On a corporate network, the ordinary prescription for a sick machine is familiar: isolate it, patch it, restart it. Try that casually inside a refinery, power station or water plant and the cure can become an outage. Industrial equipment is old by software standards, stubborn by design and attached to physical processes that do not appreciate surprises. Dragos built its company around this inconvenient fact. It sells visibility, threat detection, vulnerability guidance and response expertise for operational technology, or OT - the controllers, workstations, sensors and networks that make heavy machinery behave.
The customers are asset owners rather than app users: electric utilities, oil and gas operators, manufacturers, water systems, mines, transport networks, pharmaceutical plants, government agencies and even breweries. Public examples include Koch Industries, Boston Beer Company, Dominion Energy, Lundin Mining and Littleton Electric Light & Water Departments. Dragos says its platform now watches 7.8 million assets across hundreds of industrial facilities and protects systems on which 507 million lives depend. Those numbers are company claims, but they describe the unusual shape of the market. The person benefiting from a detection may never see the dashboard. They just expect the tap, train or bottling line to keep working.
The reluctant vendor and the prototype that ran out of road
The Dragos origin story is better than the usual garage mythology because one founder had to be talked into the company. Robert M. Lee, Jon Lavender and Justin Cavinee had worked in the U.S. intelligence community. Around 2012 and 2013 they built CyberLens, a tool that processed packet captures and drew a map of industrial devices and protocols. It was useful for Lee's students and assessments. It also carried the limitation of many expert-built tools: three people could get it working, but the software did not yet have the scale or stability of a product that a large utility could run every day.
Lee has written that he disliked much of the cybersecurity vendor culture - the snake oil, the easy claims, the temptation to take credit for a smart operator's work. Mike Assante, an influential industrial-security practitioner and Lee's mentor, pushed him to make the leap anyway. The argument that changed Lee's mind was not that software was glamorous. It was that hard-won knowledge needed a distribution system. Dragos, Inc. was founded in May 2016 to codify what a scarce group of practitioners knew and put it in front of defenders who could not all hire the same experts.

“The product is not merely a map of machines. It is a way to bottle practitioner judgment without pretending the bottle can replace the practitioner.”YesPress analysis
The cost of making that leap was substantial. Dragos raised a $1.2 million seed round in 2016, $37 million in a 2018 Series B, $110 million in a 2020 Series C, $200 million in a 2021 Series D and another $74 million in 2023. Total disclosed funding reached roughly $440 million. The 2021 round valued the company at a reported $1.7 billion. This was not a weekend conversion of a script into SaaS. It required industrial protocol support, deployable sensors, threat researchers, an incident-response bench, enterprise sales, and the trust to sit inside networks where mistakes can affect physical safety.
What Dragos actually sells
The Dragos Platform begins with asset discovery. It listens passively to network traffic, with targeted active collection available when an operator decides it is safe. Deep packet inspection identifies the industrial dialects spoken by programmable logic controllers, human-machine interfaces and newer connected devices. A continuously updated inventory shows what is present, how it communicates and where a strange connection appears.
Next comes prioritization. A generic vulnerability scanner can produce an impressive list and a useless panic. Industrial teams often cannot patch immediately because a vendor has not approved the update, replacement parts are scarce or downtime is scheduled months away. Dragos adds OT-specific context and uses a “Now, Next, Never” framework. The company says only about 3 to 6 percent of OT vulnerabilities require immediate action. For the rest, it can suggest mitigations such as segmentation or monitoring rather than a reckless patch sprint.
Threat detection sits on top of that context. Dragos researchers track more than 26 OT-focused adversary groups and study malware, infrastructure and tactics. Their findings become detections, vulnerability notes and step-by-step response playbooks delivered through regular Knowledge Packs. WorldView sells the underlying threat intelligence. OT Watch adds managed threat hunters for organizations that lack a specialist team. Professional services cover assessments, architecture, tabletop exercises, proactive hunting and incident response. Neighborhood Keeper lets participants share anonymized threat observations, creating a collective-defense signal across companies and geographies.
