Security Stack Logo
Dragos Platform logo

Cyber-Physical Systems (CPS) Security

Dragos Platform

Industrial cybersecurity platform delivering OT asset visibility and threat detection.

Dragos Platform Overview

What it does

The Dragos Platform is purpose-built cybersecurity software for operational technology (OT) and industrial control systems (ICS), providing asset visibility, threat detection, vulnerability management, and incident response specifically for critical infrastructure. Unlike IT security tools that lack understanding of industrial protocols, the platform uses threat behavior analytics that characterize adversary tactics, techniques, and procedures (TTPs) to identify malicious activity with high confidence while minimizing false positives that plague generic solutions.

How it works

The platform discovers and classifies OT, IT, IoT, and IIoT assets through passive network monitoring and active ICS device collection, capturing device type, manufacturer, firmware version, and communication patterns with detailed vulnerability context. Detection capabilities use composite threat analytics based on real-world attack groups documented by Dragos WorldView intelligence researchers, providing alerts with investigation playbooks that guide security teams through efficient response workflows and automated risk prioritization based on environmental context rather than generic CVE scores.

Credentials and traction

The Dragos Platform is ISO/IEC 27001:2022 and SOC 2 Type II certified. Dragos was named a Leader in the 2026 Gartner Magic Quadrant for Cyber-Physical Systems Protection Platforms, its second consecutive placement, and holds a 4.5 out of 5 rating on Gartner Peer Insights in the CPS Protection Platform category. Frost & Sullivan ranked it #1 in Innovation in the 2025 Frost Radar for OT Cybersecurity Solutions. The platform serves critical infrastructure operators across the electric, oil and gas, manufacturing, and water sectors.

Key Capabilities

mapped to solution categories
Industrial Control Systems (ICS) Security

Monitors ICS network traffic by analyzing span port or tap data without injecting any traffic, critical for environments where active probing can cause PLC faults or safety system trips.

Inspects industrial protocols (Modbus, DNP3, IEC 61850, EtherNet/IP, PROFINET, OPC-UA, BACnet) at function-code level for commands and configuration changes. Coverage breadth and inspection depth (command-level function code analysis vs. packet-level header parsing) both vary across ICS security products and are primary evaluation criteria.

Models expected behavior of safety-instrumented systems (SIS) separately from process control systems, preventing false alerts on normal SIS state machine transitions.

Identifies device vulnerabilities by fingerprinting asset type, firmware version, and protocol implementation from passive traffic observation, no active scan that could disrupt device operation.

Maps network topology, identified vulnerabilities, and detected anomalies to IEC 62443 zone and conduit requirements and security level targets.

Provides a single platform, or integration paths, for monitoring enterprise IT and industrial control networks together, forwarding ICS alerts and asset data into SIEM, SOAR, ITSM and CMDB tooling with control-system context (asset criticality, Purdue level, process impact) preserved so that a unified SOC can act without separate ICS tooling or ICS-specialized analysts.

Builds ICS asset inventories (PLCs, RTUs, HMIs, engineering workstations and nested devices behind controllers) with model, firmware and version detail, primarily from passive network observation and, where supported, OT-safe active queries and controller project-file parsing that cannot disrupt operations. Passive-only versus multi-method discovery is the main difference between products.

Critical Infrastructure Protection

Ingests and applies threat intelligence specific to critical infrastructure threat actor groups (Sandworm, ELECTRUM, Volt Typhoon), and sector-specific attack techniques.

Generates pre-formatted incident notifications compliant with CISA reporting requirements, NERC CIP-008, and sector-specific regulatory reporting obligations.

Supports sector-specific compliance frameworks alongside IEC 62443: NERC CIP for electric utilities, TSA security directives for pipelines, NRC cybersecurity requirements for nuclear.

Monitors OT system availability, process variable integrity, and control system state, flagging deviations that indicate cyberattack or equipment failure affecting operational continuity.

Operational Technology (OT) Security

Discovers and identifies OT assets, including nested devices behind controllers, with manufacturer, model, serial number, firmware and version detail, using passive traffic analysis first and, where the product supports them, OT-safe methods such as selective active querying, controller project-file parsing, lightweight host executables and switch or firewall telemetry. Passive-only versus multi-method discovery and the depth of identification vary widely.

