Frenos Raises $1.52M for AI-Powered OT Penetration Testing as PLC Attacks Surge Across US Water Systems

Frenos Raises $1.52M for AI-Powered OT Penetration Testing as PLC Attacks Surge Across US Water Systems

August 7, 2026 — The industrial automation sector is confronting a watershed moment in cybersecurity. Days after the FBI and EPA issued a rare joint warning about malicious actors breaching programmable logic controllers (PLCs) across more than 30 municipal water systems in seven states, startup Frenos has closed a $1.52 million seed extension to accelerate what it calls the industry's first AI-powered simulated penetration testing platform built specifically for operational technology (OT) environments.

The timing could not be more urgent. Since July 27, Iranian-affiliated cyber actors have exploited internet-facing Rockwell Automation/Allen-Bradley MicroLogix 1100 and 1400 series PLCs — changing IP addresses, setting unauthorized passwords, and modifying ladder logic in ways that disabled critical shutdown and alarm functions without alerting operators. The attacks underscore a structural vulnerability that has plagued industrial automation for years: traditional IT security tools simply do not work in production environments where availability and process safety are non-negotiable.

🔍 ANALYST INSIGHT

The convergence of three forces — escalating nation-state PLC attacks, regulatory pressure on critical infrastructure operators, and AI lowering the barrier for both attackers and defenders — makes Frenos' SAIRA platform a bellwether for the next generation of OT security architecture. The company's 10x ARR growth since 2025 signals that the market is moving from awareness to procurement.

From IT Penetration Testing to OT-Safe Simulation

Conventional penetration testing tools — think Metasploit or Burp Suite — are designed for IT networks where rebooting a server is an inconvenience. In an industrial setting, probing a PLC that controls a water treatment process, a turbine, or a chemical batch reactor can trigger physical consequences. Frenos' core innovation is an AI agent architecture that simulates adversarial behavior against PLC firmware, ladder logic, and industrial network configurations without risking production disruption.

The platform, branded SAIRA, uses long-context AI models to analyze extensive information about network architecture, device configurations, vulnerability data, and security controls before recommending or executing simulated attack paths. In one customer deployment, SAIRA ingested more than 12,000 OT vulnerability findings — and surfaced just eight that were actually exploitable, dramatically reducing the noise-to-signal ratio that plagues industrial security teams.

The Numbers Behind the Momentum

The seed extension, co-led by Momenta and Exposition Ventures with participation from Riptide Ventures, brings Frenos' total funding to $6.4 million. But the real story is in the operational metrics:

📊 Frenos Growth Metrics (Click to Expand)
  • ARR Growth: Up more than 10x since January 2025; grew 215% in H1 2026 alone
  • Pipeline: Up 2.7x year-over-year
  • Average Deal Size: Up 5x as the company moves upmarket into defense and large critical infrastructure
  • 2026 Bookings: Already quadrupled full-year 2025 figures with five months remaining in the year
  • Total Funding to Date: $6.4 million

The Regulatory Tailwind

The funding arrives amid an intensifying regulatory landscape. The joint advisory AA26-097A — co-signed by the FBI, CISA, NSA, EPA, Department of Energy, and U.S. Cyber Command — explicitly warns that nation-state and advanced persistent threat (APT) actors are actively exploiting internet-facing PLCs across U.S. government services, water systems, and energy infrastructure. The advisory recommends regular OT-specific security assessments — precisely the gap Frenos aims to fill.

Beyond the immediate water-sector crisis, the attackers have demonstrated interest in Siemens S7-1200 series, Schneider Electric Modicon M340, and Allen-Bradley CompactLogix and Micro850 controllers — covering the dominant PLC architectures in global manufacturing and infrastructure.

🛡️ PLC Vendors Targeted in 2026 Water Utility Attacks (Click to Expand)
  • Rockwell Automation/Allen-Bradley: MicroLogix 1100, MicroLogix 1400, CompactLogix, Micro850
  • Siemens: SIMATIC S7-1200 series
  • Schneider Electric: Modicon M340 (BMX P34)

Source: FBI/CISA Joint Advisory AA26-097A, updated July 22, 2026

AI: The Double-Edged Sword

The same AI technology powering Frenos' defensive platform is being weaponized by adversaries. Google's Threat Intelligence Group reported in 2026 the first known zero-day exploit developed using AI, warning that machine learning tools are lowering the barrier for attackers to build sophisticated exploits against industrial targets. This asymmetric threat landscape is driving the OT security market from an estimated $27.4 billion in 2026 toward a projected $58.9 billion by 2031, according to MarketsandMarkets.

📈 MARKET TREND

The broader penetration testing market is projected to grow from $2.72 billion in 2026 to $5.54 billion by 2031 (CAGR 15.29%). The OT-specific segment within this market is poised for even faster expansion as industrial operators shift from reactive patching to proactive, AI-augmented security validation. Frenos' 215% H1 2026 growth rate significantly outpaces the sector average, suggesting first-mover advantage in a category with high barriers to entry.

What This Means for Industrial Automation Professionals

For plant managers, control engineers, and OT security leads, the Frenos announcement — combined with the ongoing PLC exploitation campaign — signals a shift in best practices. The era of air-gapped industrial networks is over. Even unintentionally internet-exposed PLCs are now being scanned and exploited at scale. Key implications include:

⚡ Action Items for OT Security Teams (Click to Expand)
  1. Audit PLC Exposure: Verify that no PLCs — particularly Rockwell MicroLogix, Siemens S7-1200, or Schneider M340 units — are directly accessible from the internet. Use secure gateways and firewalls as recommended by FBI/EPA.
  2. Implement Access Control Lists (ACLs): Restrict communication to only authorized control system devices.
  3. Deploy OT-Specific Security Validation: Traditional IT vulnerability scanners may miss PLC logic modifications. Consider AI-augmented platforms like SAIRA that understand industrial protocols and can safely test without disrupting production.
  4. Enforce Strong Authentication: The water utility breaches exploited default or weak passwords. Rotate credentials and enforce multi-factor authentication where feasible.
  5. Monitor for Ladder Logic Tampering: Several victims only discovered breaches after noticing discrepancies in PLC project files and ladder logic across multiple sites.
❓ FAQ: AI-Powered OT Penetration Testing (Click to Expand)

Q: How does AI-based OT pen testing differ from traditional IT penetration testing?
Traditional tools actively exploit vulnerabilities, which can crash or damage industrial processes. AI-native platforms like SAIRA simulate adversarial behavior — analyzing firmware, logic, and network configurations — without sending disruptive packets to live PLCs.

Q: Which PLC brands does Frenos support?
The platform is developing modules for Rockwell Automation/Allen-Bradley, Siemens SIMATIC, Schneider Electric Modicon, and Mitsubishi Electric MELSEC — covering the four dominant global PLC architectures.

Q: Is OT penetration testing required by regulation?
While not yet universally mandated, the FBI/CISA/EPA joint advisory strongly recommends regular OT-specific assessments. Sector-specific regulations (NERC CIP for energy, AWWA guidelines for water) increasingly reference the need for active security validation in industrial environments.

Frenos is headquartered in Fulton, Maryland. The seed extension round was co-led by Momenta and Exposition Ventures, with participation from Riptide Ventures.

Related Articles

Terug naar blog