Overview

Product video
The Dragos Platform provides the most advanced OT cybersecurity technology to protect critical infrastructure organizations. The platform delivers comprehensive asset visibility, precise detection of advanced threats, vulnerability prioritization based on operational risk, and guided investigation and response without disrupting operations.
Unlike security solutions built for IT and later adapted for OT, the Dragos Platform was designed specifically for the complexity, safety constraints, and uptime requirements of critical infrastructure environments. Built on the world's largest proprietary OT dataset, platform capabilities are continuously refined by the latest frontline threat intelligence, vulnerability research, and incident response.
The Dragos Platform supports a wide range of critical infrastructure sectors, including electric, oil and gas, manufacturing, water, transportation, data centers, and more.
For private offers or custom pricing, please contact awsmarketplace@dragos.com .
Highlights
- Technology: Purpose-built for ICS/OT environments, the Dragos Platform delivers asset visibility, threat detection, vulnerability management, and investigation & response in a single solution designed for safe OT deployment.
- Intelligence: Powered by the Dragos Intelligence Fabric, the platform delivers continuously updated OT threat intelligence, OT-specific vulnerability prioritizations, high-fidelity detections and AI-assisted analysis to cut through noise and focus on what matters.
- Expertise: Built by the industry's largest team of OT cybersecurity practitioners, Dragos codifies frontline expertise directly into the platform, so every analyst has expert guidance at their fingertips.
Details
Introducing multi-product solutions
You can now purchase comprehensive solutions tailored to use cases and industries.
Features and programs
Buyer guide

Financing for AWS Marketplace purchases
Pricing
Dimension | Description | Cost/12 months |
|---|---|---|
Dragos CentralStore | Dragos CentralStore Cloud Subscription, up to 50 Connected SiteStores | $100,000.00 |
Dimensions summary
Top-of-mind questions for buyers
Vendor refund policy
Please refer to the Dragos Terms and Conditions.
How can we make this page better?
Legal
Vendor terms and conditions
Content disclaimer
Delivery details
Software as a Service (SaaS)
SaaS delivers cloud-based software applications directly to customers over the internet. You can access these applications through a subscription model. You will pay recurring monthly usage fees through your AWS bill, while AWS handles deployment and infrastructure management, ensuring scalability, reliability, and seamless integration with other AWS services.
Resources
Vendor resources
Support
Vendor support
Support is available through the Dragos Customer Portal. To open a support ticket or find documentation visit
AWS infrastructure support
AWS Support is a one-on-one, fast-response support channel that is staffed 24x7x365 with experienced and technical support engineers. The service helps customers of all sizes and technical abilities to successfully utilize the products and features provided by Amazon Web Services.
Standard contract
Customer reviews
Struggled with fragmented security and high costs but have gained some asset visibility
What is our primary use case?
I have been working with Dragos almost since the time when they started the company.
What is most valuable?
More or less every vendor in this same space, such as Clarity, Nozomi, and Dragos, are very similar to each other. There is no differentiation in terms of what output you get from Dragos, Nozomi, or Clarity. It is almost the same, but I can say it is a good vendor.
What needs improvement?
First, these are point solutions that provide vulnerabilities with respect to assets. One issue is that they have to tie up with OT security OEMs from big companies such as Honeywell and Schneider. Dragos's product success is basically dependent on how much testing is done by those vendors, and they have technology partnerships that are dependent on a third party. Second, they lack sovereign intelligence. For example, if anybody wants to buy Dragos in the UK, they do not have UK-specific threat intelligence data regarding threat actors and how they are going to target UK-based plants or some other critical infrastructure. These solutions lack this capability.
Dragos is a point product, so the customer still needs to buy ten other solutions when doing threat analytics, and they do not really guide on incident response. If I am in pain, then I have to pay more to solve that problem. These vendors charge for their services, which is expensive, and another gap is in terms of security architecture. Dragos does not provide a complete OT security architecture either. These vendors are in a money-making capital race where they try to acquire companies or use consulting companies to pitch OT projects. However, I feel customers do not need to buy ten products. They can expand use cases with the same sensors and give more benefit to clients. The output ROI is less from Dragos, Nozomi, and Clarity compared to what the customer really spends.
