Dragos xOT Acquisitions closed on September 21, bringing NetRise and runZero under the operational-technology security company after Accenture completed its majority investment. The combination is designed to connect network asset discovery, exposure management and firmware-level software visibility, but Dragos has not yet published a finished integration roadmap or separate transaction prices.

Dragos xOT acquisitions: what changed at close

The June transaction announcement established the structure: Accenture would acquire a majority stake in Dragos and acquire all of runZero and NetRise, with the two smaller companies moving into the Dragos platform. The September disclosure moves that arrangement from an announced transaction to a completed operating structure.

Dragos says it remains independently operated and vendor-neutral. Co-founder Robert M. Lee has added the chairman role while remaining chief executive. runZero chief executive HD Moore, NetRise chief executive Thomas Pace and NetRise chief technology and chief scientist Michael Scott are joining Dragos and will lead integration work while existing customers continue to receive service.

SecurityWeek independently reported the close, while ITPro’s reporting on the original deal documented the broader transaction structure and the distinct roles of the acquired technologies. Those reports do not independently validate future product performance; they corroborate the deal and its intended architecture.

Dragos acquisition stackFour verified elements of the completed Dragos acquisitions and the security capabilities they add.Dragos acquisition stackCompleted acquisitionsNetRise and runZeroMajority investorAccenturerunZero contributionAsset visibility and exposure managementNetRise contributionFirmware and software-component visibility

Facts at a glance

Item Verified detail Source
Completed acquisitions NetRise and runZero Dragos
Majority investor Accenture Dragos and ITPro
runZero contribution Asset visibility and exposure management Dragos
NetRise contribution Firmware and software-component visibility Dragos

Three visibility layers, one operational question

Operational technology includes the digital systems that influence physical processes: controllers, sensors, industrial networks and the supporting computing systems around them. As those environments connect to cloud services and enterprise networks, a security team needs more than a list of traditional computers. It needs to know what assets exist, what software is inside them and whether an exposed path can affect a physical process.

runZero is positioned at the first two parts of that problem. It consolidates asset and risk data across IT, internet-of-things, cloud and operational environments. That helps teams find systems that are missing from a central inventory and compare exposure signals without assuming that one scanner can safely interrogate every industrial device.

NetRise works deeper in the stack. Its technology analyzes firmware and software components embedded in connected equipment. The practical use is identifying inherited vulnerabilities, obsolete libraries or hardcoded credentials that may not be visible from network telemetry alone. For regulated operators, a software component inventory can also support documentation obligations.

Dragos already provides operational-technology monitoring, threat intelligence, vulnerability management and incident-response expertise. The combined proposition is therefore not simply three dashboards in one sales bundle. It is a chain of evidence from an observed device, through its software contents and exposure, to activity that may threaten a physical process.

Why integration quality matters more than deal size

The June announcement placed a combined enterprise value of about $4.175 billion on Accenture’s majority investment in Dragos and its acquisitions of runZero and NetRise, subject to adjustments. That number describes the wider set of transactions; Dragos did not disclose stand-alone purchase prices for the two acquisitions in its September close announcement.

The better customer question is whether the combined data remains explainable. Industrial defenders need to distinguish a discovered asset from a confirmed vulnerability and a vulnerability from an actively exploitable path. If product integration collapses those distinctions into one score, teams can gain noise rather than visibility.

Vendor neutrality is also operational, not rhetorical. Critical infrastructure sites often contain equipment from many manufacturers with long replacement cycles. Dragos says it will preserve neutrality, but customers should test whether integrations continue to import third-party data cleanly and whether recommendations avoid steering them toward a narrow stack.

The acquisition also introduces execution risk. Existing runZero and NetRise users need continuity, stable APIs, retained expertise and a clear migration path. Dragos says the full teams are joining and that current customers will continue to be served. Detailed sequencing, packaging and pricing remain future disclosures.

How the combined xOT evidence chain worksA three-step flow from asset discovery through firmware visibility to operational monitoring, ending in analyst prioritisation.Combined xOT evidence chain1. Discover assetsIT · OT · IoT · cloud2. Inspect softwareFirmware · components3. Monitor operationsThreats · exposureAnalyst traces priority back to evidence

What critical-infrastructure buyers should verify

Buyers can ask for four concrete demonstrations. First, show how the platform resolves duplicate identities when the same device appears in network telemetry, a cloud inventory and a firmware record. Second, show which claims are observed directly and which are inferred. Third, show how an analyst can trace a risk score back to evidence. Fourth, show how the system behaves when a fragile industrial endpoint cannot tolerate active scanning.

They should also separate visibility from remediation. Finding an outdated embedded component does not mean a patch exists or can be applied without affecting safety certification. The platform’s value will depend on whether it helps operators prioritize compensating controls, segmentation or maintenance windows when replacement is not immediate.

Recent supply-chain incidents reinforce that distinction. Lapaas Voice’s report on the indexed-btree disclosure exposes a runtime blind spot showed how malicious code can evade a narrow review, while the Plugin4Shell shows why a pin is not verification case showed why recorded identifiers still need verification.

The consequence of the completed deal

The September close gives Dragos control of the teams and technology needed to attempt an end-to-end xOT platform. It also gives customers a clearer accountability point: one company now has to make discovery, firmware intelligence and operational monitoring work together in live environments.

Dragos xOT acquisitions matter because they join complementary security evidence, not because consolidation automatically makes infrastructure safer. The next proof points are documented integrations, preserved third-party compatibility and measurable reductions in unknown or untriaged operational assets.

Frequently asked questions

What did Dragos acquire?

Dragos completed its acquisitions of runZero and NetRise, bringing their teams and technologies into its extended operational-technology security platform.

What does runZero add to Dragos?

runZero adds asset discovery and exposure management across IT, operational technology, connected devices and cloud data sources.

What does NetRise add?

NetRise examines firmware and software components inside connected devices to identify issues such as outdated components and hardcoded credentials.

Are product integrations complete?

No. Dragos said existing customers will continue to be served and that more detailed integration plans will be shared later.

Get the day’s top stories in your inbox

One concise email. No spam, unsubscribe anytime.