Decoding the world of cybersecurity

Dragos closes runZero and NetRise acquisitions

Dragos has completed its runZero and NetRise acquisitions after Accenture’s majority investment, expanding from OT security into asset discovery and software supply-chain visibility.

Dragos closes runZero and NetRise acquisitions
Summary
  • Dragos has formally acquired runZero and NetRise following completion of Accenture’s majority investment.
  • RunZero adds asset intelligence and exposure assessment, while NetRise adds device and software supply-chain analysis.
  • The combination broadens Dragos across OT, connected devices, cloud dependencies, firmware, and industrial asset visibility.

Dragos has completed its acquisitions of runZero and NetRise as part of a wider Accenture-backed consolidation of operational technology security, bringing asset discovery and firmware supply-chain capabilities into the industrial security vendor.

Dragos said the transactions closed alongside Accenture’s majority investment in the company. RunZero adds exposure assessment and asset intelligence, while NetRise brings firmware and software supply-chain analysis focused on connected devices.

The transactions were originally announced in June as part of a combined deal valued by Accenture at about $4.175 billion, subject to adjustments. Cyber Insider covered the proposed structure when the deals were announced; the fresh development is that the acquisitions have now completed.

Accenture’s majority investment in Dragos closed on 16 September, while runZero closed on 17 September. NetRise had already closed on 31 July.

The resulting product strategy expands Dragos beyond the traditional core of operational technology threat detection. The company wants to cover a broader environment of industrial devices, networks, cloud-connected assets, embedded software, firmware, and operational systems.

That reflects how industrial security boundaries have changed. Operational technology networks may still include specialised controllers and engineering systems with long service lives, but they increasingly depend on standard operating systems, remote access, cloud services, management platforms, third-party software, and connected devices.

Asset visibility is a persistent difficulty in those environments. Operators cannot assess exposure reliably if they do not know which devices are present, what software they contain, how they communicate, or which dependencies connect them to broader enterprise infrastructure.

RunZero’s technology is intended to strengthen discovery and exposure assessment across that estate. NetRise approaches the same problem deeper in the product stack by analysing software and firmware inside devices, where vulnerable components and inherited open-source dependencies can remain hidden from conventional network inventories.

The integration also illustrates how the industrial cybersecurity market is consolidating around a wider definition of asset risk. OT security was once treated as a relatively separate discipline built around specialised networks and protocols. The boundary now extends through IT systems, cloud platforms, edge devices, software components, and external suppliers.

European regulation reinforces that expansion. NIS2 places greater emphasis on risk management and supply-chain security across essential and important entities, while the Cyber Resilience Act introduces security obligations for manufacturers of products with digital elements. Operators and manufacturers therefore face overlapping questions about devices, software dependencies, vulnerability management, and third-party exposure.

Vendor consolidation can simplify some procurement and integration work, but it can also concentrate dependence on a smaller number of platforms. Customers will still need to establish where capabilities genuinely integrate, how data from acquired products is combined, and whether contractual or architectural changes alter existing deployment models.

Dragos says it will continue operating independently, with Robert M. Lee remaining chief executive and also becoming chairman. The company has emphasised vendor neutrality, an important consideration in critical infrastructure where asset estates contain equipment from many manufacturers.

The acquisitions do not by themselves create end-to-end visibility across every industrial environment. Their significance lies in the direction of the market: discovery, OT monitoring, firmware analysis, software supply-chain intelligence, and exposure management are increasingly being treated as parts of one operational problem rather than separate security categories.

×