Frenos Raises $1.52 Million More to Test Factory and Power-Grid Security Without Touching the Real Thing

The startup runs fake cyberattacks inside a virtual copy of your industrial network, so it can find the dangerous paths before real criminals do.

ThreatVectr Newsdesk· 4 min read
Photoreal news-editorial style, 16:9 framing, edge-to-edge composition
Share

Key points

  • Frenos, an AI-focused industrial cybersecurity startup founded in 2023, raised $1.52 million in a seed funding extension, bringing its total funding to $6.4 million.
  • The round was led by Momenta and Exposition Ventures, with Riptide Ventures also taking part.
  • Frenos builds a virtual copy of a customer's industrial network and runs fully simulated break-in attempts inside it, with no risk to real equipment.
  • The company also launched SAIRA Co-Work, an AI reasoning tool designed to guide security teams through complex investigations.
  • New funding will go toward expanding customer support staff and growing the AI research team.

Most of us interact with computer security through the world of laptops, apps, and stolen passwords. Industrial security is a different beast. The systems running water treatment plants, power grids, oil pipelines, and factory floors, known collectively as operational technology (OT), were built to run machines, not to defend against hackers. Testing them for weaknesses the traditional way, by poking at them the way an attacker would, risks shutting down the very equipment keeping the lights on.

Fresnos, a US-based startup, wants to solve that problem without anyone ever unplugging a turbine.

How does Frenos actually test industrial systems safely?

Fresnos builds a digital twin, meaning a detailed virtual replica of a customer's industrial network, and then uses an AI system called SAIRA to run simulated penetration tests (staged break-in attempts) entirely inside that copy. No real equipment is touched. The platform maps out the routes an attacker could take through the network, chains together weaknesses the way a real criminal would, and ranks which risks matter most.

According to the company, this cuts assessment time from weeks down to minutes, requires no extra hardware, and carries no risk of disrupting production.

Robert M. Lee, co-founder and chief executive of industrial cybersecurity firm Dragos and a member of the Frenos advisory board, put the core problem plainly: "Most OT security testing today tells you what's vulnerable, not what's defensible. The question that matters is what path takes an attacker from an exposed HMI to a process they can actually disrupt, and almost nobody is testing for that."

An HMI, or human-machine interface, is the screen a factory operator uses to control physical equipment. Getting from a hacked HMI to disrupting a production line is exactly the kind of attack chain Frenos claims to map.

What is the new money for?

The $1.52 million extension, first reported by SecurityWeek, was led by Momenta and Exposition Ventures, with Riptide Ventures joining in. Total funding now stands at $6.4 million since the company was founded in 2023.

Fresnos plans to use the cash to hire customer success staff and push forward on AI research. Alongside the funding announcement, the company launched SAIRA Co-Work, a new AI reasoning tool that helps security investigators work through complex incidents by surfacing evidence and suggesting next steps.

Round detail Figure
Extension amount $1.52 million
Total raised to date $6.4 million
Year founded 2023
Lead investors Momenta, Exposition Ventures
Additional investor Riptide Ventures

Should people who work in factories or utilities be worried?

The funding round itself changes nothing about anyone's immediate safety. What it signals is that investors see a genuine gap: industrial facilities are attractive targets, and the tools to safely audit their defenses are still catching up.

If you work at a plant or utility, the practical takeaway is straightforward. Ask whether your organization runs any kind of regular security assessment on its control systems. Many do not. Awareness of what an attacker's path through your network actually looks like is the first step toward blocking it.

Common questions

What makes industrial cybersecurity different from regular IT security?

Industrial systems control physical processes like pumps, valves, and generators. Shutting one down to test its security is not an option the way rebooting a laptop is, so the tools used have to be much more careful.

Is SAIRA a replacement for human security analysts?

No. The Co-Work branding is deliberate: the tool surfaces evidence and reasoning to support analysts during an investigation rather than replacing their judgment.

© 2026 Threat Vectr