OT/ICS and Cyber-Physical Security
In 2025 ServiceNow agreed to buy Armis for $7.75B, a deal it said would more than triple its security-and-risk market opportunity, and in June 2026 Accenture bought a majority of Dragos (valuing it ~$3.25B) plus runZero and NetRise in a ~$4.18B package. Two of the largest independent asset-visibility franchises changed hands inside twelve months. Operational-technology security — the domain that protects factories, grids, pipelines, hospitals, and weapons systems — has moved from a niche specialist field to a focus of acquisition activity among the largest platforms in software and services.
What "OT / ICS security" actually is
Operational technology (OT) is the computing that runs the physical world: industrial control systems (ICS), SCADA, programmable logic controllers (PLCs), distributed control systems, building-management systems, and the broader universe of cyber-physical systems (CPS) that now includes IoT and connected medical devices (IoMT). Securing it is a fundamentally different problem from IT security, and that difference shapes the segment:
- Devices usually cannot be patched, rebooted, or fitted with an agent. A turbine controller or an infusion pump runs proprietary, decades-old, safety-certified firmware that the operator will not touch. OT security is therefore built around passive techniques — monitoring the network rather than instrumenting the device.
- Availability and safety outrank confidentiality. In IT a breach leaks data; in OT a breach can stop a production line or endanger lives. The operator's first question is never whether a product can block a threat but whether it will ever interfere with the process.
- The estate is invisible by default. Most operators do not know what is on their plant network. The foundational product is therefore asset discovery and visibility — and that, not threat detection, is the value the strategics are paying for.
The product stack, layer by layer:
- Asset discovery & inventory — passively (or via safe active queries) build a real-time map of every device, firmware version, protocol, and communication path. The control plane everything else runs on.
- Network monitoring & threat detection — deep packet inspection of industrial protocols (Modbus, DNP3, EtherNet/IP, S7, BACnet) to baseline normal process behavior and flag anomalies and known ICS threats.
- Vulnerability & exposure management — match the discovered firmware to CVEs and prioritize the handful that actually matter in a network that can't be freely patched.
- Secure remote access — control the single most common breach path: third-party integrators and engineers dialing into the plant.
- Network segmentation / protection — enforce the Purdue-model zones (and increasingly micro-segmentation) that keep IT compromise from crossing into OT.
How each actor makes money and how they differ
The market splits into pure-play cyber-physical platforms, IT-security and networking vendors reaching down into OT, and the industrial automation OEMs defending their own installed base.
| Vendor | Owner | Posture | Differentiation / economics |
|---|---|---|---|
| Claroty | Private (VC; ~$1.5B raised) | CPS platform leader | Deepest protocol coverage + clinical (Medigate/IoMT) and xDome SaaS; ~80% of new revenue now cloud; surpassed $100M ARR; Gartner-leader for ability to execute. The largest scaled independent |
| Armis | → ServiceNow ($7.75B, closed Apr 20 2026) | Asset intelligence platform | Agentless, breadth-first asset visibility across IT/OT/IoT/IoMT; tendered at $4.5B in 2025 before the ServiceNow deal; the "asset graph" ServiceNow is buying to feed its CMDB/ITSM |
| Nozomi Networks | Mitsubishi Electric (acq. completed Jan 28 2026; ~$1B EV / ~$883M for the 93% it didn't own) | OT/IoT detection | Strong DPI + wireless and OT-endpoint sensing; premium-priced, deep in industrial/energy; slower SaaS transition than Claroty; formerly the other big independent platform — now an industrial-OEM subsidiary |
| Dragos | Accenture (majority, Jun'26; ~$3.25B) | ICS-pure threat platform | Industrial-only by design; world-class ICS threat intelligence + managed threat hunting; brand leader in electric/utilities; narrower device breadth than Armis. Stays independent under CEO Robert M. Lee |
| Tenable (OT Security / ex-Indegy) | Public (TENB) | Exposure-led | OT bolted onto a vulnerability-management platform — exposure management spanning IT+OT; the comp for "OT as a feature of exposure mgmt" |
| Microsoft (Defender for IoT / ex-CyberX) | MSFT | Bundler | OT detection folded into the Defender/E5 estate — the commoditization threat to standalone monitoring |
| Cisco (Cyber Vision) | CSCO | Networking-embedded | OT visibility delivered in the industrial switch — security as a feature of the network they already sell into the plant |
| Fortinet | Public (FTNT) | Ruggedized network security | Rugged firewalls + OT-aware segmentation; the OT story attached to a network-security platform |
| Palo Alto (IoT/OT Security, ex-Zingbox) | PANW | Platform bundler | ML-based device security folded into the NGFW/SASE platform; OT as a subscription on the firewall |
| Honeywell / Siemens / Schneider / Rockwell | OEMs | Automation incumbents | Sell OT security as a service wrapped around their own control systems and installed base; channel + trust advantage, narrower independence |
