Advice to Action Gap
Whenever a new cybersecurity threat to US Critical Infrastructure (CI) emerges, well written advisories come out.
From a very recent example of IRGC threat actors exploiting PLCs, the Key Actions are:
Remove PLCs from the internet
Query logs for IOCs
Check other logs for suspicious traffic on specific ports
Place controller physical mode switches into run and
Contact authoring agencies for guidance.
But do the “Target Rich, Cyber Poor” US water and energy sector organizations respond and do all of this? How? Who puts the key actions into place? Using what? When?
There is nothing wrong with the guidance. It is rich, sector-specific and accurate.
But it is also practically challenging, if not impossible for most. Should we do it? Who makes the call? Do we need to?
Similarly, when the Water-ISAC put out an incredible 12 Cybersecurity Fundamentals guide in 2023, how do the fundamentals get built, implemented and maintained within a water utility?
(A few more solid resource examples for good measure: CISA, FBI & EPA Water IR Roles & Responsibilities, AWWA Cybersecurity Risk Management, CISA & FEMA Planning Considerations for Cyber Incidents)
So again, GREAT information. YES!
But is the rubber meeting the road?
Do the utilities have the remit and resourcing to make this happen?
How many hours will it take, can it work and will it keep working?
Current State
We’re almost halfway through 2026 and to build best practices, most utilities are:
figuring it out (cheers to you!)
outsourcing (if they can afford it)
using awfully low bar templates (shelfware)
doing nothing (back to the former)
There are plenty of best-in-class tools available for detection and response. I’m a strong believer in “Rules Before Tools” but still, to detect adversaries breaking in, they do their jobs well.
What the highly passionate and dedicated folks within CI owners and operators also need is a way to:
piece together what they have
manage what they know
learn what they don’t know
access information they need
action information
Cybersecurity isn’t always shiny. Often, the biggest impacts are laying somewhere in the trenches that nobody wants to touch.
We’re bridging those gaps and helping critical infrastructure (CI) owners and operators stop bad guys from logging in.
Introducing Lodestar
On Friday, 19-Jun-26 we’re releasing Cabreza Lodestar for free.
It’s the Free tier of a modular software platform we’ve been moving towards for the past year.
Lodestar lets a utility owner or operator, regardless of expertise or budget, access a centralized, unbiased data lake of cybersecurity knowledge, track emerging topics, model their business and processes, and author and manage procedure and policy content within hours, on their own.
Upload the Water ISAC 12 Cybersecurity Fundamentals and generate a plan for Incident Response
Add the FEMA Roles & Responsibilities guide, and make a new version
Turn the plan into a technical procedure written for the SCADA team
Take the plan and procedure and draft a memo for leadership
Keep going
And all based on the utility’s specific business, operations and technology
Why Lodestar is Free
We’re releasing Lodestar free for two reasons:
When LLM’s hit the market heavily more than a year ago, we saw this as a fantastic use-case and still believe that to be the case today. But after making the content generation so darn (sometimes surprisingly) good, we noticed the AI chatbot market raised expectations. So we turned our focus to the data, enrichment and use-case driven functionality on top.
No shame, we can offer Lodestar Free because it’s subsidized by paid modules and helps us sleep better at night knowing we’re putting fundamental capabilities into the hands of utility owners and operators who need it most.
Sign up, use it, give us your feedback and share it. You don’t have to know us or Cabreza to know that some CI sectors need support and we’re releasing Lodestar free for them.
If you can help but want to get to know us first, shoot us a message. We always make time for new relationships. If you want to read more about this new chapter for Cabreza, read this.
Protecting critical infrastructure takes more than just a strong defense. Bad guys aren’t just breaking in, they’re logging in. Let’s support the great people who supply the services our civilization relies on.
Best,
Jason & Marcello | Co-Founders | Cabreza, Inc.



