Phosphorus Cybersecurity
Phosphorus Cybersecurity provides an agentless xIoT cyber-physical security platform that discovers, assesses, hardens, and remediates IoT, OT, IoMT, and IIoT devices for enterprise customers in healthcare, financial services, manufacturing, and government. Now operating as Phosphorus, A Dragos Company.
- Company typePrivate
- Founded2017
- HeadquartersNashville, United States
- Headcount101–250
- GTM typeB2B
- OfferingSoftware
What Phosphorus Cybersecurity does
Phosphorus Cybersecurity is a Nashville, Tennessee-based provider of an xIoT (Extended Internet of Things) cyber-physical security and management platform covering IoT, OT, IoMT, and IIoT devices. Founded in 2017, the company built an agentless, hardware-free architecture that uses patented Intelligent Active Discovery (IAD) to communicate with devices via their native protocols, producing high-fidelity fingerprints across more than one million device models from over 1,200 vendors. The platform is organized into three module families — Discover & Assess, Harden & Remediate, and Monitor & Manage — spanning asset discovery, vulnerability assessment with KEV/EPSS exploit prioritization, automated password/firmware/certificate remediation, configuration hardening, state monitoring, and device backups, with compliance mappings for NIST 800-53/82, IEC 62443, NERC CIP, HIPAA, NIS2, OTCC, NDAA Section 889, CISA BOD 26-02, and 33 CFR Part 101.
Phosphorus sells primarily through enterprise field sales supported by a global network of VARs, Global SI Partners, and Technology Partners, with additional distribution via the Microsoft Azure Commercial Marketplace. Revenue is generated through per-device subscription licensing (made transparent in November 2025) supplemented by professional services for large deployments. The company raised approximately $70 million in venture funding across a 2017 seed, a $38 million Series A in February 2022 led by SYN Ventures and MassMutual Ventures, and a $27 million round in December 2023 led by Evolution Equity Partners. In June 2026 Phosphorus was acquired by Dragos to extend Dragos's OT platform into the broader Extended Operational Technology (xOT) environment; the business continues to operate under the 'Phosphorus, A Dragos Company' brand with President and COO Sonu Shankar serving as General Manager. Leadership comprises CEO Chris Rouland, President and COO Sonu Shankar, and a co-founding team including CTO Earle Ady and CFO Rebecca I. Rouland.
Phosphorus Cybersecurity firmographics
Firmographics- Name
- Phosphorus Cybersecurity
- Legal name
- Phosphorus Cybersecurity Inc.
- Website
- https://phosphorus.io
- Company type
- Private
- Founded year
- 2017
- Operating status
- Acquired
- Headcount range
- 101–250 employees
- Short description
- Phosphorus Cybersecurity provides an agentless xIoT cyber-physical security platform that discovers, assesses, hardens, and remediates IoT, OT, IoMT, and IIoT devices for enterprise customers in healthcare, financial services, manufacturing, and government. Now operating as Phosphorus, A Dragos Company.
- Ownership category
- akta.pro rank
Phosphorus Cybersecurity industry classification
Industry- Product category
- Extended IoT (xIoT) Cybersecurity
- NAICS
- Security Systems Services (56162), Security Systems Services (except Locksmiths) (561621), Computer Systems Design and Related Services (54151), Computer Facilities Management Services (541513)
- SIC
- Services-Computer Integrated Systems Design (7373)
- akta.pro primary industry
- Secure Industrial Gateways, Data Diodes & Unidirectional Security (HDADAJAM)
- akta.pro secondary industries
- Secure Smart Home Setup & Device Onboarding (Segmentation/Zero Trust) (HSAHAJAH), IoT Connectivity Management (Private APN, SIM/eSIM, Device Connectivity) (HDAIAGAG), Intrusion Prevention/Detection Systems (IPS/IDS) (HDADABAH)
Keywords
Where Phosphorus Cybersecurity is headquartered
LocationHeadquarters
- HQ city
- Nashville
- HQ country
- United States
- HQ region
- North America
Markets served
Phosphorus Cybersecurity business model
Business model- GTM type
- B2B
- Offering type
- Software
- Cost components
- Personnel, Technology or R&D, Marketing or Sales, Operations, Infrastructure
Revenue model
- Per-Device Subscription Licensing: Recurring revenue from a fully transparent per-device pricing model for the autonomous xIoT security platform, covering active discovery, risk assessment, device hardening, and remediation. Announced as an alternative to opaque CPS security pricing and passive discovery vendors.