| runZero | → Dragos (closed Sep 17 2026) | Active asset discovery | Fast, unauthenticated asset discovery (co-founded by HD Moore, who joins Dragos with his team); the IT+OT inventory layer in the xOT stack. Acquired by Dragos, not by Accenture directly |
| OTORIO / Shield-IoT / SCADAfence (Honeywell) | various | Specialists | Risk-assessment, IoT-at-scale, and SCADA niches — classic tuck-in supply |
This market is fundamentally a contest over who owns the asset graph. The pure-play platforms (Claroty, Armis, Nozomi, Dragos) earned the trust and built the protocol depth that IT vendors can't easily replicate — but they sell into a buyer (the plant/operations side) with smaller and slower budgets than the CISO, which historically capped their growth and is exactly why the scaled ones are selling to bigger platforms that can cross-sell the CISO. The IT-security and networking vendors (Microsoft, Cisco, Fortinet, Palo Alto, Tenable) reach into OT to make their platform "see everything," and they have the distribution and the CISO relationship — their weakness is depth and the operations team's distrust of anything that might touch the process. The automation OEMs (Honeywell, Siemens, Rockwell, Schneider) own the installed base and the operator's trust but are conflicted vendors securing their own gear. The strategic logic of both mega-deals is identical: a horizontal platform (ServiceNow's workflow/CMDB, Accenture's services) buys the asset graph because asset intelligence is the connective tissue that makes exposure management, ITSM, and remediation work across the whole physical estate.
Where the value pool is migrating
The 2026 PLC campaign and the specificity barrier
Through July and August 2026 the sub-segment acquired the demand evidence it had previously argued from analogy. CISA reported malicious activity against more than 100 internet-exposed systems in the US water and wastewater sector during July, most commonly programmable logic controllers connected directly to a cellular modem, with operational disruption at community water systems across at least twelve states. A joint advisory issued on Aug 19 2026 by the NSA, CISA, the FBI, the Department of Energy and the Environmental Protection Agency (AA26-231A) then described the tooling: attackers combining AI coding assistants with open-source industrial-automation libraries (snap7.dll / python-snap7) to produce custom software that imitates OT monitoring tools and reads from and writes to controller memory, configuration data and ladder logic over S7comm. The affected devices are internet-exposed Siemens S7 Series PLCs across critical manufacturing, energy, water and wastewater, chemical, food and agriculture and commercial facilities, and the advisory notes the same controllers are present in the Defense Industrial Base. It carries no attribution; Iran-affiliated actors are suspected in the related intrusions. Separately, the Telegraph reported on Aug 22 2026 that Iranian actors disabled a UK power plant for four days in July — the facility is unnamed and the account is not government-confirmed, so it stands as a press report rather than a verified event.
What changes commercially is the barrier, not the technique. The intrusions themselves are unremarkable: internet-exposed controllers running outdated software or default credentials, located through commercial scanning services. Attacking them has nonetheless required knowledge that is scarce and slow to acquire — the protocol, the ladder logic, the physical process being controlled. The agencies' stated concern is that model assistance reduces the OT domain knowledge an attacker needs and shortens the path to a working attack chain. The population of actors capable of reaching a controller therefore widens without any new vulnerability being introduced, which is the demand argument OT vendors have made for a decade and could not evidence.
The controls the advisory prescribes are the ones this page's value-migration section already identifies as where the money sits: inventory every S7 controller, patch it, take it off the internet, and monitor S7comm for connections from non-engineering workstations, unusual data-block access and writes outside change windows. None of that is an AI control. It is asset discovery, segmentation and protocol-aware monitoring — the capability set ServiceNow, Mitsubishi Electric and Accenture paid for in the three exits below. The read-through for the remaining independents and for the OEM channel is that the buying case strengthens on visibility and network monitoring rather than on any new product category. (CISA AA26-231A · The Register, Aug 19 2026 · Infosecurity Magazine, Aug 24 2026) See also AI for Offense and Threat Economy.
The bulk-power exclusion order and what it obliges
An Executive Order signed Aug 26, 2026 declared a national emergency over the security of the United States bulk-power system and generally prohibited the purchase or installation of covered foreign-produced bulk-power electric equipment, including the associated critical software and digital capabilities. It excludes local-distribution facilities, so its scope is transmission and generation. The order also permits the Secretary of Energy to impose conditions on the continued use and operation of equipment already installed, and directs the Department of Energy to publish implementing rules.
