Here’s a question that may give pause: after the last few years of headline-grade OT incidents, why are we, in 2026, still writing blog posts about the need for visibility? You’d think that box got checked a while ago. Somewhere between the tenth tabletop exercise and the fifteenth “lessons learned” webinar, you’d hope somebody solved it.
They didn’t. Most organizations never had the kind of visibility that today’s xOT environment requires. They had an asset list somebody built during a slow week two audits ago. A spreadsheet with a few too many “unknown” rows. A rough network diagram of what’s plugged in where. That’s not visibility. That’s a rumor about your xOT environment, and rumors don’t hold up well when someone’s trying to get into your historian.
Knowing a device is “a Rockwell PLC” or “a Siemens PLC” is a fact, sure. It’s also not a particularly useful one on its own. What matters is the detail like the firmware version it’s running right now, the patch level it’s sitting at, who has credentials to touch it, what configuration changes have been quietly made and by whom, and what the ladder logic is telling it to do. Two PLCs, same make, same model, sitting on the same line, can have wildly different risk profiles depending on those answers. An inventory that stops at make and model is a directory. It’s not defense, and it never was.
The old picture of OT, PLCs, HMIs, a DCS humming away in the background, was a fine picture for its time. Its time has passed. The control loop, or xOT environment that actually keeps a process running now stretches through IT systems feeding data into operational decisions, IoT and connected devices that didn’t exist on these networks a decade ago, and a long tail of dependencies sitting well outside where the “OT perimeter” used to be drawn on a whiteboard. If you’re only watching the control room, you’re watching one room in a house with the doors left open.
This is the actual problem the Dragos Platform was built to solve, and its about outcomes, not a feature list: see everything, regardless of what you’ve got deployed.
The Exposure Management capability takes the asset identification and classification Dragos has always done and extends it out past sensor-covered OT, into IT, cloud, and hybrid environments. It pulls data in from whatever’s already sitting in a customer’s tech and security stack, including tools from other vendors, and rolls it into one prioritized exposure view. If you’ve got asset data but no sensors deployed, you get real value on day one.
The other gap is the one nobody wants to talk about at the code review: what’s inside the software and firmware before it ever ships. Every commit, every open-source dependency, every firmware build is a door that can be propped open, and the current enthusiasm for AI-assisted, “vibe coded” software has made it easier than ever for something unwanted to hitch a ride in without anyone noticing. A network sensor isn’t going to catch that; it’s not looking there. A Software and Supply Chain capability is. Firmware and binary analysis, SBOM (Software Bill of Materials) generation, and open-source provenance and contributor risk assessment, all aimed at finding weaknesses in compiled code before a device ever reaches the extended operational environment, not during the incident review afterward. Same principle as the exposure side: know the risk before it becomes a problem, checked continuously, not once at delivery and then forgotten.
Each of these new capabilities enhances complete situational awareness using the Dragos Platform. And neither is meant to be where the story ends. Wherever an organization walks in the door, whether that’s supply chain risk intelligence with zero sensors deployed anywhere, or a full exposure view before anyone’s touched an xOT network, the road leads to the same place: a fully deployed Dragos Platform, backed by detection, response, and the intelligence underneath all of it.
None of this works as a pile of disconnected parts, which is usually how these things end up if you’re not careful. The Dragos Intelligence Fabric is what turns telemetry, adversary research, and years of frontline incident response into context a defender can operationalize, and Dragos EmberAI puts that context in an analyst’s hands whether they’ve been doing this for six months or sixteen years. Dragos Services including Tabletop Exercises that stress-test a response plan before there’s anything to respond to, and the Rapid Response Retainer that gets responders moving within an hour of first contact, put that same intelligence to work when it counts.
Add it up and this is what full court exposure management is actually supposed to mean: visibility and control before an event, covering the full depth of firmware, code, and configuration and the full width of IT, IoT, and OT; situational awareness during one, grounded in more than a decade of OT-specific frontline work; and expert-backed response after one, so recovery doesn’t start from a blank page.
So, what is the ultimate goal for visibility in out xOT environments? All of this adds up to stopping the attack that hasn’t happened yet, because the weakness it would have used was already found and closed. That takes visibility deep enough to read a single line of firmware, wide enough to see every device touching the control loop, and intelligence sharp enough to tell you which of those weaknesses were ever going to matter in the first place. That’s not a marketing claim. It’s what Dragos does.
This is exactly why Dragos closed its acquisitions of NetRise and RunZero. Join us October 19 at 1 PM EDT as Dragos Chairman and CEO Robert M. Lee, runZero CEO and Founder HD Moore, and NetRise CEO and Co-Founder Thomas Pace, break down what this combination means for practitioners.