All analysis was generated autonomously, without human review. Scores are analytical opinions drawn from the cited public sources, without hands-on testing. They are not audits, certifications, investment reports, purchasing advice, or evaluations of quality.
Nozomi Networks sells sensors and management consoles that inventory industrial equipment, watch plant networks and flag threats for utilities, manufacturers, hospitals and other operators of critical infrastructure. Mitsubishi Electric completed its purchase of the company in January 2026, and Nozomi now runs as a wholly owned subsidiary that keeps its own brand, staff and roadmap. That owner complicates the neutrality argument Nozomi has long made to buyers, because Mitsubishi Electric builds and sells industrial automation and control products itself. Watch whether Siemens keeps running Nozomi software on its RUGGEDCOM devices, which CISA last documented in January 2026, because that distribution path is not Nozomi's to keep.
| Description | Nozomi Networks sells an operational technology and IoT security platform to critical infrastructure operators, pairing passive network sensors, wireless sensors and endpoint sensors with cloud or on-premises consoles that inventory industrial assets, score risk and detect threats. | [f1] |
|---|---|---|
| Acquisition | Mitsubishi Electric, announced 2025-09-09 | [f2] |
| Founded | 2013 | [f3] |
| HQ | San Francisco, CA | [f4] |
| Funding | $250M total | [f5] |
| Latest funding | Series E, $100M, March 2024 (Mitsubishi Electric and Schneider Electric among the investors) | [f5] |
| Product | What it does |
|---|---|
| Vantage | Cloud console that consolidates asset inventory, risk scoring, vulnerability data and alerts from every deployed sensor across sites, sold on an asset-count subscription. |
| Central Management Console | On-premises counterpart to Vantage, aggregating monitoring and security data from sensors for operators that cannot send industrial data to a cloud service. |
| Guardian | Passive network sensor that watches mirrored industrial traffic to discover assets, build a behavioral baseline, flag vulnerabilities and detect threats without transmitting on the monitored network. |
| Guardian Air | Wireless sensor that extends monitoring to the radio spectrum in operational environments, covering OT and IoT wireless protocols the wired sensors cannot observe. |
| Arc | Endpoint sensor for operational hosts that adds host-based detection and automated threat response, running mostly in user space to limit the risk of disturbing industrial processes. |
| Arc Embedded | Sensor built with equipment makers to run inside industrial controllers, monitoring process variables and controller logic changes at the lowest levels of the Purdue model. |
| Vantage IQ | Add-on that applies a company-trained AI assistant to a customer's own asset, vulnerability and alert data to prioritize findings and suggest response actions. |
Cyber Defense Matrix
| Identify | Protect | Detect | Respond | Recover | |
|---|---|---|---|---|---|
| Devices Workstations, servers, phones, tablets, storage, network devices, IoT infrastructure, and similar hardware. | |||||
| Applications Software, interactions, and application flows on the devices. | |||||
| Networks Connections and traffic flowing among devices and apps, plus communication paths. | |||||
| Data Content at rest, in transit, or in use across devices, apps, and networks. | |||||
| Users The people using the devices, apps, networks, and data. |
Nozomi Guardian inventories industrial devices and monitors wired network traffic for threats, Guardian Air covers wireless spectrum, and Nozomi Arc adds endpoint detection with automated response inside operational environments. These capabilities are mapped to the Cyber Defense Matrix. [f6]
How well the company can compete in its security market, scored across eight dimensions against public evidence.
