Kai HackbarthA few mandates open · available now

Independent advisor and interim manager for industrial AI and IoT.

An agent is only as good as the context it can reach. I advise on both halves — the agentic-AI decision and the industrial IoT foundation it runs on — vendor-neutral, and I never bid on the build. Plus GTM engineering for deep-tech that stalls in enterprise selling. Ex-Bosch, 25 years.

Agentic AI and the industrial IoT foundation it runs on — advised vendor-neutral. Plus GTM engineering for industrial deep-tech. Ex-Bosch, 25 years.

The evidenceThree numbers from the work. Each one links to where it comes from.

Three buyer profiles, one common ground.

All of them face the same task: turning connected products and AI into a defensible business model — with real revenue, clear costs, and a team that can sustain it.

Industrial mid-cap & enterprise

Upper industrial mid-market to large enterprise

Boards and supervisory boards of industrial manufacturers turning connected products and AI into measurable revenue — for an operator who moves comfortably between the boardroom and engineering.

Built a commercial platform business from acquired middleware and carried operational accountability for FOTA mandates at OEM scale.

Interim 3–9 moStrategy mandateBoard advisorBook a 30-min call

Industrial-tech scale-ups

Series B / C · IoT, AIoT, B2B SaaS

Founder teams that have the technology — but stall in enterprise selling. A GTM operator who has closed these accounts himself, not another tech advisor.

A career spent selling industrial platforms across industries — the playbook for those accounts, a repeatable pre-sales motion, and pricing discipline in enterprise selling.

Interim GTM HeadGTM auditAdvisoryBook a 30-min call

Private equity & growth investors

Industrial-tech portfolio · pre- and post-Series B/C

Partners who need to validate the commercial or technical side of an industrial-tech investment — pre-investment audit or post-investment value creation inside a portfolio company.

Commercial and tech DD with operator depth; interim mandates inside portfolio companies stuck in enterprise selling; selective access to industrial OEM and standards-body relationships.

GTM auditTech DDInterim value creationBook a 30-min call
Before any signature

Three steps before any contract is signed.

Trust is not built in a pitch. It is built when both sides know how the engagement will be measured — before money changes hands.

01

Two confidential conversations

A sounding, not a sales pitch. You describe the situation; I listen and ask the awkward questions.

02

A written memorandum

Feasibility, timing, cost envelope — in writing. If the assessment does not hold up, the engagement ends here. No invoice.

03

A fixed-fee audit as entry point

If you prefer, start with a clearly scoped fixed-fee audit instead of a long-running mandate — roadmap, architecture, or AI readiness.

Specified in 2000, missing from too many products

Week 36 · 6 Sept 2026NEW
CISA
28 May 2026
ICS Advisory ICSA-26-148-08: XCharge C6

The piece of the week, because here is something sitting in a shipped product that usually stays inside architecture discussions. CISA rates the XCharge C6 charging point at CVSS 9.8 (v3.1) and classifies the flaw as "Download of Code Without Integrity Check": "Because cryptographic signatures are not verified, an attacker with the ability to interfere with or impersonate the management channel could cause the device to install an unauthorized firmware package." What actually happens inside the device is described by SaiFlow, whose researchers reported it (saiflow.com, "RCE by Design"): the only validation is an MD5 sum the sender supplies alongside the firmware, and a script inside the package then runs with root privileges. None of that is in the advisory: CISA records only that cryptographic signatures are not verified. Anyone attributing the MD5 detail to CISA is citing the wrong source. The obvious reflex is the wrong one. A stronger hash changes nothing, because the sender computes that too. What is missing is a key. And the same advisory carries a third flaw almost nobody quotes: a service reachable through the charging connector accepts a default administrative credential. Not remotely: that one needs the cable in your hand. XCharge says it has deployed the correction to all affected chargers.

Fox Business
25 May 2026
Hyundai recalls over 421,000 vehicles to fix software bug causing unexpected braking

The case where the path does not reach this control unit. More than 421,000 Tucson and Santa Cruz vehicles from model years 2025 and 2026: the front camera software shows increased sensitivity to objects ahead in certain driving scenarios, so the collision avoidance system engages prematurely. 376 reports between October 2024 and April 2026, four crashes in which the Hyundai was rear-ended by a closely following vehicle, and four alleged injuries. NHTSA filing 26V316 gives the remedy as "Remedy Type: Software", a file and nothing else. Five weeks later Hyundai filed a second recall on the same model years, and that one reads "Remedy Type: Software, Software OTA". So the cars can be reached. This control unit was not on the path. Every owner is to be notified from 17 July and to drive to a dealer, where a technician reflashes the camera. There are good reasons to keep a braking-relevant camera in a workshop: calibration, a work order and a functional check per vehicle, and the blast radius of a variant-matching error at fleet speed. Those reasons are simply not weighed at the recall. They are settled years earlier, in the architecture and in a sourcing contract.

Cybersecurity Dive
31 Jul 2026
US authorities see “significant escalation” in attacks on water system devices

The case where nobody knows which devices their own remote path reaches. On 30 July the FBI and the EPA issued a warning, and CISA published its own alert the same day. The targets were Rockwell Allen-Bradley controllers, the MicroLogix 1100 and 1400 series; the FBI notes explicitly that it has only observed this behaviour with those. The linked report also names Schneider Electric and Siemens devices; those belong to a separate advisory from April. It began over the weekend of 26 July in Minnesota, and utilities in at least seven states then reported incidents. The actors changed passwords and IP addresses, and operators lost monitoring and control of their own plants. One utility also reported modified PLC project files, noticed as ladder logic discrepancies across several sites (FBI announcement I-073026-PSA). That is the only unauthorised change to code on a device anywhere in this week, and it did not arrive over an update path. It arrived over an open port. Boil-water notices, manual operation, flooding, pressure loss. The sentence I wrote down is in CISA’s internet exposure guidance from August, where the agency counts more than a hundred internet-exposed systems across the water and wastewater sector: the attack surface includes "cellular modems installed by operators, vendors, or system integrators that may not be documented or included in routine attack surface scans". Build a remote path without knowing which modems are in the field, and you have not built a maintenance interface. You have a door that is on nobody’s list.

The full list with my commentary

What collaborators say.

Request referencesAll 29 recommendations on LinkedIn

Let’s have a conversation.

Whether you have a concrete IoT or AI mandate in mind or want a strategic read on where you stand, the introductory call is confidential and non-binding.

Email
kai@kaihackbarth.com
Phone · used discreetly
+49 176 4515 1099
Location
Hagener Str. 67
58285 Gevelsberg · DE
also Athens · EU-wide
linkedin.com/in/kaihackbarth