- Channel Partner Resale & Distribution: Recurring revenue generated through a global network of VARs, distributors, Global SI Partners, and Technology Partners who resell the Phosphorus platform with software discounts and recurring revenue model benefits.
- Marketplace Sales (Microsoft Azure): Revenue transacted via the Microsoft Azure Commercial Marketplace through the Phosphorus Connector for Microsoft Sentinel solution, enabling cloud marketplace procurement.
- Enterprise Implementation & Professional Services: Large enterprise deployments (e.g., discovery across 1.2 million IPs for a financial institution in 6h 40m) typically bundled with onboarding, training, and integration services delivered with channel partners.
Pricing tiers
| Model | Billing | Price |
|---|---|---|
| Unit Pricing | Annual | Per-device transparent pricing for autonomous xIoT security platform |
| Other | Annual | Channel partner reseller pricing with software discounts |
Go-to-market motion1 record
Phosphorus Cybersecurity product offering
Product offeringCore offering
Phosphorus Cybersecurity provides an autonomous xIoT (extended IoT) cyber-physical security and management platform that delivers full-lifecycle security for connected IoT, OT, IoMT, and IIoT devices across discover, assess, harden, monitor, and remediate functions. The agentless, hardware-free architecture uses native device protocols via patented Intelligent Active Discovery (IAD) to actively profile, fingerprint, and remediate devices at enterprise scale. The platform supports on-premises, cloud (AWS, Azure, GCP), and hybrid deployments, integrates with a broad partner ecosystem, and is sold via per-device subscription licensing.
Differentiator
Problem solved
Functional benefit
Brands
- Phosphorus Labs: Threat research, security analysis, and assessment arm of Phosphorus.
Products and services
- Phosphorus xIoT Security and Management Platform Autonomous xIoT cyber-physical security and management platform that delivers full-lifecycle security for connected devices (IoT, OT, IoMT, IIoT) across discover, assess, harden, monitor, and remediate at enterprise scale, with automated controls, zero-touch deployment, and support for on-premises, cloud (AWS, Azure, GCP), and hybrid deployments. Sold as a per-device subscription to enterprise customers.
Companies that use Phosphorus Cybersecurity
Customer profileIdeal customer profiles6 records
Phosphorus Cybersecurity technology and API
TechnologyTechnology focussed Yes
API detail
- Has API
- Yes
- API docs
- API detail
Core technology
AI maturity
App detail
Integration20 records
AI capability7 records
Feature7 records
Phosphorus Cybersecurity partnerships and signals
Strategic signalRecent moves6 records
Expansion highlights6 records
Phosphorus Cybersecurity competitors and assessment
Company assessmentDirect peers
- Forescout: Forescout is a longstanding network access control and device visibility platform that has expanded deeply into OT/IoT asset discovery and segmentation. Phosphorus has a native integration with Forescout but also competes for the same xIoT visibility and policy enforcement budgets.
- runZero: runZero (formerly Rumble Network Discovery) provides agentless asset discovery and fingerprinting across IT, OT, and IoT environments. It overlaps with Phosphorus's asset discovery and classification capabilities and is named alongside Phosphorus in Dragos ecosystem deal commentary.
- Nozomi Networks: Nozomi Networks delivers OT and IoT cybersecurity with deep network and endpoint visibility, anomaly detection, and asset intelligence. It competes with Phosphorus in industrial, critical infrastructure, and healthcare verticals for xIoT visibility and threat detection.
- Ordr: Ordr is an agentless connected device security platform focused on asset inventory, risk profiling, and segmentation across IoT, OT, and IoMT environments. It is a direct competitor to Phosphorus in healthcare and enterprise xIoT security.
- Claroty: Claroty provides cybersecurity for extended IoT (xIoT) and OT environments across industrial, healthcare, and commercial sectors, with strengths in deep protocol analysis and asset discovery. It is one of Phosphorus's closest direct competitors in OT/IoMT/IIoT security.
- Armis: Armis is the leading agentless IoT/OT/IIoT asset intelligence and security platform, offering device discovery, vulnerability management, and threat detection. It directly competes with Phosphorus across xIoT asset visibility and is frequently referenced alongside Phosphorus in vulnerability management integrations.
Broad incumbents
- Dragos: Dragos is the OT cybersecurity market leader, focused on industrial control system threat detection, incident response, and the Neighborhood Keeper community. Phosphorus is now a Dragos subsidiary ('Phosphorus, A Dragos Company'), making Dragos both the parent and the closest adjacent platform for xOT convergence.