| Dimension | Score | Rationale |
|---|---|---|
| Problem Clarity How precisely the company defines its problem, with evidence the problem exists at the scale claimed. | 3/5 | Nozomi names a specific buyer, the operator whose control network may not be actively queried, and builds Guardian to watch passively for sites under grid, nuclear and defense rules. The pain itself is asserted on the vendor's own pages, and the reviewed sources carry no independent quantification of it. [s5, s11] |
| Capability Depth How specific the technical capabilities are, with evidence beyond marketing claims such as docs and third-party validation. | 4/5 | Product pages document five sensor types down to controller-resident monitoring at Purdue levels 0 and 1, and Arc is described as running primarily in user space with kernel modules used only when necessary. Outside scrutiny is real: CISA advisories in 2023 and again in January 2026 document Nozomi Guardian and management console flaws inside Siemens RUGGEDCOM devices, and NVD carries records Nozomi itself assigns. [s5, s7, s16, s17, s27] |
| Market Timing Whether the market is ready for this product, with evidence that buyers are actively seeking solutions. | 4/5 | Nozomi's own demand is documented: an SDxCentral article states that it passed $100 million in annual revenue at 33% year-on-year growth in January 2026. Analysts have named the category as well, with a Gartner Magic Quadrant for cyber-physical system protection platforms published in March 2026, and a federal edition entered FedRAMP review in October 2025. [s1, s14, s22] |
| Team Credibility Demonstrated domain expertise with public signals such as prior exits, publications, and industry recognition. | 4/5 | Both founders hold doctorates in the field, Carcano on intrusion detection for control systems and Carullo in artificial intelligence, and Carullo is a long-time member of the IEC TC57 WG15 standards subcommittee. The company they built sold to Mitsubishi Electric, and the reviewed record documents no earlier venture either way. [s3, s9, s19, s20] |
| GTM Proof Evidence of actual traction (customers, revenue signals, partnerships) beyond stated intentions. | 5/5 | Revenue scale and growth are reported outside the company, a listed acquirer paid roughly a billion dollars for the business, and Vantage sells on AWS Marketplace at a published contract price. Case studies name Vermont Electric, Trustpower, the Valencian Health Department and Konkuk University Hospital. [s11, s14, s20, s25] |
| Funding Efficiency Whether funding matches go-to-market ambition, with signs of capital-efficient growth. | 4/5 | Against more than $250 million raised through the March 2024 Series E, the company reached disclosed revenue above $100 million and sold for about a billion dollars. Its break-even claim is its own, but the revenue figure and the sale price were reported outside the company. [s9, s12, s14, s20] |
| Category Clarity Whether the company creates or fits a recognizable category that buyers can quickly place in their stack. | 4/5 | The category has a named analyst artifact and a published roster: Gartner runs a Magic Quadrant for cyber-physical system protection platforms, and an SDxCentral article places Nozomi in it by calling Armis a Nozomi rival. Nozomi's leader placements are read off its own pages, which is display rather than independent confirmation, so the score stops at 4. [s1, s19, s20] |
| Incumbent Defensibility How vulnerable the core value proposition is to absorption as a feature by a platform vendor. | 3/5 | Deployed sensors, an OEM arrangement that put Guardian inside Siemens hardware, and controller-resident monitoring each add work to a swap. The same graphic Nozomi publishes places Microsoft, Cisco and Palo Alto Networks in the category already, and the reviewed sources document no exclusive asset standing between them and the same buyers. [s1, s7, s17, s27] |
Nozomi starts from a claim about the tools operators already own: its Arc page says traditional agents are trained on IT environments and do not understand OT protocols or recognize OT baselines. Some of these environments prohibit active querying outright, and Nozomi names grid operators under NERC CIP rules, nuclear plants and defense sites among them. Its main sensor watches rather than probes: Guardian sits on mirrored ports or taps and, in the company's description, monitors local traffic without disrupting critical processes, triggering alarms or generating additional traffic.
The named buyers are utilities and healthcare organizations. Nozomi's published case studies name Vermont Electric, the New Zealand utility Trustpower, the Valencian Health Department and Konkuk University Hospital, and the company sells a separate government edition of its cloud console for federal agencies. CISA's industrial advisories show the same population from the other side, in this case cataloguing flaws in Nozomi's own components as shipped on Siemens hardware.
Buyers of companies have been paying large sums in this category. Within roughly a year, according to SDxCentral, ServiceNow paid $7.75 billion for Armis, Accenture paid $4.1 billion for Dragos, and Mitsubishi Electric completed its purchase of Nozomi. All three targets sit in the same protection-platform category on the graphic Nozomi publishes. [s5, s7, s11, s14, s17, s20, s22]
The platform is organized into sensors that collect and managers that consolidate. Guardian handles wired networks, Guardian Air covers the wireless spectrum, Arc runs on operational endpoints, Arc Embedded runs inside industrial controllers, and Remote Collector gathers data at small remote sites. Vantage consolidates all of it in the cloud, and Central Management Console does the same job on premises, which Nozomi pitches at operators under data residency or cloud connectivity restrictions.
