What happens when artificial intelligence gives cybercriminals the ability to identify, map, and exploit critical infrastructure faster than defenders can respond? For the organizations responsible for power grids, manufacturing plants, water utilities, and data centers, that question is no longer hypothetical.
In this episode of The Business of Cybersecurity, I welcome Almog Apirion, CEO and Co-Founder of Cyolo, to discuss why the rules of defending operational technology are changing. Drawing on his experience leading the Israeli Navy's cyber unit and serving as a CISO before founding Cyolo, Almog shares why the rise of AI-powered attacks demands a renewed focus on the security fundamentals many organizations have overlooked.

One of the strongest messages from our conversation is that AI has dramatically lowered the barrier for attackers. Capabilities that once required highly skilled specialists are now becoming accessible to a much wider range of threat actors. Rather than spending weeks researching vulnerable systems, attackers can now automate reconnaissance, identify weak points, and prepare attacks at unprecedented speed. That leaves defenders with far less time to react.
Instead of relying solely on detection and response, Almog argues that businesses must build security into their environments from the beginning. We discuss why identity controls, multi-factor authentication, segmentation, and tightly governed access remain some of the most effective ways to reduce cyber risk, even as AI continues to reshape the threat landscape. Sometimes the simplest security controls still prevent the biggest attacks.
Our conversation also examines why traditional VPN-based remote access has become increasingly difficult to justify inside critical infrastructure. Almog explains why giving users access to an entire network creates unnecessary exposure when modern approaches can limit access to only the specific systems people need to perform their work. That principle sits at the heart of mature zero trust strategies, where every connection is verified and every action is tightly controlled.
Another area we explore is microsegmentation and why it is becoming an increasingly important part of protecting operational technology. Rather than assuming attacks can always be prevented, organizations should prepare for the possibility of compromise and focus on limiting how far an attacker can move through a network. Reducing the blast radius can often make the difference between a contained security incident and a major operational disruption.
We also discuss the practical challenges security leaders face every day. Replacing legacy remote access tools, introducing zero trust without disrupting production, supporting third-party vendors, and maintaining always-on access for mission-critical operations all require careful planning. Almog explains why cybersecurity cannot come at the expense of uptime, particularly in industries where every minute of disruption carries real-world consequences.
This conversation serves as a timely reminder that while AI is changing both sides of cybersecurity, the strongest defenses are still built on solid foundations. As attackers become faster and more automated, organizations must ensure that identity, access, segmentation, and resilience are designed into their environments from the start rather than added after an incident occurs.
If AI is making attacks faster, should security teams spend less time chasing alerts and more time reducing opportunities for attackers altogether? And are the foundations of your security strategy strong enough for the threats that already exist today? I'd love to hear your thoughts after listening.
Useful Links
Connect with Almog Apirion
Learn more about Cyolo

[00:00:00] The leading issue of agentic AI in businesses right now is ensuring agents act with compliance guidelines. And Denodo applies guardrails across your entire data estate. By aligning your company's data infrastructure under one system, these guardrails perform consistently across your platform. So start scaling your business and start with Denodo. Simply visit denodo.com to learn more.
[00:00:33] What happens when AI gives attackers the ability to move faster than your security team can respond? This is something we'll discuss today as I'm joined by the CEO and co-founder of Cyolo. And he spent his career protecting some of the world's most sensitive environments from military operations to critical infrastructure.
[00:00:57] And as cyber threats become increasingly automated and AI powered, he will argue that many organisations are focusing on the wrong battle. Because while headlines often focus on sophisticated detection tools, he thinks the answer actually lies in getting the fundamentals right before the attackers even gain a foothold.
[00:01:21] And you'll also hear today why legacy remote access tools, how they're continuing to create unnecessary risks. But the solution and what a mature zero trust strategy actually looks like in practice. And most importantly, what you need to be thinking about doing differently when protecting systems that cannot simply be patched or upgraded overnight.
