IronNet Cybersecurity
IronNet Cybersecurity provides network detection and response (NDR) and Collective Defense platform services to large enterprises and government agencies in financial services, defense, healthcare, public sector, and energy verticals. Following a 2026 merger with ITC Secure, the combined entity operates as Collective Defence.
- Company typePrivate
- Founded2014
- HeadquartersMclean, United States
- Headcount11–50
- GTM typeB2B
- OfferingSoftware
What IronNet Cybersecurity does
IronNet Cybersecurity is a provider of network detection and response (NDR) and Collective Defense platform services founded in 2014 by retired U.S. Army General Keith Alexander, former Director of the National Security Agency and founding commander of U.S. Cyber Command. The company's core technology stack centers on IronDefense, a behavioral-analytics NDR product that applies machine learning to enterprise network telemetry for anomaly and threat detection, and IronDome, a shared-defense platform that enables member organizations to share anonymized threat intelligence in real time. The company primarily serves large enterprises and government agencies across the financial services, defense, healthcare, public sector, and energy verticals.
IronNet's go-to-market combines direct enterprise sales into security operations centers with channel relationships through Carahsoft, Accenture, AWS, Microsoft, and Hitachi. Named customers include Southern Company, Thomson Reuters, and an undisclosed Tier 1 financial institution with approximately $2 trillion in assets under management. Revenue mechanics are anchored on enterprise software subscriptions with associated managed detection and response services.
Following its August 2021 NYSE listing via SPAC merger with LGL Systems Acquisition Corp at roughly $125 million enterprise value, the company encountered material financial distress, relying on a $175 million standby equity line with Tumim Stone Stone Capital and subsequent C5 Capital tranches to extend runway. The company completed a financial restructuring and went private in 2025, and in February 2026 merged with UK-headquartered ITC Secure to form a combined entity operating as Collective Defence, adding operations across the UK, Luxembourg, and Singapore.
IronNet Cybersecurity firmographics
Firmographics- Name
- IronNet Cybersecurity
- Legal name
- IronNet, Inc.
- Website
- https://ironnet.com
- Company type
- Private
- Founded year
- 2014
- Operating status
- Operating
- Headcount range
- 11–50 employees
- Short description
- IronNet Cybersecurity provides network detection and response (NDR) and Collective Defense platform services to large enterprises and government agencies in financial services, defense, healthcare, public sector, and energy verticals. Following a 2026 merger with ITC Secure, the combined entity operates as Collective Defence.
- Ownership category
- akta.pro rank
IronNet Cybersecurity industry classification
Industry- Product category
- Network Detection and Response (Cybersecurity)
- NAICS
- Computer Systems Design and Related Services (54151)
- SIC
- Services-Computer Integrated Systems Design (7373)
- akta.pro primary industry
- Intrusion Prevention/Detection Systems (IPS/IDS) (HDADABAH)
- akta.pro secondary industries
- OT Threat Detection & Monitoring (NDR/IDS for ICS) (HDADAJAF), Network Security Managed Services (Firewall/IDS/IPS/SASE) (BPAEADAG), OT/ICS & Critical Infrastructure Cybersecurity Services (BPAKAHAN)
Keywords
Where IronNet Cybersecurity is headquartered
LocationHeadquarters
- HQ city
- Mclean
- HQ country
- United States
- HQ region
- North America
Offices4 records
Markets served
IronNet Cybersecurity business model
Business model- GTM type
- B2B
- Offering type
- Software
- Cost components
- Personnel, Technology or R&D, Marketing or Sales, Operations, Infrastructure
Revenue model
- Software Subscriptions: Subscription-based licensing for the Collective Defense platform including IronDefense, IronDome, and IronRadar products. Enterprise agreements likely include annual or multi-year contracts with tiered pricing based on network scale or user counts.
- Training Services: Professional training services including the IronNet Certified Analyst (INCA) course, live instructor-led training, e-learning, and custom cyber threat seminars.
