Signing you in...

Please wait while we verify your authentication

Article · Tuesday, September 22, 2026

Cybersecurity · Industry brief

Top three stories shaping Cybersecurity today, written for someone who already works in the industry: regulation, M&A, new entrants, notable filings, and any precedent worth pulling. Cite the trade publication (e.g. trade press, government source, court docket) directly so I can follow up.

By Marius BongartsTech66 editions
← See today's latest
Editions
2 / 66
Generated by AI overnight from public sources, refreshed daily.
Cybersecurity · Industry brief
Tuesday, September 22, 2026
Cybersecurity · Industry brief

Dragos closes dual acquisition; OCC updates exam framework; M&A consolidation thesis holds

1 min read

Dragos xOT platform expansion

Dragos is buying its way into firmware visibility.

The operational technology specialist acquired both NetRise and runZero, pairing firmware vulnerability detection with asset inventory and exposure management across IT, IoT, and OT environments [Quelle: Dragos]. Combined with Dragos's earlier Phosphorus deal, the stack now spans asset discovery, software analysis, and threat response—the full xOT stack in one platform. Accenture's majority investment bankrolls over 100 new hires, mostly in R&D.

Watch whether this vertical consolidation model attracts platform acquirers.

OCC exam framework realigns

Bank examiners now have a NIST-aligned playbook.

The Office of the Comptroller of the Currency updated its Cybersecurity Supervision Work Program to mirror the refreshed NIST Cybersecurity Framework categories, effective September 21 [Quelle: OCC]. The revision maintains existing examination procedures and clarifies that banks need not adopt the CSW—only use it as a scalable assessment tool for risk-based scoping. Community and large banks alike get flexible implementation pathways.

Expect vendors to certify alignment with the updated framework immediately.

xOT M&A reshapes buyer priorities

Strategic consolidation is outpacing pure expansion plays.

Beyond yesterday's Wiz stall, the Dragos-plus-Accenture move signals that enterprise buyers now prize integrated stacks over point solutions—a thesis confirmed by the Syntrix distributor play two days ago. Firmware, exposure management, and threat response bundled into one vendor narrative reduce procurement friction and operational complexity. Private equity and strategic acquirers are racing to build comparable depth.

The next tier of xOT M&A will likely consolidate visibility layers first.

Sources
Dragos Aquires NetRise and runZero: What's Next for xOT Security
Dragos Aquires NetRise and runZero: What's Next for xOT Security
15 hours ago ... He is CEO and co-founder of Dragos, a global technology leader in cybersecurity for operational technology (OT)/industrial control systems (ICS) environments.
dragos.com
AI Summary

Dragos has acquired NetRise and runZero, expanding its cybersecurity platform for operational technology environments. The acquisitions coincide with Accenture's majority investment in Dragos. NetRise provides vulnerability detection inside OT device software, while runZero offers exposure management and asset intelligence across IT, IoT, and OT systems. Combined with Dragos's earlier acquisition of Phosphorus, these additions create an integrated platform for extended operational technology (xOT) security, enabling defenders to identify assets, understand software running on them, and respond to threats. The company plans to hire over 100 positions, primarily in R&D, to accelerate product development and integration of the newly acquired technologies.

Visit source
Cybersecurity: Cybersecurity Supervision Work Program - OCC.gov
Cybersecurity: Cybersecurity Supervision Work Program - OCC.gov
12 hours ago ... This update maintains alignment between the CSW structure and the evolving NIST CSF. The CSW does not establish new regulatory expectations, and banks are not ...
occ.gov
AI Summary

The OCC updated its Cybersecurity Supervision Work Program (CSW) structure to align with the updated NIST Cybersecurity Framework categories and subcategories, effective September 21, 2026. The update maintains the existing examination procedures without adding new ones and clarifies that banks are not required to use this work program to assess cybersecurity preparedness. The CSW remains scalable for banks of different sizes and complexity, supporting risk-based examination scoping for community and large banks alike.

Visit source
Compiled overnight by MorningMail.aiDelivered at 02:40 AM