-

The CVE Program Recognizes Dragos as a Numbering Authority for Common Vulnerabilities and Exposures

Dragos brings its leading OT threat and vulnerability research to the CVE Program to help industrial asset owners

HANOVER, Md.--(BUSINESS WIRE)--Dragos Inc., the global leader in cybersecurity for industrial controls systems (ICS)/operational technology (OT) environments, today announced it has been designated by the CVE Program as a CVE Numbering Authority (CNA). As a CNA, Dragos is authorized to assign CVE IDs to newly discovered vulnerabilities and publicly disclose information about these vulnerabilities through CVE Records. This includes assigning CVE IDs to vulnerabilities found in the company’s own products as well as any third-party products not covered by another CNA that Dragos finds through its ongoing research to help organizations protect their ICS/OT systems.

As cyber threats to critical infrastructure and industrial organizations increase, it is critical that ICS/OT vulnerabilities are identified, assigned, and published consistently to the CVE List. The addition of Dragos as a CNA will support the industrial community in getting the timely, accurate, and actionable information they need.

“Dragos has the largest and most experienced team of OT threat hunters, researchers, and analysts in the world,” said Ben Miller, vice president of services at Dragos. “Vulnerabilities are already incorporated into the Dragos Platform, but the CNA designation will enhance our ability to quickly, clearly, and accurately communicate vulnerability information to the broader industrial community.

Dragos OT-CERT (Operational Technology-Cyber Emergency Readiness Team)—a free cybersecurity resource for industrial asset owners and operators designed to address the OT resource gap that exists in industrial infrastructure—will coordinate with original equipment manufacturers (OEMs) regarding disclosures for vulnerabilities discovered by Dragos threat intelligence researchers, as well as cyber threats detected by Dragos targeted at the OEMs’ products. OEM partnerships are critical to coordinated vulnerability disclosures and effective threat response to protect and support industrial infrastructure in the escalating cyber threat environment. Newly assigned CVE IDs and corrections to existing inaccurate or incomplete CVE records will be publicly disclosed through OT-CERT in accordance with Dragos’s Vulnerabilities Policy.

The CVE Program is sponsored by the Cybersecurity and Infrastructure Security Agency (CISA), of the U.S. Department of Homeland Security (DHS) and is operated by the MITRE Corporation in close collaboration with international industry, academic, and government stakeholders. It is an international, community-based effort with a mission to identify, define, and catalog publicly disclosed cybersecurity vulnerabilities. Dragos joins a growing list of 237 global trusted partners across 35 countries committed to strengthening the global cyber security community through discovering and sharing valuable cyber intelligence.

About Dragos, Inc.

Dragos has a global mission: to safeguard civilization from those trying to disrupt the industrial infrastructure we depend on every day. The practitioners who founded Dragos were drawn to this mission through decades of government and private sector experience.

Dragos codifies the knowledge of our cybersecurity experts into an integrated software platform that provides customers critical visibility into ICS and OT networks so that threats are identified and can be addressed before they become significant events. Our solutions protect organizations across a range of industries, including power and water utilities, energy, and manufacturing, and are optimized for emerging applications like the Industrial Internet of Things (IIOT).

Dragos is privately held and headquartered in the Washington, DC area with regional presence around the world, including Canada, Australia, New Zealand, Europe, and the Middle East.

Contacts

Kesselring Communications for Dragos
Leslie Kesselring, 503-358-1012
Leslie@kesscomm.com

Dragos, Inc.


Release Versions

Contacts

Kesselring Communications for Dragos
Leslie Kesselring, 503-358-1012
Leslie@kesscomm.com

More News From Dragos, Inc.

Dragos OT Cybersecurity Report: Adversaries Increase Real-World Impact, Map Control Loops Across Industrial Infrastructure

HANOVER, Md.--(BUSINESS WIRE)--Dragos Inc., the global leader in cybersecurity for operational technology (OT) environments, today released the Dragos 2026 OT/ICS Cybersecurity Report and Year in Review report. In its 9th year, the report is the most comprehensive analysis of cyber threats facing industrial and critical infrastructure. The report identified three new threat groups targeting critical infrastructure globally and found adversaries progressing from reconnaissance to operational dis...

Dragos Expands Collaboration with Microsoft to Deliver OT-Native Cybersecurity at Global Industrial Scale

HANOVER, Md.--(BUSINESS WIRE)--Dragos Inc., a global leader in cybersecurity for operational technology (OT) environments, today announced an expanded collaboration with Microsoft to help organizations modernize and secure their cyber-physical operations amid accelerating digital transformation, cloud adoption, and AI-driven change. This collaboration focuses on integrating Dragos’s capabilities with Microsoft’s cloud and security platforms. By deploying the Dragos Platform on Microsoft Azure,...

Dragos Names Dawn Mitchell Chief People Officer

HANOVER, Md.--(BUSINESS WIRE)--Dragos, Inc., the global leader in cybersecurity for operational technology (OT) environments, today announced the appointment of Dawn Mitchell as Chief People Officer. Mitchell will lead Dragos's People organization and partner across the business to support the company's growth and execution as demand for OT cybersecurity accelerates globally. She will focus on building the organizational capacity to serve more customers, expand into new markets, and maintain th...
Back to Newsroom