Two design choices show how much Nozomi bends its own product to avoid disturbing the process. Arc runs primarily in user space and uses kernel modules only when necessary, mostly read-only, which Nozomi contrasts with endpoint tools built for IT. Arc Embedded, which Nozomi says it developed with equipment makers, runs inside controllers at Purdue levels 0 and 1 and watches process variable readings and controller logic changes, which is a layer below what the network sensors observe.
The analysis layer runs on what the sensors accumulate. Guardian builds a baseline of normal behavior by observing traffic and device interactions, Vantage ranks assets by risk using anonymized asset data with customer-adjustable scoring, and the threat intelligence add-on distills feeds from Nozomi Labs and Mandiant into threat cards with suggested mitigations. Vantage IQ, which SDxCentral describes as a company-trained assistant built on a secure model that learns from an organization's own asset, vulnerability, threat and risk data, sits on top of that. [s4, s5, s6, s7, s14]
The field is laid out in a graphic Nozomi publishes itself. The Gartner Magic Quadrant for cyber-physical system protection platforms, dated March 2026, shows Nozomi Networks, Claroty and Armis as leaders, Forescout Technologies, Tenable and Fortinet as challengers, Darktrace as a visionary, and Microsoft, Cisco, Palo Alto Networks, Honeywell, TXOne Networks and Dragos as niche players. A vendor-displayed placement is real recognition and not independent confirmation, but the roster itself is useful, because large platform vendors are already inside the category.
Ownership changed for three names on that graphic in about a year. ServiceNow bought Armis, Accenture bought Dragos, and Mitsubishi Electric bought Nozomi, so three of the vendors on that graphic now sit inside larger companies. The parents differ in a way that matters here. An SDxCentral article calls Accenture a consulting giant, and a SecurityBrief article states that Mitsubishi Electric sells industrial automation and control products.
That matters because Nozomi's stated differentiator is neutrality. Its chief executive at the time of the sale called the vendor-agnostic approach a critical ingredient of the company's success, and the transaction was announced with a commitment to preserve independent operations and a vendor-neutral roadmap. The channel is where the commitment gets tested: CISA recorded in January 2026 that Siemens was preparing fixes for Nozomi Guardian and management console flaws in its RUGGEDCOM APE1808 devices, and Nozomi's own announcements name Schneider Electric, Hitachi Cyber, Nvidia, Dispel and Xona as expanded partnerships. [s1, s9, s13, s17, s20, s27]
Some of the traction evidence was reported outside the company. An SDxCentral article dated January 2026 states that Nozomi had passed $100 million in annual revenue at 33% year-on-year growth, and the company says it has reached sustained cash flow and break-even performance. Nozomi also claims 5 of the top 10 oil and gas companies, 7 of the top 10 pharmaceutical manufacturers, 7 of the top 10 utilities and 4 of the top 10 mining operations as customers, a claim the reviewed record carries in the company's own voice.
Partner and marketplace routes run alongside direct selling. Vantage is listed on AWS Marketplace with a single published pricing dimension, a twelve-month contract at $218,880 covering up to 5,000 assets, and buyer reviews on that listing describe licensing by protected asset count. Nozomi's own announcements name Schneider Electric, Hitachi Cyber, Nvidia, Dispel and Xona among recently expanded partnerships, and a federal edition of the console entered the FedRAMP process in October 2025.
Reported figures for the sale price differ, at $1 billion in the company's own announcement and around $880 million in the analyst estimates SDxCentral cites. Named references cover several regulated sectors: Vermont Electric, Trustpower's power and telecoms network in New Zealand, the Valencian Health Department and Konkuk University Hospital. Third-party recognition beyond the analyst placements is thinner in the reviewed record, resting on rankings the company reports itself, including the Deloitte Technology Fast 500 and Fast Company's innovation list. [s9, s11, s14, s19, s22, s25]
Nozomi is founder-led again. Andrea Carcano, who co-founded the company in 2013 and ran it as chief executive until 2016 before moving to product, was appointed chief executive in July 2026, six months after the sale closed. Edgard Capdevielle, chief executive for the decade in between, moved to an advisory role. The company frames the earlier arrangement plainly: the founders brought Capdevielle in to take the platform to market, build a go-to-market organization and raise capital.
