ZeroHour
CyberScooppublished ()ingested @snlyngaas

Dragos to open Saudi Arabia office, announces new funding round

criticalExploit / PoC exploited in the wildimportance 60
Full article1,061 words · extracted from cyberscoop.com · click to collapse
Skip to main content

Get our latest cybersecurity news first on Google.

Click here!

Incident responders will be ready to deploy in a region ripe with cyberthreats to industrial control systems.

Riyadh, Saudi Arabia
Riyadh, Saudi Arabia at night. The country's National Cybersecurity Authority has warned of a new destructive malware variant (CC0 Creative Commons).

Industrial cybersecurity company Dragos plans to open an office in Saudi Arabia next year to allow the company to more quickly respond to cyberthreats to energy infrastructure in the Middle East, Dragos CEO Robert M. Lee told CyberScoop.

From the 2012 Shamoon attack on a state-owned oil company, to the infamous Trisis malware that caused a Saudi petrochemical plant to shut down in 2017, the Kingdom has been the scene of high-profile cyberattacks on industrial facilities.

“A large reason for us to build the office there in Riyadh simply boils down to that’s where threats are,” Lee said. “And identifying those [threats] and learning from them makes our software, makes our approach better for all of our global customers.”

The Saudi office will mark a major expansion for the Maryland-based company that Lee, a former Air Force and National Security Agency cybersecurity official, founded in 2016. Dragos on Wednesday also announced a $37 million Series B funding, some of which will be used to stand up the new office.

The office is projected to open in the Saudi capital of Riyadh in the second quarter of 2019, Lee said. Dragos’ incident response specialists will be based there to counter hackers targeting industrial control systems in the region.

The company’s expansion to the Kingdom comes as the international spotlight has been on Saudi Arabia’s dismal human rights record. Saudi journalist and dissident Jamal Khashoggi’s grisly murder last month sparked a global outcry. It is unlikely that Khashoggi would have been killed without the knowledge of Saudi Crown Prince Mohammed bin Salman, according to news reports citing Western intelligence officials.

Lee said there was a robust discussion within Dragos about whether the company should expand to Saudi Arabia. The decision to do business in the Kingdom ultimately came down to the benefits Saudi civilians – and not an authoritarian government – could derive from the company protecting infrastructure from hackers.

“We’ve made hard choices as a company before in doing what we think is right for our customers,” Lee said, adding: “A simple guiding principle keeps Dragos moving forward, and that is that we protect civilians.”

That means infrastructure serving civilians, regardless of which government owns it, deserves protection, according to Lee, who said he would help protect the Iranian power grid if that were feasible.

Whether a government or civilians benefit from cybersecurity protection is, of course, not a zero-sum question. The Saudi government, for example, inevitably benefits from having state-owned Saudi Aramco protected from cyberthreats.

But for Dragos, Lee said, as long as the infrastructure is serving civilians and not military purposes, the company wants to protect it.

“We don’t take contracts in the U.S. or anywhere else to protect weapons systems,” he said.

New investors 

The $37 million in Series B funding that Dragos announced Wednesday included investments from venture capital firm Canaan; industrial company Emerson; the investment arm of power company National Grid; and Schweitzer Engineering Laboratories.

The new funding “gives us years of runway to invest heavily across all areas of our business,” Lee told CyberScoop. The company is putting money into things like research and development, engineering, and incident response capabilities, he added.

In announcing the funding, Andre Turenne, director of National Grid Partners, said that “critical asset threats are on the rise, so an industrial specific cybersecurity strategy is increasingly important to companies.”

Dragos also said Wednesday that Joydeep Bhattacharyya, a partner at Canaan, would join the Dragos board of advisers.

More Scoops

Arik Ashkenazi, chief engineer at the Ein Netafim wastewater treatment plant, walks between water clarifier basins at the facility in Israel’s southern Red Sea port city of Eilat on July 13, 2023. Hemmed in between the Red Sea and a desert, isolated from the rest of Israel and with no natural freshwater, Eilat’s drinking water is a combination of desalinated groundwater and sea water. After its domestic use turns it into sewage, it is treated and then allocated to farmers, enabling the arid region to support an agricultural industry. While Eilat used to be the exception in Israel’s water management, it is now more of a prototype for the country and perhaps to the world. (Photo by MENAHEM KAHANA / AFP) (Photo by MENAHEM KAHANA/AFP via Getty Images)

Dragos: Despite AI use, new malware targeting water plants is ‘hype’

ZionSiphon was designed to find and sabotage Israelis’ water supply. An OT expert said it appears to be ineffective and the work of amateurs using AI.

Wind turbines are seen on a wind farm on a field between agricultural produce in a countryside in a village near Radom, Poland on May 19, 2025. (Photo by Dominika Zarzycka/NurPhoto)

After major Poland energy grid cyberattack, CISA issues warning to U.S. audience

Signage at the headquarters of SAP AG, Germany’s largest software company on January 8, 2013 in Walldorf, Germany. (Photo by Thomas Lohnes/Getty Images)

SAP cyberattack widens, drawing Salt Typhoon and Volt Typhoon comparisons

Latest Podcasts

Text extracted automatically; images, tables and formatting may be missing. Original: https://cyberscoop.com/dragos-saudi-arabia-office/