The B2B Podcast Index
Index
All categories
MarketingSalesSaaSFinanceHROpsLeadershipCustomer SuccessAI & DataProductStartups & FoundersRevOpsEngineering & DevTools
MethodologySubmit
Best of:MarketingSalesSaaSFinanceHROpsLeadershipCustomer SuccessAI & DataProductStartups & FoundersRevOpsEngineering & DevTools
An independent project byFame
SearchBest episodesGuestsInsightsMethodologySubmit a podcast
Index/HR/The Pair Program
The Pair Program artwork

Securing the Industrial Frontier with Frenos | The Pair Program Ep76

The Pair Program · 2025-10-21 · 46 min

0:00--:--

Franos, a seed-stage OT cybersecurity startup, is tackling one of cybersecurity's hardest problems: securing operational technology systems that control critical infrastructure like power plants, water treatment facilities, and refineries. Harry Thomas (CTO and co-founder) and Colin Murphy (chief hacking officer, formerly CIO at NoBefore and a seven-year collaborator with Kevin Mitnick) discuss how the company emerged from the gap between visibility and action - customers installing tools like Dragos or Nozomi but not knowing what to do next. Franos bridges this by building a proprietary digital twin that ingests network configuration files and vulnerability data, then deploys Cyra, an AI agent that assumes threat actor personas to identify attack paths and prioritize defenses. The company closed a $3.88M seed round led by DataTribe and operates with roughly 20 people. The conversation explores the stark differences between IT and OT security cultures, why digital twins enable safe penetration testing without operational disruption, and how AI agents simulate threat scenarios at millisecond speeds - compressing years of manual red-teaming into weeks of actionable, prioritized remediation.

Key takeaways

  • →OT systems are often a company's profit/loss center but lack the security focus of IT environments, creating a major vulnerability gap that Frenos addresses through AI-driven attack path identification.
  • →Digital twins allow threat simulation at scale without impacting live operations, enabling security teams to test against advanced threats like Iranian state actors in milliseconds rather than requiring expensive boutique red team engagements.
  • →Frenos is designed to empower junior security staff to operate the platform effectively, addressing the critical shortage of OT cybersecurity talent without requiring additional headcount.
  • →The transition from IT to OT cybersecurity requires a fundamental mindset shift from fast iteration to methodical, conservative changes that won't cause safety or operational failures.
  • →Graph database technology at the core of Frenos enables processing of millions to billions of nodes and edges at millisecond speeds to deliver prioritized risk-reduction recommendations.

In this episode

  1. 1Introduction and Pair Me Up Segment
  2. 2Frenos Origin Story and OT Cybersecurity Fundamentals
  3. 3Transition from IT to OT Security and Digital Twin Technology
  4. 4AI-Powered Threat Simulation and Prioritized Risk Recommendations
  5. 5Real-World Impact and Scaling Red Team Capabilities

Mentioned

FrenosDragosNozomiKevin MitnickHarry ThomasColin MurphyDraftKingsBlackstoneGuinnessYoderOpticaCyra

Guests

Harry ThomasColin Murphy

Topics in this episode

FrenosOperational Technology (OT) securityDigital twin technologyCyra (simulated adversarial intelligent reasoning agent)Graph databaseDragosNozomiKevin MitnickData TribeOptica

Questions this episode answers

What is the difference between IT and OT cybersecurity?

IT cybersecurity operates at high speed and tolerates failures; OT (operational technology) is methodical and risk-averse because it controls physical systems like power grids and water treatment that can cause real-world harm or loss of life if compromised or tested carelessly.

How does Franos' digital twin help secure industrial control systems?

Franos builds a network replica from configuration files and vulnerability data, then deploys an AI agent called Cyra that simulates threat actor tactics at scale and speed, identifying attack paths without risking operational disruption - something traditional penetration testing cannot do safely in live environments.

Does using Franos require companies to hire additional security staff?

No; Franos is designed to operate intuitively enough that junior security resources can use it effectively, allowing companies to upskill existing staff rather than requiring new headcount in the already scarce OT cybersecurity field.

What was Colin Murphy's background before joining Franos as chief hacking officer?

Murphy was CIO at NoBefore, worked in private equity and deregulation for seven years in the energy space, and spent seven years conducting red team engagements and penetration testing with Kevin Mitnick's firm before transitioning to OT security.

What funding has Franos raised and at what valuation?

Franos closed a $3.88 million seed round in January led by DataTribe, with Dragos CEO Rob Lee serving on the advisory board.

Conversation analysis

Computed from the transcript - who did the talking, and the words that came up most.

Share of words spoken

  • Speaker A33%
  • Speaker C29%
  • Speaker D25%
  • Speaker B12%

Most-used words

franos23nice16platform16security15cybersecurity14systems14visibility14team13cool12harry11space11world10colin10infrastructure10long10side10

Episode notes

Securing the Industrial Frontier with Frenos | The Pair Program Ep76 In this episode, hosts Tim Winkler and Mike Gruen chat with Harry Thomas, CTO of Frenos, and Colin Murphy, Chief Hacking Officer at Frenos, two cybersecurity experts redefining how we protect critical infrastructure. They unpack what it takes to defend operational technology (OT) environments that keep power grids, water systems, and manufacturing lines running safely. We dive into: The origin of Frenos and its AI-powered “digital twin” for OT defense Bridging IT and OT security mindsets How their new tool, Optica, boosts visibility and resilience The rise of OT security posture management Balancing commercial growth with national-security applications About Harry Thomas: Harry is an expert offensive penetration tester specializing in industrial and healthcare cybersecurity, with over a decade of experience. As CTO of Frenos, he leads innovation in protecting critical infrastructures. He has taught “Hacking PLCs” at DefCon and BSIDES Orlando, spoken at BSIDES NH, and been featured on the Secure Insights Podcast. Previously, he directed Product R&D at Dragos and led AI/ML-driven UBA development at AWS.