[00:01:44] So if you're responsible for cyber security, operational technology, critical infrastructure, or just simply want to understand how AI is changing the threats landscape, today's conversation will offer a timely look at some of the challenges security leaders are facing right now and the actions that they should be taking next. But enough from me. Let me introduce you to my guest right now. So thank you for joining me on the podcast today.
[00:02:14] Can you tell everyone listening a little about who you are and what you do? Yeah, so my name is Omog. I'm one of the founders and the CEO of Sciolo. We are protecting critical infrastructure. This is what we do in Sciolo. I'm a security practitioner. I like to call myself a recovering seesaw. So I was a customer of solutions like Sciolo for quite a lot of time.
[00:02:39] I was the head of the cyber unit for the Israeli Navy and went to the corporate world and did the CISO role there. And we started Sciolo in order to solve a big problem from our perspective of protecting critical infrastructure with secure connectivity. So this is who I am. And it's great to be here. Love it. Well, thank you for sitting down with me today.
[00:03:05] And looking at your origin story there, you've spent your career protecting some of the world's most sensitive environments. But when you look at today's threat landscape, especially with the rise of global conflict that we're seeing every day, why are critical infrastructure organizations becoming such attractive targets, not just for cyber criminals, but also nation state actors too? Yeah, no, no, it's a good point.
[00:03:30] I think that it's so the short answer is the magnitude and the echo of the impact. Right. And, you know, when you're impacting critical infrastructure, it propagates to a lot of people and it gets the right or the amplified attention the attackers, you know, want to achieve. And we also saw it, you know, in the latest conflict between the US and Iran, right?
[00:04:00] Like drones that are attacking data centers, right? If someone is doing something as noisy as sending drones, I think that he will try to steal, you know, credentials of third parties that are getting into this data center way before. It's way easier, but the target stays the same, right? Yeah. To do something that will create a big damage.
[00:04:23] So, you know, obviously we got used to nation states or nation state, let's call it adversaries playing there. And with AI, and we are going to talk about it during this podcast, the barrier just got significantly lower.
[00:04:39] So now it's way more accessible to, you know, a wider audience of attackers and practically you don't need to be an expert nowadays with all the tools that are outside in the market and using attackers to do vibe hacking, which is the, you know, the new trend. And I'm glad you brought up AI there.
[00:05:07] And we do hear a lot about how AI can help defenders from reducing burnout of people in the industry to alert fatigue, bringing that down as well. But attackers are adopting AI too. So I'm curious, how are you seeing AI changing the way that adversaries identify targets, move through networks and plan their attacks against operational technology and critical infrastructure environments? What are you seeing here? I think that it's, it's not a, it's not a small shift.
[00:05:37] It's a, it's, it's a huge change of mindset that is happening for defenders because the world is, is completely different. You know, all the methods like detect and respond are becoming less relevant nowadays. You know, at the age of mythos and all, all the, all the, the other tools.
[00:06:04] And just yesterday we had another announcement coming from one of the, one of the vendors talking about another, another capability. So we're talking about something that is way easier. And, and, and, and, you know, currently the ratio between vulnerabilities to the vulnerabilities that are actually being catalogued. Right. The ratio is something around one to 10. Right. So it's a rain out there.
[00:06:34] And, and, and, you know, the way that we are looking at it, it, it, it, it's still, you know, the, the, the fundamentals are becoming more and more relevant because organizations must be protected by design. And there's, there's no other way you don't have enough time to respond and being practical here and just wearing my CISO hat again. Right. Specifically with, with critical infrastructure, there's not a lot of things that you can do.
[00:07:04] You cannot run security on the machines that are actually manufacturing stuff. So you need to make sure that you don't have digital assets that are accessible from the outside because nowadays it's practically game over. But you also know that everyone that is getting into your plant is just risking you million times more than before. Right. So what organizations are doing, they're looking at their external exposure.
