# The OT Security Industry Is Finally Asking the Right Question — and One Startup Is Getting Paid to Answer It


Most vulnerability assessments in operational technology tell you what's broken. They hand you a list — CVEs, misconfigurations, unpatched firmware — and leave you holding a spreadsheet while attackers map your network like a chess board. Frenos thinks that's the wrong product.


The Austin-based startup announced Monday a $1.52 million extension to its seed round, bringing total funding to $6.4 million. The round was led by Momenta and Exposition Ventures, with Riptide Ventures participating. Small money by Silicon Valley standards, but in OT security — where the sales cycles are long, procurement is byzantine, and the customers are utilities, manufacturers, and water treatment facilities — it's enough to prove something is working.


## Why You Can't Just Scan a Power Plant


The fundamental problem with OT security testing has always been that the environment is hostile to testing itself. IT security teams run continuous vulnerability scans, push scanners into CI/CD pipelines, schedule penetration tests that can safely break things because nothing breaks permanently. Industrial control systems don't work that way.


A misconfigured network scan sent at the wrong moment to a programmable logic controller can freeze a production line. A packet that would bounce harmlessly off an enterprise firewall can cause a SCADA system to trip an emergency shutdown. The consequence of getting pen testing wrong isn't a failed authentication log — it's tons of steel in the wrong place, or a chemical process running out of spec.


This is why OT security assessments have historically been expensive consulting engagements: you send a team of specialists onsite, they move carefully, they document what they can observe without touching anything dangerous, and four months later you get a report that's already partially outdated. The alternative — doing nothing — is exactly what most industrial operators chose until ransomware operators started targeting them specifically.


Frenos is attacking that gap with a digital twin approach: build a simulated replica of the customer's OT network, then run SAIRA — their AI reasoning system — to conduct fully automated penetration tests against the twin rather than the live environment. No scanners touching production assets. No downtime window required. No hardware shipped to the site.


## What Robert M. Lee's Advisory Board Seat Actually Means


The endorsement that matters here isn't from an investor. It's from Robert M. Lee, co-founder and CEO of Dragos — arguably the most credible voice in ICS/SCADA security today. Lee didn't just invest; he joined the advisory board. His quote in the announcement is worth reading carefully:


*"Most OT security testing today tells you what's vulnerable, not what's defensible. The question that matters is what path takes an attacker from an exposed HMI to a process they can actually disrupt."*


That framing is the entire thesis. The industry has been optimizing for the wrong metric — vulnerability count — while sophisticated adversaries (state-sponsored groups like Volt Typhoon, Sandworm, and others who have spent years pre-positioning inside critical infrastructure) are thinking in attack paths, not CVEs. They want to know if they can get from an internet-facing engineering workstation to the historian server to the DCS without triggering alarms. A traditional assessment doesn't answer that.


Lee's involvement also signals something about where Dragos itself sees the market moving. Dragos built its business on detection — knowing when an adversary is inside your OT network. Frenos is in the validation layer: knowing whether an adversary could get there, and how, before they try. These are complementary, and the fact that the dominant ICS security vendor's founder is quietly backing a startup doing pre-breach simulation work suggests he sees that layer as genuinely underbuilt.


## SAIRA Co-Work and the AI Reasoning Angle


Alongside the funding announcement, Frenos launched SAIRA Co-Work — a new AI reasoning agent positioned as an investigation partner during complex security assessments. The product name is an awkward portmanteau, but the concept is sound: when analysts are working through a multi-hop attack path scenario, having an AI that can surface evidence, correlate findings, and structure hypotheses against a digital twin environment is meaningfully different from a search bar and a wiki.


The AI angle here is specific rather than decorative. This isn't "we use AI to prioritize alerts" — the actual work the model is doing (chaining exploits, validating lateral movement paths, simulating what an attacker's next move would be given the network topology) is the kind of structured reasoning that large language models have gotten genuinely better at. Whether SAIRA's implementation delivers on that is something customers will have to validate, but the architecture isn't theater.


## HackWire Analysis


Six-point-four million dollars total is a tight budget for a company trying to sell into critical infrastructure, where procurement processes can run 18 months and compliance requirements vary by sector, jurisdiction, and whether your customer just had an incident. The $1.52M extension rather than a larger round suggests Frenos is either being deliberately capital-efficient, or the Series A market for OT security hasn't fully thawed.


What makes this funding announcement worth more attention than it's getting is what it implies about the competitive landscape. The major OT security platforms — Dragos, Claroty, Nozomi — have all built excellent detection and monitoring tooling. None of them have made continuous, production-safe pen testing their core product. That gap is real, and the industrial sector is increasingly under pressure to demonstrate it's doing more than passive monitoring after the CISA critical infrastructure guidance that followed the Volt Typhoon disclosures.


The timing is also significant: the Biden-era executive orders on critical infrastructure cybersecurity have been partially paused under the current administration's review, but the threat actors haven't paused with them. Utilities and manufacturers sitting on monitoring-only security programs are going to face hard questions from their boards — and from their cyber insurers — about whether they actually know what an attacker could reach. Continuous automated validation without production risk is a compelling answer to that question.


The pattern here fits a broader post-Dragos maturation of OT security: the market has moved from "do you know what's on your network" to "do you know how it can be attacked." Frenos is one of the first pure-play companies betting that enterprises will pay for that answer as a continuous service rather than a one-time audit.


The real test is whether the digital twin fidelity is good enough. A simulation that doesn't accurately model how a specific vendor's PLC communicates on a legacy protocol will give you false confidence, which is arguably worse than no test at all. Frenos will need to prove their twin-building process works against the actual equipment sprawl inside real industrial facilities — not just clean lab environments.


— HackWire Editorial


---


## Related Coverage


  • Read more in our [Vulnerabilities](https://www.hackwire.news/category/vulnerabilities) coverage
  • Cross-reference with [Breaches](https://www.hackwire.news/category/breaches) and [Malware](https://www.hackwire.news/category/malware)
  • Stay current via the [HackWire homepage](https://www.hackwire.news/)