- Palo Alto Networks IoT Security (Zingbox): Palo Alto Networks IoT Security, originating from the Zingbox acquisition, offers AI-driven IoT device discovery, risk assessment, and policy enforcement within the broader Strata platform. It competes with Phosphorus at enterprise scale and bundles xIoT capabilities into broader network security contracts.
- Microsoft Defender for IoT (formerly CyberX): Microsoft Defender for IoT is the hyperscaler-incumbent OT/IoT security offering, natively integrated with Sentinel, Defender XDR, and Azure. It is both a Phosphorus integration partner (Phosphorus Connector for Sentinel) and a direct competitor for xIoT asset discovery.
- Tenable (Tenable OT / Nessus): Tenable is the broader vulnerability management incumbent with Tenable OT (acquired from Indegy) extending into industrial environments. While it is a vulnerability management platform rather than an xIoT-native discovery/remediation product, Phosphorus integrates with Tenable-adjacent platforms (Qualys, Armis) and competes for adjacent budgets.
Market position
Strengths5 records
Weaknesses5 records
Competitive moat6 records
Key risks6 records
Key highlights7 records
Customer concentration
Phosphorus Cybersecurity social profiles
Digital presencePhosphorus Cybersecurity compliance and trust
Trust signalCompliance10 records
Phosphorus Cybersecurity financial estimates
Financial estimateRevenue estimate
Valuation estimate
Phosphorus Cybersecurity leadership team
Management profileNumber of profiles
Profiles7 records
Phosphorus Cybersecurity funding detail
Funding detailFunding overview
Funding rounds4 records
Investors6 records
Funding detail is available on the Subscription and Enterprise plan.Contact sales →
Phosphorus Cybersecurity M&A and investment
M&A and investmentM&A
Investments
M&A and investment is available on the Subscription and Enterprise plan.Contact sales →
Frequently asked questions about Phosphorus Cybersecurity
What does Phosphorus Cybersecurity do?
Phosphorus Cybersecurity provides an autonomous xIoT (extended IoT) cyber-physical security and management platform that delivers full-lifecycle security for connected IoT, OT, IoMT, and IIoT devices across discover, assess, harden, monitor, and remediate functions. The agentless, hardware-free architecture uses native device protocols via patented Intelligent Active Discovery (IAD) to actively profile, fingerprint, and remediate devices at enterprise scale. The platform supports on-premises, cloud (AWS, Azure, GCP), and hybrid deployments, integrates with a broad partner ecosystem, and is sold via per-device subscription licensing.
Is Phosphorus Cybersecurity a public or private company?
Phosphorus Cybersecurity is a private company. It is classified as corporate owned and is currently acquired.
When was Phosphorus Cybersecurity founded?
Phosphorus Cybersecurity was founded in 2017. It employs 101 to 250 people.
Where is Phosphorus Cybersecurity based?
Phosphorus Cybersecurity is headquartered in Nashville, United States, in the North America region.
How does Phosphorus Cybersecurity make money?
Four revenue lines are on record. Per-Device Subscription Licensing is the primary driver. The others are channel Partner Resale & Distribution, marketplace Sales (Microsoft Azure) and enterprise Implementation & Professional Services.
Who are Phosphorus Cybersecurity's main competitors?
Direct peers on record are Forescout, runZero, Nozomi Networks, Ordr, Claroty and Armis. Broad incumbents are Dragos, Palo Alto Networks IoT Security (Zingbox), Microsoft Defender for IoT (formerly CyberX) and Tenable (Tenable OT / Nessus).
Does Phosphorus Cybersecurity have an API?
Yes. Phosphorus supports modern, API-driven environments with full REST API access for automation and orchestration, integration into cloud-native workflows and pipelines, support for custom integrations and extensibility, and enables dynamic scanning and automated security actions. Cloud-extensible across AWS, Microsoft Azure, and Google Cloud Platform (GCP).
What industry is Phosphorus Cybersecurity in?
Phosphorus Cybersecurity's product category is Extended IoT (xIoT) Cybersecurity. Its primary akta.pro industry code is HDADAJAM, Secure Industrial Gateways, Data Diodes & Unidirectional Security, with a secondary code of HSAHAJAH, Secure Smart Home Setup & Device Onboarding (Segmentation/Zero Trust). Its NAICS code is 56162 and its SIC code is 7373.