For years, software and supply chain risk sat at the bottom of the xOT priority list. That no longer works.
Most xOT security programs were built around a reasonable bet: know what’s on the network, watch it, patch what’s exploitable. That bet worked; until now. It’s a worse bet every year that passes, because the thing sitting underneath every asset on that network, the firmware and the code, has quietly become the part attackers understand better than most defenders do.
That’s not a hypothetical for Dragos customers either. It’s why Dragos recently announced acquisitions to bring firmware and software visibility in addition to ingesting data from existing tech stacks into the same platform as everything else in an xOT program.
Three things changed. First, AI-assisted development means more compiled code shipping faster with less human review than at any point in this industry’s history. Second, real supply chain attacks stopped being a hypothetical: a single compromised open-source maintainer nearly slipped a backdoor into a piece of infrastructure software used across the internet in 2024, caught by one engineer who happened to notice a login taking 500 milliseconds too long. Most organizations don’t have that engineer. Third, regulators noticed. NERC CIP, NIS2, and TSA pipeline directives are starting to expect answers about what’s inside a device, not just where it sits on the network.
Put those three together and the old hierarchy, network visibility first, supply chain risk somewhere on a future roadmap, stops making sense. The attack vector with the least scrutiny is now the one growing fastest.
IT security learned this lesson at scale years ago; xOT hasn’t caught up, and the stakes are higher when it does. A vulnerable dependency in a web app gets patched with a deploy. A vulnerable dependency baked into a decade-old PLC firmware image gets patched during the next planned outage, if there is one. OT devices run longer, get touched less, and inherit whatever their vendor’s build pipeline picked up years before the device ever shipped.
That’s the part most xOT programs still treat as someone else’s problem, usually the vendor’s. It isn’t. A device can be fully inventoried, fully monitored, and still be running a hardcoded credential or an abandoned open-source library nobody’s touched since the maintainer walked away. A network scan won’t find that. A threat detection rule won’t catch it either, because there’s nothing to detect until it’s already been used against you.
Giving software and supply chain security a real seat in an xOT program means more than generating an SBOM once and filing it. Firmware that was clean at compile time doesn’t necessarily stay clean. (And truth be told, it may have unknowingly been problematic on the initial compile.) A maintainer disappears, a dependency gets poisoned, an object called for vibe coding was compromised. A CVE gets published years after the device is running in a plant.
That means three checkpoints, not one: what’s built into the firmware before a device ships, what’s actually running on it today, and what changes the moment a patch or firmware update lands. A program that only checks at build time is running a supply chain security theater, not a supply chain security program.
This is the Dragos Platform: Software & Supply Chain capability. It extends the Dragos Intelligence Fabric down to the binary level, generating and enriching SBOMs, analyzing compiled firmware for embedded weaknesses, and tracking open-source provenance (abandoned maintainers, nation-state contributors, poisoned dependencies) before a device deploys, while it runs, and every time it’s updated.
Elevating this doesn’t mean treating every dependency like a five-alarm fire; it means scoring supply chain findings with the same discipline already applied everywhere else in the program. “Now, Next, Never” exists so teams act on the fraction of vulnerabilities that actually require it, only 3 to 6 percent of xOT vulnerabilities, per Dragos’s 2026 Year in Review. Apply that same scoring earlier and a hardcoded credential caught before deployment, or a dependency flagged the week it turns malicious, gets handled before it’s ever exposed. A “Now” stops being an incident and becomes a procurement decision, or a patch ticket.
Every organization is somewhere on that path, whether that’s a procurement team vetting a vendor’s firmware or a security team finally getting an SBOM for what’s already deployed. Getting bigger is easy: add an API, buy a tool, cover another category of risk. Getting stronger means putting software and supply chain risk on the same footing as everything else in the program, scored with the same discipline and acted on with the risk appropriate urgency. That’s what separates an inventory from a program built to last.
This is exactly why Dragos recently acquired NetRise. Extending the Intelligence Fabric down to the binary level, so firmware and open-source provenance get the same discipline as everything else in the program, is what NetRise brings to the Dragos Platform.
Join us to learn more when Dragos Chairman and CEO Robert M. Lee, RunZero CEO and Founder HD Moore, and NetRise CEO and Co-Founder Thomas Pace break down what the combination means for practitioners, live on October 19 at 1 PM EDT.