Tutti i fornitori

Vendor lineage

Nozomi Networks

Built on the constraint that you cannot scan an industrial network without risking the plant.

Andrea Carcano and Moreno Carullo founded Nozomi Networks in Switzerland in 2013, with European operations in Mendrisio and a later headquarters in San Francisco. Carcano had done security engineering at Eni, the Italian energy company, and research for the European Commission, and had published academic work including a description of early malware targeting SCADA systems. Carullo holds a doctorate in artificial intelligence and has served on IEC TC57 WG15, the subcommittee that writes security standards for power system communications,. Between them that is the exact pair of backgrounds the problem needed.

The constraint that defines this whole category is worth stating first, because it explains the product. In ordinary IT security you find out what is on a network by scanning it: you send traffic to a device and read what comes back. On an industrial control network you cannot do that. A programmable logic controller running a production line may be twenty years old, may have a network stack that predates the idea of hostile input, and can be knocked over by an unexpected packet. The scan that inventories your office safely can stop a plant.

So OT security had to be built the other way round: passively. You watch the traffic that is already flowing, infer from it what devices exist, what they are, what they normally say to each other, and then notice when that changes. The flagship product was named SCADAguardian, and the technique is network behavioural analytics applied to a place where behaviour is unusually predictable - which is the one advantage of industrial networks. An office network is chaos; a bottling line does roughly the same thing every day, so an anomaly actually means something.

The founders ran it themselves until about 2016, when they recruited Edgard Capdevielle to build a commercial organisation while they concentrated on the product. That arrangement lasted a decade, during which the company passed $100M in annual recurring revenue and, by its own account, became the first privately held OT security company to reach sustained cash-flow break-even. Its platform reportedly runs at five of the ten largest oil and gas companies, seven of the top ten pharmaceutical manufacturers and seven of the top ten utilities.

Then the ownership question. Mitsubishi Electric acquired the company for about $1B, completing in 2026, and on 28 July 2026 Carcano returned as chief executive with Capdevielle moving to an advisory role. The company states that it continues to operate independently and that its vendor-neutral approach is unaffected.

That claim deserves attention rather than acceptance, and this timeline is the right place to say why. Mitsubishi Electric manufactures industrial automation equipment. Nozomi's product monitors industrial automation equipment - including, necessarily, its new owner's. The strategic investors on the cap table before the acquisition were already the same shape: Honeywell, Schneider Electric and Johnson Controls, all of them vendors of the very equipment being watched.

The same question runs through several companies of this kind. CompTIA's certifications are valuable because they belong to no vendor, and whether that survives private equity is unresolved. Kyndryl's advice became worth more the moment IBM stopped owning it, because a services arm of a cloud vendor cannot credibly recommend a competitor's cloud. Equinix built an entire business on being a landlord with no network of its own. Nozomi is the live case: a monitoring company owned by a manufacturer of the things it monitors, asserting that this changes nothing. It may well be right. The point is that the assertion is the thing to watch, and the answer arrives over years in whether its findings about one vendor's equipment read the same as its findings about another's.

Founding stories

2013

Nozomi Networks

Switzerland · Founders: Andrea Carcano, Moreno Carullo

Two people with exactly complementary halves of the problem: one with industrial security engineering at an energy company and published research on SCADA malware, the other with a doctorate in artificial intelligence and a seat on the committee that writes security standards for power system communications. Industrial security needs somebody who understands plants and somebody who understands anomaly detection, and it is unusual to get both in the same room at the start.

The timeline

  1. Founded in Switzerland

    With European operations in Mendrisio and a later headquarters in San Francisco.

  2. A commercial organisation

    Edgard Capdevielle brought in to build the go-to-market while the founders stayed on the product - an arrangement that ran for about a decade.

  3. Guardian Air

    A wireless spectrum sensor, on the observation that a device can talk to a control system without ever appearing on the wired network - and therefore without appearing in any inventory built from wired traffic.

  4. Arc, Vantage IQ, and the offer

    Automated response in operational environments and a private AI assistant, in the same year Mitsubishi Electric offered $883M for the company on 9 September.

  5. Completed, on 29 January

    The company continues under its own brand as an independent subsidiary. In the same period it was named a Leader in Gartner's Magic Quadrant for cyber-physical systems protection for the second consecutive year, with the highest scores in all four critical-capability use cases.

Flagship products and solutions

  • GuardianThe passive network sensor, formerly SCADAguardian: it reads the traffic already on the wire, builds the asset inventory from what it hears, learns what normal looks like, and reports deviation. Nothing is sent to the devices.
  • Guardian AirA wireless spectrum sensor. A rogue device on a rooftop or in a vehicle never touches the wired network, so a wired-only inventory cannot see it - this listens to the radio instead.
  • ArcAn endpoint sensor for the machines that can carry one, extending visibility to where network traffic alone cannot reach, and from 2025 automating response in environments where automated response has historically been unthinkable.
  • VantageThe cloud console tying network, wireless and endpoint together across sites - a single view for organisations whose plants are in dozens of countries.
  • Smart PollingSelective, carefully-shaped active queries for the cases where passive listening genuinely cannot answer the question. The interesting part is how narrowly it is scoped, because the entire product philosophy exists to avoid exactly this.
  • Asset and Threat IntelligenceFeeds identifying industrial equipment and known vulnerabilities in it - the reference data that turns an observed device into an assessed one.

Key innovations

  • Inventory by listeningBuilding an asset register from observed traffic rather than from queries is the founding constraint turned into a technique. It also produces something a scan cannot: not just what exists, but what it normally talks to, which is the baseline everything else depends on.
  • Extending to the spectrumOnce the inventory is built from what the network hears, the obvious gap is anything that communicates without joining the network. Listening to the radio closes it, and it is the same architectural logic applied one layer out.
  • Automating response where automation was forbiddenAutomated containment is routine in enterprise security and has been close to unthinkable in operational technology, because the wrong automated action stops production. Shipping it at all is a claim about confidence in the baseline, and it is the hardest thing in this product category to get right.
  • Predictability as the exploitable propertyThe advantage of industrial networks is that they are boring. A production line does the same thing every day, so a deviation carries information that the same deviation on an office network would not. The whole detection model rests on that, and it is why the technique does not transfer cleanly to IT.

Main markets

Critical infrastructure: energy, pharmaceuticals, utilities, manufacturing, transport - the environments where the consequence of a security failure is physical. Its partner list includes Schneider Electric, Hitachi Cyber and Nvidia, and its compliance framing runs through the industrial standards rather than the IT ones.

Its competitors are the other OT security specialists and the large security platforms extending downward into operational environments, and its differentiator is depth in industrial protocols rather than breadth across an enterprise.

Analyst standing

  • A Leader in Gartner's Magic Quadrant for CPS protection platforms in both 2025 and 2026, the only vendor named a Customers' Choice in the corresponding Voice of the Customer, and a Leader in Forrester's IoT security assessment. In the 2026 critical capabilities evaluation it took the highest score in all four use cases rather than in one or two, which is the distinction worth noting - it indicates a platform not tuned to a single deployment shape.
  • One fact belongs beside the ownership question raised above, because it sharpens it. Mitsubishi Electric was not a new arrival: the company's own materials named it, alongside Johnson Controls and Schneider Electric, as an existing investor before the acquisition. The buyer was already on the cap table. Whether that makes the change smaller or the original arrangement larger is exactly the question, and it is not one an announcement can settle.
From the company