Lares

Empowering Organizations to Maximize Their Security Potential

Building an AI Governance Program from Zero

Building an AI Governance Program from Zero 2560 853 Andrew Heller
Most AI governance programs start with a policy and a false sense of coverage. Here is how to build one from zero, in five explicit, testable decisions. read more

How Security Assessments Are Priced & How to Run a Better RFP

How Security Assessments Are Priced & How to Run a Better RFP 1200 630 Andrew Heller
Security assessment pricing follows scope, not quality. Learn how vendors price tests and how to write an RFP that gets you real coverage. read more

Technical Analysis of the Rockstar Games Compromises: Exploit Chaining and Zero Trust Failures (2018–2026)

Technical Analysis of the Rockstar Games Compromises: Exploit Chaining and Zero Trust Failures (2018–2026) 1672 941 Andrew Heller
What the Rockstar Games security incidents teach defenders about phishing-resistant MFA, SaaS token risk, internal segmentation, and data exfiltration detection. read more

Minnesota Water Attacks and the Predictable Reality

Minnesota Water Attacks and the Predictable Reality 1200 630 Andrew Heller
How possible Iran-linked actors exploited exposed PLCs in the 2026 Minnesota water attacks. MITRE ATT&CK mapping, risk matrix, and OT security lessons from Lares. read more

Part 3: The Collapse of the Testing Boundary: Why Purple Teaming is Mission-Critical

Part 3: The Collapse of the Testing Boundary: Why Purple Teaming is Mission-Critical 1672 941 Andrew Heller
Point-in-time pen tests can’t catch AI agents that fail in minutes. See why continuous purple teaming is the only defense — and how to build the budget case. read more

Part 2: The Collapse of the Testing Boundary: Anthropic and the Behavioral Threat

Part 2: The Collapse of the Testing Boundary: Anthropic and the Behavioral Threat 1672 941 Andrew Heller
Claude models attacked real infrastructure while believing they were in a simulation. Anthropic’s retrospective reveals a new AI risk class beyond alignment. read more

Part 1: The Collapse of the Testing Boundary: Deconstructing the OpenAI Agent Breakout

Part 1: The Collapse of the Testing Boundary: Deconstructing the OpenAI Agent Breakout 1672 941 Andrew Heller
OpenAI’s frontier model escaped its sandbox and breached Hugging Face’s cluster in under 13 hours. See the full kill chain mapped to MITRE ATT&CK and ATLAS. read more

The Importance of OT Assessments in Critical Infrastructure

The Importance of OT Assessments in Critical Infrastructure 1200 630 Lares Labs
Why testing operational technology (OT) and ICS/SCADA systems is an operational imperative for securing critical infrastructure beyond compliance. read more

Social Profiling – OSINT for Red/Blue

Social Profiling – OSINT for Red/Blue 1200 630 Lares Labs

This post will give you an overview of key things to look for from an offensive and defensive perspective to look out for employees, interns, and contractors over sharing information…

read more

Multiple Paths to Compromise An Environment

Multiple Paths to Compromise An Environment 1200 630 Lares Labs
Attackers rarely need zero-days. Weak passwords, poor data governance, and flat networks give them multiple paths to compromise your environment. Learn how these weaknesses combine into real attack paths and how to shut them down. read more

Where There is Unity, There is Victory

[Ubi concordia, ibi victoria]

– Publius Syrus

Contact Lares Consulting logo (image)

Continuous defensive improvement through adversarial simulation and collaboration.

Email Us

©2025 Lares, a Damovo Company | All rights reserved.