“I started Insane Cyber because the sites that need protection most, like remote substations, offshore platforms and air-gapped plants, are exactly where traditional tools can’t reach and specialists can’t be. Claude inside Valkyrie helps close that gap: it works through the evidence and drafts the assessment, so analysts and operators can focus on the judgment calls that keep critical systems running safely. Joining Anthropic’s Critical Infrastructure Defense Program lets us bring what we’ve learned in the field to a broader effort, because securing these environments isn’t something any one company can do alone.”
Dan Gunter, CEO, Insane Cyber
Today we’re proud to share that Insane Cyber joins Anthropic’s Critical Infrastructure Defense Program as a partner. Securing and scaling cybersecurity across hard-to-reach critical infrastructure sites has been our commitment since we started, and we’re excited to be taking this mission to the next level. For our customers, it means Claude is now fused into Valkyrie’s automated analysis across threat hunting, incident response, site assessment and monitoring playbooks turning raw host and network data into findings, with our analysts’ expertise behind every report.
Our Mission: No Site Left Unseen
Our mission is to make sure the people running our most critical assets can see what is happening on every one of their industrial networks and know what to do about it. That sounds simple until you look at how critical infrastructure is actually built. A single utility might run dozens of substations, pump stations, and remote facilities spread across hundreds of miles, many with limited connectivity and nobody from security on site.
That geography creates two problems that feed each other. The first is awareness at scale: most operators can’t see across all of their sites at once, so the smaller and more remote locations quietly become blind spots. The second is turning data into answers — even when captures, configs, and logs exist, they pile up faster than teams can work through them.
Those problems land hardest on utilities, cooperatives, water systems, manufacturers, and data centers with lean teams and spread-out sites. Those are the operators we care most about, because they are often the ones adversaries find easiest to reach.
What We Do About It
We built Valkyrie and Cygnet to take on both problems, starting with getting the data, because getting a cybersecurity expert to a site and getting data out of it are two different challenges. Depending on the site, data reaches Valkyrie in one of three ways: a Cygnet flyaway kit shipped to the site, a virtual machine deployed on existing infrastructure, or a managed cloud deployment. Once Valkyrie or Cygnet is connected, sensors can be left in place to continuously monitor or a packet capture can be taken from a mirror port. Host data can be uploaded or passively monitored over syslog. Persistent sensors are managed together through Valkyrie’s fleet management so operators get awareness across every location instead of one site at a time.
Once the data is in, here’s what Valkyrie actually does with it:
-
- Maps the environment. It identifies the assets on the network, what each one talks to, and dives deep into the industrial operations context, so operators start from an accurate picture rather than last year’s spreadsheet.
-
- Applies our OT heuristics. Protocol-level analysis and detection logic as well as deep enrichment of operational characteristics like historian tags, process tags and PLC behaviors, enhanced from our team’s years of OT forensics and incident response, flags the things that matter, like unexpected remote access paths, engineering commands from unusual sources, or devices talking where they shouldn’t.
-
- Uses Claude to explain and prioritize. Claude works from those evidence-backed findings to connect related issues, explain what they mean for this specific environment, and draft an assessment report, help with incident response, conduct a threat hunt, perform an OT assessment or explore risks in the operational environment.
-
- Keeps an analyst in the loop. Analysts validate the output and add the context only someone who has worked these environments can provide. Our user experience balances AI inference where appropriate, injects a human into the process at critical times, and always keeps track of who does what to maintain integrity of the analysis.
There are plenty of companies adding AI to security products right now. Where we differ is the order of operations. Claude doesn’t stare at raw packets and guess. Our protocol analysis and heuristics joined with our deep operational view produce the findings first, grounded in the customer’s own data, and Claude builds on that operational picture. The heuristic analysis runs where the data lives, including disconnected and air-gapped environments, and everything is designed and checked by analysts who’ve done this work for real.
So how do you know it’s working? We’d point to three things: how long it takes to go from data collected to a report someone can act on, how many of your sites you actually have eyes on, and whether operations, engineering, and leadership can read the same report and agree on what to fix first. Those are the measures our customers care about, and they’re the ones we hold ourselves to.
Operators who want a lighter first step can bring their data and get rapid analysis, and those who want an ongoing partner can add managed services for monitoring, threat hunting, incident response, and assessments.
Where Claude fits
Our core analysis stands on its own, built on protocol-level understanding of industrial networks and heuristics our team has refined over years of real engagements. Claude is what makes that analysis faster and more valuable. It helps turn technical findings into reports people can act on, with a human analyst in the loop the whole way.
Here’s how we’ve used Claude to amplify OT cybersecurity:
-
- Inside Valkyrie. Analysts first choose the workflow they’re running: incident response, threat hunting, site assessments, or tabletop scenario building. In each analyst workbench, analysts are able to view data within the Valkyrie project and generate findings from the data. For every finding, Claude helps explain in plain language: what was observed, why it matters in this particular environment, the specific evidence behind it, and what to do next and how urgently. The same finding can then be framed for whoever is reading it, so an operations manager sees the impact on production, an engineer sees the technical detail, and a CISO sees the risk. If a user spots something wrong, they can directly edit in the workspace or interact with an agent to make the changes. As changes can cascade through a given work product, the workflow automatically adapts.
-
- In our services engagements. When our team is running an assessment or supporting an incident, Claude-enhanced Valkyrie can help them move through large volumes of data and documentation faster, so more of their time goes to judgment calls instead of paperwork.
What This Could Look Like
Picture a manufacturer with a plant three states away from its security team. Getting someone on site means travel, working around production schedules, and an MSSP quote that never makes it past budget review. Instead, a plant engineer captures a few hours of host and network traffic and the security team uploads the PCAP into Valkyrie. The automated assessment report comes back in minutes. One finding stands out: a vendor remote access connection running straight from the internet to an engineering workstation on the controller network, skipping the DMZ entirely, and that same workstation sending Modbus write commands to PLCs on the production line. Claude helps turn those findings into a report explaining why it matters and what to fix first, so the plant manager and the security lead are reading the same page. Nobody needs to get on a plane, and the plant finally has a clear picture of its own network.
Why This Program Matters To Us
Securing critical infrastructure is our commitment, and it isn’t something any one company can do alone. The technology needs to be built with the stakes of these environments in mind, where a bad recommendation can result in dangerous consequences. That takes partners who understand it. Joining this program as a member puts us in the room with people who feel the same way, and it gives us a way to bring what we’ve learned in the field to a broader effort.
For our customers, the promise is simple to say and harder to deliver: more operators getting expert-level visibility into their networks, sooner, at a cost and pace that makes sense for them.
If you run or protect an industrial environment and want to see what Valkyrie’s automated analysis finds in your data, we’d love to talk. You can reach us at [email protected], and you can read more about the program in Anthropic’s announcement link.

