// quantropic.ai · global · singapore · germany · ai resilience & advisory
Most firms sell the roadmap. We build what survives contact with reality - governed, secured, and operational in environments where failure has real consequences.
The market · vs · Quantropic
When we founded Quantropic, we built it around AI - its risks, its governance, its future. What we didn't lead with is that AI wasn't where we started. Long before "Industrial AI" became a trend, our roots were in OT/ICS and IoT security - assessing plants, hardening networks, and securing connected devices for more than 30 years.
Today, industrial AI is bringing those two worlds back together. As enterprises connect AI to the plant floor, the edge, and the field, decades of OT/IoT security experience suddenly matter again. So we're bringing it back into view - not as something new, but as the foundation we've stood on all along.
We still offer IACS Security Assessments and Architecture Reviews. But beside this, we help OT/IoT companies close the gap to the new AI universe:
// ADVERSARIAL AI RESEARCH & TOOLING
HADES - Hostile AI Detection & Exploitation System is our
autonomous adversarial assessment framework - built on the idea of a GAN,
a Generative Adversarial Network Attacker. Commercial-grade offensive tooling
built specifically for AI systems - Agents, Bots and Models. Not a whitepaper. Not a checklist.
When you want to find out if your latest deployment is secure, HADES is what runs against it.
Claude has Mythos - we have H.A.D.E.S.
// THE QUANTROPIC MODEL
A curated group of senior specialists - assembled around your specific challenge, not around our headcount targets.
Client identities are protected under NDA. The sectors, regulations, and findings below are real - the names are not disclosed.
Context An AI-assisted process-optimisation layer, live across three facilities, had passed a large consultancy's transformation programme - glossy roadmap, governance documentation, board sign-off. None of it had ever been adversarially tested. The previous consultancy had reviewed the architecture document; they had tested nothing. What we found The system prompt governing reactor-parameter recommendations could be overridden in eleven steps - demonstrated live in the staging environment in under four hours, not argued hypothetically. Outcome AI systems were pulled into NIS2 incident scope, remediation was prioritised by exposure, and adversarial testing was written into vendor acceptance criteria.
Context An AI readiness programme had stalled - three vendors, three assessments, three different scores, zero consensus on what to fix first. Leadership had stopped trusting the process entirely. What we found Ignoring the existing reports and starting from the attack surface outward, the AI governance gaps mapped directly to two open insurance claims that had never been connected to AI system behaviour. That connection alone justified the engagement inside the first week. Outcome Findings were prioritised against real financial exposure rather than abstract risk scores, and AI inference components were brought into the ISO 21434 cyber-risk scope.
Context Six weeks out from an FDA inspection covering an AI-assisted batch-release system, the internal team was confident the deployment was sound. What we found LLM-generated deviation reports could be manipulated to suppress anomaly flags - not by an external attacker, but by a misconfigured upstream data pipeline feeding adversarial patterns into the context window. An architecture-level problem nobody had looked for, because nobody had looked from that angle. Outcome The inspection was rescheduled - the correct decision - and the exposure was closed before it ever reached a regulator.
// THE PRACTITIONER
The specialisation in AI security began in 2018 - before AI became a mainstream consulting discipline.
This background brings established security expertise to the assessment, governance, and protection
of enterprise AI systems.
Quantropic's founder is a senior security expert with a military background in the assessment of
multilevel, military-grade security systems, and has developed his own methodology for critical
infrastructure risk assessments. His work spans engagements across the EU, United States, China,
and South America, bringing a genuinely global perspective to enterprise AI security and governance.
He has also published and spoken on AI security, OT/ICS risk, and enterprise AI governance for
professional audiences worldwide.
"The firms that will struggle most with AI security are the ones who think it's just an extension of what they already do. It isn't. It requires a fundamentally different mental model - one built from understanding how these systems fail, not how they're sold."
// LADY D. - DIRECTOR
Daphne Sim is a Director at Quantropic with long-standing experience in AI application and enterprise sales across the Asia-Pacific region. She brings deep expertise in business development, go-to-market strategy, and strategic partnerships, with a track record of driving B2B revenue and profit growth for corporate AI ventures. Board and director certified, she also serves as an advocate for partnership-led growth, helping enterprises translate AI capability into commercial outcomes.
"The gap between AI capability and commercial outcome is rarely a technical one. Most AI ventures stall not because the technology fails, but because the business model, the partnerships, and the go-to-market motion around it were never built. My work is making sure that capability actually translates into value the enterprise can measure."
// GET IN TOUCH
A scoped, deliverable-defined assessment. Specific findings. No open-ended retainer. You'll know where your AI programme stands within three weeks.