The clause reaching the installed base is what makes this an OT-security matter rather than a trade matter. Complying with a condition on continued operation requires an operator to know what equipment it runs, what firmware version each unit carries, who manufactured it and what remote-management paths exist — an inventory problem before it is a security problem, and one most utilities cannot answer from records. That is the capability the asset-discovery, firmware-analysis and component-provenance vendors sell, and it is the same stack Accenture assembled in the Dragos–runZero–NetRise package: ICS threat intelligence, active asset discovery and firmware analysis. Two qualifications on the size of the effect. The covered-equipment list and designated-entity criteria do not exist until the Department of Energy rules publish, expected within 2026, so the obligation is dated but unquantified. And the exclusion of distribution removes the large population of smaller utilities from scope, concentrating the demand in transmission operators and generators. Full regime detail on US Regulation (White House fact sheet, Aug 26, 2026).
Signature deals & events
- ServiceNow → Armis ($7.75B, announced 2025, closed Apr 20 2026) — the deal that institutionalized OT security. ServiceNow folds Armis's agentless asset graph into its CMDB/ITSM to build an "AI control tower" spanning IT, OT, and medical devices; says it more than triples its security/risk TAM. The bellwether transaction. See Deals.
- Accenture → Dragos (majority, ~$3.25B) + runZero + NetRise (~$4.18B package, Jun 2026) — the services giant's answer: assemble an asset-centric "xOT" stack (ICS threat intel + active asset discovery + firmware analysis) and wrap it in Accenture's delivery muscle. Dragos stays independent under Robert M. Lee. ~20x combined ARR (~$208M, +53% YoY). The competitive response that confirmed OT visibility is now a two-platform race.
- Honeywell → SCADAfence (2023) and the OEMs' build-out — automation incumbents buying or building OT-security capability around their installed base; the conflicted-but-trusted channel.
- Microsoft → CyberX, Cisco's Cyber Vision, Palo Alto → Zingbox, Tenable → Indegy — the earlier wave of IT/networking vendors absorbing OT-visibility startups as platform features; the precedent for "OT as a feature."
- Remaining independents — with Nozomi (→Mitsubishi Electric, completed Jan 28 2026), Armis (→ServiceNow, completed Apr 20 2026), and Dragos (→Accenture majority, closed Sep 16 2026) together with runZero and NetRise (→Dragos, closed Sep 17 and Jul 31 2026) all acquired inside eight months, Claroty is now the main remaining independent; the long tail (OTORIO, Shield-IoT, Mission Secure, Frenos, and the IoMT specialists) becomes tuck-in supply.
OT consolidation: three independents acquired in six months
The independent OT/asset-visibility set compressed sharply inside one roughly six-month window (Jan–Jun 2026). Each exit removes a comparable and re-rates the remaining independents.
| Closed/announced | Target (independent) | Acquirer (type) | Value | What it signals |
|---|---|---|---|---|
| Jan 28 2026 (completed) | Nozomi Networks | Mitsubishi Electric (automation OEM) | ~$1B EV (~$883M for the 93% it didn't own) | OEM absorbs an OT-detection leader into its installed base; first of the three to go |
| Apr 20 2026 (completed; announced 2025) | Armis | ServiceNow (workflow/CMDB platform) | $7.75B | Horizontal platform buys the asset graph to feed CMDB/ITSM; the bellwether deal (~triples ServiceNow's security/risk TAM) |
| Jun 18 2026 (announced) | Dragos (+ runZero + NetRise) | Accenture (services giant) | ~$3.25B for Dragos majority; ~$4.18B package | Services giant assembles an "xOT" asset-centric stack (~20x combined ARR); confirms a two-platform race |
The IoT-edge extension — a fourth buyer archetype enters (Jun–Jul 2026)
The consolidation is no longer confined to plant-floor OT: the same asset-centric logic is being applied one ring out, at the connected-device / IoT edge, and it has pulled a fourth buyer archetype into the race — the silicon/edge platform.