- Managed Services: Overwatch managed detection and response services providing 24/7/365 SOC extension capabilities.
Pricing tiers
| Model | Billing | Price |
|---|---|---|
| Subscription | Annual | Enterprise platform pricing |
Go-to-market motion2 records
Distribution channels4 records
Marketing channels7 records
IronNet Cybersecurity product offering
Product offeringCore offering
IronNet provides a Collective Defense cybersecurity platform that combines Network Detection and Response (IronDefense) powered by behavioral analytics and AI/ML with automated cross-industry threat intelligence sharing (IronDome), proactive C2 adversary infrastructure intelligence (IronRadar), and 24/7 managed SOC extension services (Overwatch). The platform enables enterprises and government organizations to detect known and novel threats while collaborating anonymously in real time at machine speed across sectors.
Product overview
IronNet Cybersecurity offers a unified platform architecture centered on its Collective Defense Platform, which combines IronDefense (network detection and response), IronDome (automated threat sharing across industries), IronRadar (proactive threat intelligence feed), and Overwatch Services (managed NDR). The platform enables real-time threat intelligence sharing and collaboration among organizations across sectors, powered by behavioral analytics and AI/ML capabilities. Supporting services include training (INCA certification), governance maturity services, cybersecurity readiness, and incident response.
Differentiator
Problem solved
Functional benefit
Brands
- IronDefense: Network Detection and Response (NDR) solution that detects a broad range of both known and novel cyber threats using behavioral analytics.
- IronDome
- IronRadar
- Overwatch
Quantifiable outcome
- 60% reduction in mean time to response
- +3 more outcomes
Companies that use IronNet Cybersecurity
Customer profileNamed customers3 records
Segments5 records
Ideal customer profiles1 record
IronNet Cybersecurity technology and API
TechnologyAPI detail
- Has API
- No
- API docs
- API detail
Core technology
AI maturity
App detail
AI capability3 records
Feature4 records
IronNet Cybersecurity partnerships and signals
Strategic signalPartnerships
Three partnerships are on record, tiered core.
- MicrosoftcoreMicrosoft operates in strategic partnership with the merged Collective Defence entity (IronNet + ITC Secure), providing ecosystem integration and distribution support for critical infrastructure protection services.
- ITC SecurecoreITC Secure and IronNet merged to form Collective Defence, a cybersecurity firm focused on protecting critical infrastructure from hybrid warfare. Headquarters established in Luxembourg with global operations.
- CarahsoftcoreCarahsoft serves as a channel partner for US government sector sales and procurement, enabling IronNet to access federal, state, and local government customers.
Scale indicators8 records
Recent moves7 records
Expansion highlights5 records
IronNet Cybersecurity competitors and assessment
Company assessmentEmerging players
- Corelight: Open-source-based NDR platform built on Zeek, focused on high-fidelity network evidence and behavioral detection. An emerging alternative to IronDefense, particularly in technically sophisticated enterprise and federal SOC environments.
- Arista Networks (Awake Security): Arista's Awake Security division offers AI-driven NDR focused on entity and behavioral analytics. A direct NDR competitor with growing enterprise and federal traction, particularly where network telemetry is paired with Arista's switching footprint.
Direct peers
- ExtraHop: Network detection and response vendor using wire data analytics for threat detection and response. Direct competitor to IronDefense across enterprise and government verticals, with overlapping positioning on East-West traffic visibility.
- Vectra AI: AI-focused NDR vendor specializing in attacker behavior detection across enterprise networks. Competes head-to-head with IronDefense on behavioral analytics, SOC efficiency use cases, and similar enterprise customer segments.
- Darktrace: UK-based AI-driven network detection and response vendor using behavioral analytics to identify novel threats. Most direct competitor to IronDefense, with comparable enterprise go-to-market and overlap in financial services, energy, and government accounts.