Dissects OT protocol payloads at the function code level, detecting unauthorized read/write operations, unusual register ranges, and firmware upload commands in Modbus, DNP3, EtherNet/IP, PROFINET, and OPC-UA traffic.

Baselines normal device communication patterns (command frequency, connection pairs, timing) and operational state, alerts on deviations that indicate reconnaissance, manipulation or lateral movement, and rates severity by asset criticality and process impact rather than by anomaly size alone. Products differ in whether baselines self-tune over time to operational and environmental changes or require ongoing manual tuning.

Connects OT security to enterprise security operations either as a single converged console for IT and OT or through integration paths into SIEM, SOAR, ITSM, CMDB, NAC and firewall tooling, forwarding alerts and asset data with OT context (asset criticality, Purdue level, process impact) preserved so that SOC analysts can act without OT specialization. Assign only when integrations preserve OT context or run bidirectionally; basic syslog forwarding is standard across the niche.

Identifies and prioritizes vulnerabilities across discovered OT and ICS assets using device, firmware, and exposure context, recommending safe, operationally feasible remediation or compensating controls for environments where patching is constrained.

Models operational risk for each asset, zone and site by combining device vulnerabilities, network access paths, real-world exploitability, detected threats, operational errors and asset criticality, and ranks exposures by their potential impact on safety systems and crown-jewel operational assets rather than by raw vulnerability counts, reflecting that most OT assets cannot be patched on IT timelines. Risk inputs such as controller logic, device lifecycle stage and peer benchmarking vary by product.

Retains OT-specific evidence for investigations, including protocol-level packet captures, controller commands, asset criticality and process context, and guides response with OT-aware playbooks whose containment actions respect safety and uptime constraints rather than defaulting to IT-style isolation.

Detects and responds to threats on OT hosts such as engineering workstations, HMIs and SCADA servers and, where supported, on controllers through lightweight embedded agents for PLCs and RTUs, complementing network-based detection with host-level visibility and response. Agentless-only versus agent-capable coverage is the main split between products.

Tracks OT security posture against IEC 62443, NIS2, NERC CIP and other sector regulations by mapping discovered assets, zones, vulnerabilities and controls to specific requirements and producing audit-ready compliance reports and gap lists. Usability of the tracking workflow varies widely.

Monitors control networks without adding latency or traffic, using passive SPAN or TAP collection and out-of-band sensors, and keeps full detection, analysis and reporting working at disconnected, air-gapped or intermittently connected sites through fully on-premises operation. Cloud-reliant products lose function at isolated sites; isolated-site-capable products do not.

Provides curated intelligence on adversary groups, malware and vulnerabilities that specifically target industrial control systems, with detections, playbooks and recommended actions tied to that intelligence and, in some products, community sharing of threats observed across other OT environments.

Compliance

certifications
ISO 27001SOC 2 Type II

Integrations

compatible tools
Cisco Secure Firewall ASACrowdStrike Falcon Discover for IoTCrowdStrike Falcon Insight XDRFortinet FortiGateFortinet FortiSIEMFortinet FortiSOARIBM QRadarLogRhythm NextGen SIEMMicrosoft SentinelPalo Alto NetworksPalo Alto XSOARServiceNowSplunkTrellix Enterprise Security Manager

Implementation & support

Deployment model
Air-GappedCloudHybridOn-PremisesSaaS
Support channels
24/7 SupportCustomer Success TeamDocumentationEmail SupportKnowledge BasePhone SupportTechnical Account Manager (TAM)Ticketing PortalTraining / Academy

Info last updated on September 7, 2026

Buyers

Start a shortlist with Dragos Platform

Compare options, add your notes, and run informed evaluations.

Vendors

Is this your product?

Claim your profile to connect with the teams looking for your solutions.

Security Stack Logo

The curated research platform for enterprise cybersecurity solutions.

Resources

All product and company names, logos, and brands are property of their respective owners and are used on this website for identification purposes only. Security Stack does not endorse any vendor, product, or service listed, and makes no warranties, express or implied, as to the accuracy or completeness of this content, including any warranties of merchantability or fitness for a particular purpose.

© 2026 Security Stack. All rights reserved.