← Blog

What a $4.1 Billion OT Security Deal Says About the Market — and What It Doesn't Say

25 June 2026 · Maigadi Networks

Industry ConsolidationCybersecurity M&AOT Security MarketData SovereigntyOn-Premise SecurityCritical InfrastructureVendor IndependenceNDR

A $4.1 billion acquisition in OT cybersecurity was announced this week — the largest in the industry’s history. Majority stake in an industrial threat detection leader. Full acquisitions of two more companies specialising in asset discovery and firmware analysis. The combined entity promises a unified platform spanning IT, OT, IoT, and medical devices, backed by one of the world’s largest consulting firms.

The market’s reaction is predictable: validation. When this kind of capital moves, the category is real. OT security is no longer a niche concern for niche operators. It is a boardroom-level, multi-billion-dollar market, and the consolidation wave is accelerating — another major OT security platform was acquired for $7.75 billion late last year. The trend is unmistakable.

Dragos has earned its position at the centre of this moment. Over the past decade, it built the most respected threat intelligence operation in industrial cybersecurity, advanced the entire field’s understanding of ICS-targeting adversaries, and set the standard for what OT detection should look like. The acquisition price reflects that work, and the industry is better for it.

But validation is a market signal, not an operator’s decision. For the plant manager in Lagos, the grid engineer in Riyadh, the water utility CISO in Johannesburg — the question isn’t whether the OT security market is big enough. It’s whether the product they bet on today will still serve their interests tomorrow.

The Unspoken Cost of Consolidation

Every acquisition reshuffles priorities. Dragos has stated it will remain an independent business post-acquisition — and there is no reason to doubt the sincerity of that intent. The team that built Dragos didn’t spend a decade advancing OT detection to watch it get diluted.

But structural incentives don’t run on intent. They run on quarterly earnings targets, platform-synergy mandates, and parent-company strategy cycles that outlast any single product team’s roadmap. A platform absorbed into a consulting giant inherits that giant’s playbook: enterprise-first, cloud-first, Global 2000-first. The deals that make sense in a Manhattan boardroom don’t always make sense in a substation in Dammam.

The acquired company’s roadmap now answers to a parent whose incentives are different from an independent vendor’s. The parent wants platform synergies — how does this acquisition feed the cloud migration practice, the managed services pipeline, the digital transformation consulting engagement? The operators who bought a focused, on-premise OT detection tool may find themselves on a roadmap toward a cloud-connected, multi-product stack they never asked for.

This isn’t speculation. It’s the structural reality of any large-platform acquisition. Independence is not a feature you can add back later. Once a vendor is absorbed into a larger entity, the operator’s procurement leverage — their ability to influence product direction — is diluted across the parent’s much larger revenue base. A $10 million OT product line inside a $60 billion consulting firm doesn’t get to set its own priorities.

Sovereignty in an Age of Concentration

There is a second, quieter dynamic at work: data sovereignty. When an OT detection platform is deployed on-premise as an independent product, the operator knows exactly where their network data lives. But when that platform becomes part of a cloud-connected ecosystem owned by a global consulting firm — even if the on-premise deployment remains technically possible — the operator has to ask uncomfortable questions.

Who has access to the telemetry? Where does the anonymised threat intelligence flow? What happens to the data if the parent company’s privacy policy changes, or if the product is sold again, or if a regulatory body in a different jurisdiction issues a data access order?

These are not IT problems. They are operational sovereignty problems. An oil refinery in Port Harcourt cannot afford to have its network topology become subject to a foreign subpoena because its detection platform’s parent company operates in that jurisdiction. A power grid operator in the Middle East cannot accept that its asset inventory might flow through cloud infrastructure governed by laws it didn’t vote for.

Sovereignty is not paranoia. It is operational risk management. And in a consolidating market, it becomes harder to guarantee.

What Consolidation Doesn’t Solve

The consolidation narrative — “one platform, one vendor, simpler procurement” — works for IT. It works less well for OT, where environments are heterogeneous by design, where protocols are proprietary and decades old, where air gaps are literal walls of policy and physical separation. Layering a unified IT-OT-IoT platform on top of that doesn’t make the underlying complexity disappear. The console gets broader, but the environment underneath hasn’t changed.

The operators who need detection most — the regional utility, the mid-market manufacturer, the critical infrastructure operator in a developing economy — have requirements the consolidated platforms are least likely to prioritise:

  • On-premise, no cloud connection required. Not “cloud with an on-premise option.” Genuinely air-gap-capable. The sensor watches a mirror port. It never touches the control network. It never phones home.

  • Sovereign data ownership. No telemetry exfiltration. No threat-intelligence cloud dependency. The operator owns every packet, every alert, every baseline.

  • Focus, not sprawl. An OT detection platform should detect OT threats. It doesn’t need to also manage IT assets or scan firmware. It needs to be excellent at one thing.

  • Accessible to operators who aren’t Fortune 500. Pricing, deployment complexity, and support models that reflect the reality of a regional utility, not a global enterprise.

These requirements don’t go away because the market consolidates. They become more acute — because the vendors that could meet them are increasingly owned by the vendors with different priorities.

The Counter-Position

Maigadi was built for operators who need detection without compromise on sovereignty. A passive sensor that learns a network’s normal behaviour from a mirror port — injecting zero packets, never touching a PLC, with no mandatory cloud dependency. The baseline lives on-premise. The alerts live on-premise. The operator owns everything.

This approach isn’t a reaction to market consolidation. It’s the architecture the problem demanded from the start. OT networks are already complex. Adding a detection platform shouldn’t mean adding a dependency on a consulting firm’s cloud infrastructure, or accepting that your network data might flow through jurisdictions you don’t control, or betting that a platform’s independence will survive its next quarterly earnings call.

The $4.1 billion deal is good news for the OT security industry. It proves the market is real, the problem is urgent, and the capital is flowing. But for operators choosing a detection platform, the question isn’t how much the vendor is worth. It’s whether the vendor’s incentives will still align with theirs five years from now.

Consolidation concentrates control. Concentration concentrates risk. The operators who understand this will keep asking: who actually holds the keys?


Maigadi — the OT/ICS network detection & response (NDR) platform that passively learns your network’s normal and detects the novel, signature-less attacks others miss. On-premise. Explainable. Sovereign by design.

See it on your own network.