The founders' credentials sit in the domain rather than beside it. Carcano earned a doctorate in computer science on software that detects intrusions into critical infrastructure control systems, and an SDxCentral article records his earlier security engineering work at the Italian energy company Eni and research for the European Commission. Moreno Carullo, the other co-founder and chief technology officer, holds a doctorate in artificial intelligence and is a long-time member of the IEC TC57 WG15 subcommittee, working to shape cybersecurity standards for power system communication protocols.
The revenue organization is run by a hire from larger security companies. Kevin Isaac, the chief revenue officer, was chief revenue officer at Forcepoint and a senior vice president at Symantec and at Sophos. The research team is a separate asset: Nozomi Networks Labs operates from Mendrisio in Switzerland with honeypots deployed globally, and NVD records list Nozomi Networks as the CVE Numbering Authority assigning identifiers for flaws in its own products. [s3, s10, s16, s19, s20]
The assurance package covers the common enterprise requirements. Nozomi's trust center lists ISO 27001:2022 certification, SOC 2 Type II reports available under non-disclosure, a downloadable SOC 3, ISO 9001, ISO 27017 and ISO 27018, and states that third-party experts run detailed annual penetration tests. Customers choose among AWS data center locations, which Nozomi ties to their own preferences and requirements.
The federal credential is the one a competitor cannot simply assert. Nozomi announced FedRAMP Moderate In Process status for Vantage for Government in October 2025, and its licence addendum for that product represents that the service has achieved FedRAMP authorization at the Moderate baseline and commits to keeping data and system components inside approved US regions. A federal buyer would confirm that status on the FedRAMP listing itself, since the reviewed record carries the claim in Nozomi's own contract language.
Product security is handled in the open. A public product security incident response portal carries dated advisories, the most recent on 11 August 2026, covering path traversal and driver permission issues in Arc and authentication, injection and denial-of-service flaws in Guardian and the management console. CISA has published advisories in 2023 and January 2026 covering Guardian and the console as installed on Siemens RUGGEDCOM devices. On AI, the trust center states that data processed by AI features is not used to train or improve models. [s5, s8, s17, s22, s23, s26, s27]
| Company | Relationship | Note | Compare |
|---|---|---|---|
| Claroty | competes with | Named beside Nozomi Networks as a leader in the cyber-physical system protection graphic Nozomi publishes. | N/AWe captured the evidence for these companies under different evidence-model versions (v1 vs v2), so the totals were scored under different conditions and are not directly comparable. |
| Armis | competes with | An SDxCentral article describes Armis as a Nozomi rival and records ServiceNow acquiring it for $7.75 billion. | N/AWe captured the evidence for these companies under different evidence-model versions (v1 vs v2), so the totals were scored under different conditions and are not directly comparable. |
| Dragos | competes with | An SDxCentral article records Accenture acquiring Dragos, and Nozomi's alliances lead came from there. | N/AWe captured the evidence for these companies under different evidence-model versions (v1 vs v2), so the totals were scored under different conditions and are not directly comparable. |
| Tenable | adjacent | Placed as a challenger in the same protection-platform graphic Nozomi publishes, one band below Nozomi's own placement. | N/AWe captured the evidence for these companies under different evidence-model versions (v1 vs v2), so the totals were scored under different conditions and are not directly comparable. |
| Forescout Technologies | competes with | Placed as a challenger in the same protection-platform graphic Nozomi publishes. | |
| Microsoft | adjacent | Placed as a niche player in the same protection-platform graphic Nozomi publishes. | N/AMicrosoft is scored by product line, not as a whole company, so there is no company-wide column to compare. Open its profile to compare a specific product. |
Add analyzed competitors to compare them side by side with Nozomi Networks.