[00:07:30] They're making sure that, you know, everyone that is getting in is absolutely necessary. And they want to make sure that the actions that can be run by, by authorized users are limited for the things that he needs to do. And another capability that became extremely important, the ability to scan my network if I'm letting someone in. Right. Because nowadays, like, you know, the vulnerabilities are out there, exploits are ready.
[00:07:57] And the only thing that is missing for the attackers is to map vulnerable technologies and just to attack them. Right. So I think that it's a huge tectonic change in security and especially in critical infrastructure security, where you're pretty much limited in your ability to protect.
[00:08:17] So it goes back to secure connectivity and, you know, the control plane that you have when you're, you know, connecting between humans to machines and between machines to machines. So, yeah, you change.
[00:08:33] And when I was doing a little research on you, I was also reading how you highlighted an incident where attackers were using AI to map industrial gateways and assess operational systems before any human was able to detect any kind of activity at all. So, I mean, that one incident there, what kind of lessons should security leaders take away from attacks like that? And why is it that traditional detection approaches are struggling to keep pace with these attacks? Yeah, no, no.
[00:09:02] It's a good question. I think that at the end of the day, as a defender for quite some time, we want to make the attacker's life harder. And it goes back to my previous point. We need to start with the fundamentals. It was blocked by something pretty basic like MFA. Right.
[00:09:23] So, to be protected by design and to make sure that you're covering the fundamentals is becoming more and more important, especially nowadays. And it starts with identity and access. You know, computer systems were designed to serve people. People are the biggest risk for computer systems, both for operational computer systems and also MIS. Right.
[00:09:52] So, it kind of puts us back in implementing the fundamentals, knowing that, you know, detect and response is not as effective as it was before because you don't have enough time. And it's interesting you mentioned how it was blocked by MFA, a fairly basic way of blocking that. And at the same time, many organizations are investing heavily in new security tools. But these successful attacks keep happening.
[00:10:21] But in your experience, again, from what you're seeing and hearing, what are the security fundamentals that organizations are most commonly overlooking? I mean, you mentioned MFA there. But why do these basics still matter in an AI-driven threat environment? Because it feels like they're often overlooked. Yeah, I think that I kind of touched it at, you know, the first question. Let's make sure organizations need to make sure that they don't have their digital assets accessible from the outside. Because nowadays, as I said before, it's game over.
[00:10:50] They need to look at access. They need to look at what authorized user can do when he's getting in. In some cases, you have an Ajit user running something on his endpoint that he's not even familiar with. Right. So it's not, it doesn't end with authentication. It's also to see not only who is getting in, what he can do while it's connected.
[00:11:16] And the last thing that is really relevant is the ability or to block the ability to scan your network and identify your soft spots. Because nowadays, you know, attackers, they already have this stock with bullets that are already loaded, just waiting to shoot. Right. So you want to block this scanning and lateral movement. And if I'm talking a little bit about the alternatives.
[00:11:45] So I think that using VPNs nowadays in general, but specifically in critical infrastructure, this is practically a disaster waiting to happen. Nothing less than that. Because you don't want to virtually connect someone to your private network. You want to allow someone to do his job. And, you know, VPNs were invented in 1996. Right.
[00:12:15] We evolved from this point. And modern solutions like CIO are providing access to the service, never access to the network, as an example. And zero trust is another area that has been discussed for many years now. But despite that, many organizations still struggle to move beyond the concept. But in present day, what does a mature zero trust strategy actually look like inside maybe a critical infrastructure environment?
[00:12:44] And where should organizations begin if they are still early on this journey? It's hard to imagine that they are. But where should they start? Yeah. No, no. It's a good point. Because it kind of brings me back to one of the reasons of founding CIO law to begin with. Good. We are strong believers on zero trust. I think that organizations need to assume bridge.
[00:13:12] And I think that they need to apply with this mindset of never trust, always verify, including your vendors. One of the things that we did, and I'm going to address, you know, the difficulties and the practical implications of it as well. But never trust, always verify. And it should include your vendors as well. And this is why it was it was one of the reasons that we founded CIO law.
