The AI with Maribel Lopez (AI with ML)

AI Meets Cybersecurity: Protecting Critical Infrastructure with Black & Veatch’s Ian Bramson

Episode 64

In this episode of AI with Maribel Lopez, Maribel sits down with Ian Bramson, Vice President of Global Industrial Cybersecurity at Black & Veatch, to explore the growing intersection between artificial intelligence and operational technology (OT) security.

From power grids and oil refineries to manufacturing plants, critical infrastructure systems are becoming increasingly connected—and therefore more vulnerable. Ian shares how Black & Veatch is helping industrial organizations rethink cybersecurity from the ground up, integrating protection early in the design and build process rather than bolting it on later.

Together, Maribel and Ian discuss the evolution of OT threats, the rise of AI in both defense and attack scenarios, and why cybersecurity must be seen as a core business function, not an afterthought.

🧩 Key Discussion Topics

1. The Evolution of Industrial Cybersecurity

  • Ian’s unconventional career path—from Coca-Cola to futurist consulting with Alvin Toffler to leading cybersecurity initiatives.
  • Why Black & Veatch launched its dedicated industrial cybersecurity practice and how it’s integrated across engineering, procurement, and construction (EPC).

2. IT vs. OT Cybersecurity: What’s the Difference?

  • IT focuses on data protection; OT focuses on physical safety and uptime.
  • The rising threat of cyber-physical attacks on power, water, and manufacturing systems.
  • How the increasing connectivity of devices—from pumps to sensors to AI controllers—creates new risks.

3. Foundational Security: Basics Still Matter

  • Start with asset inventory—knowing what you need to protect.
  • Identify vulnerabilities and train your “human layer.”
  • Build security in from day one instead of bolting it on later.

4. The Expanding Threat Landscape

  • Why ransomware is still relevant but no longer the only concern.
  • The growing risks of supply chain attacks, remote operations, and super dependencies (as seen in the CrowdStrike outage).
  • How attackers are weaponizing AI to accelerate attacks—and how defenders can use AI for faster detection and response.

5. AI and OT: A Double-Edged Sword

  • How AI is reshaping the attack surface for industrial systems.
  • Why every company is already “in the AI game,” whether they realize it or not.
  • The three layers of AI to consider: AI used in cybersecurity, AI inside your operations, and AI in the wild used by partners and adversaries.

6. The Biggest Misconceptions About OT Security

  • The “myth of the air gap”—why physical isolation no longer guarantees safety.
  • Common organizational blind spots: board confusion between IT and OT, fragmented responsibility, and lack of lifecycle thinking.
  • The need for Cyber Asset Lifecycle Management (CALM) to ensure long-term resilience.

7. Building a Resilient Future

  • Why early planning and a holistic approach are key to managing future risks.
  • The importance of embedding security, governance, and ethics into every new AI or industrial project.

People on this episode