradit: Especially with AI, right? And I think on the IT side, the example I hear a lot, like looking at SOCs -- or SOC software or SIMs and those sort of things that like say they have AI. On the IT side of the fence, what we see a lot is a great example of, well, the EDR says this. And we see this in the network traffic from east to west. So we can -- so we -- the SIM can now say, I see this, I should take an action. And in this case, I think you can see, like EDR is saying we have malware, we can see that's trying to propagate east to west around the network. And so then what would any AI SOC say? Well, isolate the endpoint, right? Like, of course it will. And it just makes sense. And we would empower -- every IT professional on the planet would be like, totally, just isolate it. And in an OT world, that's a non-starter. And so trying to sell SOC and SIM AI services into an OT system, you can't do that. Because then all of a sudden, if you were to decide to isolate a controller's workstation, they may not have control over the asset. That means pressure change could happen and there could be a rupture. Or it could mean that we can't turn off a pump and now we've flooded or polluted a wetland area. Like these are real-world lifelong problems that this organization or any organization would have. And so the criticality of the impact matters a whole lot. And so we can't just go isolate those things. But what we can do is start to think about, like, knowing what we know, how should we respond? And build our incident response plans around better intelligence that AI can provide to us and better response plans than AI. We just don't have the comfort level to say, yeah, go isolate those machines based on that type of attack vector, right? And I think AI helps drive better responses, just not automatic yet. Because it's just too critical of infrastructure to go say, yes, you're approved, go make these changes. We wouldn't trust many people with making those changes either, right? So we certainly wouldn't trust an AI quite yet.
Dustin Childs: Yeah, I know historically a lot of OT systems still rely on the air-gapped model or the Purdue model as if they were sufficient protection. And I always laugh at air-gapped because yeah, there's, well, a long history of getting around air-gapped. Why is that misconception worth correcting head on?
Jason Cradit: Air-gapped right now means that it's just another network than somebody else's. To me, it means an ownership question. It's like, who manages that network versus that? It's just an ownership question. And that ownership is gray. Because, like, for example, one use case inside of an OT network is a historian. And a historian collects what happened over -- it's a long history of what happened over a course of time. That's really useful information. And so that happens inside the OT network. What happens then is people want to ask questions about that information. They want to know because pressure in an oil and gas or how much product moved through the pipeline is directly attributed to revenue. And so it's a leading indicator of revenue. Well, who wants that? Might be the CFO, right? He might care. She might care, right? And so if those people care, how do they get access to that information? They get access through, we poke a hole into this air-gapped environment to allow that information to be extracted. It's a one-way hole. It'll be fine. It'll be secure, Dustin, don't worry. But that, to your point, is one simple example of how air gap's not really real.
Dustin Childs: Yeah, we've been talking about resilience and availability a lot. Now, you sit on Secure World's Advisory Board. What shift in how peers talk to you about AI gives you the most hope or worries you the most?
Jason Cradit: Oh, my goodness. All right, I have a lot of hope in AI, and I think that comes from my peers and the people I'm lucky enough to work with showing incredible value in what we can do and insights to what we can do. One example of that is, I'm working with an industry group, a very forward-looking industry group in the Northeast, and they're gas operators, right? That should be enough hint without saying their name directly. But in that, I've got to work with some really good professional technologists who focus on what can we glean from information we know, like what lessons can we learn, and then how do we communicate that to the network or to everybody around this area? And that gives me so much optimism to see really smart people focused on how do we increase the velocity of how we communicate lessons learned and safety measures across the industry? On the other hand, what's scary to me is that there is some technology debt inside of OT. And then there's a lot of energy organizations who have said no to AI. And I think what we saw with Mythos and what we've seen in the industry is that we as an organization or any of our organizations in the energy and critical infrastructure can say no thanks to AI. We totally can. But you know who's not? The bad guys, right? The bad guys are absolutely empowered to go use whatever means necessary. And if we can't keep up the velocity of the bad guys with our ability to protect ourselves against it, then we will just fail as an industry. We will lose because of our own stubbornness to adopt technology.