Full transcript

46 min

Transcribed and scored by The B2B Podcast Index.

Speaker A: Welcome to the PEAR program from Hatchpad, the podcast that gives you a front row seat to candid conversations with tech leaders from the startup world. I'm your host Tim Winkler, the creator of Hatchpad.

Speaker B: And I'm your other host, Mike Gruen.

Speaker A: Join us each episode as we bring together two guests to dissect topics at the intersection of technology, startups and career growth. Welcome back to the pair program. I'm your host Tim Winkler, joined uh, again by my co host Mike Gruen. Uh, Mike, I saw a, a movie trailer the other day, got uh, me thinking these. I've been seeing a lot of these biopics popping up. So there's one coming out about Bruce Springsteen, um, with Jeremy Allen White from the Bear, um, playing the lead. So I can see it's good, good actor, uh, but I feel like we've been with everybody, have like a ton of these that have been coming out. Like we had Shalam came out with like Bob Dylan. There's like Elvis, Queen, Elton John. So my question for you would be, you know, what musician do you think deserves the, the biopic treatment?

Speaker B: Uh, that's interesting. Um, I mean, musician. So my, my immediate thoughts are like, to the, some of the drummers from like, um, from back in the day, like John Bonham or something like that. So I could see like a Led Zeppelin or ah, something like that would be pretty cool.

Speaker A: Yeah, I dig that. Yeah, I was thinking um, a little, a little bit more off the wall, But Andre Ah, 3,000 would be a good one. That'd be a good one from outkast just because he's kind of out there, a little eccentric, you know, had he had the, a, ah, flute, uh, playing area, uh, a flute playing area where he had like a whole album dedicated to the flute. Um, so yeah, we'll keep an eye out. Maybe, maybe one of our picks makes the uh, makes the cut. But um.

Speaker C: Cool.

Speaker A: Well, speaking of uh, fascinating characters, uh, let's shift gears and uh, give the listeners a little preview of our guest joining us on today's episode. So we've got a couple of uh, entrepreneurs who are leading cast, uh, members behind Franos, which is a seed stage cybersecurity startup that's working to redefine how we secure Operational Technology systems or uh, OT systems. Uh, so we've got Harry Thomas, uh, CTO and co founder of Franos, alongside Colin Murphy, the chief hacking officer at Franco. So we're going to be digging into, you know, one of the toughest challenges in cybersecurity which is, you know, More so protecting these physical systems that power our world. Uh, you know, everything from like, power plants to water treatment facilities, um, refineries, transportation networks, pretty, uh, high stake environments. Uh, a lot of complex risk involved. Uh, something that's obviously very top of mind given the political climate, uh, that we're in right now too. Um, so excited to, to hear a little bit more, uh, maybe feel a little sense of comfort, uh, after we get a little bit of a detail on some of the big problems these guys are solving. So, Harry and Colin, thank you both for joining us on the podcast.

Speaker C: Yeah, thank you. Appreciate it.

Speaker A: Cool. All right, now before we dive in, we kick things off with a, A, uh, segment we call Pair Me Up. Uh, it's going to go around the room.

Speaker D: Spitball.

Speaker A: Uh, a pairing that, uh, could be anything of your choice. Um, Mike, you lead us off. What do you got for.

Speaker B: So, nothing, uh, controversial. Guinness and chocolate. Uh, so last night I was out with a buddy and frequently, uh, have Guinness. And then it, uh, was time for dessert and I, uh, was reminded of just how well Guinness and chocolate go. Uh, I've been trying to cut down on the desserts lately, so it was a nice, uh, and I've been also trying to cut down on beer. So it was a little bit of a cheat day.

Speaker A: Get down on one or the other, keep your ramp one up.

Speaker B: No, just cut down on both. Uh, but trying to get that beach body. But, uh, time of year. It is that time of year.

Speaker A: What's the, uh, like a, is it dark chocolate or milk chocolate? Anything?

Speaker B: I'm a dark chocolate guy. I, I, I like my beer and I like my chocolate the same black and better.

Speaker A: Yeah, dude, Guinness is one of those that you could, you know, drink, drink all night and not really feel as full as it looks, you know.

Speaker B: Yep, yep.

Speaker A: A little deceiving in that sense.

Speaker B: And it's also, uh, lower on the alcohol content as well. So it's another one that you can

Speaker A: just sort of drink.

Speaker D: Yep.

Speaker A: Yeah. Good. Guinness plug. Not, not a sponsor, but we, we, uh, we enjoy it.

Speaker B: I'm looking forward to my t. Sh.

Speaker A: Uh, man. Yeah, I like that. I'm going to go with brunch, uh, and Blackstone, uh, grill. Um, so this past Father's Day weekend, we hosted some friends at our house for, uh, for brunch. Fired, um, up the Blackstone. Uh, it's pretty perfect for, for like breakfast food. So like, we, we did like omelets, pancakes, bacon. Can get all that kind of going at the same time. Um, so found it As a good use case for Blackstone, you could do stuff like hibachi steak and cheese. Um, but I'm going to pair it up with breakfast, uh, episode segment. So, um, that's, uh, that's my pairing. Um, and, uh, yeah, let's pass it over to our guest, uh, Harry, quick intro. And. And your pairing.

