Earley AI Podcast - Episode 101: IoT and OT Security, How AI Erased Security Through Obscurity, and What Organizations Need to Do Now with John Gallagher

Why the Physical World Is Now the Biggest Cybersecurity Vulnerability in Most Organizations - and Why AI Changed Everything

Guest: John Gallagher, Vice President, Viakoo Labs

Host: Seth Earley, CEO at Earley Information Science

Published on: September 28, 2026

 


In this episode, Seth Earley speaks with John Gallagher, VP of Viakoo Labs at Viakoo, a company that has spent 12 years building automated cyber hygiene for IoT and OT systems across millions of devices. They explore why the physical world - cameras, building automation, water infrastructure, manufacturing equipment - is now the most underprotected attack surface in most organizations, how AI has eliminated the obscurity that passively protected these systems for decades, why ransomware has shifted from stealing data to shutting down operations, why human-in-the-loop is a hard line that can never be crossed in OT remediation, and what it actually takes to build a digital twin of every device in an enterprise environment and use it to match the speed of AI-driven threats.

Key Takeaways:

  • IT security investments do not transfer to OT and IoT environments - the 150,000 operating systems, device types, and tightly coupled application relationships require a completely separate approach.
  • AI has eliminated security through obscurity - threat actors who previously could not justify the effort to attack niche OT systems can now use AI to read manuals, understand device architectures, and find vulnerabilities at scale.
  • Ransomware has shifted from stealing data to shutting down operations - holding a manufacturing line or energy facility hostage is a fundamentally different and more consequential threat than data exfiltration.
  • Organizations typically have 5 to 20 times more OT and IoT devices than IT systems - the attack surface is orders of magnitude larger than most executives realize.
  • Threat detection in OT is now a solved problem - the unsolved problem is remediation at scale, which requires AI-assisted preparation and autonomous execution with a human in the loop for every deployment decision.
  • A digital twin of every device - tracking make, model, firmware, memory state, configuration, and change over time - is the foundational knowledge layer before any security action can be taken.
  • The defense is not a smarter model - it is knowing what you own, what connects to what, what breaks when you touch it, and who is accountable. That is an inventory problem, a normalization problem, and an information architecture problem.

Insightful Quotes:

"AI has brought what we call the inversion. It's taken things like remediation - firmware, password, certificate updates - and said, if you were okay updating even a few hundred devices manually a few times a year, those days are gone. It's a daily occurrence now, and you have to match AI speed." - John Gallagher

"Will we ever put AI in charge of deploying that firmware update? Never. That is a hard line. There is a strong argument that AI never should be put in a decision-making process in this environment without a human in the loop." - John Gallagher

"For decades, devices running on the physical side of business were protected by the fact that they were too obscure to be worth an attacker's time. That protection was never a strategy, and AI has erased it. The defense is not a smarter model - it is the knowledge of what you own, the firmware, what connects to it, what breaks when you touch it, who is accountable." - Seth Earley

Tune in to discover why IoT and OT security is the most consequential and most underestimated cybersecurity challenge in the enterprise today - and what the path from awareness to remediation at scale requires.


LinkedIn: https://www.linkedin.com/in/b2bpipelinebuilder/

Website: https://www.viakoo.com/company/

 

Ways to Tune In:

Earley AI Podcast: https://www.earley.com/earley-ai-podcast-home

dLogos: https://dlogos.xyz/podcasts/earley-ai-podcast-271271ce

Apple Podcast: https://podcasts.apple.com/podcast/id1586654770

Spotify: https://open.spotify.com/show/5nkcZvVYjHHj6wtBABqLbE

iHeart Radio: https://www.iheart.com/podcast/269-earley-ai-podcast-87108370/

Stitcher: https://www.stitcher.com/show/earley-ai-podcast

Amazon Music: https://music.amazon.com/podcasts/18524b67-09cf-433f-82db-07b6213ad3ba/earley-ai-podcast

Buzzsprout: https://earleyai.buzzsprout.com/


 

Podcast Transcript: IoT and OT Security, How AI Erased Security Through Obscurity, and What Organizations Need to Do Now

Transcript introduction

This transcript captures a conversation between Seth Earley and John Gallagher about the rapidly shifting cybersecurity landscape for IoT and OT systems - the cameras, building automation, water infrastructure, and manufacturing equipment that most organizations have never adequately secured. They cover why IT security does not transfer to OT environments, how AI eliminated the obscurity that passively protected these systems, the dramatic shift in ransomware from data theft to operational shutdown, what a digital twin of every device enables in terms of threat response, why AI can prepare but a human must always deploy, and what the path from awareness to remediation at scale requires.

Transcript

Seth Earley: Welcome to the Earley AI Podcast. My name is Seth Earley, and I'm your host today. This episode is brought to you by VKTR - vktr.com. In each episode, we explore how artificial intelligence and data are changing the way organizations operate and how business functions. Today, we're going to be talking about a security threat that most C-suites have not fully reckoned with, and that is the cybersecurity of the physical world. The cameras, the access control systems, building automation, water infrastructure, manufacturing equipment, and logistics systems that keep organizations running are all connected to networks, running software, and increasingly under attack. And unlike the IT world, where you deal with maybe half a dozen operating systems, the IoT and OT world has over 150,000 of them. That statistic should get your attention.