[00:13:40] Because we I spoke with a lot of vendors back then about zero trust. And I asked them very basic question. I asked them, hey, guys, can you access my network without anyone in my team even familiar with it? So I had a lot of long answers. Right. We never want to. We never did it. But I had to go back to the, you know, I'm a techie. I did my bachelor and master of the game in computer science, mainly around security related topics.
[00:14:09] And I was I was refining my question. It's not about if you want to do it. Can you do it? You guys are holding my access policies. You're holding my encryption keys. If you guys are breached, I'm in a big problem. Right. Because you hold the door and the key to my kingdom. Right. So one of the things that we built, we never own our customers secrets because we shouldn't. No vendor should do it.
[00:14:40] And and. Especially in critical infrastructure, it's way more important. Like, you know, there is a huge difference between connecting third party to your ERP system rather than connecting a third party to a nuclear plant. Right. The potential of damage is significantly different.
[00:15:01] I think that the fundamentals should start with digital identity, access, the asset level controls. We are talking about very critical assets, session control. And I think that the barriers to implement zero trust is the cost of change. In a lot of cases, as a security practitioner, you know that you have a problem. You know what should be the solution.
[00:15:25] You just cannot apply it because it's the end of the quarter, because it's, you know, you're not getting maintenance windows and things like that. And it can be really frustrating. And I'm speaking as someone that was on the other side. So one of the things that we built in CIO is the ability to be tested in parallel to what our customers already have in production without risking their production.
[00:15:50] And the other thing is the ability to deploy your product in production in parallel to the existing access tool or connectivity tool, because you don't want to be in a point that you have a cutoff date and you need to plug off and plug on because it is extremely stressful. Right. I did VPN replacement projects three times in my career. And it's a lot of pressure, right?
[00:16:18] You want everything, you need everything to work because it's not only security, we're serving the business. You have, you know, employees connecting to customers. And if it's not working, you start getting phone calls from general managers asking, hey, what's going on? I'm paying salaries and my people cannot do their job. So we are distressing it with something that can be deployed gradually without any cutoff date.
[00:16:45] And I think that this is one of the biggest barriers, the ability to integrate with the existing environment with zero change management or with minimal change management. That's the blocker. Because in a lot of cases to implement zero trust, it comes with a price tag in order to do it. And the price tag is usually friction to the business. And in some cases, you cannot pay this price.
[00:17:12] So that was one of our, you know, fundamentals when we started, you know, hitting this problem and taking care of this problem is to bring a solution that can be digested by the feed and can actually distress, you know, this transition instead of doing otherwise.
[00:17:31] And for anyone listening that is on this path at the moment, they will have quickly noted that micro segmentation is increasingly being described as the defining element of a modern zero trust architecture. And for listeners that might understand the term but are yet to implement it, what problem does micro segmentation solve? And how does it limit the damage when attackers gain access to a network? Yeah, yeah, yeah. It's a good question.
[00:17:59] So micro segmentation is to limit movement and to control the blast radius and to control the communication, basically, with providing some kind of asset protection that is minimizing or reducing the exposure and contain the impact. Because the entire game is to limit movement.
[00:18:21] Because the entire game is to keep the plant or the business doing what it should do when you take care of the, and again, we talked about, you know, assume bridge. Things will happen. You want to be able to contain the risk with minimal impact on, you know, operations. Things will happen.
[00:18:44] And on the other hand, it is something that can be really difficult to implement because you're changing stuff, right? Like all the critical infrastructure are basically being run by computers and you cannot allow this friction. So we are going to announce something really soon around micro segmentation.
[00:19:12] And we are taking a completely different approach, which is let's look at solving the biggest problems first. And I'll give you an example. In our cases, you have digital assets with vulnerabilities that can be exploited remotely.