Speaker C: Yeah, thanks. Uh, CTO co founder Franos. Been in OT Cyber security for over a decade now. And funny. Uh, enough. A little fun fact about me. I used to be a nurse, uh, before I actually branched into cyber security. Uh, uh, so. So that's pretty interesting. My pairing, uh, is something that we're talking about just before we, uh, started recording Beer, uh, and draftkings. Uh, that is. That is. That is my pairing.

Speaker A: Yeah, just. Just gotta have one while you're, you know, while you're using the, uh, using the app.

Speaker C: Yeah, you gotta have one while you're using the app. You gotta have, you know, a beer in hand. Also while you're watching the UFC fight.

Speaker A: That's right.

Speaker C: You know, it's all. It's all, you know, intermingled.

Speaker A: Yeah, I feel like they're already kind of in cahoots too. It's like, you know, you're getting Bud Light or something. Always involved with, like, a collab.

Speaker B: I'm waiting for them to come out with a DraftKings beer that's spelled drafty art. You know,

Speaker A: that's a great idea, trademark that thing. Yeah, I didn't know that about the nursing background. So you've already, you know, operated in, you know, some. Some critical infrastructure environment. So obviously that seems like, applicable when you're a user mindset, when you're building. Yeah, that's cool. Uh, good stuff. Uh, thanks for joining us, Colin. Quick intro in your pairing. Yeah.

Speaker D: Uh, so Colin Murphy, chief hacking officer at Franos, joined in April. April 1, actually, which was perfectly, uh, timed with, uh, the company I had left. So previously I was the CIO at KNOW before, which is a cybersecurity company. Uh, been in and out of cybersecurity for a long time. Worked in private equity, was in the deregulation, uh, energy space for about seven years. And while at NoBe4, I also worked for Kevin Mitnick for seven years. So I got to hack and red team on one side and blue team, really, on the other. So nice that. That was a hell of an experience.

Speaker A: Yeah.

Speaker D: So, um, yeah, so my pairing. I thought of this before you guys went, but I guess we're on the beer and something team. But for me, growing up, never Was a huge, Huge, like, smoked meat kind of guy. Then a good friend of mine one day invited me over. He did a. A brisket. It took like 18 hours. I was losing my mind. Smell it. And I'm like, it can't take this long, dude. Just turn up the heat. Whole process. So mine is. And I make a brisket like, once a month. Like, I'm super addicted. Uh, a good. A good IPA with not. Not too skunky, and a, uh, brisket out of the smoker for about an hour. They just always taste good together.

Speaker B: Nice.

Speaker D: So.

Speaker A: Sounds good.

Speaker B: I'm hungry. Thanks.

Speaker C: Thirsty. You know what they say, uh, about middle, uh, aged men. You either get into World War II or you get into smoking. Me.

Speaker A: That's right.

Speaker D: I'm not gonna argue with you on that. It's exactly what happened.

Speaker A: Yeah, Traegers took off, like, during the pandemic. I remember that was like a whole, like, viral, you know, tick tocks of everybody just kind of showing off their. Their. Their smoke. Smoking skills. Right. It's like, uh, I don't know, it's a. It's a, uh, an accomplishment. You know, you were something you work on all day, and it's like, it's time. Time to. To bear the fruits of our labor here. That's awesome. What. What do you have, like, a. A smoker of choice? I just named Traeger because I know a lot of my buddies not a

Speaker D: sponsorship, so I had a Green Mountain. It wore out pretty fast. They're comp. Uh, you're about equal to a Traeger. Uh, then I did a bunch of research on Reddit, got a Yoder. There's people that have had this smoker for 10 to 12 years, and they've replaced, like, one piece on it, and that's it.

Speaker B: Nice.

Speaker D: So it's. I'm in Florida, so this thing's out in the weather all the time, and it is holding up.

Speaker A: That's awesome.

Speaker D: Yeah.

Speaker A: All right, now we're all starving and thirsty. A little thirsty. Um, let's, uh, let's. Let's transition, uh, to the. The main discussion. Um, so as I mentioned earlier, we're going to be, you know, talking about how Franos is securing these, you know, critical infrastructure systems. Um, so I do want to start with kind of like that startup origin story. M. Define, you know, what offense. Informed defense and the OT space kind of looks like. Colin, uh, you brought it up. I'm also intrigued to expand on this transformation from IT to ot and, uh, kind of hear what you had to either pick up, forget stuff like that, um, and then we'll close with an overview of one of the newly announced tools, Optica, uh, which is kind of changing the game for environments with limited visibility. So let's get into it. Um, Harry, I'll start with you. How did FRANOS kind of come to be? What was, what was that? Kind of we need to build this moment.