Johnny Hand: In your spirit of collaboration that you talked about earlier with your industry, what are three key takeaways or maybe next steps for those security leaders that are in critical infrastructure? What should they consider when they're wanting to close that gap from not allowing or zero AI to being secure and responsible with their AI adoption?
Jason Cradit: Yeah, I think my kind of three takeaways would be, you know, we started this conversation with, don't assume AI is not there, because it is. And so if it is there, you should embrace it and figure out how to use it safely. Which really is my second bullet, right? How do you think about using it safely? Just draw paths, work with people, not at people, focus on use cases and how you support them. And then I think finally, you know, start with every conversation -- this is old news, right? But start with the why, right? Start with the use case and work backwards from there. I think if you're trying to fight gravity, you've just failed, right? It is not going to work. And so let's start with, what is it that we're trying to accomplish with AI? How do we protect it? And then what are the guardrails around it? You know, where are we comfortable or we're not comfortable? Specifically more around agentic AI. If we can do those kind of three things, I think we're setting ourselves up for better conversations but also better outcomes to support organizations.
Dustin Childs: Yeah, I agree. We can't ignore it. We must move forward. Let's just do it smartly. Crawl, walk, run.
Johnny Hand: Well, Jason, thank you for a great conversation today. We really do appreciate you sharing your insights and also helping just secure AI in the critical infrastructure world, which is an interesting world. So we can't wait to have you on the show again and look forward to talking.
Jason Cradit: Yeah, I appreciate it, guys. It's been a pleasure. And yeah, we're all in this together. So I appreciate the insights.
[ Music ]
Johnny Hand: Dustin, what a great episode. Jason lives in such an interesting world. He's in critical infrastructure. He's focused on availability and safety and not necessarily confidentiality, which is something that I've always had to work in. But he also has to deal with a lot of regulations. He's dealing with NERC, CIP, TSA security directives, and they're all built to really protect the organization. But the one thing is true is AI is inevitable. Jason makes that point. But our job as security leaders is to make it intentional inside the organization. Was there something that really stuck out to you?
Dustin Childs: Yeah, I was surprised to learn TSA was involved. I had no idea they were asking pipelines to take off their shoes. But what really worked for me is that department of no doesn't work and that people just route around it to personal devices. And security leaders have to work with people and not at them to enable safe use, to set guardrails, and to decide together and move forward with AI. So security has flipped from the group of no to saying the group of we have to. If defenders don't match the velocity of attackers who are already using AI, the risk isn't missing an opportunity, it's becoming the switchboard operators who get displaced.
Johnny Hand: Yeah. And I think we know now that OT is such a different environment. It's not about traditional firewall rules or just blocking base MCP connections. That's not enough anymore.
Dustin Childs: Yeah, OT runs older by nature and the downtime for patching or hardware swaps is incredibly costly. I mean, they expect hardware to last for decades in some cases. So virtual patching and segmentation as practical moves for legacy OT doesn't become just a nice to have, it becomes an absolute necessity when you just can't take a controller down every second Tuesday of the month.
Johnny Hand: And I love Jason's optimism for how the industry can actually move forward. So thanks to Jason for sharing his insights today. For more information on how to connect directly with Jason and to learn more about AI security and critical infrastructure, please see our Show Notes.
Dustin Childs: And that does it for another episode of AI Security Brief. We want to thank you for joining us. Our goal is to host conversations that get you thinking differently about security. And if it does, consider subscribing so you don't miss what's next.
Johnny Hand: AI Security Brief is mixed and produced by Elliott Peltzman, with original music by Amneajynx. Our executive producer is Jennifer Eiben, with content strategy by Ma'ayan Plaut and Melany Gallant. Additional production help by Liz Stokes. Video editing by Sarelle Joppy and Brigitte Criqui-Wild.
Dustin Childs: Thank you so much for joining us, and we'll see you next time on the AI Security Brief. [ Music ]