A closer look at the company's product strategy, measuring how defensible it is against market forces and examining the eight areas behind it.
press the advantage
Nozomi is awkward to replace because of where its sensing layer sits. Guardian runs as hardware appliances, virtual machines, embedded devices or containers attached to taps and mirror ports. Arc runs on operational hosts, and Arc Embedded runs inside controllers built with equipment makers. Its integrations route detections into playbooks and third-party security tools. None of the reviewed sources puts a duration or a cost on replacing any of it, which is why it reads as friction rather than lock-in. The intelligence Nozomi accumulates is real, and a rival with a comparable installed base could accumulate the same, so that depth is a head start rather than a lasting lead.
| Dimension | Score | Rationale |
|---|---|---|
| Value Delivery Does the product sell software as the product, or judgment, trust, or accountability with software as the delivery mechanism. | 1/3 | The delivered artifact is software and sensor appliances, sold by monitored asset count on a contract the customer signs. Nozomi lists a designated engineer, fast track services, a health check and an optimization service as a separate professional services line, so expertise is marketed beside the product rather than as the product. |
| Switching Cost How expensive leaving is for a customer: data portability, integrations, learned workflows, network effects, regulatory data residency. | 2/3 | The record documents the three things rung 2 names: baselines Guardian builds by observing traffic and device interactions, integrations routing detections into playbooks and third-party security tools, and sensors deployed as appliances, virtual machines, embedded devices or containers. No qualifying rung-3 mechanism appears, no source shows the baselines are non-portable, and none sizes an exit. |
| Compliance Moat Whether certifications, liability acceptance, or audit trails block an easy replacement. | 2/3 | ISO 27001 and SOC 2 are entry cost that any funded rival obtains. The federal edition is different: Nozomi announced In Process status at the FedRAMP Moderate impact level in October 2025 and its licence addendum represents authorization at that baseline, a government-mediated process that takes a replacement material time to reach. |
| Problem Complexity Whether the product requires ML, optimization, real-time systems, or years of specialized expertise. | 3/3 | The documented work sits in the rung-3 band: inspecting packets with protocol context in real time, learning behavioral baselines from live plant traffic, and running a sensor inside a controller at Purdue levels 0 and 1 without disturbing the process. Nozomi has been building against these constraints since 2013. |
| Buyer Profile Whether buyers are SMB operators, mid-market IT teams, or regulated enterprises and governments with procurement gates. | 3/3 | The named deployments are utilities and healthcare providers: Vermont Electric, the Trustpower power and telecoms network in New Zealand, the Valencian Health Department and Konkuk University Hospital. Vantage for Government targets federal agencies, and the reviewed record names no federal customer. |
| Layer Whether the product is an end-user application, a platform with application features, or infrastructure other applications depend on. | 2/3 | Nozomi sells a multi-component platform rather than one application: sensors, two management consoles and add-on modules, with detections routed into playbooks and third-party tools. Where it meets other vendors hardware it is the guest, running on Siemens RUGGEDCOM devices and inside OEM controllers, which is hosting in the opposite direction from infrastructure others depend on. |
| Proprietary Data, Content, or IP Whether the product accumulates datasets, content licenses, or IP that a rival cannot recreate from scratch. | 2/3 | Two accumulated inputs appear in the record: a global honeypot network Nozomi Labs runs, and anonymized telemetry its published research draws on, with Vantage separately scoring asset risk from anonymized asset data. No cited source describes a cross-customer corpus, and the threat feed draws partly on Mandiant intelligence rather than only its own. |
Nozomi sells to organizations whose production equipment cannot be treated like office IT. Its customer-story index files references under airports, electric utilities, healthcare, manufacturing, oil and gas, pharmaceutical, stadiums and arenas, and water and wastewater, and the named references inside it are Vermont Electric, Trustpower in New Zealand, the Valencian Health Department and Konkuk University Hospital. The industry pages market to a wider set of sectors than those stories cover.
Segmentation inside that base runs by deployment constraint. Guardian's page pitches passive monitoring specifically at sites that prohibit active querying, naming grid operators under NERC CIP rules, nuclear plants and defense facilities, while Smart Polling and active collection serve operators who allow it. The cloud console and the on-premises console split the base again, with the on-premises path pitched at operators facing data residency or cloud connectivity restrictions.
The public sector is treated as its own segment with its own product. Vantage for Government is a separate edition of the cloud console built to meet federal requirements, announced as reaching FedRAMP Moderate In Process status in October 2025. Nozomi also claims concentration at the top of several industries, saying it serves 5 of the top 10 oil and gas companies, 7 of the top 10 pharmaceutical manufacturers, 7 of the top 10 utilities and 4 of the top 10 mining operations. That claim is the company's own and the reviewed record carries no independent count behind it.