Speaker C: Yeah, definitely. So, um, within operational technology, which is different from informational technology, um, ot, uh, or industrial control systems themselves, what they do is generally manipulate, uh, some form of physics. Uh, so if you think about like substations and electric utility, uh, relays open closed breakers to allow electricity to flow along the power lines and stuff like that. So that's what operational technology is. Funny enough, probably most companies out there don't know that their OT environment is actually their profit loss center. Uh, it's not the actual corporate environment. Um, but uh, the FRANOS origin story itself is, uh, me and uh, I have two other co founders, Eric and Brian. Brian and I have, uh, two different stories, but it kind of originates from the same place where I used to lead research, uh, and development at Dragos, uh, which is a visibility player in operational technology. And every time I worked with customers or clients, uh, they installed a Dragos or a Nozomi, whatever flavor you want. And they always ask, you know, what do I do next? And I was hit with that tough question. Even in consulting you're always hit with that tough question, right? You hand over a report, your ass. All right, cool. Now give me the rundown of what to do. So, uh, it took a few years actually trying uh, to develop the FRANOS platform. I actually have a long list of repository names inside my GitHub of previous ways I've tried to build a FRANOS platform. But uh, from there stemmed this, uh, ability to utilize a combination of AI, artificial intelligence, large language models and machine learning models combined with um, our flavor of a digital twin. Uh, so what we do at FRANOS is we take in your network configuration files from firewalls switches. We build our version of a network replica or a network digital twin of which then we're able to overlay the asset vulnerability information that you might get from a Dragos or Nozomi or even like flat CSV files. From there we have our Cyra, our simulated adversarial intelligent reasoning agent. All she does is assumes the personality and Persona of threats. So, uh, you know, most apt this week is Iranian cyber and ransomware. And what she can do is utilize those techniques, tactics and Procedures and the ways that these threat, um, operators work within an environment and she's able to identify those clear attack paths and then on the flip side, give you the prioritized risk reducing recommendations necessary to stop those adversaries or other adversaries that might mimic those from actually utilizing what we found.

Speaker A: Yeah, super relevant obviously right now, very top of mind as uh, you know, everybody's thinking about, you know, how a retaliation might look, you know, from Iran and it's cyber is, you know, something that's obviously being spoken about quite frequently. And um, to be able to have that kind of simulated environment, know what those types of threats kind of look like, that's really valuable. Um, little, little quick hits on, on uh, where you guys are from funding headcount. Uh, love to hear that.

Speaker C: Yeah. So, uh, we closed our series seed funding back in uh, January. Data, uh, tribe love those guys. They led it, uh, 3.88 million. And then, um, from a headcount perspective, we're probably about 20 people mixed, uh, between contractors, full time employees and stuff like that. Yeah, nice.

Speaker A: Yeah, you mentioned Dragos. We know them, they're local to the DMV area. I think they're out in Fulton, uh, Maryland. But um, I think they also were a data tribe.

Speaker B: Where I was drinking that Guinness last night was over in Fulton, over at Maple Lawn, right near their.

Speaker C: Yeah. Uh, Rob, Emily, the CEO of Dragos is actually on our advisory board.

Speaker B: Oh, nice.

Speaker A: Cool. Nice. Good stuff. Yeah, it's um, uh, we'll get a little bit deeper into, you know, obviously some of the tools and the, in the product suite. But, um, Colin, you know, I wanted to touch a little bit more on, you know, your background. Like we mentioned, it's a little bit more rooted in it, you know, cybersecurity. So maybe walk us through, you know, how you made that leap into, um, the OT side of things and what that transition was like for you.

Speaker D: So it actually works out really well because on the IT side, doing red team engagements with Kevin's company, um, a lot of the time we would, we would do the IT side of a big OT space. Right. Whether it's manufacturing, oil and gas, uh, pharmaceutical, but from the IT lens that was rarely we would end up there on accident or it would be ancillary to the crown jewels of what we're looking for. Right. And so having that kind of IT mentality leading towards operations and finance and you know, uh, data, big data, customer records, all of that intellectual property, um then kind of switching that, that hat. When I joined the Franos team has been, it's been pretty awesome. I mean I feel like a newbie to be, to be completely honest, uh, learning a lot from the group and seeing as we interact with customers and just the community. How much one have kind of diverged as two separate groups, uh, or industries or solutions. Right. It very much cutting edge. We deploy things at a speed that we don't care if things break as long as it doesn't hit the dollar, you know, no one's gonna lose power, no one's gonna lose their life. And in the OT space there's a very different methodical approach to things. And so sometimes we have a pro, we're faced with a problem and I'm like, one hour, come on, we can fix that. And then you start to dig in. I'm like, oh, I would break everything. If I applied the solutions the way I've designed them in the past or tested the same way, uh, it would be impactful, which makes sense. Why did the concept of digital twin. Why cybersecurity is taking a different path in the OT space makes sense to me now.

Speaker B: So yeah, I think it's interesting the, the whole, the kinetic aspect of ot, right. Like the fact that has real world implications. I mean as a software engineer, there were a handful of things I did where it actually had a, like, you're talking loss of life type things and whatever, but for the most part, right, you could deploy something, it would break and some people would be upset for a little while but. And maybe not able to do their job, but not right, but right. You shut down air conditioning for an apartment building and next thing you know, you know, there's, there's some real results from that. I think it's interesting. It's, it's very important to sort of have that like that change. And then I, you know, I'm curious like with the digital twin and um, the um, that a lot of OT systems I feel like have come online or become Internet enabled. Like, but they weren't necessarily designed for that space. Is that like a good use for like digital twin? Like m being able to see like what gets exposed? Because I think of all these systems that I don't know, I'm sure my H Vac was never designed to originally be online, but now it's Internet accessible. And I'm curious if that's like a good use case for like digital twinning. Like looking at it from that perspective, all these things, systems that have become Internet enabled that maybe never were intended to be.

