Breaking
PREVENTION-FIRST  OPSWAT assumes every file is malicious until proven safe NUCLEAR  Trusted by 98% of US nuclear power facilities 2026  Launches proprietary AI-native pre-execution detection engine SPACE  Sends a device toward space to test extreme-environment security SCALE  ~1,200 employees, customers in 100+ countries DEEP CDR  Rebuilds files clean instead of just scanning them FUNDING  Bootstrapped 19 years, then raised $125M from Brighton Park Capital
Company · Critical Infrastructure Cybersecurity

The Company That Assumes Every File Is Trying to Kill You

Benny Czarny bootstrapped OPSWAT for 19 years on a simple, paranoid idea: assume every file is malicious. Today that assumption guards 98% of US nuclear plants.

Most cybersecurity companies spend their days chasing the newest threat, hoping to recognize the next attack a half-step faster than everyone else. OPSWAT built a business on the opposite instinct. Its founding assumption is almost rude in its pessimism: every file is malicious until it can be proven otherwise. Not most files. Every one. That single stubborn premise, held for more than two decades, is why an unglamorous company from Tampa now sits between attackers and the machinery that runs power grids, factories, airports and government networks in over 100 countries.

The premise has a name in the industry - "prevention over detection" - but OPSWAT treats it less like a marketing line and more like a religion. Detection asks a question: is this thing bad? Prevention refuses to trust the answer. If you assume the file is already a weapon, you stop trying to spot the bomb and start defusing every package that arrives, whether it's ticking or not.

01What OPSWAT actually does

OPSWAT sells software and hardware that inspects, cleans and controls the data and devices flowing into sensitive environments. Its flagship is the MetaDefender platform, where files are scanned, sanitized, verified and controlled before they're allowed to move deeper into a network. The companion product, MetaAccess, does the same paranoid gatekeeping for devices - blocking noncompliant or risky laptops and phones from reaching corporate and cloud resources.

OPSWAT team reviewing a tablet in a server room
The room nobody photographs. OPSWAT's world is server closets and control rooms, not glass-walled startup lofts - the places where a single infected file has physical consequences.

Underneath those platforms are the ideas OPSWAT is known for. Deep CDR - Content Disarm and Reconstruction - takes a file apart, discards anything that could carry an attack, and rebuilds a clean, working copy. Metascan multiscanning runs a single file past more than 30 antivirus engines at once, on the logic that no one vendor catches everything. Around those sit sandboxing, threat intelligence, network access control, and a family of hardware for the hardest environments: scanning kiosks, data diodes and unidirectional gateways.

How a file gets in - the prevention pipeline
SCAN
Multiscan
30+ engines check one file at once
DISARM
Deep CDR
Strip and rebuild the file clean
DETONATE
Sandbox
Watch suspicious files behave
CONTROL
Verify
Allow only what's proven safe

02The USB stick problem

To understand why any of this matters, forget the movie version of hacking. In critical infrastructure, one of the scariest attack surfaces is boringly physical: the USB stick a contractor carries through the gate. Power plants, water systems and factories often run on air-gapped networks - deliberately cut off from the internet - which sounds unhackable until you remember that someone still has to move data across that gap to do their job.

That's the moment OPSWAT built its hardware for. A MetaDefender Kiosk forces removable media through inspection before it's allowed near a secure network. A data diode lets information travel in one direction only, giving attackers no return path. It's cybersecurity you can trip over, and it's precisely the part of the problem most software-only vendors would rather not touch.

Detection can be fooled. Reconstruction can't - if you rebuild the file, the bomb is gone by construction. The Deep CDR thesis
OPSWAT MetaDefender dashboard showing blocked and processed objects
The receipts. A MetaDefender console tallies what got blocked and what got through - the kind of screen an operator at a utility stares at all day so nothing weird makes it downstream.

03Why multiscanning is just math

OPSWAT's habit of running many antivirus engines at once isn't showing off - it's statistics. Any single engine misses a slice of threats. Stack enough independent engines and the odds of all of them missing the same file collapse toward zero. In an office, a missed file is an annoyance. In a nuclear facility, the tolerance for "roughly 10% miss rate" is nonexistent.

1 engine
~90%
8 engines
~98%
20+ engines
~99%+

Illustrative: detection coverage rises as independent engines are combined. Exact rates vary by threat and configuration.

04The 19-year head start

The most unusual thing about OPSWAT isn't a product - it's the founder's patience. Benny Czarny started the company in a San Francisco apartment in 2002, after technical leadership roles at NetManage, Netect and BindView. Then he did something almost nobody in security does: he refused outside money for roughly 19 years, growing a one-person startup into a global organization on revenue alone.

