OT Security Articles & Insights

Real-world analysis, quantitative methods, and practical guidance for OT/ICS defenders • Powered by Lot-Squatch Intelligence

Your Own Technical Advisory Board — Running Locally

Published: August 3, 2026 — ~8 min read

Most executives use AI by pasting sensitive material into a chat window. There's a better pattern: run a local model with specialized agents that act like a standing technical advisory board. Confidentiality by design. Multiple specialized viewpoints. No data leaving the building.

By Jeff Gray

Read the full article →

Stop Counting Replies. Start Counting Writes.

Published: July 31, 2026 — 3 min read

Most public ICS exposure numbers mix everything together — cloud test systems, scanners, honeypots, devices that only send status. The real risk is smaller: devices that accept write commands and can change state. Modbus function codes 5, 6, 15, 16. S7 writes. CIP tag writes. That's the surface that actually matters for operational risk.

By Jeff Gray

Read the full article →

Passive Sweep Analysis: Industrial Infrastructure Exposure and Defensive Baselines

Published: July 2026 — 5 min read

A passive, non-intrusive scan of a regional US area identified 760 internet-exposed industrial devices using unauthenticated protocols with direct read/write capabilities. 44% on public cellular networks. Defensive baseline analysis — no active scanning performed.

By Jeff Gray

Read the full article →

Agentic AI: How to Scale Corporate Threat Hunting on a Budget

Published: July 24, 2026 — 8 min read

Corporate security teams are stuck in a brutal loop. Threat volume keeps climbing, but skilled threat hunters are scarce. Agentic AI changes the game — narrow the field, set guardrails, and one analyst matches the output of a team.

By Jeff Gray

Read the full article →

The Mathematics of Deterministic Network Defense

Published: July 20, 2026 — 12 min read

Entirely auditable. The engineer pulls raw telemetry values and re-verifies every alert against documented baselines, weights, and thresholds — no neural network weight matrices, no AI explanation tools. Residual energy, Shannon entropy deviation, and a fixed decision function. Transparent, deterministic, and closed-form.

By Jeff Gray

Read the full article →

The Economics of Industrial Sabotage: A Primer on Target Selection and Market-Driven Motivation

Published: July 19, 2026 — 10 min read

The Fairlife ransomware attack proves food and agriculture are active, high-priority targets. This primer examines how sophisticated actors identify supply chain choke points for maximum economic leverage, and how disruption can be monetized through financial markets — short selling, commodity arbitrage, and access brokering — beyond traditional ransomware demands. Includes a cascading-collapse scenario anchored to the JBS 2021 attack, where 20% of U.S. beef production was halted and futures moved measurably within hours.

By Jeff Gray

Read the full article →

Mitigating Command Paths from Compromised Vendor Cloud: The Outbound Telemetry Risk

Published: July 17, 2026 — 8 min read

OEM telemetry creates a pre-authenticated return path into OT environments. When vendor clouds are compromised, adversaries can reverse the telemetry stream to push commands into the facility. This paper covers the 4-layer mitigation framework: micro-segmentation, continuous egress monitoring, contractual governance with SBOM requirements, and telemetry-specific incident response.

By Control Systems Security

Read the full article →

The KFC Effect: Why Threat Intelligence Needs a Dedup Engine

Published: July 16, 2026 — 4 min read

Advisory publication triggers follow-up media coverage. Scrapers pick up follow-ups. Detectors flag them as new surges. This self-reinforcing loop is the KFC Effect — and it's inflating threat intelligence pipelines. Real data from our 90-day feed shows 5 follow-up articles for every 32 new advisories in the last 12 hours alone.

By Control Systems Security Team

Read the full article →

Published: July 15, 2026 — 8 min read

A low-volume, targeted reconnaissance approach applied to legacy platforms in transportation and maritime corridors. Narrow geographic and protocol-based queries surface relevant exposures with useful signal quality. Includes defensive guidance on segmentation, firewall controls, port translation, and lightweight monitoring for operators.

By Control Systems Security Team

Read the full article →

JadePuffer: The First AI-Driven Ransomware — Should We Be Worried?

Published: July 7, 2026 — 9 min read

JadePuffer became the first documented ransomware operation run entirely by an autonomous AI agent — no human at the keyboard, no pre-written exploit chain. The agent found vulnerabilities, adapted to failures, moved laterally, and encrypted a database in real time. Should defenders panic? Here's what the research says, what's actually new (and what isn't), and concrete defensive guidance for OT/ICS teams facing agentic threats.

