About Dragos: An industrial cybersecurity company helping organizations protect the operational technology that keeps power, water, manufacturing, transportation, and other physical systems running.
Why did we invest?
When our partner Joydeep Bhattacharyya first met Dragos co-founder and CEO Rob Lee, the idea that industrial cybersecurity could become a large, essential category was far from consensus. Many investors viewed industrial cybersecurity as a niche market with slow sales cycles, difficult customers, and disappointing margins; Rob was even urged to pivot to cloud or blockchain. Joydeep saw the opposite: a massive attack surface, very few defenders, and a category that would become more important as the systems running the physical world became more exposed. We backed that non-consensus view.
But another version of cybersecurity has more physical stakes. A power plant needs to keep generating electricity. A water utility needs pumps and treatment systems to behave predictably. A manufacturer cannot casually reboot the equipment that keeps a production line moving. In these environments, cyber risk is not only about information. It is about uptime, safety, resilience, and the ordinary systems people assume will work because they usually do.
The old assumption was that industrial systems were separate enough to be safe
That history created a very different security problem than the one most corporate IT teams face. You cannot assume every device can be patched on Tuesday night, scanned aggressively, or taken offline because a security tool says so. Some use industrial protocols most general-purpose security products were never built to understand. In OT, even the act of looking too aggressively can create risk if it disrupts operations.
Dragos is built for the cyber-physical world
In plain English, Dragos gives industrial defenders a clearer picture of what is on their networks, which vulnerabilities actually matter, what suspicious behavior looks like in an industrial context, and how to respond without creating a bigger operational problem. The Dragos Platform combines asset visibility, vulnerability management, threat detection, response workflows, intelligence, and expert services built specifically for OT environments.
The difference is the context. In a typical IT system, a vulnerable server may be patched, isolated, or replaced. In an industrial setting, the same instruction may be impractical or unsafe. A vulnerability on a device that controls a physical process has to be understood alongside the asset, the process, the network path, the available maintenance window, and the consequences of downtime. Dragos’s approach is designed around those realities. It helps teams prioritize the small subset of issues that require attention now, understand what can wait, and avoid wasting effort on noise.
The difference is operational context, not just detection
What makes Dragos different is that it starts from the field. The company is built around OT expertise, threat intelligence, and incident response experience rather than a generic security model adapted after the fact. Its platform is designed to discover and monitor industrial assets, interpret vulnerabilities with OT-specific context, and provide playbooks that help defenders respond in ways that respect operational constraints. Its Neighborhood Keeper effort extends that philosophy into collective defense by enabling participants to share anonymized threat intelligence across industrial communities.
Why now
Industrial environments are more connected than they used to be. Remote access, digital operations, cloud-connected workflows, vendor maintenance, and IT/OT convergence have made many physical systems more visible to the outside world. At the same time, ransomware groups and state-linked actors have become more willing to target critical infrastructure and industrial operations. Regulation is tightening, boards are paying attention, and operators increasingly understand that cyber resilience is part of operational resilience.
Dragos’s own 2026 OT/ICS Cybersecurity Report underscored how quickly the threat has evolved. It identified three new threat groups targeting critical infrastructure in the prior year, and reported that ransomware affected more than 3,300 industrial organizations in 2025, a 49 percent increase from the year before. Those are historical figures, but they capture the direction we saw early: attackers are moving from simply gaining access toward understanding how physical processes operate and positioning for disruption.
What Canaan saw
We are drawn to companies that reveal where a market is going before the shift becomes obvious. Dragos stood out because it was not simply selling another security dashboard. Rob brought deep technical credibility from his time at the NSA and Air Force, and had spent years building specialized knowledge in the operational technology systems that run power grids, refineries, water treatment facilities, manufacturing plants, and data centers. The attack surface was enormous, the defender base was thin, and almost no one in venture capital was taking the category seriously.
For us, the significance was larger than one platform or one class of threat. Early on, Rob insisted on combining software with professional services and a threat-intelligence operation so Dragos could act as a true partner to industrial customers, many of whom had never navigated an OT security program before. That model looked unconventional by traditional SaaS standards, but we believed the market required education, handholding, and proof of value over time, not a product a customer could simply buy and walk away from.
That early model also told us something about where the market was going. Industrial security would not be won by adapting generic IT tools; it required domain expertise, services, intelligence, and products built around the operational realities of physical systems. What looked non-consensus when we first partnered with Dragos has become much harder to dismiss.
Why this matters beyond cybersecurity
For someone outside cybersecurity, the reason to care is simple. OT is where the digital world touches the physical one. It is the equipment that helps keep lights on, water moving, goods manufactured, planes operating, and hospitals supplied. When these systems are resilient, most people never think about them. When they fail, the abstraction disappears quickly.
Rob’s mission has always made that human layer concrete for us. He has spoken about a formative Engineers Without Borders experience in Cameroon, where a mother’s hope for her child depended on a wind turbine and a car battery that powered LED lights at night so the child could study after sunset. When Rob later learned that adversaries wanted to deny systems like those to civilian populations, the problem became personal: protecting infrastructure meant protecting people.
The real question
The question Dragos is asking is not simply whether industrial organizations can detect more cyber threats. It is whether the infrastructure people depend on can become more defensible without becoming harder to operate.
That is the larger future Dragos points toward: a world where critical infrastructure is not protected by obscurity, luck, or heroic manual effort, but by systems built for the environments they serve. If Dragos succeeds, industrial teams will not have to choose between security and uptime as often. They will have better visibility, clearer priorities, and safer ways to act. For us, that is the kind of company that matters beyond its category: one that helps make the invisible systems underneath modern life more resilient before most people realize how much depends on them.