| Date | Deal | Buyer archetype | What it extends |
|---|---|---|---|
| Jun 1 2026 (announced) | Dragos → Phosphorus (xIoT security & device mgmt) | OT pure-play bulking up pre-exit | Dragos bought the embedded/xIoT layer 17 days before Accenture's majority stake — the asset it sold was deliberately fattened to cover "xOT: the full environment" (Dragos PR) |
| Jul 31 · Sep 17 2026 (closed) | Dragos → NetRise and Dragos → runZero (terms undisclosed) | OT pure-play continuing to buy through its own change of control | The acquirer of both is Dragos, not Accenture. NetRise closed 47 days before Accenture's majority investment closed (Sep 16); runZero closed the day after it (SecurityWeek, Sep 21 2026) |
| Jul 1 2026 (announced) | Qualcomm → SAM Seamless Network (>$100M; telco-CPE/IoT network security, >500M devices) | Silicon/edge platform (new archetype) | On-device AI compute needs on-device defense — the chipmaker buys the security layer under its edge-AI strategy (see 11, 25) |
Three acquisitions in under four months, all made by the company being acquired. Phosphorus was announced 17 days before Accenture's majority stake was announced; NetRise closed 47 days before that stake closed; runZero closed the day after. The buying entity in all three is Dragos. The pattern is a target assembling the platform during its own sign-to-close period rather than an acquirer integrating afterwards, which places the integration risk, the retention terms and the purchase accounting inside the business being valued rather than alongside it — and means the combined ARR now quoted for the group was built by three transactions whose individual terms are undisclosed. The consequence for any multiple drawn from the arrangement is set out in Comps Methodology.
Read together with ServiceNow–Armis (IoT/IoMT breadth) and the Accenture/Dragos xOT arrangement (firmware/supply-chain), the acquirer set for device-layer security now spans four archetypes: automation OEM · horizontal software platform · services integrator · silicon/edge platform. This widens the realistic buyer list for every remaining device-security independent (Claroty's IoMT franchise, Shield-IoT, the Cylera/Asimily/Medcrypt cluster, and the consumer/telco-CPE niche SAM occupied), and it means the "who owns the asset graph" contest is being joined from below the OS as well as from the workflow layer above.
A device-security independent capitalised as a buyer (Sep 2026)
The four archetypes above are established acquirers buying into the device layer from outside it. A fifth entered in September 2026 from inside it, financed differently.
Exein, an Italian embedded- and firmware-security company founded in 2018, raised $270M on Sep 15 2026 at a $1.7B post-money valuation, led by Headline with Sofina, Goldman Sachs, the EIB Group (through the European Tech Champions Initiative), KfW Capital and T.Capital (Deutsche Telekom's strategic arm) joining existing backers Balderton, HV, Intrepid Growth Partners, 33N Ventures, Lakestar, Supernova Invest, Blue Cloud Ventures and Geodesic Capital. The company puts total capital raised — equity and debt combined — above $600M, or about 35% of the new valuation, and describes the mark as thirtyfold its Series B of roughly two years earlier, which implies a Series B valuation near $57M. Its December 2025 round raised $100M; the new mark is described as more than double the one set then, placing the December 2025 valuation below $850M. Alongside the equity, Exein upsized a revolving credit facility led by J.P. Morgan, with KfW joining as an additional lender, and stated its purpose as pursuing M&A across Europe and the United States (Exein, Sep 15 2026 · SecurityWeek).
Two things follow for the device-layer buyer set. First, the acquirer universe is no longer composed only of large incumbents. A venture-funded specialist carrying a committed revolver underwrites adjacency inside its own layer rather than portfolio completion, and it competes for the same tuck-in supply the table above identifies — the sub-scale embedded, xIoT and IoMT assets — on a different cost of capital and a shorter decision path than an automation OEM or a services integrator. Second, the measurement basis differs from every price on the tables above. $1.7B is a post-money valuation on newly issued preferred stock, not an enterprise value for the whole company: it prices the last share sold and sits above a liquidation preference, whereas the Nozomi (~$1B), Armis ($7.75B) and Dragos (~$3.25B) figures price control. The Exein mark is 1.70× Nozomi's January 2026 exit value and 0.52× Dragos's June 2026 valuation, on bases that do not compare directly and should not be set against each other in a comp set without that adjustment.
The claim underneath the round is a data one. Exein reports a footprint of more than two billion devices and roughly 5,000 new non-repetitive attacks per week across that network — five times the prior year's rate, implying about 1,000 per week a year earlier — and is training a proprietary foundation model on two years of machine telemetry drawn from that footprint. The agentic architecture is scheduled to ship by the end of 2026 and the first foundation models in Q1 2027. Both dates, the telemetry volume and the device count are company statements, not independently verified, and no revenue figure was disclosed.