The capability set is organized around collection points rather than around features. Guardian watches wired networks from mirrored ports or taps, Guardian Air covers the wireless spectrum, Arc runs on operational endpoints, Arc Embedded runs inside industrial controllers, and Remote Collector picks up asset and network data at small remote sites. Vantage and the on-premises Central Management Console aggregate what the sensors produce.
Two capabilities are hard to reach from a network-only position. Arc Embedded, which Nozomi says it built with equipment makers, runs at Purdue levels 0 and 1 and reads process variables and controller logic changes, which is a layer below what a network sensor observes. Arc itself is designed to be safe in that setting, running primarily in user space and touching kernel modules only when necessary and mostly read-only, a design Nozomi contrasts with endpoint tools built for IT.
AI is applied as method rather than sold as the subject. Guardian learns a behavioral baseline by observing traffic and device interactions, Vantage ranks asset risk from anonymized asset data with customer-adjustable scoring, and the threat intelligence add-on turns feeds from Nozomi Labs and Mandiant into cards with suggested mitigations. An SDxCentral article describes Vantage IQ as a company-trained assistant built on a secure model that learns from an organization's own asset, vulnerability, threat and risk data. The trust center states that data processed by AI features is not used to train or improve models, which is a constraint an industrial operator can check before deploying it.
Distribution runs through partners and equipment makers alongside the company's own selling. Nozomi names Schneider Electric, Hitachi Cyber, Nvidia, Dispel and Xona among recently expanded partnerships, and the CISA advisory record shows the deeper form of the same motion: Siemens RUGGEDCOM APE1808 devices run Nozomi Guardian and the management console, an arrangement CISA documented in 2023 and again in January 2026, when Siemens was preparing fixes for flaws in those Nozomi components.
Investors and partners have overlapped for years. A SecurityWeek article states that the 2024 Series E brought in Mitsubishi Electric and Schneider Electric alongside earlier equipment-maker investors Honeywell and Johnson Controls, and In-Q-Tel appears in the same investor list. What the record shows is coexistence rather than cause: OEM investment, named partnerships and one packaged deployment sit side by side, and the Mitsubishi purchase now sits on top of all three.
The revenue organization is run by a hire from larger security companies. Kevin Isaac, chief revenue officer, held that title at Forcepoint and senior vice president roles at Symantec and Sophos, and the company also sells through AWS Marketplace with a published contract price. The reviewed record therefore shows selling led by a hired chief revenue officer, running alongside two documented routes to buyers: a marketplace listing and a separate federal path through the government edition of the console.
Nozomi charges by monitored asset, and a buyer review on the marketplace listing describes the model in the same terms. The AWS Marketplace listing carries one pricing dimension, a twelve-month contract at $218,880 for a bundle covering up to 5,000 assets, with sensors not billed separately. Buyer reviews on the same listing describe the licensing model in the same terms, as a count of assets to be protected.
The published figure is a useful anchor, since it puts a 5,000-asset deployment in the low six figures per year. It also tells a buyer what growth costs: crossing the asset ceiling means moving to a larger bundle, so the bill tracks the size of the monitored estate rather than the number of sensors deployed.
No price list appears on Nozomi's own pages in the reviewed record, and the marketplace listing covers one bundle rather than the whole catalog. Add-ons including Vantage IQ, Asset Intelligence, Threat Intelligence and Smart Polling are marketed as separate items, and the reviewed record does not disclose pricing for the full catalog.
Deployment starts with placing sensors, which shapes the operational questions that follow. Guardian sensors ship as hardware appliances, virtual machines, embedded devices or containers and attach to mirrored ports or taps, and the company describes them as transparent to the monitored network, generating no additional traffic and triggering no alarms. Arc installs on operational hosts, Arc Embedded goes inside controllers built with equipment makers, and Remote Collector handles low-resource sites.
Operators choose where the aggregated data lives. Vantage is the cloud option, with a choice among AWS data center locations, and Central Management Console is the on-premises option, which Nozomi pitches at operators facing data residency or cloud connectivity restrictions. The federal edition adds a stricter version of the same promise, with a contractual commitment that storage, processing, backups, logs and administrative access stay inside approved US regions.
