Agonist / Blog Platform How it works Blog
EN TR
Funding Note

Frenos's Seed Extension Bets on AI for OT Penetration Testing

Frenos raised $1.52 million to grow an AI-native OT security platform built on simulated penetration testing — a bet on solving pentesting's oldest OT constraint: you can't touch the live system.

August 4, 2026 5 min read OT Threat Intelligence
EN TR

Frenos closed a $1.52 million seed extension, led by industrial investors Momenta, Exposition, and others, to grow what it calls an AI-native OT security platform built around simulated penetration testing. It’s a modest round by software standards, but the problem it’s chasing is not modest at all: how do you pentest an environment where you’re not allowed to actually test anything live.

That constraint defines OT security more than almost any other decision made in this industry. Nobody’s going to let a red team run exploit code against the DCS controlling a cracking unit, and rightly so — the downside of a false positive is a plant trip, not a Slack alert. So the industry has spent years building workarounds: tabletop exercises, digital twins, offline replicas, and now a wave of vendors, Frenos among them, betting that language models and simulation can approximate an attacker’s path without ever touching the PLC.

What “AI-native” actually buys you

The honest version of this pitch is that AI helps with the parts of pentesting that are mostly grunt work: correlating asset inventory against known vulnerability data, mapping plausible attack paths across a network model, generating the kind of report that used to take a consultant three days to write after a two-week engagement. That’s real value, worth funding. It is not the same as an AI system independently discovering a novel exploit against an RTU it’s never seen before, and vendors in this space earn credibility by being clear about which of those two things they’re actually selling.

Simulated penetration testing has an inherent honesty problem too: a simulation is only as good as the model behind it, and industrial environments have a habit of drifting from whatever model was built to represent them. A firmware update six months ago, a firewall rule added for a contractor and never removed, a spare PLC swapped in after a failure — none of that necessarily makes it into the twin unless someone actively refreshes it. The value of a simulated attack path degrades quietly, and nobody gets an alert when it does.

Why the money is going here anyway

None of that undercuts the bet Frenos’s investors are making. Traditional OT penetration testing is expensive, infrequent, and disruptive to schedule around outages, so anything giving asset owners continuous or near-continuous insight into exposure, without a physical engagement, will find a market. The industrial investor names in this round — firms that specifically back OT and industrial technology rather than generalist cyber — suggest this is being read as an operations problem as much as a security one.

The category is getting crowded, and simulation-based approaches will increasingly need to prove their models actually track reality, not just produce a clean-looking report. That’s the same discipline Agonist applies from a different angle: proving, safely and without touching production, whether the controls a plant already has actually work as intended, rather than whether a hypothetical model says they should. Different door into the same house — asset owners burned by paper-based assurance are shopping for anything that gives them a real answer.

Source: https://industrialcyber.co/news/frenos-raises-1-52m-seed-extension-to-expand-ai-native-ot-security-platform-and-simulated-penetration-testing/

ICSOT Security

More from the blog