[00:19:36] So let's say that you have, you know, 100 assets, 90 of them vulnerable for remote code execution, which means that someone can connect from the outside and create some damage, right? But just 30 of them are remotely accessible. Are you going to fix a problem that is not applicable? Not in our world, right?
[00:20:01] So to keep it very practical, starting from your remotely accessible assets, knowing that this is your biggest risk. And we talked about mythos and all of these capabilities that were released to the world recently to block the access from scanning your network and to minimize the blast radius and to make sure that, you know, the machine to machine connectivity is being done as it should be.
[00:20:29] Because you don't have a lot of other options when you think about actually protecting. I'm not talking about detecting. I'm talking about to actually protect and minimize the risk. You need to protect things from the outside because you cannot run on the machines that are running the operations themselves, right? So micro segmentation is becoming more and more important.
[00:20:55] And again, it's always the trade-off between doing the right thing to, you know, to minimize your cyber risk, but also having the right solution that is easy to digest that you can actually go and deploy without, you know, the risk of disrupting operations and creating downtime. I love a good teaser. It sounds like we will need to get you back on in a few months, find out more about that big announcement when it drops.
[00:21:22] But I think there will be people listening that they know exactly what they should be doing. But at the same time, they're juggling how many operational environments still rely on legacy remote access technologies that ultimately were never designed for today's threat landscape. So what risk do those older approaches create? And again, any practical steps that people listening could take to modernize access, but without disrupting operations? I appreciate some massive balancing out, but any advice there? Yeah, yeah, absolutely.
[00:21:51] So first of all, I'm going to repeat something that I already said. VPN is a disaster waiting to happen. It's a matter of time. You shouldn't let someone into your bedroom, right? Without knowing why it's necessary. So to bring someone to your network is never a great idea. But it goes back to, you know, being practical and realistic.
[00:22:19] So we need to minimize broad access. We need to minimize the use or eliminate the use of shared credentials. And one of the things that we hear quite a lot is, you know, we start deploying our solution. And we are currently protecting more than 750 organizations worldwide. And there's always this some variation of the following story.
[00:22:46] Something happened last Friday in 3 a.m. And it was done by operator one. That's great. Who is operator one? And they don't know. And in a lot of cases, they have third parties connecting, connected to the network for years. They have people that left the organization, but they never changed passwords. Right.
[00:23:13] And they have, you know, network access. And again, a disaster waiting to happen. So the combination of, you know, bringing security in a way that it is digestible. So that's the key from our perspective, because, you know, everyone knows that zero trust is what organizations should do.
[00:23:39] Everyone knows that VPN is not a great idea, especially when you think about critical infrastructure. But there are some barriers. I really hope that we removed to make it practical and easy, because if it's too difficult, it won't happen. 100% with you. And finally, before I let you go, if you were advising a CISO or plant manager or critical infrastructure operator listening today,
[00:24:04] what would you say are the most important actions they should be taking over the next 12 months to help reduce cyber risk and prepare for the growing use of AI threat actors? And also, finally, I'm throwing a lot of questions away here, but any other trends that you think they should be looking out for too? I think that 12 months is too long. I think that I'll advise what to do in the next 12 days, right? Yeah.
[00:24:30] So first of all, we need to make sure that we don't have digital assets that are accessible from the outside, first and foremost. The other thing, we need to make sure that everyone that is getting in is absolutely necessary, because the level of risk of every user is just significantly higher. We need to minimize the blast radius, right? If someone that is getting in, even authorized users, what can he do while he's in?
[00:25:00] Can he scan my network? Can he do things that is not part of what is necessary for him to do his job, right? So it's pretty, pretty, pretty important. And also things like resilience. When you think about, you know, at the end of the day, it's assume bridge and what should happen, right?
[00:25:26] So if your access tool is not highly available, especially your, you know, emergency access. I'll give you an example. With all of this, you know, huge investment in AI infrastructure, we have more and more data center customers that wants to connect to the infrastructure of the data center for cooling and electricity and things like that.
