Dragos helps industrial organizations protect the operational technology that keeps power, water, manufacturing, transportation, and other physical systems running.
Most cybersecurity stories begin with stolen data. Someone clicks the wrong link, a password is exposed, a company loses customer records, and the damage is measured in privacy, money, and trust.
But there is another version of cybersecurity where the stakes are more physical. A power plant needs to keep generating electricity. A water utility needs pumps and treatment systems to behave predictably. A manufacturer cannot casually reboot the equipment that keeps a production line moving. In these environments, cyber risk is not only about information. It is about uptime, safety, resilience, and the ordinary systems people assume will work because they usually do.
Dragos, one of our portfolio companies, is built for that world. Led by CEO and co-founder Robert M. Lee, the company helps organizations protect operational technology, or OT, which is the hardware and software that controls industrial processes in sectors like electric power, oil and gas, manufacturing, water, transportation, chemicals, food and beverage, and pharmaceuticals. For us, Dragos sits at the center of a larger shift: the systems that run the physical world now need the same level of cyber attention as the systems that run the digital one.
When our partner Joydeep Bhattacharyya first met Rob, that view was far from consensus. Industrial cybersecurity was still dismissed by many investors as a niche market with slow sales cycles, difficult customers, and disappointing margins; Rob had even been urged to pivot to cloud or blockchain. Joydeep saw the opposite: a massive attack surface, very few defenders, and a category that would become more important as the systems running the physical world became more exposed. We backed that non-consensus view.
The old assumption was that industrial systems were separate enough to be safeFor a long time, that belief made sense. Many industrial environments were designed around reliability first. Equipment could run for decades. Networks were often isolated. The people responsible for keeping plants, substations, pipelines, and facilities operating were rightly cautious about change. If a system controlled pressure, temperature, flow, voltage, or production, the priority was not to move fast. It was to keep the process stable.
That history created a very different security problem than the one most corporate IT teams face. You cannot treat a factory floor like an office network. You cannot assume every device can be patched on Tuesday night, scanned aggressively, or taken offline because a security tool says so. Some assets are old. Some are fragile. Some use industrial protocols most general-purpose security products were never built to understand. In OT, even the act of looking too aggressively can create risk if it disrupts operations.
The hard part, then, is not simply finding threats. It is understanding what is safe to do about them.
Dragos is built for the cyber-physical worldIn plain English, Dragos gives industrial defenders a clearer picture of what is on their networks, which vulnerabilities actually matter, what suspicious behavior looks like in an industrial context, and how to respond without creating a bigger operational problem. Its platform combines asset visibility, vulnerability management, threat detection, response workflows, intelligence, and expert services built specifically for OT environments.
The difference is the context. In a typical IT system, a vulnerable server may be patched, isolated, or replaced. In an industrial setting, the same instruction may be impractical or unsafe. A vulnerability on a device that controls a physical process has to be understood alongside the asset, the process, the network path, the available maintenance window, and the consequences of downtime. Dragos’s approach is designed around those realities. It helps teams prioritize the small subset of issues that require attention now, understand what can wait, and avoid wasting effort on noise.
That may sound like a narrow technical distinction, but it is actually the heart of the category. Industrial security is not corporate security with different labels. It is security for systems where availability and safety are part of the mission. A false alarm can exhaust a team. A careless remediation step can interrupt production. A missed signal can give an adversary time to move deeper into an environment that was never designed for modern threat activity.
The difference is operational context, not just detectionWhat makes Dragos different is that it starts from the field. The company is built around OT expertise, threat intelligence, and incident response experience rather than a generic security model adapted after the fact. Its platform is designed to discover and monitor industrial assets, interpret vulnerabilities with OT-specific context, and provide playbooks that help defenders respond in ways that respect operational constraints. Its Neighborhood Keeper effort extends that philosophy into collective defense by enabling participants to share anonymized threat intelligence across industrial communities.
That last idea is important. Critical infrastructure is fragmented by design. Utilities, manufacturers, municipalities, energy companies, and industrial operators all run different systems under different constraints. But adversaries learn across targets. If defenders cannot share what they see, every organization has to rediscover the same danger on its own. Dragos’s view is that industrial defense becomes stronger when knowledge can move more quickly than the attacker.
Why nowIndustrial environments are more connected than they used to be. Remote access, digital operations, cloud-connected workflows, vendor maintenance, and IT/OT convergence have made many physical systems more visible to the outside world. At the same time, ransomware groups and state-linked actors have become more willing to target critical infrastructure and industrial operations. Regulation is tightening, boards are paying attention, and operators increasingly understand that cyber resilience is part of operational resilience.
Dragos’s own 2026 OT/ICS Cybersecurity Report underscored how quickly the threat has evolved. It identified three new threat groups targeting critical infrastructure in the prior year, and reported that ransomware affected more than 3,300 industrial organizations in 2025, a 49 percent increase from the year before. Those are historical figures, but they capture the direction we saw early: attackers are moving from simply gaining access toward understanding how physical processes operate and positioning for disruption.
What we sawWe are drawn to companies that reveal where a market is going before the shift becomes obvious. Dragos stood out because it was not simply selling another security dashboard. Rob brought deep technical credibility from his time at the NSA and Air Force, and had spent years building specialized knowledge in the operational technology systems that run power grids, refineries, water treatment facilities, manufacturing plants, and data centers. The attack surface was enormous, the defender base was thin, and almost no one in venture capital was taking the category seriously.
For us, the significance was larger than one platform or one class of threat. Early on, Rob insisted on combining software with professional services and a threat-intelligence operation so Dragos could act as a true partner to industrial customers, many of whom had never navigated an OT security program before. That model looked unconventional by traditional SaaS standards, but we believed the market required education, handholding, and proof of value over time, not a product a customer could simply buy and walk away from.
That early model also told us something about where the market was going. Industrial security would not be won by adapting generic IT tools; it required domain expertise, services, intelligence, and products built around the operational realities of physical systems. What looked non-consensus when we first partnered with Dragos has become much harder to dismiss.
Why this matters beyond cybersecurityFor someone outside cybersecurity, the reason to care is simple. OT is where the digital world touches the physical one. It is the equipment that helps keep lights on, water moving, goods manufactured, planes operating, and hospitals supplied. When these systems are resilient, most people never think about them. When they fail, the abstraction disappears quickly.
Rob’s mission has always made that human layer concrete for us. He has spoken about a formative Engineers Without Borders experience in Cameroon, where a mother’s hope for her child depended on a wind turbine and a car battery that powered LED lights at night so the child could study after sunset. When Rob later learned that adversaries wanted to deny systems like those to civilian populations, the problem became personal: protecting infrastructure meant protecting people.
[NEED COMPANY INPUT: Is there a specific public customer example or deployment story we can reference to make the human layer more concrete without overstating outcomes?]
The real questionThe question Dragos is asking is not simply whether industrial organizations can detect more cyber threats. It is whether the infrastructure people depend on can become more defensible without becoming harder to operate.
That is the larger future Dragos points toward: a world where critical infrastructure is not protected by obscurity, luck, or heroic manual effort, but by systems built for the environments they serve. If Dragos succeeds, industrial teams will not have to choose between security and uptime as often. They will have better visibility, clearer priorities, and safer ways to act. For us, that is the kind of company that matters beyond its category: one that helps make the invisible systems underneath modern life more resilient before most people realize how much depends on them.