Kalen opens with a framing that runs through everything else he says: the majority of his time at ChemStation was not spent deploying AI. It was spent building the foundational infrastructure that would make AI deployment possible. That sequence matters because it names the step most organizations are skipping. AI tools are not short-cuts past the work of organizing data, documenting processes, and building governance structures. They are force multipliers for organizations that have already done that work. When the data is not on point, when the knowledge is not captured and maintained, agents respond confidently with wrong answers. Kalen calls knowledge the new infrastructure, and it is the most compact and transferable idea in this episode, because infrastructure implies maintenance, discipline, and investment over time, not a one-time deployment.
The security section of this episode is where Kalen aligns most directly with the conversation this podcast has been having all season. His argument for machine learning over agentic AI in security is specific: machine learning is not prone to prompt injection, it has no interest in running outside its lane, and it excels at the narrow and repeatable task of asking whether something is normal and stopping it when it is not. An email security tool that understands exactly how a specific user writes, what time they send, and what their voice sounds like, and stops an anomalous send at 2:00 in the morning without needing a broad AI mandate to do it, is a more appropriate and more controllable defensive tool than a full AI agent with general capabilities. Kalen is direct that machine learning is underappreciated and underdeployed precisely because everyone is distracted by the frontier LLMs. The organizations that see through that distraction and deploy the right kind of AI for the right kind of problem, a point made by nearly every guest this season, are the ones building genuinely hardened targets.
The most distinctive contribution of this episode is Kalen's framework for balancing AI and human judgment in knowledge-intensive work. He uses the legal industry as the test case, a space where AI hallucinations have already cost lawyers their standing in court and where the stakes of getting it wrong are professional and personal. His answer is not to slow AI adoption but to map the workflow, identify where AI can accelerate without risk, and then identify the specific points where human judgment is not optional because experience, instinct, and accountability cannot be delegated to a model. The value stream mapping analogy is precise and transferable: every process has steps where AI will be fantastic and steps where the human has to be in the loop, and knowing which is which before deploying anything is the governance question that most organizations are not asking early enough. AI does not have experience in the way a human does. The decades a domain expert has accumulated cannot be replicated. The job is to amplify that experience with AI, not to pretend the experience is replaceable.
Resources mentioned in this episode
This episode is brought to you by CyberLynx.com
CyberL-Y-N-X.com.
CyberLynx is a complete technology solution provider to ensure your business has the most reliable and professional IT service.
The bottom line is we help protect you from cyber attacks, malware attacks, and the dreaded Dark Web.
Our professional support includes managed IT services, IT help desk services, cybersecurity services, data backup and recovery, and VoIP services. Our reputable and experienced team, quick response time, and hassle-free process ensures that clients are 100% satisfied.
To learn more, visit cyberlynx.com, email us at help@cyberlynx.com, or give us a call at 202-996-6600.
Legacy Vulnerabilities, Machine Speed Attacks, and Routing AI Safely with Mike Hiltz - Ep 225
The Economics of Cybercrime and the AI Strategy Behind Getty with Isaac Straley - Ep 224
No Longer Exploratory: Building AI Governance for K12 with Desmond Grant - Ep 223
CIO and Fractional CTO
ChemStation
Matthew Connor: Matthew Connor here, host of the Cyber Business Podcast. Today we're joined by Kalen Howell Sr., CIO at ChemStation. Kalen, welcome to the show.
Kalen Howell Sr.: Thank you very much. Pleasure to be here.
Matthew Connor: It's a pleasure having you. Before we get too far in, a quick word from our sponsors. Hackers are getting smarter — is your security keeping up? Cyberlynx sells industry-leading, AI-powered cybersecurity solutions that detect threats in real time, so you know about an attack before the damage is done, not after. Learn more at cyberlynx.com. And now back to our show.
Kalen, for those who aren't familiar, can you tell us about ChemStation and your role there as CIO?
Kalen Howell Sr.: Sure. ChemStation is a chemical manufacturing company, family-owned, headquartered in Dayton, OH, with franchises and corporate-owned manufacturing centers across the United States, Canada, and Mexico — delivering commercial-grade cleaning products to clients across the nation. My role was really focused on digital transformation: modernizing and revitalizing the technology space. It's been a fantastic learning experience and a real growth opportunity for myself and the team.
Matthew Connor: That's really cool. And I can't help but wonder — over the course of your time there, a lot has changed in terms of transformation, and AI obviously plays a huge role in that. Were you able to leverage AI at ChemStation, and where do you see it taking digital transformation in the future?
