← All episodes

Jason Rivera: Why Most OT Security Tools Never Pay Off

Jason Rivera · Co-Founder & CEO · Cabreza
· Hosted by
Come on the show →

Starts with a 20 minute pre-interview call. I handle everything else.

About this episode

Jason Rivera is the co-founder and CEO of Cabreza, and his argument is that the tool was never the problem. Most critical infrastructure teams buy an OT security tool first and then wait for it to tell them what they do not know. The missing rules were the real gap.

Rivera spent ten years in the field, built an OT practice at a consultancy, then took the analyst seat at Gartner before leaving to found Cabreza. He explains what a one-control security program looks like, why a utility does not need a million dollar budget to start, and what water utilities and rural co-ops told him that never reached him from the analyst seat.

In this conversation

Watch the full episode on YouTube →

Full transcript

Jason Rivera (00:00.216) Mm-hmm. Mikulas Zach (00:01.725) Okay, welcome back to another Agentee Digital Podcast episode. Today I'm joined by Jason Rivera, the co founder and CEO of Cabreza.

Jason, it's great to have you here today. Jason Rivera (00:17.07) Thanks for having me. Pleasure to be here.

Mikulas Zach (00:19.781) So for the folks that don't know you, how would you describe yourself? Who is Jason? Jason Rivera (00:24.28) Yeah, yeah.

Jason Rivera (00:30.466) That's such a loaded question. I'll stick to the professional version though. We'll keep it we'll keep it there.

well I have been in cybersecurity for more than 10 years now. I started off as a defender in in a cybersecurity operations center at a consultancy before becoming a consultant. I then took a year consulting hiatus and built a an InfoSec team and program at a cloud compute company before they were acquired.

I then returned to consulting. And fell into OT security and ultimately never looked back. I spent the next five years doing OT security tool deployments, controls developments, leading programs, many other things, ultimately building a successful practice at that firm before needing to do more on the OT market itself than than just the service.

And then at that time I left and joined Gartner, where I was part of their cyber physical system security cohort. but I felt the pull to still do more and that's why I I ended up leaving and founding Cabreza, which I've been building and leading now for more than a year and a half. Mikulas Zach (01:39.448) Hmm.

You know it's it's interesting that you say that because I feel like most people if they would be given a analyst seat at a company like that, it's sort of like the destination where most people want to get, right? And so what actually made you leave and build your own thing? Jason Rivera (01:58.446) Yeah.

Jason Rivera (02:07.902) It's the best I can best way I can put it is you know how when you watch if you if you watch sports at all, a lot of the analysts are are former players and and they're the ones who like know the pitch or they know the field or they know the game and they're up in the booth. Every so often you know there's that one analyst who's like, I don't care how old I am, I wanna be back on that field. And that's kind of what happened to me where I was was I was analyzing and I was doing all the the it's great work.

It's it's Mikulas Zach (02:14.339) Yeah. Jason Rivera (02:37.676) It's satisfying. There's a lot of complexity and a lot of cool stuff that you do.

But I just had this this this like I I think I want to be doing it though, not not analyzing it right now. And that ultimately led me to like it was just kind of a conviction at that point that there was something I I felt on on that I didn't get to do yet that I wanted to do. Mikulas Zach (02:47.801) Mm.

Mikulas Zach (03:00.537) And so for people that might not know Cabreza, because correct me if I'm wrong, but you you guys launched in 2025, so it's we are still in the early days. So who do you think benefits the most from what you guys do? Jason Rivera (03:01.451) That was it.

Jason Rivera (03:13.132) Yep. Yeah. Jason Rivera (03:22.028) Great question.

The smaller to mid market critical infrastructure utilities and asset owner and operators. So smaller to mid market, like there are water utilities and authorities and such who have, you know, five hundred thousand to a million residents they serve. They're probably a little bit more resourced.

They're gonna have a big tool stack and you know have have maybe even budget to to hire external resources. What What I built Cabreza to do is similar to what we were talking about a moment ago, is to with a mission to help critical asset owner and operators build their own protection themselves, to provide capability ultimately, more than a license key or a statement of work, right? To actually impart the knowledge that exists within the industry, but make it actionable and effective to take NIST sp eight hundred eighty-two or three or a si ISA six sixty four four three and like to do something with it and to have that be a a turnkey moment where you don't necessarily need my former self as a as a as a as a you know OT security consultant with with billable hours.

You don't need me if the if a solution can represent the experience and expertise that I have And and you can leverage that on your own terms. And so that's really what what we've built is that is is leaning into that capability of like helping the individual owners and operators to understand what they need to do and do it themselves and understand. Mikulas Zach (05:05.908) Hmm.

Is there any big misconception that you feel like people have around, you know, critical infrastructure, OT? Jason Rivera (05:19.832) Mm-hmm. Jason Rivera (05:23.38) I think I think the industry has done a really good job at clarifying OT and clarifying how it is different than than IT.

I I would say that I don't think there's a misconception per se. I think there's a lack of fundamental knowledge still. So so less misconception and more kind of first principle fundamentals is where I see the.

the the challenges in the industry. there's a there's a you know this innate focus to like, you know, go do this thing and and go build around this. And this is headlines and and you know it's the FUD mechanics, the fear, uncertainty, and doubt mechanics that that lead into cybersecurity.