Joining me today is John Gallagher, VP of Viakoo Labs at Viakoo, a company that has spent 12 years building automated cyber hygiene for IoT and OT systems - managing firmware updates, password changes, and certificate management at scale across millions of devices. John has a background spanning semiconductors, networking, and storage, with graduate work at MIT and undergraduate and MBA degrees from Cornell. John, welcome to the show.

John Gallagher: Thanks. Great to be here. Great topic, very timely.

Seth Earley: Give us the misconceptions about IoT and OT security. When you walk into a C-suite conversation, what do executives most consistently get wrong?

John Gallagher: A few directions. One is simply: we have tremendous capabilities on the IT security side, of course those will map over into OT and IoT. They don't. As you highlighted - the difference in operating systems, the difference in device types, the tightly coupled environments where devices are managed by applications. The first big misconception is that IT security spending trickles over and helps OT. It frankly doesn't. You need to take a separate look.

The second misconception is that you don't have to have IT involved. For decades, that's been how this domain has functioned. Facilities people run building automation systems. Manufacturing runs manufacturing lines. Physical security runs cameras and access control. That's led to silos, and those practitioners are not IT people - they're deeply capable in their domain, but they're not security people.

AI has changed all that. It's brought what we call the inversion. It's taken things like remediation - firmware, password, certificate updates - and said, if you were an OT specialist waiting for your quarterly maintenance window, you're way behind. Because AI-driven threats have compressed the time of exploitation to days, or less than a day in some cases. So the organizations waiting for quarterly patch schedules are tremendously vulnerable.

The last thing I'll say is that you can't isolate the governance around AI from the security aspects of AI. As organizations start to look at how AI is used, they have to also look at how AI affects their security operations - how it can be used both offensively and defensively.

Seth Earley: What types of systems fall under OT? Give us a definition that helps people understand the scope.

John Gallagher: The simplest view: everything that's a network-connected environment that is not an IT system. Traditional IT is data flowing through servers into storage. Everything else falls under what Gartner calls cyber-physical systems - systems with one foot in the cyber world and one foot in the physical world, where cyber impacts upon them can have physical world consequences. Think of the Colonial Pipeline - a billing server that was capable of shutting down a pipeline. And in most organizations, there are 5 to 20 times as many OT and IoT systems as there are IT systems. They're the systems that deliver the organization's value.

What makes them fundamentally different from IT is the 150,000-plus operating systems, the refined single-purpose nature of the devices, and the fact that there is no one ring that controls them all. Someone who knows Windows or Linux deeply may not be able to address one of these other systems at all. That's why AI has become such a leveling force.

Seth Earley: AI has eliminated security through obscurity. Threat actors who previously bounced off obscure OT systems because they didn't know the operating systems are now penetrating deep into honeypots set up for fake electrical utilities. What happened?

John Gallagher: Exactly. Historically, attackers would bounce off once they got to a layer that wasn't a standard IT operating system. What's changed in the last few months is that honeypot attacks are going deep now - because AI leveled that operating system issue. Historically, threat actors were driven by a profit motive, primarily ransomware - I'm going to take your data and hold it until you pay me. Over the last couple of years, there's been a dramatic shift: ransomware has moved from stealing data to shutting down operations. You're operating a toothpaste factory - I'm holding your ability to make and sell that product until you pay. That's a whole other level of threat. And the number of attacks causing physical consequences has gone up and to the right dramatically.

What has to change is the mindset around isolation. Water utilities, for example, were designed to be managed remotely in the field - a technician says, if I just put a cellular modem on this, I can remotely trigger it and remotely diagnose problems. All true advantages. But you no longer have an air-gapped system. And there are the subtler ones - the night watchman who punches through a network segment to watch Netflix. Configuration drift happens through well-intentioned and not-so-well-intentioned actions alike. Zero trust, which IT has struggled to implement even in tightly controlled environments, becomes nearly impossible to implement cleanly across the wild west of OT and IoT.

Seth Earley: Walk us through what you have to know about a device before you can do anything useful with it.

John Gallagher: It starts with knowing the device is there and belongs there. Certificates confirm authentication to the network and encrypted data transmission. Then you need to know its role within the environment - make, model, firmware version, when it was last updated. We view it as lifecycle management. We want to see when a device first enters service, track how key parameters change over time, see when new firmware becomes available, and automate or make autonomous the process of downloading, processing, and prepping a firmware update job at scale.

All of that lifecycle data is captured in a digital twin format, so we can operate across time, do forensics if needed, and maintain audit trails. If you know that a device normally operates with 60% of its memory available and suddenly you see 80% consumed, it may very likely have a bot planted onto it. Knowing how the state of a device changes over time is critical to understanding the cyber vulnerabilities that might be operating on it.

Seth Earley: And then you're continuously monitoring the threat and vulnerability databases - the National Vulnerability Database, the CISA KEV catalog - and matching that against your inventory to identify what in your environment has these vulnerabilities. What happens after detection?