Kalen Howell Sr.: Definitely — we were able to incorporate AI and learn about it within the context of the digital transformation. That said, the majority of my time there was really about rebuilding and establishing a foundational structure around how we deliver technology. And I think that's an important point: AI is not a silver bullet. It doesn't come in and just solve everything. The fundamentals of business, technology enablement, and security still apply — if anything, even more so with AI.
But we were able to grow with the evolution of the frontier models. Anyone following the space knows that the transition between 2025 and 2026 was a real pivot point in terms of model capabilities. We got to watch that, learn from it, and develop a genuine understanding of what AI can do, what it can't do, and where humans still need to be engaged and involved.
Matthew Connor: I think you're right — AI is not a magic cure, and the fundamentals still need to be there. But I get really excited about AI, especially on the security side. The reality is that cyber criminals are leveraging AI. They're well-funded because of it, well-organized, and far more effective because of it. And we're starting to see better AI security products respond to that — things like Darktrace and Abnormal, and even the way products like SentinelOne and CrowdStrike are using AI to help SOC analysts understand what's happening faster. But where I get most excited is products like Darktrace using the right kind of AI — not just for email security, but network security and endpoint security — where it sees what's happening, understands what's normal, and when hackers come at you at machine speed, it can respond at machine speed: stop it, and call for a human to investigate. That's where every organization needs to be. Otherwise, it's bringing a knife to a gunfight. The knife worked great until someone invented a gun. What are your thoughts?
Kalen Howell Sr.: What you're describing is really the agentic era — where we can deploy agents that are smart enough to work autonomously, respond, react, and notify at machine speed. But the most important prerequisite is that the core policies, procedures, knowledge, and data have to be in place, organized, and up to date for those agents to work effectively. I read recently that knowledge is the new infrastructure. And that takes real discipline — continuously updating and maintaining that knowledge and that data.
From the very beginning of the AI conversation, it's always come back to your data. If your data isn't organized and captured properly, your agents are going to respond confidently with the wrong answer. So it goes back to the discipline and domain expertise of cybersecurity professionals to define and articulate best practices across a multi-layered security approach. And with that in mind, the fundamentals will change — the tried-and-true practices and procedures will evolve to accommodate what agents and AI can do. That's a new frontier.
Matthew Connor: And that's the real challenge with agentic AI — how do you properly govern it? How do you make sure you don't have a situation where it's going and doing things you never intended? I do think that ultimately, in the future, we'll have agents that are smart and directed enough to work beautifully on all fronts. But in the meantime, I think the unsung hero of AI is machine learning. It's come so far over the last fifteen years or so, and it's really what we need to be using more of on the security side — because it's not prone to prompt injections, it gets to understand what normal looks like, and when something isn't right, it can stop it quickly without the risks that come with a full blown AI agent. It works in directed lanes: I'm email security, I understand how Kalen writes and when he writes, and at 2 AM when something goes out that doesn't sound like him — I'm stopping it. That machine learning approach is what's going to carry us into the future until agentic AI is truly ready to be deployed more broadly. I don't think it's leveraged nearly enough right now. Most people are so focused on ChatGPT and Anthropic that they miss the fact that machine learning-powered security products are the ones that will secure the organization today. What's your take?
Kalen Howell Sr.: I think at this particular moment, we also have to reckon with what you might call the token and compute shortage. We can't all be fully reliant on the large frontier models — they're expensive, and subsidization of token costs is going to decrease. Organizations are starting to look at smaller models: how do you get frontier-quality output from a more tightly bound model focused on a narrow lane? And that's where some of our machine learning capability can push the agentic space forward in a focused, precise way.
The other element that comes into play is the combination of the deterministic approach alongside the model. By deterministic, I mean your scripts, your technical implementations, the things we've already built to solve specific problems — your SQL code, your software, your proven tooling. You combine that deterministic foundation with what the model is genuinely good at — its latent space capabilities — and you get something much more reliable than either approach alone. I think that's the framework for solving problems until agents become sophisticated enough to handle things more autonomously.
Matthew Connor: Couldn't agree more. So as you transition from the CIO role at ChemStation — what's next on the radar for you?
Kalen Howell Sr.: I've been working in the fractional CTO space. I'm currently working with a couple of organizations, helping them understand how technology can be an enabler — AI enablement specifically, but also data transformation more broadly. How can technology help an organization, a team, or even an individual achieve their goals and their mission? It's a very exciting time and I'm passionate about it. My background spans over eighteen years in software quality engineering, software development, engineering management, and executive leadership. Technology and business together — that's a beautiful thing right now. The opportunity and necessity for organizations to embrace this is real and it's urgent.