And they still exist. And for what it's worth, they're they're also still effective sometimes, unfortunately. That's not the game that we play and that's not so what I what I mean by that is There's a there's a shift to that stuff.

W and when it does it is it kind of takes you away from the fundamentals, the fundamentals of of basic principles within within industrial cybersecurity and industrial security itself. and that's that's probably more the challenge I see than than misconceptions per se. Mikulas Zach (06:38.29) Hm.

What's your take on the u use of AI within cyber security? Jason Rivera (06:45.78) Mm. I think that there are I think there are some some valid, incredibly valid, valuable, and fit-for-purpose uses use cases for AI in industrial environments as well as in industrial cybersecurity.

that is my politically correct way of saying that I think there are plenty of not valid use cases for it and and those are a matter of Mikulas Zach (07:17.075) Mm. Jason Rivera (07:20.536) Probably just more of a matter of opinion opinion and bias than than anything at this point. but I I I think that Those use cases which are valid are clear and present and inarguable.

And if we look at what machine learning and the current state of artificial intelligence brings to bear, I hope that a lot of people can make their own deductions as to where it it it's good to be used and and and where it's not. And I think that'll become more clear over time anyway. Mikulas Zach (07:53.778) Jason, you call yourself captain of team discipline.

in March you you put that into practice with the frontline infrastructure program, which was aimed at water utilities and rural co-ops. What did you learn talking to those operators that maybe you hadn't seen from kind of the consulting or analyst side. Jason Rivera (08:30.563) Yeah.

that we as cybersecurity practitioners need to stop talking and start listening more. it's it's kind of a contradictory way of going about our business because if you're a subject matter expert, it's like, okay, well tell me what to do. but when you're working with smaller utilities and and utilities in general, Cybersecurity is a discipline in itself.

And so if I'm classically trained to be a cybersecurity professional, then I understand the nature of things in cybersecurity and what should be done or what should not and can be done and cannot, all these things. but I if it unless I've been in the shoes of a SCADA supervisor at a water utility or an emergency manager within energy, I I don't know the world. And in order for any form of cybersecurity to actually be meaningful and and adoptable and adaptable to to the environment, we we need to shut up and listen.

Listen to the people who know their world the best and then be able to answer questions that they have in a way that makes sense to them. And there's there's information that they can use from from our experience and knowledge. and I think that's that's the biggest takeaway from from those conversations is that you can come with an industrial security mindset and principles and theories and disciplines and all the fancy words, right?

But that doesn't that doesn't sit on top of a a water utility and a specific role in a small utility without there being some form of putting it all to the side. And you tell me what you need. What is it that you're looking for?

And that's that's what I learned from from a lot of that program. Mikulas Zach (10:21.688) Hm. Hm.

W what do you feel like is the hardest part of the work that you do? Jason Rivera (10:35.075) Which which which part of the artist part? The the founder work, the the the product work, the go to market, the there's Mikulas Zach (10:43.68) Well, you tell me from from from your position, you can you can pick your your heart.

Jason Rivera (10:51.245) Sure. All right. Well, the hardest part isn't isn't any of yeah, the hardest part isn't cybersecurity at all.

The hardest part nowadays is is is getting the getting attention and getting it the right way. So I I mean, as much as Cabreza is is a fantastic organization built with the right from the right from the right things, right? We come from the right place, we're mission oriented, doing all the right things.

Frontline infrastructure program. free software, free utilities, you name it, all the right things, right? That means nothing unless I got a unless I can get that in front of an operator.

And so how do I do that? This the the information the information realm of today is just full. It is completely full.

And so trying to trying to find the right channels and avenues and ways of Mikulas Zach (11:36.212) Mm. Mikulas Zach (11:42.636) Mm. Jason Rivera (11:47.854) Getting our message to be heard is is the hardest part.

That is it. Hands down. there are so many different everybody's competing for for attention and priority.

And especially when you're to your point, earlier stage, right? Year and a half. I don't have 10 years ahead start on this.

I do for myself. My company doesn't, but that's what I'm competing against. You know, and so I have to I have to find a way to fight without fighting.

I have to find a way to Mikulas Zach (11:54.22) Mm. Mikulas Zach (12:09.961) Hmm. Hmm.

Jason Rivera (12:17.05) to grab attention without without fudding. And there there are all these different kind of challenges and restrictions and issues to navigate. and that's that's the worst part, quite frankly.

but that that's where the opportunity is and that's what we're chasing at the same time. It's just equally the hardest, the hardest part of it all. Mikulas Zach (12:38.164) Hmm.

Is there something that surprised you about starting your own company? Jason Rivera (12:46.37) Every day. Every day.

if you ask any thought I mean hopefully I'm not the exception here, but I I've got I've got a list of a hundred different things that I've learned. and they're all they're all huge. yeah, I learn all the time.

and you you also end up learning the hard way when it's you making the decisions and you figuring out what works and doesn't work. But yeah, yeah, I learn the learnings are are there there are more learnings than anything as long as you have if you have a good mindset to it. yeah that's Mikulas Zach (13:22.994) Yeah, f for sure.