Speaker C: Yeah. The purpose of Our digital twin. Uh, and the reason why we went down that route is particularly because um, you can't have really any impact to operations as operations is working. Uh, that's why, like generally red, uh, team or hackers consultants that you hire to come perform penetration tests in operational technology, they're given like a decommissioned site or maybe a site that isn't being commissioned just yet. They're handling everything with kid gloves. Uh, the purpose of the digital twin for us is to let's unleash everything, unleash whatever we need to unleash imaginable because these threat actors aren't having kids gloves. They're actually going to go out there and they're going to do it and let's see what they can do. Um, and our, our digital twin operates at a speed that is incomprehensible. I mean, um, you know, it's the basis of it is really just a graph database in all honesty. But, um, it's our, our homegrown proprietary, you know, patent pending graph database that allows us to scale. I mean we're able to ingest millions, if not billions of nodes and edges and run calculations at scale speeds of milliseconds. Um, being able to provide this information not only to our users and our customers, but being able to provide this information to our AI models to allow them to calculate just as fast. Um, and give these results.

Speaker B: I was going to say that's the other thing that it just occurred to me, right. You're able to do things at a speed because you have AI agents that are doing that. You're not working, you're not operating at human speed. So you're not waiting for that. You can actually simulate several hours in seconds, or several days in minutes or whatever where it might take a little while for that temperature to heat up or for that, you know, for the outcome to be seen in the physical world.

Speaker C: Well, yeah, uh, you can add to that.

Speaker D: Yeah, yeah. Because, uh, you know, coming from that space of we would do big red team engagements. I mean Kevin and Kimberly and crew were always so adamant on delivering above and beyond for any customer. Right. They ran a very boutique bin testing company. But with that, you know, you can only cover so much. We had our scope and we had our systems and you know, we there. The customer would do great. It was digestible. They do, they would always fix things, which I loved. Then we'd go test again and we'd get in again and over and over and over. And usually it took, uh, years for their cybersecurity plan. And infrastructure and readiness to get to a level where we're really scrambling to get, you know, creative and do things that, you know, you're no longer doing the 80%, the low hanging fruit right now. You're a very uh, advanced adversary. Well, two years ago, Franos and Harry and their product was pitched to me by one of the co founders and I went that, that piques my interest because I've always wanted to do what we do on the red team side at a scale and at an accuracy that we could then deliver a prioritized list that covers much more. Now you still have to work to secure it and burn that list down, but you're not looking at four years. Right. And if you're prioritized correctly and can rerun tests very quickly, you're speeding things up. And so because uh, in the end we do what we do because not just a paycheck, but impact to a safer world. Right. Nothing makes you more upset to get breach notices or, you know, I was in the Dominican Republic for a few years of the business, literally went there to, to get money out to pay my staff. And there's a line out front and the bank's like, we're closed, we got hacked. And I'm like, what? That doesn't happen. Their, their primary server was in the lobby next to where the tellers are working. And I went, man, this is, this isn't good. I can't pay my staff. Like those are the types of things we work to secure. So Sara for me and Franos was uh, a very logical next step in on my path.

Speaker A: Yeah, we uh, we actually have run a couple of episodes on the, in the cyberspace. One, one recently that comes to mind was um, empowering, you know, the soc. Right. Uh, there's a, a shortage of, you know, that, that type of workforce and you know, burnout's a, a big issue in that space. Um, you know, folks working 247 and you know, so this was you know, kind of AI empowering. Um, the SOC analys, uh, all see, you know, when you partner with a, you know, with a customer, uh, you know, you're hyp, you know, your product's going to be, you know, maybe adding more visibility, enhancing uh, a lot more visibility to some of the threats as well. Do you see the need for uh, almost an added lift in additional, you know, team members as well, like on their side or do you guys employ like a services side as well in addition to the product offering when you're uh, you know, turning on an engagement

Speaker C: yeah, so um, quite frankly, so uh, we've built the Franos platform to not need additional headcount in order to operate. Uh, it's actually built so intuitively and simple that um, quite frankly a lot of our customers are utilizing junior resources to operate and manage the Franos platform and dictate the work to the architect or the other uh, network security folks. Um, which is great because now we have a human shortage of people being able to come into the cybersecurity field. But not just cybersecurity, ot cybersecurity which is a niche within a niche and uh, us giving that ability to these junior resources to up level them and get them smart on the right things right now, um, has been useful for all of our customers I think.

Speaker D: Oh, just real quick. I think there's a outcome though that you know, we're bringing value to existing tools and assets and you know, focusing effort. So there's probably going to be many scenarios where it's a uh, justified and a much easier ask to get the right people to get additions to a team to go and get more Nozomi or Dragos, et cetera. Because now I don't want to, you know, I don't want to start a marketing thing and call ourselves a pane of glass or you know, that everyone seems to think every platform is now, but the outcome of what we do is a collaboration of all these different tools and efforts. And so I think that collectively it's giving a very focused prioritized ROI that up up levels the entire cyber team.

Speaker A: So Harry, I want to uh, pull on a thread on something uh, you kind of posted on LinkedIn about how we secure systems that we can't fully see. Um, I want to talk about some more of these real world scenarios. You kind of alluded to one obviously more recently with the ah, Iranian threats, um, um, and dual use is a topic uh, that comes into play quite a bit on this podcast just because we talk a lot with defense tech or uh, we also talked to uh, uh, startups that are aligning with critical infrastructure. If it's healthcare, cyber national security issues, um, talk to me a little bit about that balance for you all between maybe the commercial side of business and then maybe some national security or defense customers. How do you align the product team, uh, how that differs at all? Are they all aligned on the same teams or break those up based on you're going to be working in a natsec environment, you're going to be working in healthcare. I mean they're all pretty Regulated. But talk to me a little bit about that. I'm curious on that breakdown on the dual use.

