Dragos announced its acquisition of Network Perception on October 1, 2024. The deal brought NP-View, a tool for analyzing network-device configurations, into Dragos’s operational technology (OT) security portfolio. The strategic aim was to connect two different views of an industrial network: what monitoring observes happening and what network configurations allow to happen. The companies did not disclose the purchase price. The announcement described several product capabilities as planned integration, not as proof that every feature was already available in a unified product.
What Dragos acquired
Dragos acquired Network Perception, the company behind NP-View. The announcement described the companies as having significant exposure to the North American electric sector and said Dragos intended to extend the capabilities to oil and gas, manufacturing, and other industries globally. Financial terms were not disclosed, according to SecurityWeek’s October 1, 2024 report.
Dragos said it planned to integrate NP-View’s topology and firewall-rule analysis into the Dragos Platform. That is an announced direction, not confirmation of a specific release date, interface, supported-device list, or licensing arrangement. The October 1, 2024 announcement did not provide those product details.
What NP-View analyzes
NP-View works from configuration files for network equipment such as switches, routers, and firewalls. From those inputs, it can build a topology view and analyze firewall rules and potential access paths. In other words, its primary perspective is configured connectivity—what the network architecture permits—not simply a record of live traffic.
Do these 3 things before closing this tab:
1Repair Windows errors before they cause bigger problems2Fix the driver behind crashes, sound loss and screen glitches3Clear out junk files and repair common Windows errors#1 Best Overall
- Industrial Cybersecurity: Efficiently monitor the cybersecurity posture of your ICS environment, 2nd Edition
- ABIS BOOK
- Packt Publishing
Dragos described NP-View as supporting offline, non-invasive analysis. That can matter in operational environments where active scanning may be undesirable. However, obtaining configuration files can still require privileged access, change-management procedures, or vendor assistance; a non-invasive analysis product does not make every collection step risk-free. Help Net Security’s contemporaneous report also described the configuration-analysis and compliance use cases.
How the two visibility layers fit together
Dragos’s existing platform was described as providing OT asset visibility and monitoring, asset identification, vulnerability context, threat detection, and related threat intelligence and services. NP-View adds a configuration-centered view. These capabilities are complementary: one does not replace the other.
| Security question | Relevant view |
|---|---|
| What devices are known? | Asset discovery and inventory |
| What is communicating now? | Observed traffic or monitoring telemetry |
| What could communicate under the configured rules? | Switch, router, firewall, and access-control configuration analysis |
| Is segmentation working as intended? | Compare policy and configured paths with observed activity |
| Which weakness deserves attention? | Relate asset and vulnerability context to reachable paths |
| What can an audit review? | Topology, configuration analysis, and retained compliance evidence |
A permitted path is not necessarily active, and an observed connection does not reveal every path that could be used. Combining both views can help defenders spot a gap between intended segmentation and network behavior. The value depends on the completeness and freshness of the underlying data, as well as how deeply the products share it.
How path analysis could help limit lateral movement
- Identify an asset or weakness. Monitoring and vulnerability context can help teams understand which system is exposed or potentially compromised.
- Determine possible reach. Configuration analysis can show which other systems may be reachable through permitted network paths, including paths not active during a monitoring period.
- Prioritize a response. Teams can review overly broad rules, consider segmentation changes, or adjust sensor placement based on the paths that matter most.
- Validate the result. After an approved change, teams should collect current configurations and review monitoring data to check whether the intended boundary is reflected in the network.
This is exposure analysis that may help reduce opportunities for lateral movement; it is not automated prevention or a guarantee that an attacker cannot move between zones. A theoretical route may not be exploitable, while undocumented remote access or runtime behavior may create routes absent from an imported configuration.