Dragos is very expensive, charging more than the OEMs. For example, if a PLC costs ten thousand dollars, a customer pays Dragos almost one to ten price in relation to what they would have spent building their plant. They are not really doing something extraordinary or out of the box, so in today's world, these vendors need to improve on their use cases. They can build a SOC along with their tool, integrate a log analytics concept, and allow the customer to not go with ten products while doing holistic threat detection and response. I feel there are gaps disturbing client operations because they do not have that much money. In OT security, spending is difficult.
The risk quantification is also not clear with Dragos-like products. They do not highlight the financial impact of detected threats to customers. They do not give visibility regarding malware artifacts or detection capabilities they research on. Such visibility is not available to the client. It is running a product in isolated environments where capabilities are not one hundred percent visible to the client. The customer is more in fear in terms of their plant operations, leading them to purchase point products, which is the challenge with these products. The market is moving from these point products to expanded solutions. They can expand use cases, but costs are high again, and I do not think with AI's advent development costs have really gone down. Cost for clients should reduce, especially since labor costs are going down significantly with AI investments.
If I am the client, I would ask them why, if AI is used for development, costs have not reflected that, and use cases have not expanded. These vendors are part of the cybersecurity capitalist game, nothing else.
Regarding Dragos's incident response capabilities, downtime and operational integrity are fine but depend on what part of your plant is affected. Since these players do not address that angle, the customer does not understand the operational processes either. They do not alert customers if a critical section of the plant is impacted. There is no business context in these solutions. It is a half-hearted play. They brought technology very late with Clarity being the first vendor, which I prefer over Dragos. It depends on how strong your research teams are to take it back to markets, as regulations and compliance are enabling sales.
What customers want is sovereign intelligence, which is not available from any vendors. If I am in the UAE today, the country wants that intelligence, but vendors sell the same offering everywhere, focusing on larger markets and not investing in small country intelligence teams. There is a gap in building intelligence, and open-source intelligence is available to everyone now. Anyone can create an AI tool, making it easy for countries to develop their own tools. Vendors need to come up with brilliant ideas to survive. The transfer of development to AI means they need to address this reality.
What do I think about the stability of the solution?
The stability and scalability of Dragos are fine. I would rate it an eight.
How are customer service and support?
Technical support is difficult to reach, and they should simplify the process. They need to create an engagement process with engineering teams directly because we do not need support. We want access to engineers and developers to solve problems immediately. We are operating critical infrastructure. Why should we adhere to a four-hour, twenty-hour, or thirty-hour SLA? A four-hour downtime in a plant equates to millions of dollars. Why cannot we have developer support in a region? The support strategy for critical infrastructure is inadequate, and I rate them one out of ten for support due to their failure to create the best strategies. In critical operations, there should be zero downtime, and this requires direct development access to the client because they are paying millions.
What other advice do I have?
I feel Dragos plays a lot of diplomatic political games when dealing with clients, which presents challenges in working with them. It is not straightforward, and their channel is the most problematic. I have not seen it doing the right things or enabling the market or creating a community. There is no customer community in the region. They protect critical infrastructure but have not established their own community, which surprises me. They are typically sold as antivirus products. There is little difference from an antivirus vendor. There are various challenges, and they have not reflected on giving back to society. They need training portals, easy access to training, awareness training, and enablement for the community. Their work is lacking.
They should partner with institutions to support building the right ecosystem, which I have not seen them do. There are good things and bad things. Dragos does what it is supposed to do, but I expect more from the founders. Because of that and the lack of proactivity amid AI advancements, I see vendors from small countries developing their own technology, and I anticipate failure for Dragos. Due to not being proactive, I would rate them between three and five.
If I have to choose, I give them four. Because they are not proactive, I rate them four. Their branding is good, and the website is good, but that does not solve the problem. The interface, reports, security, and customization are fine. Anyone can achieve that with AI tools now. Vendors need to come up with brilliant ideas because AI will replace their concepts eventually. They must provide customers more in detection and protection. Security should not be sold in parts. As a security partner, it is necessary to give a holistic package without charging for one problem at a time.