When OPSWAT finally raised, it wasn't a scrappy seed round - it was $125 million from Brighton Park Capital in 2021. By then the company had a profitable business, a real product moat, and no need to explain itself to a boardroom for two decades. In 2022 it moved its headquarters from Silicon Valley to Tampa, Florida, and kept expanding.

2002
Founded in a SF apartment
98%
Of US nuclear plants trust it
100+
Countries served
$125M
First institutional raise
~1,200
Employees worldwide
~$122M
Reported annual revenue

05Ten acquisitions, one platform

OPSWAT didn't build everything itself. It ran a patient roll-up, buying capabilities and folding them into MetaDefender rather than letting them drift as separate products. The pattern is consistent: acquire a piece that critical-infrastructure customers need - network access control, sandboxing, OT visibility, threat intelligence - and integrate it into the prevention pipeline.

2012
Napera Networks - network monitoring
2015
Red Earth Software - email security
2019
Impulse - network access control and SDP
2021
Bayshore Networks + SNDBOX - OT/ICS and sandboxing
2022
CIP Cyber + FileScan.IO - training and file analysis
2024
InQuest + Fend - federal, threat intel and data diodes

06Who buys it, and who it competes with

OPSWAT's customers cluster where the cost of a breach is measured in more than dollars: energy and utilities, government and defense, manufacturing, transportation, finance and healthcare. Its technology is also embedded inside products from Cisco, Microsoft, F5 Networks, Symantec and Juniper - which makes OPSWAT something rare, a vendor other vendors quietly build on.

On content disarm it lines up against Votiro, Glasswall and Sasa Software. In OT security it meets Claroty, Nozomi Networks, Dragos and Forescout. In network access control it runs into Cisco ISE and Forescout again. But its broadest competitor is a mindset: the detection-first, single-engine antivirus model that OPSWAT has spent 20 years arguing against.

What separates OPSWAT in a crowded market is less any single feature and more the seam where its pieces meet. Rivals tend to be excellent at one layer - a great sandbox, a sharp OT sensor, a slick CDR engine. OPSWAT's argument is that critical infrastructure doesn't buy layers, it buys a pipeline: the same file inspected, disarmed, detonated and controlled in one flow, with the hardware to carry it across an air gap when needed. Owning that whole path, rather than a slice of it, is the moat.

07Where the expertise lives

Two decades in one problem space compounds into something hard to copy. OPSWAT's engineers have spent years on the unglamorous edge cases - the malformed file formats, the obscure OT protocols, the removable-media workflows a regulator will actually audit. That depth shows up in its certification work, where OPSWAT has long run programs that test how security applications interoperate, and in OPSWAT Academy, a free training arm that turns practitioners into certified users and, not incidentally, into advocates. The company is deliberately building the talent pipeline for its own category.

Geographically the expertise is spread across more than ten offices, from Tampa and Washington, D.C. to Romania, Hungary, Israel, the UK, the UAE, Vietnam and Japan - a distributed engineering footprint that reflects both the acquisitions it absorbed and the round-the-clock nature of defending infrastructure that never sleeps.

Engineer with a laptop working among server racks in a data center
Where the stakes live. Racks like these run utilities and factories. OPSWAT's pitch is aimed squarely at the operators who can't afford to find out a file was malicious after it executed.

08The business model, in plain terms

OPSWAT is B2B all the way down. It licenses MetaDefender and MetaAccess as subscriptions, sells the OESIS and MetaDefender SDKs to other security vendors, ships purpose-built hardware for the hardest environments, and layers on professional services, managed services and a free training arm - OPSWAT Academy - that turns practitioners into certified users. The mix leans heavily on high-compliance sectors, where regulation makes prevention a requirement rather than a nice-to-have.

At OPSWAT, we've always believed that security begins with prevention, and the assumption that every file is malicious. Benny Czarny, Founder & CEO

09What's next

Even a prevention purist has to reckon with AI. In April 2026 OPSWAT launched its Predictive AI Engine, an AI-native, pre-execution detection engine for MetaDefender that judges a file as malicious or safe before it ever runs - carefully positioned as a way to make security teams faster, not to replace them. Two months later the company did something with a straight face that most would call a stunt: it sent a device toward space to show its prevention-first approach holds up in the most extreme environment there is.

It's an oddly fitting flex for a company built on paranoia. If your entire thesis is that you can't trust the world around a file, you may as well test it where there's nothing around it at all.