Dragos has completed acquisitions of runZero and NetRise, extending its operational technology security platform into broader asset exposure management and software supply chain analysis after the completion of Accenture’s majority investment in the company.
The financial terms of the two acquisitions have not been disclosed. Both management teams are joining Dragos, with runZero chief executive HD Moore, NetRise chief executive Thomas Pace, and NetRise chief technology officer Michael Scott expected to lead integration work while continuing to support existing customers.
runZero adds asset discovery and exposure-management capability across IT, cloud, and operational technology. NetRise works further down the technology stack, analysing firmware and embedded software to identify risks including vulnerable libraries, outdated components, hard-coded credentials, and other weaknesses that may not be visible through network traffic alone.
Dragos is bringing those capabilities into what it calls an extended operational technology, or xOT, model. The term covers not only conventional control systems but the connected devices, cloud services, software dependencies, building systems, data-centre infrastructure, and other technologies capable of influencing a physical operation.
The broader definition reflects the way industrial estates have developed. A production line may still be controlled by PLCs and distributed control systems, but information now passes through engineering workstations, remote maintenance systems, virtual machines, historians, cloud applications, wireless gateways, smart devices, and software supplied by several vendors.
A security team can therefore have good visibility of conventional control-network traffic while remaining uncertain about the firmware inside a connected gateway or the unmanaged devices that have appeared elsewhere on the network. Combining several discovery methods is intended to close more of those gaps.
runZero’s contribution is particularly relevant to asset inventory. Industrial organisations often struggle to keep records accurate because equipment changes during maintenance, temporary engineering systems are connected, vendors introduce appliances, and older machines remain in service long after the databases used to track them were created.
Discovery also has to be handled carefully. Aggressive active scanning can interfere with fragile or legacy systems, while purely passive monitoring may miss equipment that communicates infrequently. A platform combining several techniques can potentially build a more complete inventory without relying on one method.
NetRise addresses a different part of the problem. Industrial products increasingly contain embedded software assembled from open-source components, commercial libraries, operating systems, and proprietary code. A manufacturer may know the model of a controller or gateway without knowing every software component inside it.
That becomes a problem when a vulnerability is disclosed. Security teams have to establish which installed devices contain the affected code before deciding where mitigation is required. Firmware analysis can shorten that process by exposing dependencies that conventional asset-management systems do not record.
The acquisition consequently gives Dragos a stronger position around software bills of materials and emerging product-security requirements. Manufacturers and operators are being asked more frequently to demonstrate what software sits inside connected products, how vulnerabilities are handled, and whether suppliers can provide evidence about embedded dependencies.
Dragos already specialises in OT asset visibility, threat detection, industrial incident response, and adversary intelligence. Its earlier acquisition of Phosphorus expanded coverage of connected and embedded devices, while runZero and NetRise extend that move further beyond the traditional control-system perimeter.
The timing is tied to Accenture’s majority investment, which closed alongside the acquisitions. Dragos says it will continue to operate independently, with Robert M. Lee remaining chief executive and also becoming chairman.
That independence has practical relevance because industrial environments rarely use a single automation vendor. A factory, utility, chemical plant, or data centre may contain equipment from dozens of suppliers accumulated through expansions and acquisitions over many years.
Security tools therefore have to operate across heterogeneous estates. A platform tied too closely to one equipment ecosystem risks missing precisely the assets created by that supplier diversity, while operators often want threat monitoring to remain separate from the vendors whose devices are being assessed.
The challenge for Dragos now becomes integration. Acquiring complementary technologies does not automatically create a common operational view. Asset identities have to be reconciled, duplicate records removed, exposure data correlated, and workflows designed so analysts are not forced to move between separate interfaces for discovery, firmware analysis, and OT threat detection.
Industrial customers will also expect existing runZero and NetRise products to remain usable during that work. Both serve environments beyond traditional process industries, so integration has to preserve IT and cloud use cases while adding the process context required for OT.
That context determines priority. A vulnerable business server and a vulnerable device controlling cooling for a critical data centre can carry similar technical severity scores but materially different operational consequences.
Dragos is effectively betting that asset discovery, software composition, exposure management, and process-aware threat intelligence will increasingly need to sit within one security workflow. The acquisitions provide more of those capabilities; the next test is whether they can be combined without turning three useful products into one more complicated platform.


