Dragos Broadens Its xOT Cybersecurity Platform Strategy

Author photo: Larry O'Brien
ByLarry O'Brien
Category:
Acquisition or Partnership

OT Cybersecurity Market Development Is Increasing Platform Demand

The industrial cybersecurity market is evolving as organizations reassess fragmented security architectures. Over much of the past decade, many companies deployed separate tools for asset discovery, network monitoring, threat detection, vulnerability management, remote access, risk assessment, and incident response. As threat activity increases and operational environments become more interconnected, some organizations are considering more integrated approaches to improve visibility, reduce operational complexity, and support more consistent security outcomes.

Recent acquisitions and governance changes at Dragos, including the acquisitions of NetRise and runZero, indicate that the company is broadening its xOT cybersecurity strategy. Dragos has historically focused on OT threat detection, threat intelligence, and incident response. Its current direction extends that focus to a wider platform for extended operational technology, or xOT. This approach reflects the expansion of operational environments beyond traditional industrial control systems to include connected devices, cloud-connected applications, software supply chains, and digital infrastructure that can affect physical processes.

Established Position in OT Cybersecurity

Dragos has developed a recognized position among OT cybersecurity specialists. Its platform provides industrial asset visibility, threat detection, incident response, and OT-focused threat intelligence. ARC research identifies Dragos as a notable participant in the industrial and OT cybersecurity market, particularly for organizations that value operational-domain expertise and knowledge of industrial threat activity. The company’s market position centers on protecting environments that support critical infrastructure and industrial production.

Extending Coverage Beyond Traditional OT: Phosphorus

Dragos accelerated its platform expansion in 2026. In June, the company acquired Phosphorus, adding connected-device security capabilities. The transaction extended Dragos’ visibility into devices operating within industrial and critical infrastructure environments. Phosphorus contributes device discovery, credential management, automated remediation, and connected-asset hardening. These capabilities expand the Dragos platform beyond industrial networks to include a broader range of operationally relevant connected devices.

Accenture Investment Supports a Broader Growth Strategy

Shortly afterward, Accenture announced plans to acquire a majority interest in Dragos. This majority stake, combined with the runZero and NetRise acquisitions, supports a broader cybersecurity platform encompassing asset visibility, exposure management, software supply chain security, and OT threat operations. Accenture reported that its majority investment in Dragos closed on September 16, 2026, followed by the runZero acquisition on September 17, 2026. NetRise had previously closed on July 31, 2026. After the closing, Dragos acquired runZero and NetRise. Industrial cybersecurity programs often require consulting, systems integration, architecture design, managed services, and organizational change management. Accenture’s global presence and industrial customer relationships will support broader deployment of Dragos technologies among large critical infrastructure operators.

runZero and NetRise Address Additional Platform Requirements

runZero adds asset discovery and exposure management across IT, OT, IoT, and cloud environments. NetRise contributes firmware analysis and software supply chain visibility, enabling organizations to identify vulnerabilities and assess risk within device firmware and embedded software components. Together with Phosphorus, these technologies extend the Dragos platform's functional coverage.

The acquisitions add the following capabilities to the broader platform:

  • Dragos Core Platform: OT asset visibility, threat detection, threat intelligence, and incident response.

  • Phosphorus: Connected-device discovery, credential management, and remediation.

  • runZero: Asset discovery and exposure management across IT, OT, IoT, and cloud environments.

  • NetRise: Firmware analysis and software supply chain visibility.

Collectively, these capabilities broaden Dragos’ coverage toward a more comprehensive cyber-physical security platform.

xOT Defines the Broader Strategic Direction

From ARC’s perspective, the strategic significance of these acquisitions lies less in the individual products than in the combined architecture they could support. The strategy addresses a challenge faced by many industrial organizations: operational risk increasingly originates from systems outside traditional control networks. Cloud-connected analytics platforms, edge devices, wireless sensors, software-defined infrastructure, engineering workstations, and connected operational applications can all affect physical processes. The company’s xOT strategy reflects a need for visibility and protection across the broader operational ecosystem rather than only within traditional OT environments. Addressing this scope requires coverage of assets, software, devices, networks, and cloud-based infrastructure.

Integration Will Be a Key Execution Requirement

The acquisitions have a clear strategic rationale, but their value will depend on execution and integration. Cybersecurity acquisitions do not always result in cohesive platforms. Industrial customers increasingly expect unified workflows, integrated analytics, consistent user experiences, and common data models. Providing these capabilities across several acquired technologies will require sustained engineering investment and coordinated product development.

Competitive activity is also increasing. Suppliers including Claroty, Nozomi Networks, Armis, Fortinet, Palo Alto Networks, Microsoft, and others are pursuing broader OT cybersecurity strategies. All of these companies are emphasizing platform integration, ecosystem partnerships, operational outcomes, and data quality rather than individual security functions alone.

Engage with ARC Advisory Group

Representative End User Clients
Representative Automation Clients
Representative Software Clients