RSS Amplifier

Blog

The Cabreza Independent

Dedicated to the discipline and standards by which critical infrastructure measures itself, while also sitting at the intersection of AI and software development.

cabreza.substack.comSource feed ↗14 posts

Live Last read · last published · next check

Written by

Latest posts

Reachability is the Vulnerability

A Programmatic Take on Water/Wastewater Sector's Challenges

Claude, GPT and the Minnesota attackers all used known bugs and weak logins

Three separate incidents, all of them starting at something exposed and unauthenticated

Model Monogamy Is an OT Problem Too

Enterprise IT is rediscovering the cost of vendor lock-in while operational technology has been paying the tuition for years.

Water Protection Needs Focus & Energy

Recent events in and around water/wastewater critical infrastructure are confusing and concerning. We need to do better.

Cabreza Lodestar: Pre-Launch Announcement

Build CIP cybersecurity discipline and stop bad guys from logging in.

Cabreza: Our CIP Market Positioning

Cybersecurity within Critical Infrastructure Protection is a big opportunity for fundamentals, and discipline.

Choose Your AI Applications Wisely

As the frontier model race continues, that’s precisely where foundation model providers want your attention: the models.

Discipline #1: Rules Before Tools

"If you can't describe what you are doing as a process, you don't know what you're doing."

BREAKING NEWS: CIP ENTERS FREE AGENCY

After two decades with one team, Critical Infrastructure Protection is testing the open market, and the rest of the league is paying attention.

One Advice Gap: Two Tools, Two Very Different Results

Critical infrastructure owners and operators need help, and not just the "what should I do" kind.

The Difference Between Incident & Catastrophe

CISA says adversaries are pre-positioned in US critical infrastructure. Does anyone care?

Boundary Engineering

Building AI systems where trust isn't required

146 Advice Organizations: Which Ones Matter?

The critical infrastructure information landscape is vast. Finding the signal in the noise is a full-time job nobody seems to have time for.

It’s Not 30 Vulnerabilities. It’s One.

The one weakness in AI tools is known. The fix is security hygiene.