Speaker C: Yeah, so, uh, since the beginning of, uh, the inception of the frameless platform, we built it in such a way where we don't really have to split focus like that. Um, it's not like a Frankenstein platform where you're just bolting on thing after thing to acquire customers. We've had a, uh, very clear, uh, focus and clear concept of what we need to build. So, uh, the agencies, uh, that we're talking with and such see the use of this platform kind of differently than how commercial would. But in the grand scheme of things, it's still the same features and the same original vision that we had for the platform that they're all adhering to.

Speaker A: Yeah, I mean, you talk about, you know, an attack on an energy plant, whatever it might be. It's a national security threat, um, at large. So they all kind of have a little bit of a bleed right into national security implications. Um, let's talk about, um, Optica for a little bit because, you know, you, uh, just. Just kind of, you know, rolled this out. Um, you know, tell me a little bit about what it is and how it might be different. You know, traditional asset discovery or like kind of mapping tools.

Speaker C: Yeah, definitely. So when you're talking to mature cybersecurity ot organizations where we're all talking about this elusive 100% visibility, meaning deploying enough sensors or deploying enough, uh, tools out there to be able to understand 100% of your environment, know all your assets, what they are, what they speak and what they talk and who they talk to. Unfortunately, even the most mature of organizations are at maybe a 30, 35% visibility. It's just so hard to deploy these sensors or to touch these technologies. I mean, you're talking about like an 8 to 12 month Runway just to deploy a sensor in a substation. And we have customers that have thousands of substations like that. It's going to take years and years for all that to roll out. So what we came up with is Optica. Optica is our way of bridging that gap between your 35% visibility and the 100% visibility. What we do is build, uh, templates of your assets. So in ot, in industrial control systems, a lot of the assets are generally the same. If you have one line on the manufacturing floor, generally line two, line three, line four, they're, uh, kind of all the same. They have all the same vulnerabilities, they have all the same protocols so what we have developed is a way to templatize these assets utilizing either services or even just talking with the customer themselves to um, ascertain what these assets are, what they do, their critical functions and their vulnerabilities. And then we can apply these asset templates or asset blueprints to network blueprints. So we're also able to find your networks that are missing visibility and from there have a export of whatever version of asset, uh, visibility you want. So if you have a Dragos, we're able to export, uh, the asset inventory in dragos, run 0nozomi clarity, whatever your flavor is, whatever you want, we're able to export in those native formats and upload it into the FR platform. Because the FRANOS platform doesn't really work as well if you have a lack of asset data. Right. You don't have assets for us or for Cyra to simulate against. It's all just guesswork at that point. Well, let's, you know, shift a little bit more and let's, you know, have more educated guesses by doing the manual work of talking to people, talking to the OT engineers, talking to the network engineers and gathering that data and putting it in Optica. So then we can, you know, reach our end point of uh, those risk reducing recommendations.

Speaker A: Very cool. How long was that, uh, you know, in the works for? How long was the team kind of heads down on that?

Speaker C: Um, we, we developed it in less than a week.

Speaker D: I have a story on this because it came about from another problem and this is a, uh, a good kind of going back to the journey from it to ot because I'm like, hey, let's do this. And everyone around the table is like, what do you, we can't do that because there's no visibility. What do you not understand about no visibility? And I'm like, well, they have to, they know what they have. And they're like, well, well, no. And this was a, I was at RSA when this was going on and then, and then Harry, just out of the blues, like, well, I've been working on this thing after hearing this conversation and it was like the early stages of Optica and it just dropped it on our laps, like as a, as a solution. I mean, it came about in two days, the original form. Um, but yeah, that was a big, that's a big thing for me that I'm still kind of tackling is, uh, how real that lack of visibility is it. We have m. We don't have thousands of sites, right? I mean, every business I've consulted for, been part of, we have a few sites know before we had 13 large offices around the world. We knew what we had in every one of them. We built the same infrastructure, I had the same monitoring. It was easy. No one fought with me to get it in place. It took days to get it in place. That doesn't apply to the OT space. So that's probably one uh, of the larger things that I've been grappling with.

Speaker B: You mean OT as code isn't, isn't a thing.

Speaker C: OTS code. I like it.

Speaker A: So I guess uh, kind of a couple closing questions here, maybe a two part question here in terms of where you guys see this OT security landscape heading over the next couple of years, any big shifts that you're anticipating and then how does that translate over to what success looks like for Franos over the next 12 to 24 months?

Speaker C: So the big shift that um, I've been seeing is there's a lot of consolidation in cybersecurity right now. Uh, a lot of M and A, uh, but not just that. Um, generally the M and A really in IT drives what's going to eventually happen in operational technology. You know, we're just a couple years if not a decade sometimes behind depending on the type of um, infrastructure or tool technology we're trying to create. With uh, the acquisition of Wiz into Google. Great, uh, acquisition. Those founders. Good, good on you.

Speaker A: Good for them.

Speaker C: Um, good for them. But what we've been hearing a lot through our conversations with not just investors but customers as well, especially customers that have used Wiz, which is a uh, cloud, uh, security posture management tool. They are saying that Franos is the OT security posture management tool for industrial control systems. They're making it akin to Wiz in its early days. So my um, kind of foresight within the next 12 to 18 months is we're going to be hearing a lot more of that and we're going to be hearing a lot more of OT security posture management technologies coming into uh, the space as well.

Speaker A: Nice. And what you're saying is in like five years the next round of Guinnesses will be on you then?

Speaker C: Yes, 100%.

Speaker D: I'll bring the brisket.