What remains independent: at the plant-floor layer, Claroty is now essentially the lone scaled independent (>$100M ARR, ~80% cloud-new-revenue) — the marquee remaining prize, re-rating on scarcity. Below it, the tuck-in long tail: OTORIO, Shield-IoT, Mission Secure, Frenos, Verve (Rockwell-owned) and the IoMT specialists (Cylera, Asimily, Medcrypt). The buyer archetypes divide by the evidence behind them. Three have completed acquisitions of scaled independents — automation OEM (Mitsubishi), horizontal software platform (ServiceNow) and services integrator (Accenture). A fourth, the silicon/edge platform, has one transaction at the device ring (Qualcomm–SAM, >$100M) rather than at plant-floor scale. A fifth, the venture-funded device-security specialist (Exein), has committed capital and a stated acquisition programme but no announced transaction, so it is a declared buyer rather than a demonstrated one. All five sit alongside the standing IT/networking bundlers (Microsoft, Cisco, Palo Alto, Fortinet, Tenable).
Rob Lee on the Accenture structure and the AI-into-OT wave (E25 transcript, Jul 2 2026)
The Inside the Network E25 transcript (recorded ~2 weeks before the Jun 18 announcement, published Jul 2 2026) provides seller-side detail on the year's defining OT transaction:
- Why a majority stake, not an IPO or platform sale: "I knew I wanted to build a hundred year kind of company, and it didn't matter to me… is there a PE leader? Is there an IPO leader?… you could divorce control and equity. You could divorce autonomy from structure." (21:54–22:26). The Accenture structure — majority stake, Dragos independent under Lee, runZero + NetRise operating under Dragos — is the autonomy-preserving path. For founder-led OT assets, structure terms (autonomy, brand, operating control) can outrank headline form, and buyers who can offer them widen the sellable universe.
- The demand thesis in one line: the attacks that matter in OT are misoperation, not exploits ("if the electric operator can open up a circuit breaker, so can the adversary"), and one capability now scales across hundreds of sites; Lee reports observed state→non-state capability transfer (Internet-connected-HMI defacement to PLC implants/ladder-logic manipulation "a month later") (48:17–50:08).
- AI-into-OT is outrunning validation: boards are pushing AI vendors into process-control environments in ~3 months versus the normal 12–18-month testing cycle, and "the market's gonna reset to some degree… you're gonna have startups that are now part of critical infrastructure that are no longer in existence the next day" (51:52–52:31) — both a risk datum and a consolidation predictor for the AI-in-OT startup cohort. The durable budget line is pre-incident data collection/visibility ("you can use that same data for operational value… cybersecurity value… root cause analysis"), i.e., the asset-graph thesis underlying this domain.
The bear case
The OT bull case is powerful: critical-infrastructure attacks are rising, regulation (NIS2, CIRCIA, TSA pipeline directives, the EU CRA) is forcing spend, IT and OT are converging, and the asset graph is a durable, defensible control plane — so the pure-plays compound into strategic infrastructure, as the ServiceNow and Accenture prices attest. The bear case has two prongs. First, OT security may be a feature of a bigger platform, not a standalone market. That is precisely the thesis behind both mega-deals — neither ServiceNow nor Accenture believes Armis or Dragos is a durable independent business; they believe asset intelligence is connective tissue that belongs inside a workflow/CMDB platform or a services wrapper. If they're right, Microsoft (Defender for IoT in E5), Cisco (visibility in the switch), and Palo Alto (OT on the firewall) commoditize the monitoring layer for the CISO, and standalone OT valuations compress. Second, the budget problem never fully went away — OT security is bought by operations teams with capital-budget cycles and safety conservatism, not by the fast-moving CISO software budget; demand is real but lumpier and slower than IT security, which is why even the leaders took years to cross $100M ARR. Falsifiable test: watch whether Claroty — now essentially the last marquee independent — reaches a clean public listing at a premium multiple, or whether it too gets absorbed by a platform/OEM below a standalone-IPO mark (the path Nozomi took into Mitsubishi Electric, ~$1B, Jan 2026) while Microsoft/Cisco/Palo Alto quietly win the net-new asset-visibility budget bundled into deals already signed. If the independents all sell into bundles rather than scaling to public-market independence, "OT security is its own durable platform" is breaking — and the strategics were buying a feature.
→ Cross-references: Vendors, Network & SASE, Sovereign & Government, Regulation, Deals & Comps, Valuation, Bear Case.
Adjacent market: the physical-security and IoT industry whose devices this segment defends is mapped on Physical Security & IoT.
Updated 2026-10-04 19:34 UTC · © El Dorado Capital · el-doradocapital.com · Market intelligence for informational purposes only; not investment advice.