Summary
- Dragos has completed its acquisitions of runZero and NetRise alongside the closing of Accenture’s majority investment.
- runZero adds asset discovery across IT, OT, and cloud environments, while NetRise brings analysis of firmware and software supply chains.
- The enlarged platform reflects the growing overlap between physical operations, embedded devices, enterprise networks, cloud services, and third-party software.
Dragos has completed its acquisitions of runZero and NetRise, extending an industrial cybersecurity platform built around operational technology into asset discovery, cloud visibility, exposure management, and software supply-chain risk.
The transactions closed alongside Accenture’s majority investment in Dragos and follow Dragos’s earlier acquisition of connected-device security company Phosphorus. Although the company describes the resulting environment as “extended operational technology”, the underlying change is more concrete: security teams are being asked to understand systems that now stretch from conventional industrial equipment into embedded devices, enterprise networks, cloud services, and the software components connecting them.
runZero brings technology for discovering and assessing assets across IT, OT, and cloud environments, including information drawn from systems organisations already operate. NetRise focuses on software supply-chain visibility, including analysis of firmware and software components that can introduce vulnerabilities into connected devices long before those weaknesses appear as conventional network alerts.
Dragos said both acquired teams will remain involved in the integration, with senior runZero and NetRise executives joining the enlarged business. Robert M. Lee has also become chairman while retaining the chief executive role, and Dragos says it will continue to operate independently.
Industrial security is spreading beyond control networks
Operational-technology security was once treated largely as the specialist problem of protecting industrial control systems from threats crossing the boundary between corporate networks and production environments. That boundary has become harder to define as factories, utilities, ports, data centres, and other physical operations acquire internet-connected devices, remote management systems, cloud services, and software-defined components.
The result is an asset problem before it becomes a detection problem. An organisation cannot assess the exposure of an industrial environment if it cannot establish which devices, systems, firmware versions, software dependencies, and cloud services can influence it. Nor is a conventional enterprise inventory necessarily enough, because operational networks frequently contain equipment installed over decades, specialist protocols, unmanaged devices, and systems that cannot tolerate aggressive scanning.
runZero gives Dragos a broader discovery layer across that mixed estate, while NetRise adds another level beneath the visible device by examining software components inside equipment. The combination reflects a shift in cyber risk from securing individual endpoints towards understanding the relationships between physical machinery, embedded software, enterprise systems, and external dependencies.
That becomes more consequential as European product-security rules place greater responsibility on manufacturers for vulnerabilities inside connected products. Even where a manufacturer is responsible for maintaining a product, an industrial operator still needs to know where it is deployed, which version is running, whether a vulnerable component is present, and what physical process could be affected if it were compromised.
Accenture adds a services route
Accenture’s majority investment also changes the commercial scale around the enlarged company. The consulting group agreed in June to acquire its Dragos stake alongside full ownership of runZero and NetRise in transactions valued at roughly $4.175 billion in total, while Dragos itself remains independently operated.
That arrangement gives the technology companies access to a large systems-integration and managed-services channel at a time when industrial cybersecurity is becoming harder to separate from wider transformation projects. Modernising a plant network, connecting equipment to cloud analytics, adding remote maintenance, or introducing AI into physical operations can all expand the number of digital paths leading towards systems with real-world consequences.
The acquisitions therefore reflect more than consolidation between security vendors. Industrial organisations have historically bought separate products for OT monitoring, IT asset management, vulnerability analysis, and software composition, while internal teams often maintain separate inventories of the same estate.
Bringing those views together could simplify investigation and prioritisation, although the result will depend on how effectively Dragos integrates the acquired products rather than presenting them through a common commercial wrapper. OT specialists value products that understand industrial protocols and physical processes, while enterprise security teams increasingly want common workflows across their whole estate.
Dragos says its intelligence platform will also absorb information from the expanded product set, including data used by its EmberAI capabilities. More assets and richer software inventories can give analysts additional context, although automated guidance in operational environments carries a higher burden than equivalent tooling around ordinary office systems because an incorrect remediation step can interrupt production or affect safety.
The commercial test will therefore be whether defenders gain a more accurate view of which weaknesses can influence physical operations. As factories, utilities, data centres, and logistics infrastructure accumulate connected systems, the distinction between an enterprise cyber asset and an operational one is becoming steadily less useful.