Speaker A: Yeah, that's right. Any, any new like um, use cases or, or verticals that you're you know, especially excited to support? I mean, I think, you know, what we kind of pointed out at the beginning of this one um, is like I said, is top of mind for a lot of folks. You know, it seems like these are going to be things that are going to continue to escalate, you know, as long as there's going to be, you know, the way that wars are kind of fought, unfortunately, in, in today's environment, a lot of cyber warfare. So. But do you see any new use cases or verticals that may be popping up down the line?

Speaker C: Yeah, so, uh, your talk track about the national security, um, we've been actually getting a lot more interest, uh, from those agencies within the past two months, two, three months than we were before. Um, so that is that new, I guess, vertical that we will be pursuing. Um, it's a long road, obviously, you know, selling into federal and whatnot. But, um, they are willing to share information with us that they won't share publicly to allow us to simulate threats in higher fidelity. And that's for me, uh, you know, previous hacker, and I know Colin hacker as well, um, to be able to simulate those types of threats in a fidelity or accuracy that is unparalleled without that information. Because quite frankly, what happens with the FRANOS platform is we're weaponizing threat intelligence. Right. We're taking threat intelligence that's being deployed from record future or whoever out there, and we're able to take that information, codify it into the platform, and utilize AI in order to simulate what those threats could be doing in the future. Um, so that, that's, yeah, very cool.

Speaker A: Good stuff. All right, um, yeah, thank you guys again for the work that you're doing. Uh, securing the backbone of our infrastructure. It's stuff, uh, that maybe doesn't get the same spotlight as a lot of new shiny app security, but it's, uh, just as critical, not more.

Speaker B: I mean, I like my power grid.

Speaker C: So.

Speaker B: Yeah, I think. Yeah.

Speaker D: This morning I got an alert on my phone from Telegram, and I stay in a bunch of these adversary groups to see what they're doing. And they're reposting something that Hacker News had said. And they were talking about the four key critical control systems for the, um, the missile, the. What's the Dome in Israel?

Speaker B: Uh, the Iron Dome.

Speaker D: Iron Dome. They were saying, hey, hackers go after a gps, use jammers. These are tools, these are research paths. And they're trying to. But yeah, I didn't even think about that. But that's critical infrastructure.

Speaker A: Right?

Speaker B: I mean, that's, it's. Sorry, that's the one thing, because I've talked to a lot of people across over the years about OT and just, uh, it's such a broad thing. It covers so many things, whether you could be Talking about planes, trains and you know that you could be talking about power grids. You can be talking about, you know, all these different systems. It's where that, that you know, uh, that kinetic, you know, the, the computers meet, you know, actual real world. And, and I am kind of curious about that with you guys. Like are you, where are there certain areas of OT that you're focused more on? Um, because it is just such a broad like thing, if you will domain.

Speaker D: There's some key verticals that I think everyone's background ah, kind of alludes to. Right. And energy and manufacturing. Um, you know there's, there's some other areas though that we definitely apply. So I've been doing a lot, I'm part of what I do at Franos is on the research side and all those Fortinet breaches earlier in the year, you know, pulling those into our platform. It's actually also an incident response tool. Yeah, know that. But when you can model attacks against the configuration attacks that already happened, it gives you a pretty good idea of what they probably did and where to go look for your IR program. Um, but some of those firewalls that I ingested ended up being OT organizations and you know, they were at Power One's manufacturing paper products overseas. And so it's, it's, it's kind of useful in a lot of different verticals but from a background standpoint and Harry can probably give a little more background, um, in all of the verticals, but definitely in, in gas and energy, um, manufacturing.

Speaker C: Yeah, yeah, we're focusing on those. But um, the way that Brian, uh, our CEO likes to put it, we have applicability to all 16 sectors of critical infrastructure as defined by CISA. Um, so that's eventually what we're going to branch into. Um, you know, for me, near dear to my heart, our hospitals and such like that, um, you know, protecting patient, patient data but just protecting lives in general. Um, that's, that's always what I wanted to do and that's the reason why I've directed myself into OT cybersecurity was because you have that, you know, that mission. You know, I'm going to protect modern civilization as it stands right now.

Speaker A: Yeah, we need to hook you guys up with a former, you know, episode. We just had a guest that's building a rare earth metals refinery in the northeast. Uh, here which you talk about the reach of rare earth metals and you know, the, the impact those have of you know, shortage of those or you know, something happens to the refinery that's it's another one of those critical infrastructure settings. Uh, I'll link, I'll link the connection. Phoenix, uh, Tailings is the name of the company. Pretty, pretty cool stuff they're doing. Um, and actually backed by in qtel. Right. So you think about all those commercial, uh, use cases that have impacts to national security in Q. Tel is a big one of making those connections. So it seems real applicable. Um, cool. All right, uh, we're going to transition here to, ah, the final segments, the five second scramble. So you'll each get a few rapid fire, uh, questions. Try to answer under five seconds. Um, Mike, you lead us off with Colin, then I'll, I'll close with Harry.

Speaker B: Sounds good. Colin, you ready?

Speaker D: I'm not ready. Let's do it.

Speaker B: All right, Sounds perfect. That's the right answer. Uh, if friendis were an animal, what animal would it be?

Speaker D: Aardvark.

Speaker B: Nice.

Speaker A: First time, first time answer.

Speaker B: Uh, what's your favorite part of the culture there?

Speaker D: Uh, international. Right. We're, we're global. Everyone works remote.

Speaker C: Cool.

Speaker B: Uh, what tech roles are you hiring for in the next six to 12 months?

Speaker D: Uh, AI and SRE platform lead. Okay.

Speaker B: Uh, what's one thing about OT you think would surprise people to learn?

Speaker D: I mean, all my. Everyone I know from it would be the lack of visibility.