Consolidation is needed. Dragos is not proactive and is merely selling. From a marketing perspective, they are good, with a good website, good reports, and sufficient funds to hire and fire salespeople. I have worked in IT since two thousand ten onwards. My overall rating for Dragos is four out of ten.
Gained deep OT visibility and detect unauthorized access while monitoring gas infrastructure
What is our primary use case?
The main use case I had for Dragos during that period was for infrastructure monitoring and to begin detecting any incidents or problems that could arise, especially configuration failures, such as unauthorized accesses or RDP sessions, mainly for an assessment of the OT infrastructure that existed at that time in the gas industry in Colombia.
A specific example of an incident or relevant finding that Dragos helped identify during that assessment occurred during installations when the switches were not being correctly set to monitor mode. Once we started to receive some initial traffic, it was detected that RDP sessions existed to devices on the OT network that should not have had them, which raised an incident that proved very significant because people thought RDP was never used, and it turned out that it was being used.
What is most valuable?
The best features that Dragos offers include a really appreciated dashboard and especially the way the sensors are integrated, which allows any field engineer to perform the integration and see all the traffic that is going through. The only critical part is enabling Port Mirror to truly see all the traffic passing, which often causes problems or concern about losing information.
Dragos positively impacted the organization by providing visibility of all their components, although I do not know the current status since it has been almost a year since I left the company where Dragos was implemented.
I noticed specific improvements in security processes and team responses to incidents due to the visibility Dragos provided, especially when I got certified as an implementer and began to see more information until the operation of the dashboard was taken away from me, limiting my time to keep investigating and discovering more findings.
What needs improvement?
Being able to do more tuning and investigation in the dashboard to search for interesting things, along with some threat hunting, would help identify something beyond what is already there.
Dragos could be improved by integrating it or having modules for different types of industries to offer specific characteristics or information for the pharmaceutical, oil, gas, and manufacturing industries, creating a modularized product that segments the scope effectively and reduces the size of its database.
It would be beneficial for those who get certified to have a small demo that can be installed on a virtual machine to provide visibility and showcase what can be done with Dragos without relying solely on a large box, just for certified individuals or those who know the tool.
For how long have I used the solution?
I have been in cybersecurity for more than 25 years, but as a Security Architect, I have been for four months. I have been using Dragos for approximately a year, first training myself and then preparing for an implementation for Colombia, but due to some issues within the company, I did not end up doing the implementation myself; I only did remote monitoring from Mexico.
What do I think about the stability of the solution?
Dragos was quite stable during my time using it, with only one sensor experiencing issues due to a voltage fluctuation without a regulator, but it functioned seamlessly otherwise. The biggest challenge was the improper configuration of Port Mirrors, which hindered visibility of all traffic.
How are customer service and support?
My experience with Dragos technical support was non-existent since I had no need to contact them; I was certified to carry out the implementation, thus not requiring support.
How was the initial setup?
The main challenges I faced during the implementation of Dragos were getting people to correctly implement Port Mirror, but beyond that, I did not encounter problems executing the commands since I have extensive experience working with switches and Linux.
Which other solutions did I evaluate?
My experience with integrating Dragos with other tools or systems was that no additional tools were integrated, as it was the first tool put in place and, to the best of my knowledge, it is still in use today unless it has been removed for some reason.
What other advice do I have?
Dragos basically helped us get to know the entire infrastructure because there were many devices that not even the client themselves knew existed or that were still active, making it a very good tool; however, it requires a lot of hardware and knowledge, especially expertise from people who have worked in the industry and know security, which was lacking in the company where it was implemented, leading to lucky hits but ultimately prompting my decision to change companies.
My advice to companies considering implementing Dragos is to evaluate the tool but ensure they have a person who truly understands the industry, what operates within their OT infrastructure, and cybersecurity expertise, rather than someone who has simply taken a course or has a casual connection selling them the product.
Asset inventory has become automated and vulnerability management is saving our team time
What is our primary use case?
My main use case for Dragos is for vulnerability management, which I rely on day-to-day. A quick specific example of how I use Dragos for vulnerability management in my daily work is that I made an asset inventory with Dragos sensors.
