The Deal Closes
Industrial cybersecurity vendor Dragos has completed its acquisitions of NetRise and runZero, finalizing a broader restructuring that began with Accenture's $4.1 billion investment announced in June 2026. That deal saw Accenture acquire a majority stake in Dragos at a $3.25 billion enterprise valuation; specific financial terms for the two follow-on acquisitions have not been disclosed.
What Each Company Brings
NetRise specializes in firmware-level visibility, giving Dragos insight into device exposure and software supply chain risk that sits below the network layer most OT monitoring tools operate at.
runZero, founded by Metasploit creator HD Moore, contributes asset discovery, exposure assessment, and attack surface intelligence — capabilities more commonly associated with IT security than industrial environments.
Combined with Dragos' existing operational technology asset visibility and threat detection platform, the acquisitions are aimed at what Dragos leadership is calling "xOT" — the extended environment of systems, devices, and firmware that can affect physical processes, spanning both traditional OT and the IT infrastructure increasingly connected to it.
Leadership
Dragos CEO Robert M. Lee continues in his role and has also assumed the position of chairman. Key leaders from both acquired companies are joining Dragos to lead platform integration — including runZero's HD Moore and NetRise's Thomas Pace.
Strategic Rationale
The combined platform is targeted squarely at critical infrastructure operators — electric utilities, oil and gas, manufacturing, and data centers — where the line between IT and OT exposure has been steadily eroding. As Lee put it, organizations "need to defend every system that can influence a physical process," a framing that extends Dragos' traditional OT-only remit into firmware and general IT asset exposure.
Why This Matters
This is the second act of a deal CosmicBytez Labs flagged when it was first announced: Accenture's investment in Dragos was never just about capital, it was about assembling a broader exposure management platform for critical infrastructure operators who have historically had to stitch together separate OT monitoring, firmware analysis, and IT asset discovery tools from different vendors. Consolidation like this tends to simplify vendor management for asset owners, but it's also worth watching whether integration actually happens at the product level or whether these remain three separately-operated tools under one sales umbrella.