Speaker B: Uh, what was your favorite toy growing up?

Speaker D: G.I. joe.

Speaker B: Uh, what was the first. What was the first thing you ever hacked?

Speaker D: Uh, a state. It was long. It was long ago. I was a little kid. Put that out there. It was a state server. Uh, farm.

Speaker B: Uh, uh, what was your first car?

Speaker D: First car was a BMW, an 80, 83.

Speaker B: Okay. Is there a charity or cause that's near and dear to you?

Speaker D: So I, uh. A few years ago we had a couple hurricanes hit Florida. I joined the Cajun Navy and got to see firsthand what they do and went and volunteered for two weeks with them. And we, we were there when FEMA wasn't.

Speaker B: So today I learned there's a Cajun Navy. I had not heard of that.

Speaker D: Katrina. They came out of Katrina.

Speaker B: Yep. Makes sense. What's a, uh, surprising hobby of yours, man?

Speaker D: Uh, I just had this conversation with my wife this morning. I have too many. Um, I build firearms. I make my own guns.

Speaker B: Oh, nice. Uh, and last one. If you could live in any fictional universe, which would you choose?

Speaker D: Any fictional universe. Dune. Mhm.

Speaker B: All right. Strong, very good. Very strong. Very quick. That was nice.

Speaker A: It's the second, uh, Chalamet reference in the episode too. Uh, had him on the, uh, the Bob Dylan Biopic and then Dune. Um, cool. Nice. Uh, Harry, you ready?

Speaker C: Oh yeah.

Speaker A: All right, pitch uh, Franos to me as if I was a five year old.

Speaker C: You have maybe, uh, one apple and there are more apples inside a basket and you don't know how many apples are there. So you then ask your mom.

Speaker D: Where is the mom?

Speaker A: The mom platform. Um, nice. Uh, what's uh, one word that you would use to describe the OT security space right now?

Speaker C: Progressing.

Speaker A: What, uh, what kind of technologist do you say thrives, uh, at Franos?

Speaker C: Uh, can I swear?

Speaker A: Sure, sure.

Speaker C: Get done.

Speaker A: Mhm.

Speaker C: That's the type of people.

Speaker A: Nice. Um, what is one of the most underrated skills in cyber offense communication? What's one emerging tech that you think is kind of over. Over hyped in cybersecurity?

Speaker C: Large language models like chatbots and rappers.

Speaker A: What's the weirdest, uh, job that you've ever had?

Speaker B: Um,

Speaker C: the weirdest job. Yeah, so I was, uh, before I became a, a nurse, I was a licensed nursing assistant and I used to handle things, uh, from bodily fluids, um, that most people would refuse to.

Speaker A: Yeah. Seen some, I'm sure, literally.

Speaker D: M. My wife did that for a few years. I know exactly what you're talking about.

Speaker A: Yeah, God bless those folks though, man, they need them. Um, aside from your phone, what's a gadget? Ah, that you a, ah, tech gadget that you can't live without.

Speaker C: A guitar tuner.

Speaker A: Nice. If you could have dinner with any technologist, past or present, who would, uh, who would it be with?

Speaker C: It's a cliche, but. Steve Jobs, Uh, a charity.

Speaker A: Charity or corporate philanthropy that's near and dear to you?

Speaker C: Uh, Alzheimer's, uh, walk to end Alzheimer's.

Speaker A: And then last one, uh, what is one thing that is still on your bucket list?

Speaker C: I want to skydive. I've never been.

Speaker A: Nice. Good stuff, man. All right, that's a wrap. Uh, again, Harry, Colin, congrats on continuing to build Franos and solving these big world problems, um, globally. Thank, uh, you guys for, uh, joining us and wishing you guys continued success. So thanks for hanging out with us on the podcast.

Speaker C: Thank you.

Speaker D: Thanks for having us,

Speaker A: Sam.

Related episodes across the Index

Other episodes covering the same guests and topics, from across The B2B Podcast Index.

  • Managing Risk with Digital Twins - What Do We Do Next? [the industrial security podcast]The Industrial Security Podcast · on Frenos85 / 100
  • Skills Shift - Thriving With AI, Part 2The Future of Work · on Digital twin technology80 / 100
  • Raj SubramaniamThe David Rubenstein Show · on Digital twin technology79 / 100
  • The Human Side of Cybersecurity with Dawn Cappelli, Head of OT CERT at DragosThe Human Side of Cybersecurity · on Dragos78 / 100
  • Automating Warehouse Inventory with Drones: An MIT SCM Capstone ProjectMIT Supply Chain Frontiers · on Digital twin technology72 / 100
  • Ep 136 | The end of the cyber road with Dan McDermott, Gar O'Hara and Vinh NguyenThe Get Cyber Resilient Show · on Operational Technology (OT) security46 / 100

More from The Pair Program

All episodes →
  • Founder-Led Growth in the AI Era: Rethinking the CRM from First Touch to Close | The Pair Program Ep9865 / 100
  • From Snapshots to Systems: Why 3D Earth Awareness Is Becoming Critical Infrastructure | The Pair Program Ep9788 / 100
  • From Sidewalks to Scale: What It Actually Takes to Build Real-World Robotics | The Pair Program Ep9686 / 100
  • Designing the Impossible: AI, Quantum Mechanics, and the Future of Materials | The Pair Program Ep9575 / 100
  • From Services to Software: How Dual-Use AI Companies Actually Scale Inside Government | The Pair Program Ep9482 / 100
Explore the best B2B HR podcasts →
All The Pair Program episodes →