Real-world analysis, quantitative methods, and practical guidance for OT/ICS defenders • Powered by Lot-Squatch Intelligence
Your Own Technical Advisory Board — Running Locally
Published: August 3, 2026 — ~8 min read
Most executives use AI by pasting sensitive material into a chat window. There's a better pattern: run a local model with specialized agents that act like a standing technical advisory board. Confidentiality by design. Multiple specialized viewpoints. No data leaving the building.
Most public ICS exposure numbers mix everything together — cloud test systems, scanners, honeypots, devices that only send status. The real risk is smaller: devices that accept write commands and can change state. Modbus function codes 5, 6, 15, 16. S7 writes. CIP tag writes. That's the surface that actually matters for operational risk.
Passive Sweep Analysis: Industrial Infrastructure Exposure and Defensive Baselines
Published: July 2026 — 5 min read
A passive, non-intrusive scan of a regional US area identified 760 internet-exposed industrial devices using unauthenticated protocols with direct read/write capabilities. 44% on public cellular networks. Defensive baseline analysis — no active scanning performed.
Agentic AI: How to Scale Corporate Threat Hunting on a Budget
Published: July 24, 2026 — 8 min read
Corporate security teams are stuck in a brutal loop. Threat volume keeps climbing, but skilled threat hunters are scarce. Agentic AI changes the game — narrow the field, set guardrails, and one analyst matches the output of a team.
Entirely auditable. The engineer pulls raw telemetry values and re-verifies every alert against documented baselines, weights, and thresholds — no neural network weight matrices, no AI explanation tools. Residual energy, Shannon entropy deviation, and a fixed decision function. Transparent, deterministic, and closed-form.
The Economics of Industrial Sabotage: A Primer on Target Selection and Market-Driven Motivation
Published: July 19, 2026 — 10 min read
The Fairlife ransomware attack proves food and agriculture are active, high-priority targets. This primer examines how sophisticated actors identify supply chain choke points for maximum economic leverage, and how disruption can be monetized through financial markets — short selling, commodity arbitrage, and access brokering — beyond traditional ransomware demands. Includes a cascading-collapse scenario anchored to the JBS 2021 attack, where 20% of U.S. beef production was halted and futures moved measurably within hours.
Mitigating Command Paths from Compromised Vendor Cloud: The Outbound Telemetry Risk
Published: July 17, 2026 — 8 min read
OEM telemetry creates a pre-authenticated return path into OT environments. When vendor clouds are compromised, adversaries can reverse the telemetry stream to push commands into the facility. This paper covers the 4-layer mitigation framework: micro-segmentation, continuous egress monitoring, contractual governance with SBOM requirements, and telemetry-specific incident response.
The KFC Effect: Why Threat Intelligence Needs a Dedup Engine
Published: July 16, 2026 — 4 min read
Advisory publication triggers follow-up media coverage. Scrapers pick up follow-ups. Detectors flag them as new surges. This self-reinforcing loop is the KFC Effect — and it's inflating threat intelligence pipelines. Real data from our 90-day feed shows 5 follow-up articles for every 32 new advisories in the last 12 hours alone.
A low-volume, targeted reconnaissance approach applied to legacy platforms in transportation and maritime corridors. Narrow geographic and protocol-based queries surface relevant exposures with useful signal quality. Includes defensive guidance on segmentation, firewall controls, port translation, and lightweight monitoring for operators.
JadePuffer: The First AI-Driven Ransomware — Should We Be Worried?
Published: July 7, 2026 — 9 min read
JadePuffer became the first documented ransomware operation run entirely by an autonomous AI agent — no human at the keyboard, no pre-written exploit chain. The agent found vulnerabilities, adapted to failures, moved laterally, and encrypted a database in real time. Should defenders panic? Here's what the research says, what's actually new (and what isn't), and concrete defensive guidance for OT/ICS teams facing agentic threats.
The 5-Step AI Productivity Loop That Turns ChatGPT Into a Real Colleague
Published: June 21, 2026 — 8 min read
Most people use AI like a fortune teller. This 5-step loop — DISCOVER, PLAN, EXECUTE, VERIFY, ITERATE — turns it into a real colleague. With 7 iterative guardrails including the 8-iteration limit and zero tolerance for simulated success. Built from hundreds of hours of real production work.
The AI Agent Honesty Test: Why Sycophantic Agents Are Your Next Security Risk
Published: June 20, 2026 — 10 min read
Most AI agents are trained to agree with you. We built a self-contained 10-test honesty framework that exposes sycophancy, hallucination, and blind agreement before deployment. Results: our baseline model scored 93.6% (DEPLOY-READY). The only weakness: vague on fabricated topics. Full breakdown inside.
We recreated the greatest strategic debate in military history using five AI agents — Eisenhower, Montgomery, Patton, Rommel, and a time-traveling AI analyst — tearing apart the D-Day invasion plan. The roasts were brutal. The insights were real. And one AI general wanted to skip France entirely and invade Norway instead.
Glomz: AI Agent Bloodsport Is Training the Defenders of Tomorrow
Published: June 12, 2026 — 8 min read
AI agents are fighting each other in a 24/7 coding arena called Glomz. 43 agents, 80+ solutions, 500+ peer reviews. Here's how adversarial AI competition is training the next generation of automated security tools — and what it means for OT/ICS defense, vulnerability discovery, and red team automation.
The OT Risk Measurement Gap: From Qualitative Guesses to Quantitative Dollars
Published: June 10, 2026 — 8 min read
If you manage OT security, you've probably sat in the meeting where someone says the risk is "high" with no supporting numbers. This article explains why qualitative risk assessment fails in OT environments and how the quantitative FAIR-for-OT methodology we developed turns vague feelings into boardroom-ready dollar values.
Includes real examples (firewall failure = $1.747M), compliance mapping for NERC CIP / ISA/IEC 62443 / NIST CSF 2.0, and details on the Excel-based calculator included in the guide.
Unauthorized Remote Access: The #1 Attack Vector in OT Networks
Published: June 10, 2026 — 11 min read
From the municipal water treatment facility incident to Colonial Pipeline and beyond — remote access remains the single biggest vulnerability in industrial environments. This deep technical and operational analysis covers the Remote Access Security Hierarchy (Basic → Controlled → Zero-Trust), practical steps you can take this week, and what we're building in the upcoming OT Remote Access Playbook.
Why Your AI Assistant Needs Professional Personalities (OpenClaw Essentials Review)
Published: June 10, 2026 — 9 min read
Most teams waste 15–25 hours configuring AI behavior through brittle prompts. OpenClaw Essentials delivers 45 professionally engineered personalities (20 Fun, 20 Serious, 5 Adult) plus complete security, ethics, and implementation frameworks. Real-world ROI examples included.
Municipal Water Treatment Facility Incident: Lessons for Every OT Team
Published: June 10, 2026 — 7 min read
A detailed case study of the 2021 municipal water treatment incident where an attacker used TeamViewer with a weak password to attempt changing sodium hydroxide levels from 100 ppm to 11,100 ppm. What went wrong, what should have been in place, and the practical controls every OT operator should implement today.
NERC CIP Compliance Made Practical: A Step-by-Step Approach
Published: June 10, 2026 — 10 min read
NERC CIP doesn't have to be a paperwork nightmare. This guide walks through a pragmatic, risk-based approach to compliance using quantitative methods, clear documentation templates, and real operational examples. Includes how our OT Risk Management Guide directly supports CIP-002 through CIP-011 requirements.
Beyond Threat Intel — Build Better AI Agents
Practical guides and tools from the Cyborama team. Real configs used in production.