Artificial intelligence is reshaping cybersecurity — but in operational technology (OT), industrial control systems (ICS), and critical infrastructure, the most dangerous threats aren't coming from AI‑powered superattacks. They're coming from something far more basic: Internet‑exposed systems. Legacy equipment. No asset inventory. Weak controls. Minimal monitoring. And decades of cybersecurity debt. In episode 57 of Cyber Security America, Joshua Nicholson sits down with Santosh Kaveti, CEO & Founder of ProArch, for a candid conversation about the escalating risks facing water treatment facilities, power grids, manufacturing plants, and other essential services. Recent attacks on U.S. water systems exposed a painful truth: many PLCs, HMIs, remote access portals, and ICS components are still directly reachable from the internet — no zero‑day required. When those systems control the infrastructure communities rely on, cybersecurity failures become public safety failures. This isn't just an IT problem anymore. It's a national security problem. In this episode, you'll learn: Why internet‑exposed PLCs and ICS devices represent one of the biggest OT security breakdowns of our time How AI can strengthen OT environments through asset discovery, behavioral baselining, anomaly detection, and accelerated response Why separating IT and OT security is no longer viable for modern critical infrastructure The hidden risks inside supposedly "air‑gapped" systems that aren't actually monitored or governed How secure remote access, vulnerability management, change control, and recovery planning can dramatically reduce OT incident impact Why legacy infrastructure continues to hinder utilities and critical operations How compliance‑driven cultures create blind spots that undermine true cyber maturity and resilience Why visibility, accountability, and continuous assessment matter when outages affect entire communities Joshua and Santosh also dig into the uncomfortable questions: Who is responsible when critical infrastructure operators fall behind? How transparent should utilities be with regulators and the public? And why do basic cybersecurity failures still persist despite rising consequences? This conversation explores the intersection of AI, OT security, legacy systems, resilience, and national security — and challenges the idea that cybersecurity must be complex to be effective. Sometimes the most impactful improvement is simply knowing: What you have. Who can access it. What changed. What's normal. And whether you can recover. About Santosh Kaveti Santosh Kaveti, CEO & Founder of ProArch, brings more than 18 years of experience modernizing technology environments across energy, healthcare, manufacturing, and critical infrastructure. His insights offer a grounded, practical view of how organizations can modernize OT systems without compromising safety or reliability. Who should listen? This episode is essential for CISOs, OT/ICS defenders, critical infrastructure operators, utility leaders, cybersecurity engineers, risk teams, and anyone responsible for protecting the systems communities depend on. If you care about OT cybersecurity, ICS security, PLC protection, industrial resilience, AI in cybersecurity, or the safety of water and power systems, this episode delivers a clear look at the real risks — and what organizations can do right now to address them. Subscribe to Cyber Security America for more conversations with cybersecurity leaders, responders, and innovators shaping the future of digital and operational defense.