Outdated Drivers Are Slowing You Down
One free scan finds every outdated or missing driver and matches the right update for your exact hardware.Free scan · exact hardware matchWindows Errors? Fix Them Before They Spread
Repair common Windows errors and clear accumulated junk for a smoother, more stable PC - no reinstall needed.Free scan · no reinstallCompliance support is not compliance certification
Dragos connected NP-View with NERC-CIP network-access requirements, including CIP-003 and CIP-005, TSA-related requirements, and IEC 62443 support. The company also described audit evidence and continuous compliance checks as use cases. These capabilities may help teams assess network controls and document findings, but a report does not make an organization compliant or replace the applicable compliance determination.
Requirements depend on an entity’s role, jurisdiction, system classification, and the specific standard or rule that applies. Dragos’s statement that NP-View is trusted by NERC auditors is a vendor claim, not a NERC certification or regulatory endorsement. Buyers should confirm which controls the product supports, what evidence it generates, and whether their auditors accept that evidence.
Rank #4
Where a network map can be wrong or incomplete
- Stale snapshots: A configuration report can miss changes made after the files were collected.
- Missing or unsupported devices: An incomplete inventory or parser coverage can leave gaps in the path analysis.
- Configuration/runtime differences: NAT, routing behavior, access-control order, failover, or vendor-specific behavior can make actual connectivity differ from a file-based model.
- Undocumented connections: Jump hosts, vendor remote-access tools, serial gateways, wireless links, and manual exceptions may not appear in the expected sources.
- False confidence: A clean topology does not establish that credentials, firmware, remote access, or application-layer controls are secure.
- Evidence mistaken for a verdict: Generated records can support an audit, but compliance still requires appropriate organizational judgment and control operation.
These limitations apply to the underlying visibility task, not just to one vendor. Network engineers still need to review configurations, collection schedules, change records, and operational exceptions.
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.What buyers should verify before evaluating it
The acquisition announcement did not establish current packaging or technical coverage. A buyer should get answers specific to their sites and equipment rather than assume that acquisition means a single console, license, or migration path.
What’s actually slowing this PC down?
Pick the symptom - the matching free tool is one click away.
- Device coverage: Which switch, router, firewall, and industrial-network vendors and configuration formats are supported? How are customized or legacy configurations handled?
- Collection method and cadence: What exports, access credentials, and privileges are required? How often can configurations be collected, and how are stale files flagged?
- Reachability model: Can the analysis trace transitive paths across zones and account for the network features in use? How does it distinguish a permitted path from a path confirmed reachable in operation?
- Operational safety: Is analysis offline, and does collection require any active interaction with fragile process-control systems?
- Integration status: Which data and workflows are available inside the Dragos Platform today, and which remain separate? Ask for the relevant release, product edition, and demonstration.
- Commercial terms: Is NP-View separately licensed or included, what is the migration path for existing customers, and what are the support arrangements? The acquisition announcement disclosed no purchase price or product pricing.
- Compliance evidence: Which specific controls and reports are supported, how are timestamps and change history retained, and will the organization’s auditor accept the output?
For comparison, distinguish the capability being purchased. OT monitoring platforms focus on observed assets, traffic, and threat detection; network-configuration analyzers focus on rules and possible paths; asset or vulnerability platforms emphasize inventory and exposure context; segmentation-enforcement tools implement controls rather than merely analyze them; managed services add operational expertise. Products from Claroty, Nozomi Networks, Armis, Microsoft Defender for IoT, Tenable OT Security, and Cisco Cyber Vision may be worth assessing in their relevant categories, but they should not be treated as direct substitutes for NP-View without checking the required capability and coverage.
What is known about the acquisition’s status in 2026
The acquisition was announced in 2024, not as a new 2026 transaction. In a June 1, 2026 announcement about acquiring Phosphorus, Dragos continued to describe Network Perception as contributing network visibility, segmentation validation, and compliance to its broader platform strategy. That later company announcement supports continuity in the strategic role, but it does not document every 2024 integration promise, current license, or generally available feature.
Quick Recap
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.