Broad incumbents
- CrowdStrike: Publicly traded endpoint and extended detection and response (XDR) leader whose Falcon Network Detection offering overlaps with IronDefense. A much larger incumbent with a broader platform, deeper R&D budget, and stronger channel.
- Tanium: Converged endpoint and network visibility platform used in large enterprises, defense, and federal customers. Competes with IronNet for high-end enterprise and government security budgets where real-time visibility across the environment is required.
- Palo Alto Networks: Publicly traded cybersecurity incumbent whose Cortex XDR and network security portfolio competes with IronNet's Collective Defense platform. Operates broadly across enterprise and government with significantly greater scale.
- Cisco (Secure Network Analytics / XDR): Networking giant with an NDR offering (formerly Stealthwatch / Secure Network Analytics) and broader XDR portfolio. A broad incumbent with deep enterprise distribution that competes for the same network security budget.
- Microsoft Defender for Identity / Sentinel: Microsoft's identity, network, and SIEM/XDR offerings compete with IronDefense at the platform layer. As IronNet's strategic partner, Microsoft is also a potential substitute and a key distribution channel—creating both opportunity and platform risk.
Market position
Strengths4 records
Weaknesses4 records
Competitive moat5 records
Key risks6 records
Key highlights6 records
Customer concentration
IronNet Cybersecurity social profiles
Digital presenceIronNet Cybersecurity compliance and trust
Trust signalCompliance4 records
IronNet Cybersecurity financial estimates
Financial estimateRevenue estimate
Valuation estimate
IronNet Cybersecurity leadership team
Management profileNumber of profiles
Profiles9 records
IronNet Cybersecurity subsidiaries and ownership
Company hierarchySubsidiaries1 record
IronNet Cybersecurity funding detail
Funding detailFunding overview
Funding rounds6 records
Investors10 records
Funding detail is available on the Subscription and Enterprise plan.Contact sales →
IronNet Cybersecurity M&A and investment
M&A and investmentM&A
Investments
M&A and investment is available on the Subscription and Enterprise plan.Contact sales →
Frequently asked questions about IronNet Cybersecurity
What does IronNet Cybersecurity do?
IronNet provides a Collective Defense cybersecurity platform that combines Network Detection and Response (IronDefense) powered by behavioral analytics and AI/ML with automated cross-industry threat intelligence sharing (IronDome), proactive C2 adversary infrastructure intelligence (IronRadar), and 24/7 managed SOC extension services (Overwatch). The platform enables enterprises and government organizations to detect known and novel threats while collaborating anonymously in real time at machine speed across sectors.
Is IronNet Cybersecurity a public or private company?
IronNet Cybersecurity is a private company. It is classified as corporate owned and is currently operating.
When was IronNet Cybersecurity founded?
IronNet Cybersecurity was founded in 2014. It employs 11 to 50 people.
Where is IronNet Cybersecurity based?
IronNet Cybersecurity is headquartered in Mclean, United States, in the North America region.
How does IronNet Cybersecurity make money?
Three revenue lines are on record. Software Subscriptions are the primary driver. The others are training Services and managed Services.
Who are IronNet Cybersecurity's main competitors?
Emerging players on record are Corelight and Arista Networks (Awake Security). Direct peers are ExtraHop, Vectra AI and Darktrace. Broad incumbents are CrowdStrike, Tanium, Palo Alto Networks, Cisco (Secure Network Analytics / XDR) and Microsoft Defender for Identity / Sentinel.
Does IronNet Cybersecurity have an API?
No public API is recorded for IronNet Cybersecurity.
What industry is IronNet Cybersecurity in?
IronNet Cybersecurity's product category is Network Detection and Response (Cybersecurity). Its primary akta.pro industry code is HDADABAH, Intrusion Prevention/Detection Systems (IPS/IDS), with a secondary code of HDADAJAF, OT Threat Detection & Monitoring (NDR/IDS for ICS). Its NAICS code is 54151 and its SIC code is 7373.