Turning OT Security Findings into Action with Frenos 3.7

Turning OT Security Findings into Action with Frenos 3.7
An OT security team finishes an assessment and brings the findings to operations. There are viable attack paths to critical systems. There are vulnerabilities worth addressing. There are recommendations. It’s all a bit overwhelming.
Then someone asks, “What do you actually want us to change?”
That is where the harder conversation begins.
A patch may need to wait for a maintenance window. A firewall rule may support a process nobody wants to interrupt. A recommendation that looks straightforward on a security dashboard may involve several asset owners, an equipment vendor, and a plant manager who needs to understand the operational implications.
The team needs to explain how the exposure exists, what an attacker could accomplish, and which changes would make a meaningful difference. Frenos 3.7 is built around helping teams have that conversation and make defensible decisions.
Explore the exposure picture, then select a segment to investigate the findings behind it.
The new exposure view gives that conversation a starting point. Teams can explore how findings fall across exposure and prioritization dimensions, then follow a segment into the specific issues behind it. They can narrow the investigation to a site, business unit, or network and begin answering the question that matters to the people responsible for that environment: where should we focus?
From there, the redesigned Defend experience brings the finding, affected assets, attack paths, and mitigation options together. The investigation has a thread people can follow, from the broader exposure picture down to the evidence behind a proposed change.
Consider a vulnerable system supporting an operational process. Replacing or patching it may be difficult in the near term. The security team still needs to understand whether an attacker can reach it, what conditions make the modeled attack possible, and whether another change could interrupt that path.
That is a much more useful discussion to bring to operations. It gives people something concrete to evaluate: an access relationship, a set of affected assets, a mitigation option, and the expected effect on the modeled exposure.
It also raises a fair question: “How do we know?”
We want customers to ask that. A recommendation should hold up when someone looks closely at the reasoning behind it.
In Frenos 3.7, Defend makes the supporting evidence part of the investigation. Findings draw on modeled network behavior, attack path information, asset and vulnerability relationships, and segmentation data. Analysts can examine what supports a finding and where the available information leaves uncertainty.
When the evidence supports a condition, Frenos identifies it as confirmed within the model. When a scenario is plausible but the data is insufficient, it remains unconfirmed. That distinction helps the team decide whether it has enough information to act or needs to investigate further.
For the person being asked to approve a change, that transparency matters. They need to understand what the recommendation rests on, especially when the change could affect production.
The next question is usually, “What are our options?”
OT teams make security decisions within real operating constraints. A mitigation has to fit the equipment, the process, and the time available to implement it. Sometimes the preferred long-term fix is different from the change the team can make this week.
The updated Trade-Offs experience helps teams compare available mitigation approaches for a finding. It brings projected security outcomes together with implementation effort and operational considerations. Teams can examine how the options differ in exposure reduction, protection of critical assets, and threat relevance, alongside what each would take to implement.
The people responsible for the environment still make the decision. Frenos gives them a clearer basis for making it and guidance for implementing and verifying their chosen response.
External connectivity is another part of that conversation that deserves more scrutiny. A connection at the edge of an environment can have implications several steps deeper into the network. Understanding those implications requires a model that represents the Internet boundary explicitly.
Frenos 3.7 adds that context to the Digital Twin. Teams can inspect Internet boundaries, explore connected networks, and review the evidence behind an Internet-facing classification. Where imported configurations need additional context, manual boundary definitions let customers contribute what they know about their environment.
That brings external exposure into the same investigation as the internal paths and assets it may affect.
SAIRA Co-Work helps analysts work through these questions with deeper awareness of Defend findings. They can ask about affected assets, priorities, related findings, and mitigation opportunities, then return to conversations linked to those findings as the investigation develops. The evidence remains available for inspection as analysts use SAIRA to explore it.
We have also strengthened the foundations that support this work: more granular platform access controls, native MFA for local accounts, richer integration data, and improvements for large investigations and disconnected deployments. These capabilities help teams put Frenos to work within the access requirements and operating conditions of their own environments.
The moment that matters comes when the security team returns to operations with a proposal people can evaluate.
Here is the exposure. Here is the evidence behind it. Here are the systems affected. Here are the available changes and the trade-offs. And here is how we will use repeatable simulation to verify whether the selected change blocks the modeled attack path.