If I am following the right procedure, it is good to go with good procedure. If we do not have the step-by-step procedure or the guidance, it may not be very simple to use.
What is most valuable?
The best features Dragos offers are its capabilities for vulnerability management and asset inventory building, and the sensor can detect a lot of assets.
What stands out to me about the inventory building and asset detection is the simplicity of detecting the assets and building tables that contain all the assets that I need to collect. Dragos has positively impacted my organization by aiding us to compensate our time. It is useful to have less manpower, so we do not have to use a lot of time to collect our assets and make an organized sheet manually. Dragos makes this automatically. It has already reduced our time and manual work since using Dragos, but I cannot share specific details because they are confidential.
What needs improvement?
From my point of view, Dragos cannot be improved at the moment, but having more user-friendly platforms would be good. Enhancing the user interface experience to be better or more smoothly would be beneficial.
For how long have I used the solution?
I have been using Dragos for just a few months, and I used the application and some of the accessories of Dragos, including sensors and the vulnerability management application.
What other advice do I have?
I have not used Dragos's AI capabilities before. I gave this review a rating of 8.
Risk monitoring has improved and real-time fraud detection provides transparent banking control
What is our primary use case?
Dragos is a tool that is very specialized in OT and ICS cybersecurity platforms. Dragos is very stable and widely used in critical infrastructure sectors, mainly in banking, education, and insurance sectors. It provides excellent detection visibility, threat detection, governance alignment, and incident response capabilities. In a real-time banking security operation, Dragos is a very strong choice.
In real-time banking environments, I use Dragos for fraud and transaction monitoring. Dragos integrates with other SOC systems to monitor OT and ICS systems in banking data centers as well as ATM networks. It integrates with all the different machines to identify any fraud or transaction issues that may be happening, such as incorrect deposits or withdrawals for particular customers. All of these things are monitored through fraud and transaction monitoring, which is one of the best real-time examples.
Dragos also has asset visibility capabilities where it identifies and maps critical banking infrastructure assets like servers, ATMs, and payment gateways. Asset visibility helps understand what type of ATM and what type of servers are being used, who is accessing them, who is withdrawing funds, who is depositing funds, and who is using different features.
Threat detection is another important capability where Dragos detects protocol anomalies and threats in real time while reducing false positives compared to IT-centric tools. If someone tries to detect the tool with improper options, tries to break down machines, or commits fraud, threat detection helps identify who that person is and what they have done.
Dragos integrates with SOC systems, especially OT and ICS systems, to give a clear picture of a particular customer who has been using a specific ATM at a center. If a customer goes to a bank and tries to use different options such as depositing, making fixed deposits, withdrawing, or conducting any kind of transaction or fraud, the fraud and transaction monitor helps identify which bank the customer visited, which data center was used, what servers are in it, and what ATM networks are across it. It tries to identify each piece of information related to that customer and helps understand whether proper or improper things have taken place. It is more of monitoring and transaction control, and it is very transparent toward any customer.
What is most valuable?
Risk detection while using Dragos helps identify that incident response planning is one of the options in risk detection. I have reduced it from 40% to 18.5%, and ICS visibility has also contributed to a 60% improvement overall.
Dragos includes features like automated asset discovery, protocol-aware detection, incident response playbooks, and threat intelligence reports. Dragos supports monitoring of hundreds of thousands of assets and has positive false positive reduction.
Governance alignment with formats like NERC, CIP, IEC, and others, broad-level reporting, and operational resilience are some of the best governance features providing the right guidelines and policies.
What needs improvement?
Dragos should be improved in deployment complexity as it requires OT engineering coordination. One needs to have proper engineering coordination to understand the system, deploy it, integrate it, and make all the complex things into one system. This is very challenging, and one should be really skillful and have experience to accomplish this.
Cost is another area for improvement. The cost is higher due to site-based licensing and expert services. The licensing is very heavy, and expert services are required for deployment. Cost-wise is also challenging and needs to be improved.
Integration needs alignment with IT security systems and compliance frameworks. Controlling cybersecurity where any fraudulent person or third party should not access the system is controlled, and managing that level of complexity is quite challenging.