[00:25:55] In order to provide always on infrastructure, you need to have always on access. As someone that was in charge of more than 60 data centers in my previous role, try to think about the following use case. You have a heating data center. You want to connect this technician from Siemens to help you and rescue you. And your access tool is, is down because it's running over AWS and there is some kind of a glitch, right?
[00:26:26] It's the probability is not high, but it happened before. You rely on Cloudflare for routing. And now something happened, right? So this is, this is something that should be done. You need to think about what will happen if things will go wrong. Am I still in the right place to react? Basically. So this is basically how we look at it, look at it.
[00:26:55] And it's, as I said before, it's to go back to the fundamentals and to keep in mind that, you know, there's not enough time for detecting response anymore. Organizations need, they need to be protected by design. And it's starting with human to machine and continue with machine to machine. So this is our advice. Look at your connectivity layer as the control plane and, and use it.
[00:27:24] And use it in, in a smart way because, you know, to look at the plumbing of ports that were open or closed. This is yesterday's approach, right? Nowadays, attackers are way more sophisticated. If, you know, you're counting on a specific pattern that will ring the bell, think twice, right?
[00:27:47] Because if you're trying to attack someone and you know that using a specific behavior is going to, you know, start the alarm, you're going to avoid it and use another method, right? So it's all about looking at the data and understanding the context and also the intent that is coming from the context.
[00:28:11] And again, not to, not to, not to give a spoiler, but this is another capability that we are thinking of and, and going to release to the market. The ability to look at the entire session and to extract context instead of technical attributes that can be misleading.
[00:28:33] I love it. And I think that is another spoiler free moment to end on and anyone listening that is interested in learning more about your zero trust platform and indeed some details about that upcoming micro segmentation capabilities. When that launches, of course, where, where should everyone go to keep up to speed with everything that you're doing there?
[00:28:53] Yeah. Yeah. So, so we can, we can be found in our website and we would love, you know, to speak with people and help them understand how we can help them on their specific environment, because we know that every environment has its own uniqueness.
[00:29:13] And in a lot of cases, you know, when we speak with customers, the first sentence is, hey, here things are extremely more complicated than what you, that you guys have ever seen. Yeah. And, and that's, that's, you know, that's the situation. So the, the, the ability, you know, to, to protect complex environments with zero change management, that's the key.
[00:29:36] And this is, this is something that we would love to help with and make it extremely practical for each and every organization, because we know that, that every organization and every network is different. And at the end of the day, you know, it's all about uptime and uptime can, can, can, can take a penalty from cyber threat, but also from, you know, implementing the wrong product.
[00:30:02] So we are here, we are here to help and we would love to show more, more organizations how we can help them protect their unique and complicated environment. Well, we covered a lot today from the real cost of legacy remote access tools, still running inside some of the most sensitive facilities out there. How AI is actually being weaponized by threat actors right now.
[00:30:26] And also why micro segmentation is rapidly becoming the defining capability of mature zero trust architecture. And I expect there will be more news on that one later, but I will add links to everything that you mentioned so everyone can stay up to speed. But thank you for sitting down with me today. Really appreciate your time. It was fun, Neil. Thank you. I enjoyed it. I think as we close today's conversation, one message stands out above all others.
[00:30:54] In a world of AI powered threats, it's security fundamentals that matter more than ever. And that compelling case that my guest shared today, that organizations can no longer rely on detecting attacks after they happen.
[00:31:10] Because the speed, the scale, the accessibility of AI driven cyber attacks mean businesses need to think about protection by design, reducing exposure, controlling access and limiting the potential impact when something inevitably goes wrong. So as AI lowers the barrier to entry for cyber criminals, how are your security controls keeping pace?
[00:31:38] Or are they still built for a threat landscape that no longer exists? Remember, techtalksnetwork.com. That's where you'll find all the information from today's episode and 4,000 other interviews across a podcast at the Tech Talks Network. But that's it for today. So keep your messages coming in and I'll be back real soon with another guest. Bye for now.