Matthew Connor: And it is the most exciting time in human history when it comes to technology. You rewind eighteen years, especially in software development — it was hard. Google helped, but it's a completely different world now. AI speeds everything along and makes everyone's job so much more human-friendly. Instead of trying to think and act like computers to get them to produce what we want, we get to be human about it — interact with AI in natural language to get ideas, answers, and output. No more exciting time than this. Who's your ideal client as a fractional CTO?
Kalen Howell Sr.: The small to mid-size organization is the sweet spot. I find my interest is to be close to the technology solutions — working with the development or technology team doing the actual implementation, while also working with executives to understand where the organization needs to go. What's the current state? Where do they want to be? Being part of that strategic planning and helping them close the gap. In terms of size, I'd say somewhere from several hundred to around one to five thousand employees tends to be a good fit, though some of that depends on the industry and how the organization is structured.
Matthew Connor: And the real value of that diverse background — having worked in legal software, healthcare, finance, chemical manufacturing — is the ability to come into an organization and bring a perspective they don't have. You see a problem that industry has always solved one way, and you say, "You know, we solved something similar in legal software this way, and it might apply here." Specialized expertise is valuable, but cross-industry diversity in thought and experience brings something that's genuinely hard to replicate. That's really where large consulting firms have traditionally won — until AI starts to encroach on that space too.
Kalen Howell Sr.: Exactly. And I learned a while ago what my core strengths and passions really are — strategic thinking, analytical learning, continuous curiosity. I used to go on vacation and struggle to read something just for pleasure because everything felt like it needed to be feeding me intellectually. But I've come to embrace that as part of who I am. Getting engaged in different industries and connecting the dots across different domains is one of the things I genuinely enjoy most.
Matthew Connor: You mentioned LexisNexis and the legal software space — eighteen years there. With AI, I think that's going to be one of the most fascinating industries to watch. What's your take on what AI is going to do to legal software specifically?
Kalen Howell Sr.: LexisNexis was actually in the AI game long before AI was a buzzword — recommendation engines, big data, that kind of work was happening well before the current wave. From what I've seen, the legal software industry is embracing AI in a big way. There are a lot of forward-thinking organizations moving fast in that space. And organizations within any industry that are genuinely embracing AI right now — learning what it can do, changing how they work, rethinking their business models — they are far ahead of those who aren't. I can't predict exactly where legal software goes from here, but they're already adopting, learning, and evolving their businesses around AI and agentic capabilities.
Matthew Connor: And it is fascinating, because on the surface you'd think an LLM would excel in law — until you get into the hallucination problem. We've seen plenty of stories about lawyers citing cases that don't exist. The hallucinations are getting better, and you always have to verify your outputs, but ultimately I think AI is going to be a real game changer for the legal industry once organizations find the right balance. The challenge is that AI naturally lulls us into a false sense of security. It's the same thing with self-driving cars — it's been hundreds of hours of great performance, so you start to trust it completely, which you can't quite do yet. We were coming back from New York a few weeks ago, full self-driving engaged, and a car veered into our lane. Our car reacted in lockstep — moved over, slowed down, avoided the collision — in less than a second. There's no way I could have reacted that fast. It was a thing of beauty. But that doesn't mean I stop supervising. 99% of the time it does the right thing — but it's that 1% that reminds you the human still needs to be in the loop. How do you advise organizations to balance that in this interim period?
Kalen Howell Sr.: It comes back to two things: the knowledge and data have to be on point — you need accurate data in place for correct answers, not hallucinated ones — and you need to incorporate deterministic checkpoints into your workflows. Think of it like a value stream mapping exercise. You look at a workflow and identify the specific points where AI is going to be fantastic and the points where human judgment is genuinely required. You build those human-in-the-loop moments in by design.
My core view is that AI is an amplifier of human capability, not a replacement for it. And right now, that amplification is most effective when the human is a genuine expert in their domain — because an expert can smell when something is wrong. A non-expert can be fooled. An attorney's experience, their judgment, the decades they've spent developing intuition in their field — AI cannot replicate that. We shouldn't try to erase it. We should capitalize on it and use AI to amplify what that expert can already do.
Matthew Connor: Couldn't agree more. That is very well said. Kalen, I cannot thank you enough for coming on today. This has been an absolute blast. Before we go, can you tell everyone where they can find out more about you?
Kalen Howell Sr.: Sure. My website is www.kalenhowesr.com — everything about me is there, including a contacts page with my LinkedIn link and email address.
Matthew Connor: Fantastic. We'll be sure to link that for everyone. Kalen, until next time — thank you.
Kalen Howell Sr.: Thank you so much for having me. It's been a pleasure.