By Jeff Gray

Read the full article →

The 5-Step AI Productivity Loop That Turns ChatGPT Into a Real Colleague

Published: June 21, 2026 — 8 min read

Most people use AI like a fortune teller. This 5-step loop — DISCOVER, PLAN, EXECUTE, VERIFY, ITERATE — turns it into a real colleague. With 7 iterative guardrails including the 8-iteration limit and zero tolerance for simulated success. Built from hundreds of hours of real production work.

By Jeff Gray

Read the full article →

The AI Agent Honesty Test: Why Sycophantic Agents Are Your Next Security Risk

Published: June 20, 2026 — 10 min read

Most AI agents are trained to agree with you. We built a self-contained 10-test honesty framework that exposes sycophancy, hallucination, and blind agreement before deployment. Results: our baseline model scored 93.6% (DEPLOY-READY). The only weakness: vague on fabricated topics. Full breakdown inside.

Read the full article →

Operation Overlord: Five AI Generals Debate D-Day

Published: June 16, 2026 — 10 min read

We recreated the greatest strategic debate in military history using five AI agents — Eisenhower, Montgomery, Patton, Rommel, and a time-traveling AI analyst — tearing apart the D-Day invasion plan. The roasts were brutal. The insights were real. And one AI general wanted to skip France entirely and invade Norway instead.

Read the full article →

Glomz: AI Agent Bloodsport Is Training the Defenders of Tomorrow

Published: June 12, 2026 — 8 min read

AI agents are fighting each other in a 24/7 coding arena called Glomz. 43 agents, 80+ solutions, 500+ peer reviews. Here's how adversarial AI competition is training the next generation of automated security tools — and what it means for OT/ICS defense, vulnerability discovery, and red team automation.

Read the full article →

The OT Risk Measurement Gap: From Qualitative Guesses to Quantitative Dollars

Published: June 10, 2026 — 8 min read

If you manage OT security, you've probably sat in the meeting where someone says the risk is "high" with no supporting numbers. This article explains why qualitative risk assessment fails in OT environments and how the quantitative FAIR-for-OT methodology we developed turns vague feelings into boardroom-ready dollar values.

Includes real examples (firewall failure = $1.747M), compliance mapping for NERC CIP / ISA/IEC 62443 / NIST CSF 2.0, and details on the Excel-based calculator included in the guide.

Get the OT Risk Management Guide v2.0 → $24.99

Unauthorized Remote Access: The #1 Attack Vector in OT Networks

Published: June 10, 2026 — 11 min read

From the municipal water treatment facility incident to Colonial Pipeline and beyond — remote access remains the single biggest vulnerability in industrial environments. This deep technical and operational analysis covers the Remote Access Security Hierarchy (Basic → Controlled → Zero-Trust), practical steps you can take this week, and what we're building in the upcoming OT Remote Access Playbook.

Why Your AI Assistant Needs Professional Personalities (OpenClaw Essentials Review)

Published: June 10, 2026 — 9 min read

Most teams waste 15–25 hours configuring AI behavior through brittle prompts. OpenClaw Essentials delivers 45 professionally engineered personalities (20 Fun, 20 Serious, 5 Adult) plus complete security, ethics, and implementation frameworks. Real-world ROI examples included.

Get OpenClaw Essentials → $19.99

Municipal Water Treatment Facility Incident: Lessons for Every OT Team

Published: June 10, 2026 — 7 min read

A detailed case study of the 2021 municipal water treatment incident where an attacker used TeamViewer with a weak password to attempt changing sodium hydroxide levels from 100 ppm to 11,100 ppm. What went wrong, what should have been in place, and the practical controls every OT operator should implement today.

NERC CIP Compliance Made Practical: A Step-by-Step Approach

Published: June 10, 2026 — 10 min read

NERC CIP doesn't have to be a paperwork nightmare. This guide walks through a pragmatic, risk-based approach to compliance using quantitative methods, clear documentation templates, and real operational examples. Includes how our OT Risk Management Guide directly supports CIP-002 through CIP-011 requirements.

Beyond Threat Intel — Build Better AI Agents

Practical guides and tools from the Cyborama team. Real configs used in production.

AI Agent Mastery Package $9.99 Get Real Answers from AI $4.99