In 2026, Dragos extended the package in two directions. It acquired Phosphorus to cover the many connected xOT devices that sit beside traditional control systems, including credential and hardening problems. It also introduced EmberAI, an assistant built on what Dragos calls its Intelligence Fabric: telemetry, protocol knowledge, adversary research, vulnerability work and years of incident-response experience. The sensible part of the pitch is “analyst first.” In an environment where an automated recommendation can touch physical operations, a faster answer is valuable only when a human can inspect its context.

The moat is the commute from fieldwork to code
Dragos competes with specialists such as Claroty, Nozomi Networks, Armis and Forescout, plus OT offerings from Microsoft, Tenable, Cisco and others. Its differentiation is not simply that it can inventory a controller. Several competitors can. The more defensible claim is organizational: threat analysts, vulnerability researchers, consultants and incident responders feed their observations back into the platform. The software ships with an opinion about which alert matters and what the operator should do next.
This is also the business model. Enterprise customers buy subscriptions, usually with quote-based pricing shaped by sites, sensors, assets and deployment choices. They can add intelligence, managed hunting, training and professional services. Dragos sells through its own team, channel partners and cloud marketplaces. Microsoft integrations send OT context into Sentinel and Defender and support Azure deployment. AWS provides another cloud and procurement route. Palo Alto Networks integrations help translate asset context into firewall segmentation decisions.
Boston Beer offers the most legible public result. The brewer paired the platform with OT Watch while modernizing manufacturing security. Its case study reports 100 percent return on investment in the first year of a five-year program and a 15 percent year-over-year reduction in cybersecurity insurance premiums. Vendor case studies deserve the usual squint, but these figures point to an effective sales language: less downtime risk, a smaller workload, better insurance economics and clearer coordination between IT, plant teams, executives and the board.
Accenture's June 2026 agreement to acquire a majority stake in Dragos puts the company inside a much larger industrial-services machine. The announced $4.175 billion enterprise value also covers Accenture's full acquisitions of runZero and NetRise, so it is not a standalone price for Dragos. Together, the three businesses were estimated to produce about $208 million in annual recurring revenue as of June 2026. The strategic logic is clear: combine Dragos detection, runZero exposure assessment and NetRise device supply-chain security with Accenture's industrial client access. Dragos is expected to remain independently led by Lee, assuming the transaction closes as planned.
What a founder can steal - and where it breaks
Build beside the people doing the manual work. Their repeated decisions are the first product specification.
Passive-first monitoring and careful patch guidance exist because industrial systems punish generic security habits.
Feed incidents, hunts and assessments back into detections, intelligence and playbooks for every customer.
Reduced workload, insurance savings and safer uptime travel farther than a long list of security acronyms.
The most copyable Dragos idea is to treat services as product research instead of an embarrassing non-recurring sideline. Every assessment exposes a workflow. Every incident reveals an attacker behavior. Every threat hunt tests a hypothesis. When those lessons become product updates, expertise compounds instead of remaining trapped in a consultant's notebook. The second useful move is collective defense: give customers a safe way to contribute observations, then return a stronger signal to the network.
Conditions where the blueprint fails
This model is a poor fit when the problem is ordinary IT, the buyer wants a cheap self-serve tool, or the vendor lacks continuing access to real practitioners and incidents. It also falters when a customer will not maintain sensors, ownership, network architecture or response procedures. Visibility without authority produces a beautiful inventory of problems. AI without OT context produces faster guesses. And a services team that never feeds the product is simply an expensive services team.
Dragos spent a decade making an unfashionable category legible. The company did not invent industrial control systems, and it does not make them easy. It built a translation layer between the engineers who keep physical processes alive and the defenders who understand adversaries. CyberLens failed first at scale; the commercial platform answered that failure with capital, process and distribution. Assante changed Lee's mind by reframing a software company as a teaching mechanism. That may be the cleanest reading of Dragos: a very large classroom attached to machines with no convenient off switch.