Since there is continuous monitoring, it can reduce operational risk losses by 20% to 30% annually. Controlling that huge amount of data and transactions, especially regarding storage, requires a lot of database space. The space-wise storage should be reduced.
For how long have I used the solution?
I have been using Dragos for the last four years.
What do I think about the stability of the solution?
Dragos is a stable tool. It is scalable and ideal for any banking sector. Dragos's scalability is good. It is highly scalable, especially as it handles large-scale banking networks operating with different users from different varieties, especially in India across different branches. It is a stable tool with strong reliability ratings in critical infrastructure environments. Out of five, I would rate it as 4.5 in enterprise reviews. Dragos is a stable tool with high scalability and strong stability.
What do I think about the scalability of the solution?
Dragos's scalability is good. It is highly scalable, especially as it handles large-scale banking networks operating with different users from different varieties, especially in India across different branches. Dragos is a stable tool with strong reliability ratings in critical infrastructure environments.
How are customer service and support?
Customer support is good. I could rate it a 10 out of eight. They are very good in customer support. If someone is looking for Dragos, especially who are into specialized handling of cybersecurity platforms in a very high scalable manner, maybe toward any banking sector, and if they want to provide any asset visibility, threat detection, and governance alignment with incident response capabilities, I think when all of these come into picture, Dragos is a strong choice. There are other tools available, but Dragos is a very strong tool when comparing all its metrics, scalability, and governance.
Which solution did I use previously and why did I switch?
I have not used any previous solution. I started with Dragos in my current organization.
What was our ROI?
The return on investment is more about time saved. Dragos saves time compared to other tools, especially for employees. Together, I achieve reliability and accuracy at 99.9% uptime. The time saved has been significant compared to other tools in the market. It has really helped in achieving cloud data integration with different tools, saving time. It gives access to valid users, allowing me to know the transactions of different customers. Banking sectors can recover various banking sector operations in no time. Transactions and everything are covered in very little time. The time saved is a good example compared to other things.
What's my experience with pricing, setup cost, and licensing?
Pricing-wise, I am not certain because there is a third party who handles the pricing in my company. The setup cost and licensing is quite critical. Licensing is always handled for access users, and only valid users can access this license. The organization level access is compared to individual level access. Dragos setup and cost is handled by a third party. Licensing is a valid license for specific accessible users.
Which other solutions did I evaluate?
I have not used any other tool, but there is one more tool called Nozomi Networks. That is another option I had considered, but I always use Dragos. Dragos was the very first option I used.
What other advice do I have?
Risk detection is something where I identify that incident response planning is one of the options in risk detection, which has reduced to 18.5% from 40%. Using ICS visibility has helped a lot, and a 60% improvement has been done overall.
There are some features like automated asset discovery where I have proper visibility of the vendor and model context, determining what is automated to that particular option or for banking usage. Protocol-aware detection tunes to iOS or IoT OT environments, knowing what protocols and what aware detections exist. If any improper detection happens, the protocol gives awareness that something is going wrong. Incident response playbooks guide investigations of what is happening across banking systems, especially servers and databases.
Scalability is another important feature. It supports monitoring of hundreds of thousands of assets across multiple sites. More customers or different users who come and access different monitors, especially banking systems, have been enabled through this scalability. False positive reduction is another feature that understands behavior analytics tuned to OT protocols, minimizing alert fatigue. If false positive reductions or any deductions happen, they are tracked.
Governance alignment has been very much improved in my organization by using Dragos. It supports formats like NERC, CIP, IEC, and standards called NIST and CFC compliances. These are government and governance compliance according to banking sector requirements based on unique identifiers and are always valid toward any system. Broad-level reporting provides risk scoring and incident records for audits. If any risk happens, I know what should be improved next time. If anything changes, I know what needs improvement. The reporting level, especially at board level in a high-level capacity controlling branches, especially from headquarters, is one of the benefits Dragos has provided. Operational resilience is another benefit where continuous monitoring of Dragos ensures reduced downtime and financial risk.
Operational resilience is continuous monitoring. Metrics-wise, it helped me achieve downtime reduction of less than two hours of downtime per year for critical banking services. The Reserve Bank of India guidelines require banks to set impact tolerances for critical operations like payment processing. Recovery time objective helped me achieve under 30 minutes for core banking systems. Earlier it was around 3-4 hours and now it has reduced to 30 minutes.
