All
Loading article…

Critical Infrastructure has a Security Problem. Solitude Labs has a Fix.

How a zero-trust security layer is protecting vulnerable industrial systems from cyberattacks.

Last year, a cyberattack on Jaguar Land Rover's manufacturing operations in the UK cost the company hundreds of millions of dollars and was significant enough to register as a drag on the country's GDP. It wasn't a breach of a website or a leaked database. Attackers got into JLR's corporate IT network — and because that network wasn't properly separated from the systems running the factory floor, the company had no choice but to shut down production entirely. Cars didn't roll off the line for roughly five weeks.

Daniel Kawiecki wasn't surprised. As co-founder and COO of Solitude Labs , an operational technology (OT) cybersecurity startup, he's spent the past two years trying to get ahead of exactly that kind of attack. "You can look at numerous incidents in the past six to 12 months to see how big of an impact this can have on a business," he said. "And now AI is enabling hackers to perform automated attacks and discover software vulnerabilities faster than ever."

The good news, Kawiecki will tell you, is that there's a lot we can do about it — but that starts with understanding why these systems are so exposed in the first place. The industrial systems running power grids, refineries, and manufacturing plants were largely built around a security assumption that made sense 20 years ago but looks increasingly reckless today.

Solitude Labs got its start in late 2024, when Kawiecki and two co-founders — all graduate students at the time — began pulling on that thread. Kawiecki was pursuing a PhD in mechanical engineering at the University of Illinois at Urbana Champaign (UIUC). Nikita Volynskiy, co-founder & CTO, was completing a master's in computer science also at UIUC. James Wolf, the CEO and the one who first identified the problem, was in a master's program at the University of Chicago, and had worked at Spider Oak, a cybersecurity firm that serves the U.S. government. He'd seen the gap firsthand.

"James approached Nikita and I, looking at some of the cybersecurity problems on the electric grid," Kawiecki said. "We went around and talked to professors, research scientists, and industry experts working in this space, and we quickly realized this was a significant problem."

The problem, in short, is this: industrial networks — the computers and control systems that run physical infrastructure, as distinct from the laptops and servers of traditional IT — were originally designed to run in isolation, with no expectation they'd ever touch the internet or a corporate network. That assumption meant security was never built into the devices or protocols themselves — no authentication, no encryption, no rules about who could talk to whom. As long as the network stayed physically isolated, that didn't matter. But as operators connect these systems to the internet and to IT networks for remote access, data collection, and operational efficiency, the risk increases. Each new connection is another way past a boundary that was only ever meant to be a single line of defense, and once an attacker is inside, there's nothing to stop them: devices still communicate in clear text, with no authentication, and no rules about who can talk to what.

This is known as the castle-and-moat model in cybersecurity.

"You rely on the perimeter firewall, and everything else inside is essentially isolated from the outside world," he said. "That might have been a good approach 20 years ago. Today, this approach is simply not enough to protect your environment."

Two things have eroded the castle-and-moat model. The first is IT/OT convergence — the business pressure to connect industrial systems to the internet for operational efficiency, which pokes holes in the perimeter whether organizations want it to or not. The second is AI, which has lowered the bar for attackers and dramatically accelerated the pace at which software vulnerabilities get discovered and exploited.

Solitude Labs' answer is a zero-trust security overlay. The company deploys nodes across a customer's network — software or hardware gateways that give each industrial device a cryptographic identity. Solitude’s management console then lets operators configure secure communication channels and set precise rules: which devices can communicate, under what conditions, over which protocols. The effect is that every device becomes its own security perimeter: even after breaching the outer firewall, an attacker can't just talk to anything on the network — every connection has to prove its identity and satisfy policy first. Instead of being free to roam around in a flat, trusting network, they hit a wall.

"You're now eliminating that widespread attack vector and reducing operational risk for the customer," Kawiecki said.

From those grad-school origins, the company has moved quickly. Winning third place in both the University of Chicago's New Venture Challenge and the University of Illinois' Grainger Engineering Challenge, gave the team its first real runway. Today Solitude Labs works across electric and water utilities, oil and gas pipelines and refineries, data centers, and a range of manufacturing environments. Data centers and robotics are areas Kawiecki flags as fast-emerging opportunities.

The Grainger prize earned Solitude Labs access to TeamWorking by TechNexus — the shared workspace from TechNexus Venture Collaborative. Between having dedicated downtown Chicago space for its team, access to advisors who also use the space, and as a space to connect with customers, TeamWorking has given Solitude Labs a centralized location to support the company's growth.

"It's great to have that space available to us," Kawiecki said. "If we want to bring in customers and get a conference room — just the other people who are working there are great. You get the benefit of being able to talk to other startups and see what kinds of problems they're facing."

Solitude Labs is working on problems most people walk past every day without knowing it. The meter on the side of your house, the lines running into it, the systems managing the gas flowing to your stove — all of it runs on infrastructure that was never built with modern threats in mind. Solitude Labs is betting that's about to change, and that the companies moving first to secure it will define the next generation of critical infrastructure protection.

By Jim Dallke at TechNexus Venture Collaborative