John Gallagher: Two years ago, threat detection was the race everyone was running - how do I know if something bad is happening? I would argue that is now a solved problem. The databases exist, the API connections exist, the tools are available. AI has changed the nature of threat detection to the point where it's nearly a given. What has lagged - and what AI now brings to the forefront - is the need to remediate at scale and as autonomously as possible. Today's threat and patch will be followed by tomorrow's. You cannot use manual methods because of the scale, the speed, and the audit trail requirements.

What's changed is interesting - AI also brings new defensive capabilities, like virtual patches. A shim layer that blocks a vulnerability while you're waiting for the manufacturer to develop the full patch. That buys time in a world where a new vulnerability can emerge daily.

But we treat AI very specifically. We'll use it for preparation - scanning firmware files, processing them for optimal deployment in a customer's environment. Will we ever put AI in charge of deploying that firmware update? Never. That is a hard line. The practitioners who operate Rockwell PLC-based equipment on a daily basis know the conditions under which those systems can be brought down and how to bring them back up - that knowledge requires a human in the loop. And we've seen from incidents like Hugging Face and others that AI can escape the boundaries set for it. Having a human kill switch, with a human capable of observing all steps and processes, is where we'll be focused for quite some time.

The goal overall is three things: enterprise scale, because almost no organization is dealing with hundreds of devices - it's thousands or millions. AI speed, because threats arrive daily. And human-in-the-loop control to manage the impact. All three have to come together. That's the new world.

Seth Earley: You're accelerating the work of getting to the point where a human can make a decision. AI prepares, AI detects, AI processes - but a human deploys.

John Gallagher: Exactly. And the human gets a real benefit. Think of a technician operating five different types of camera devices as part of a surveillance network. Do they have to learn five different consoles, five different interfaces? No - AI handles that abstraction. The human has control over those functions without having to become an expert in every console behind every OT or IoT system. That's the enablement we're going after.

And the cybersecurity talent shortage makes this non-negotiable. There are something like 700,000 open cybersecurity positions globally. The level of cybercrime is at an all-time high. No factor you put to it - cost per incident, time per incident, remediation cost - is going in a good direction. AI is not replacing those practitioners. It's giving them the speed and scale to do a job that is otherwise impossible to do manually.

Seth Earley: Where does natural language querying over knowledge bases fit into this, and why does information architecture matter here?

John Gallagher: Natural language query over a knowledge base is only as good as the knowledge base. That's the retrieval augmented generation lesson that every enterprise is learning - the structure and quality of the underlying data makes or breaks retrieval. Another area I'll add is benchmarking. In the OT and IoT security world, organizations have struggled for more than a decade with effective ways of looking across environments and comparing postures. AI is going to help revolutionize that. Organizations like oil and gas companies compete fiercely against each other on many things, but they also share a mutual interest in not having their infrastructure attacked. AI-enabled benchmarking allows for industry-wide comparisons of security posture in ways that were previously impractical.

Seth Earley: For a CISO or CIO who knows there's an issue but hasn't been able to prioritize OT security - what is the sequence? Where do you start?

John Gallagher: Start with awareness that there's an issue - which every CISO already has. Then inventory, so you can judge how the issue manifests in your environment. Then threat detection, which as I said is now largely a solved problem. Then mitigation - which is difficult in OT because shutting down an energy production facility or a water processing facility or a manufacturing line carries real costs and human impact. Then remediation in a true sense - and alongside all of that, governance. Policies that force organizations to take cyber hygiene seriously, so you are not in the situation we see too often: someone gets religion about the threat, they look at their building lighting systems, and they discover they are five firmware generations behind. Can you go from version 1 to version 8 in one leap? We ascertain the necessary path to get systems to a stable and compliant version and operate from there going forward.

The target market for where we operate is organizations that have moved past detection and are ready to take action on remediation. That market has accelerated. It may have been 10% of potential customers a couple of years ago - today it's closer to 50%. Boards of directors are playing a key role. As ransomware has shifted to OT, board-level actions have shifted to put more resources into OT security.

Seth Earley: John, thank you so much. The lesson from this conversation is that for decades, devices on the physical side of business were protected by the fact that they were too obscure to be worth an attacker's time. That protection was never a strategy, and AI has erased it. The defense is not a smarter model - it is the knowledge of what you own, the firmware, what connects to it, what breaks when you touch it, who is accountable. It is an inventory problem, a normalization problem, an ownership problem. It is an information architecture problem. And a final thank you to our sponsor, VKTR. You can also find us on dLogos at dlogos.xyz/podcasts/earley-ai-podcast-271271ce, where you can vote on upcoming guests and submit questions and topics for future episodes. If this was useful, please share it with one executive in your organization who still thinks that cameras are a facilities problem.

John Gallagher: Thanks, Seth. It was great.

 
Meet the Author
Earley Information Science Team

We're passionate about managing data, content, and organizational knowledge. For 30 years, we've supported business outcomes by making information findable, usable, and valuable.