Accenture has unveiled a landmark $4.175 billion strategic investment to build a dominant force in the operational technology (OT) and critical infrastructure cybersecurity market. The initiative involves three major acquisitions: a majority stake in Dragos, the market leader in OT threat detection and response; the complete acquisition of runZero, an asset intelligence and attack surface management firm; and the complete acquisition of NetRise, a specialist in firmware and software supply chain security for extended IoT (xIoT) devices. This aggressive move signals Accenture's ambition to transition from a security services provider to a dominant software platform player in the rapidly growing OT security space, driven by increased geopolitical risk and AI-powered threats.
The transaction, announced on June 18, 2026, involves Accenture paying $4.175 billion in cash. This includes the acquisition of a majority stake (reportedly 51%) in Dragos at a valuation of $3.25 billion, and the full acquisition of both runZero and NetRise. The acquisitions are subject to customary closing conditions and regulatory approvals and are expected to be finalized in August or September 2026. Following the closure, runZero and NetRise will be integrated under the Dragos brand, which will continue to operate as an independent business unit led by its current CEO, Robert M. Lee. This structure aims to preserve Dragos's specialized focus and brand recognition in the OT community while leveraging Accenture's global scale and resources.
The move primarily impacts organizations within the Critical Infrastructure sectors, including energy, manufacturing, utilities, transportation, and data centers, who are the target customers for the combined platform.
While this is a corporate acquisition rather than a new regulation, the strategic driver behind it is the increasing compliance burden on critical infrastructure operators. Regulations like the NERC CIP standards in North America and the NIS2 Directive in Europe mandate stringent cybersecurity controls for OT environments. The integrated platform created by these acquisitions is designed to help organizations meet these requirements by providing:
This series of acquisitions represents one of the largest investments ever in the OT cybersecurity market. The business impact is multifaceted:
Not applicable to the acquisition itself, but the platform's value proposition is directly tied to helping customers avoid severe financial penalties and operational shutdowns resulting from non-compliance with CNI protection regulations or successful cyberattacks.
For critical infrastructure organizations, this development underscores the urgency of adopting a holistic OT security strategy. A prioritized action plan should include:
Accenture officially announces its plan to invest $4.175B in acquiring Dragos, runZero, and NetRise.
The acquisitions are expected to close around August or September 2026.

Cybersecurity professional with over 10 years of specialized experience in security operations, threat intelligence, incident response, and security automation. Expertise spans SOAR/XSOAR orchestration, threat intelligence platforms, SIEM/UEBA analytics, and building cyber fusion centers. Background includes technical enablement, solution architecture for enterprise and government clients, and implementing security automation workflows across IR, TIP, and SOC use cases.
Help others stay informed about cybersecurity threats
Every tactic, technique, and sub-technique used in this threat has been identified and mapped to the MITRE ATT&CK framework for consistent, actionable threat language.
Observables and indicators of compromise (IOCs) have been extracted and cataloged. Risk has been assessed and correlated with known threat actors and historical campaigns.
Detection rules, incident response steps, and D3FEND-aligned mitigation strategies are included so your team can act on this intelligence immediately.
Structured threat data is packaged as a STIX 2.1 bundle and can be visualized as an interactive graph — relationships between actors, malware, techniques, and indicators.
Sigma detection rules are derived from the threat techniques in this article and can be converted for deployment across any major SIEM or EDR platform.