And i if you use those mistakes and you don't do them again, then I think that's what really matters, right? To not repeat the same Jason Rivera (13:33.905) Well yeah, that's that's learning the lesson. any lesson unlearned is the one that you didn't really you didn't actually learn from the mistake, right?

So you didn't actually learn it, you're just doing it again. I I do try it in the beginning I wasn't very good at it. it was like, well that's okay.

I'll I'll do it. I'll I'll do it different I'll do it a little differently this time. But then you get six months and a year in, you're like, no, I just need to pay attention to the fact that that didn't work, right?

And just like call that duck a duck. Mikulas Zach (13:37.982) Yeah. Mikulas Zach (14:00.883) Mm.

Jason Rivera (14:02.328) and just own it and learn it and move on. In the early days you kind of convince yourself that you have you have the thing that can change that. And later stage it's less about changing and more accepting what you can't change and finding the next thing to do instead.

Mikulas Zach (14:19.143) Yeah, yeah. across all of the operators that you've been at, you know, SRA, Gardner, we can assume that there are some kind of common patterns that you see across you know different kind of teams, infrastructure teams, and mistakes that they do. what what is like some kind of repeatable mistake that you see over and over these critical infrastructure teams make when they try to stand up an OT security program.

Jason Rivera (15:01.52) Sure, I'll I'll call two, two out. The first one is my is my actually my favorite, and it's called rules before tools. So what I often see is we don't you know, asset owner says like we need OT security, I'm gonna go, I'm gonna go buy a tool, right?

And you're gonna put the tool in and it's gonna it's gonna tell us what we don't know. It's gonna give us visibility and and all the and don't don't do it. Don't do it.

Build your rules. Like, what do you want from the tool before you buy the tool? What do you need to get from the tool before you buy the tool?

How are you going to use that data that you do get when you have the tool in place? That's what you do first. And that's quite frankly, that's the hard part.

But that's what makes the tool worth the investment in the first place, is that you have a clear understanding of your expectations. This way you can align that expectation to what is what happens in reality with that tool. And if there comes a point in time where someone's like, well, why did we buy this tool?

Well, you can look back and say that's because this is what we identified we needed and we made that decision. So rules before tools. And there's there's a lot more within that to pull on, but that's the that's the kind of the top top line of it.

the second point is probably the the the toughest one to to really understand is that. A program, an OT security program, can be any size. Any size.

It can have one control and that could be your program. What I think gets lost though is that there are people and organizations think that you need to have like multi-million dollars of investment and you need to build all this upfront and you need to run sure, maybe that's what your organization demands. And maybe you're maybe you're a global enterprise, and like, yeah, that's that's the right fit program for you.

That is not a program. That is not the program, though. That is a certain size or capacity or style or flavor of program.

If you're a different size company or you're at a different maturity, a program of any size is a program. And the the reason why to build a program though is to, is to set expectations, to have a strategy component to it, to be able to build a Jason Rivera (17:21.838) A steering committee based on it. And a steering committee doesn't have to be like every top line executive in the company.

Just pull a couple, pull somebody from the IT side, somebody from the OT side, pull from your engineering folks, pull from your operations and maintenance folks, and and and have them stacked with IT and have an executive leader. There's your program start. That's it.

But start there because that there therein lies that you you have the ability to build fundamental fundamentals across the board. You have a level of of of buy-in from the organization because every OT security program of any size needs to be aligned to the business. O OT is at the business point of a company.

It's the distribution, it's the manufacturing, it's the keep going on down the list. Like OT is what drives that. So it's closest to that bottom line.

So the program needs to be built with the business in mind, which is why a program has should should really start fundamentally within those Core concepts of leadership and fundamentals. But I but I see organizations kind of skip that and or go for like a lot of the big money programs. Cool, great.

You're gonna half of what you you spend, you're gonna not see or lose throughout the process, but sure, fine. You don't have to do it that way. It can start from the smallest thing, smart from what's achievable.

Pick the top two or three priority focuses that you have, focus on consequence. rather than chasing risk. Like there are just so many different ways to do it.

I think there's this like innate thing that like, we need all this money or we need to go buy these tools and and that's just not the way it is. Mikulas Zach (18:58.966) Hmm. Where can people find you, Jason, if they would like to check you out, get in touch?

Jason Rivera (19:08.571) Sure. I'm pretty vocal on LinkedIn. I've I've I've learned to embrace my opinions and I've put it put it out there in the public sphere quite a bit.

maybe too much. But no, I mean that's I I I I I contribute the way I do because I hope it helps people to see the contrasts and to see discussion and debate in the community. And I think that's all healthy and that's that's why I do it.

But a LinkedIn is probably the best way to find me or the Cabreza website, cabreza.com and about and then you'll see me there and there's a LinkedIn and an email and stuff like that. Mikulas Zach (19:42.089) Okay. Well thank you for listening and thank you for joining, Jason.

Jason Rivera (19:47.836) Thanks for having me, appreciate it.

Come on the show →

Grab a slot and we will record.