Dragos should be improved in deployment complexity as it requires OT engineering coordination. One needs to have proper engineering coordination to understand the system, deploy it, integrate it, and make all the complex things into one system. This is very challenging, and one should be really skillful and have experience to do that. Cost is another area for improvement as it is higher due to site-based licensing and expert services. The licensing is very heavy, and expert services are required. Integration needs alignment with IT security systems and compliance frameworks where controlling cybersecurity to prevent fraudulent persons or third parties from accessing the system is complex.
Accuracy and dependency-wise, the tool is very accurate. The percentage of error-free transactions processed in banking achieving 99% is one of the most important metrics for millions of daily transactions. Fraud detection accuracy is another metric where AI-driven fraud helps identify and especially 95% of detection happens through this accuracy. Data accuracy, especially in KYC, helps banks identify what type of KYC information like ID proofs is present, avoiding regulatory penalties at 99% accuracy. Reliability-wise, the core banking system is always at 99.9% uptime and gives the right measures toward any customer. Mean time between failure (MTBF) is another metric where ATM networks achieve more than 5,000 plus hours.
I use AWS cloud for my hybrid deployment and have purchased Dragos from the AWS marketplace.
Dragos especially ensures systems recover quickly, providing resilience. It handles all the operational resilience in banking, with metrics of 99.9% uptime, 30 minutes recovery time, and 99% transaction accuracy.
I would rate this review an 8 out of 10 overall.
Which deployment model are you using for this solution?
If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?
Offers strong incident response features but requires more asset visibility and flexibility
What is our primary use case?
I am an engineer in a service provider company where we help clients choose and implement security solutions, and I'm still looking for a new solution.
I am certified in Dragos, but I have not deployed it in client sites.
I used Nozomi a few years ago for two years, and now I'm getting trained in it so that I can help clients implement the tool. My customers are still using it.
What is most valuable?
Dragos' best features are that they are more focused towards Incident Response, so they have a dedicated playbook in their platform, making it easier for anyone investigating any incidents to investigate the alerts. One of the main features of Dragos is that they have a dedicated Incident Response team, so if clients need any help, they are there to help.
Dragos does real-time monitoring as well, collecting mirror traffic from the span port of the switch, and as soon as it gets the traffic, it analyzes it in real time and shows what's going on in the networks, which relates to the real-time visibility feature for ICS networks.
What needs improvement?
I think Dragos could be improved, as I have worked in Nozomi and compared it to Nozomi. Nozomi offers a lot of flexibility in what I am able to learn and unlearn, and I have more visibility towards the nodes, links, and process variables, which I think is missing in Dragos.
I think Dragos can offer more flexibility similar to Nozomi and more visibility into the assets, nodes, and links, which would make it more competitive in the future.
For how long have I used the solution?
I have used Clarity for two years, and it has been one year since I last used Clarity. That is how long I have been dealing with the Clarity platform.
What other advice do I have?
I have experience managing the tools Clarity, Nozomi, Dragos, Sangfor, and I am familiar with these products.
My customers are already working with Devo, Dragos, Nozomi, Clarity, and these are locally deployed in the client sites, not bought on the AWS Marketplace.
I have not used Devo, but I have used Nozomi and Dragos, so I do have experience with those products.
I completed my certification in Dragos and recommend it to my customers already, and I have been dealing with Dragos for a while now.
Dragos offers a threat intelligence subscription called worldview, so if a customer subscribes to that, they will get regular threat intelligence.
I have not used much of the detailed analytics and reporting functionalities of Dragos.
Dragos is a good option to choose, as it performs well in the market.
Dragos is a big name, and there is room for Dragos in the India market, and they should promote it more.
The company that I'm working for is a partner with Dragos. I also have partnerships with other vendors including Clarity, Nozomi, and Fortinet.
I was learning FortiSIEM three months back, but I am not certified in it, so I have been dealing with Fortinet products in a somewhat limited manner. FortiGate is what I mostly deal with from Fortinet.
On a scale of 1-10, I would rate this solution a 6 or 6.5.

