Dragos, Inc., known for its focus on cybersecurity within operational technology (OT) environments, has introduced EmberAI, an innovative AI solution designed specifically for OT cybersecurity. Built on the robust Dragos Intelligence Fabric, which boasts the largest OT cybersecurity dataset globally, EmberAI provides security analysts with streamlined access to Dragos’s extensive OT-specific knowledge accumulated over a decade.
EmberAI offers security teams comprehensive visibility into assets, vulnerabilities, and network activities within OT environments. This tool empowers analysts, regardless of their experience level, to prioritize threats based on operational impact and swiftly respond with informed decisions backed by authentic adversary data.
Strengthening OT Cybersecurity
The threat landscape targeting critical infrastructure is intensifying, highlighting a scarcity in OT cybersecurity proficiency. Traditional tools primarily focus on visibility, lacking the contextual understanding necessary to identify and prioritize critical threats. EmberAI aims to fill this gap by being grounded in the operational reality of sectors such as power grids, manufacturing, and water systems.
EmberAI aims to fill this gap by being grounded in the operational reality of sectors such as power grids
For organizations tasked with safeguarding diverse xOT environments—ranging from IT practitioners to seasoned OT professionals—EmberAI provides the confidence to act like OT experts. It emphasizes operational priorities and ensures effective responses against potential threats to safety and functionality.
Harnessing Dragos's Expertise
Robert M. Lee, CEO and Co-Founder of Dragos, emphasized the uniqueness of EmberAI, stating, "We built EmberAI to harness Dragos’s decade-plus of experience in threat intelligence, incident response, adversary tracking, and frontline operations for OT environments." This sentiment aligns with Gartner's advisement to leverage specialized, CPS-specific intelligence over generic global models.
The underlying Dragos Intelligence Fabric is a substantial repository, built with extensive telemetry and adversary tracking, proprietary OT vulnerability research, and frontline incident response data. It's designed to continually adapt through new intelligence and field insights, ensuring EmberAI remains effective and relevant.
Advanced Analytical Capabilities
EmberAI simplifies the analytical process through its intelligence-driven query engine
EmberAI simplifies the analytical process through its intelligence-driven query engine, allowing analysts to ask questions in straightforward language and receive OT-relevant insights instantly. It connects all crucial elements—assets, vulnerabilities, threat intelligence, and network activities—into a cohesive, real-time picture, enabling decisions to be made within full operational context.
Moreover, the platform offers adversary-informed guidance, mapping detections and alerts to known OT threat groups and attack patterns. The integration facilitates quicker transitions from alert investigation to actionable reporting, reducing manual work and enhancing decision-making efficiency.
Maintaining Control and Ownership
EmberAI ensures analysts maintain control over the decision-making process, offering recommendations that are both transparent and auditable. Importantly, customer data remains within the client's environment, reflecting Dragos’s commitment to a 'human in the loop' principle where final decisions reside with those protecting the environment. EmberAI is currently available through the Dragos Platform.
Dragos, Inc., a pioneer in cybersecurity for operational technology (OT) environments, announces the release of EmberAI, an OT-native AI built on the Dragos Intelligence Fabric, the world's largest OT cybersecurity data set. EmberAI gives every analyst immediate access to Dragos’s OT-specific intelligence gained from over a decade of OT actions, activity, and knowledge.
Putting historical and real-time intel in the hands of every security analyst, EmberAI enables teams to gain detailed visibility into assets, vulnerabilities, and network activity across their OT environment. They can prioritise threats by operational impact and act on findings specific to their environment. EmberAI empowers every analyst, regardless of experience, to move from alert to informed action faster, and make defensible decisions grounded in real adversary data.
Extended operational technology
Threat activity against critical infrastructure is accelerating. The OT cybersecurity skills needed to address these complex tactics and techniques continue to grow, and the shortage of professionals who can meet that demand continues to widen. Existing tools prioritise visibility over understanding, and general-purpose AI lacks the operational context to distinguish a critical exposure from background noise or to prioritise threats by their actual impact on operations. In OT, any delayed or incorrect decision can have direct consequences for operational safety, resilience, and control.
Organizations responsible for securing extended operational technology (xOT) environments, including power grids, manufacturing plants, water systems, pipelines, and data centers, need AI that is built on the right intelligence and grounded in operational reality. EmberAI helps analysts across the full range of experience—from IT practitioners and plant engineers operating in OT environments to seasoned OT professionals—to see, understand, and act with the confidence of an OT expert. They can prioritise what matters operationally, and act effectively on findings that threaten safe operations.
Frontline operations for OT environments
“We built EmberAI to harness Dragos’s decade-plus of experience in threat intelligence, incident response, adversary tracking, and frontline operations for OT environments,” said Robert M. Lee, CEO and Co-Founder, Dragos. “It is hard to reproduce this depth of OT-specific expertise and build AI that understands and can action OT specific findings."
In our opinion, Gartner® guidance on AI for cyber-physical system (CPS) security supports this approach: "Favour solutions that use a highly tuned, CPS-specific intelligence engine, instead of risking intellectual property and data sovereignty by feeding sensitive operational telemetry into an opaque, cloud-based global model."
Critical infrastructure environments
The Dragos Intelligence Fabric is built on over five petabytes of daily OT telemetry, 10-plus years of adversary tracking across named OT threat groups, proprietary OT vulnerability research as a CVE Numbering Authority, asset and protocol research spanning more than 600 OT protocols, and frontline incident response experience from critical infrastructure environments. The Dragos Intelligence Fabric continuously learns as new intelligence surfaces, field insights accumulate, and threat groups adopt new behaviours.
This foundation enables EmberAI to operate on a principle that distinguishes it from generic AI: OT specific intelligence applied in context. EmberAI is central to Dragos's xOT security strategy to secure the full extended operational technology environment that influences critical operational processes. As Dragos’s xOT integrations expand the Intelligence Fabric with new data sources, EmberAI's intelligence and capabilities will grow with it.
Irrelevant technical signals
- Intelligence-Driven Query Engine: Analysts ask questions in plain language and receive precise, OT-contextual answers grounded in the Dragos Intelligence Fabric. This eliminates the need to manually pivot across disconnected tools or correlate data from multiple sources.
- Contextual Correlation Across the Environment: EmberAI connects assets, vulnerabilities, threat intelligence, and network activity into a unified, real-time understanding. Decisions are based on full operational context, not isolated or irrelevant technical signals.
- Adversary-Informed Guidance: Detections and alerts are mapped to known OT threat groups, observed attack patterns, and real behaviors drawn from the Dragos Intelligence Fabric. Analysts understand not just what is happening, but what it means for their environment and how to prioritise their response.
- Workflow Acceleration and Automation Support: From alert triage to incident summaries and reporting, EmberAI reduces hours of friction laden and often error-prone manual work. Analysts spend less time gathering data and more time making informed decisions.
- Expert-Built OT Skills: Dragos analysts are building and validating a rich library of guided, repeatable workflows that encode the same expertise they apply during proactive services, investigations, and incident response. This library will be available soon.
- Continuous Learning Through the Intelligence Fabric: As new intelligence and field insights surface, the Dragos Intelligence Fabric evolves and EmberAI becomes more efficient and effective.
Enabling defensible workflows
The analyst remains in control at every step. Every recommendation that EmberAI surfaces is transparent and auditable, enabling defensible workflows.
Customer data never leaves the customer's environment. EmberAI operates inside the Dragos Platform deployment the organization already controls. These design choices reflect a foundational ‘human in the loop’ principle for OT: the person responsible for protecting an environment must own the final decision. EmberAI is generally available today inside the Dragos Platform.