Dragos + Phosphorus: xOT Defense-in-Depth Starts Now

Protect Every Device. Secure the Whole xOT Environment.

Phase one of the integration brings enriched device intelligence straight into your Dragos asset inventory. No exported spreadsheets. No manual transformation.

Table of Contents

Today marks a major milestone for anyone responsible for protecting an extended operational technology (xOT) environment, and we reached it fast. In under 60 days since Dragos announced its acquisition of Phosphorus, the first phase of integration is here, delivered with the release of Dragos Platform version 3.2.5. The device intelligence produced by Phosphorus, now part of the Dragos portfolio, flows directly into your Dragos asset inventory, with no exported spreadsheets and no manual work required.

The connected IoT, OT, IIoT, and IoMT devices Phosphorus secures are among the most exposed in any environment. We’ve found that roughly 70% of IoT and OT devices ship with default credentials, 68% carry vulnerabilities rated CVSS 8 or higher, and 26% are end-of-life and no longer supported by their manufacturer. Network-based discovery is powerful, but there is device-level depth it cannot reach on its own. Using its patented Intelligent Active Discovery, Phosphorus communicates with devices over their native protocols to return verified, high-fidelity detail: firmware versions, certificate posture, credential status, and the specific vulnerabilities each device carries. That intelligence now enriches the asset inventory in the Dragos Platform directly.

Each time Phosphorus completes a discovery, the devices it finds and assesses are pushed straight into your Dragos asset inventory, appearing as new entries or merging with existing ones already tracked by the Dragos Platform. Nothing about how you use Phosphorus changes. Your team keeps discovering, hardening, and managing connected devices across the estate exactly as before, while the Dragos Platform stays continuously current with what Phosphorus sees.

This is xOT defense-in-depth in action. Phosphorus assesses and protects the devices; the Dragos Platform detects threats and prioritizes action across the network. Together, they help you protect every device, detect every threat, and respond with confidence. The combination turns a list of devices into a clear picture of what each device is, what is wrong with it, and what to do about it first. Because assets arrive with verified, device-level attributes rather than inference, vulnerability matches land with higher confidence, correlated to the exact firmware versions and configurations Phosphorus reports, and threat detections grow sharper because every device carries real context. That completeness matters: in real deployments, as many as 30% of the devices Phosphorus discovers were previously unknown to the organization. The payoff is a better experience and real efficiency gains, with a single, trustworthy inventory to act on.

Respond to a new advisory with confidence. When a vulnerability advisory lands, analysts using Dragos can see exactly which devices are affected, grounded in verified firmware versions and configurations rather than best guesses, and act on what matters in minutes instead of days.

Eliminate blind spots in your device inventory. Phosphorus surfaces connected devices that network-based discovery alone can miss, giving analysts a fuller, more trustworthy inventory and sharper detections because every device now carries real context.

Joint customers can go further, hardening devices and remediating default and weak credentials, out-of-date and vulnerable firmware, expired or self-signed certificates, and risky configurations across thousands of devices during maintenance windows. Today, that direct action lives in Phosphorus, and in future releases, these remediation capabilities will be embedded into the Dragos Platform, bringing discovery, prioritization, and the power to act together in one experience.

Phase one is the first step in extending the Dragos Platform across the full xOT environment, pairing a decade of device resiliency from Phosphorus with Dragos’ OT-native network visibility and threat detection. Automated remediation workflows and a unified platform experience will follow.

If you already run both platforms, you can turn this on today. If you run Dragos, adding Phosphorus to your security stack extends protection to the device level and more fully addresses xOT security, where network visibility alone cannot reach. And if you run Phosphorus, adding Dragos brings OT-native threat detection and response to the network around the devices you already secure. Talk to your Dragos team to see it in action.

See the full picture of your xOT environment.

This integration is one piece of a bigger shift in how operational environments must be protected. Watch our on-demand webinar, From OT to xOT: What is Extended Operational Technology? to understand the full scope of what you’re defending and how to build a program around it.

Player is a Senior Director of Marketing at Dragos, Inc., where he leads product marketing across xOT, Phosphorus, industry verticals, and partners. He sets strategy and drives execution to build category leadership, brand growth, and measurable revenue impact, bringing more than 20 years of senior cybersecurity marketing experience that combines deep technical fluency with a disciplined, customer-first approach.