Nozomi markets a professional services line separately from the platform, listing a designated engineer, fast track services, a health check service and an optimization service. The software remains the delivered artifact, and the services are marketed beside it rather than bundled into it.
The certification set covers the common enterprise requirements. The trust center lists ISO 27001:2022, SOC 2 Type II reports available under non-disclosure, a downloadable SOC 3, ISO 9001, ISO 27017 and ISO 27018, and states that third-party security experts run detailed annual penetration tests. Those are the credentials an enterprise procurement review asks for, and they are table stakes rather than a barrier, since any funded competitor can obtain them.
The federal credential is the one a competitor cannot simply assert. Nozomi announced FedRAMP Moderate In Process status for Vantage for Government in October 2025, and the licence addendum for that product represents that the service has achieved authorization at the Moderate baseline and commits to maintaining it for the customer's order term. The reviewed record carries that authorization claim in Nozomi's own contract language rather than in a government listing, so a federal buyer would confirm it directly.
Product security is handled publicly and in detail. Nozomi operates a product security incident response portal with dated advisories, the most recent on 11 August 2026, covering path traversal and driver permission issues in Arc and injection, authentication and denial-of-service flaws in Guardian and the management console. NVD records show Nozomi Networks assigning CVE identifiers as a numbering authority, and CISA has published advisories in 2023 and January 2026 covering Guardian and the console as installed on Siemens RUGGEDCOM devices.
Nozomi behaves as a platform in the specific sense that other people's products carry its software. Siemens RUGGEDCOM APE1808 devices run Guardian and the management console, and CISA recorded in January 2026 that Siemens was preparing fixes for flaws in those components. Arc Embedded exists because equipment makers agreed to host a Nozomi sensor inside their controllers. Both arrangements put Nozomi code inside hardware it does not manufacture.
The surrounding ecosystem is wide. Nozomi's own announcements name Schneider Electric, Hitachi Cyber, Nvidia, Dispel and Xona among recently expanded partnerships, and the platform carries an add-on threat intelligence feed drawing on Mandiant alongside the company's own research feed. Nozomi Networks Labs adds a second kind of ecosystem presence through its CVE numbering authority role and its published research.
The Mitsubishi Electric purchase sits above that ecosystem. A SecurityWeek article describes Schneider Electric, Honeywell and Johnson Controls as OT equipment manufacturers that invested in Nozomi, and Schneider Electric is also a named partner, so at least that relationship now runs to a company owned by another equipment maker. The transaction was announced with an explicit commitment to preserve independent operations, a vendor-neutral roadmap and existing go-to-market partnerships. Whether those partners renew on the same terms is the observable test of that commitment.
The company is founder-led again, and both founders' credentials sit squarely in the problem. Andrea Carcano co-founded the company in 2013, ran it as chief executive until 2016, moved to product, and was appointed chief executive again in July 2026, six months after the sale closed. His doctorate covered software that detects intrusions into critical infrastructure control systems, and an SDxCentral article records earlier security engineering work at the Italian energy company Eni and research for the European Commission.
Moreno Carullo, the other co-founder, is chief technology officer, holds a doctorate in artificial intelligence, and is a long-time member of the IEC TC57 WG15 subcommittee, working to shape cybersecurity standards for power system communication protocols. That subcommittee writes cybersecurity standards for the power system communication protocols Nozomi's customers run.
The commercial and research benches are built out. Kevin Isaac, chief revenue officer, previously held that title at Forcepoint and senior vice president roles at Symantec and Sophos, and the alliances lead came from Dragos. Nozomi Networks Labs runs from Mendrisio in Switzerland with honeypots deployed globally and publishes threat landscape research drawn from anonymized telemetry. The handover kept continuity: Edgard Capdevielle, who built the go-to-market organization over a decade, stayed on as an advisor rather than leaving outright.
| Id | Source | Tier | Accessed |
|---|---|---|---|
| f1 | Nozomi Networks About Us page: platform description and company positioning | official | 2026-08-15 |
| f2 | Nozomi Networks press release: Mitsubishi Electric completes the acquisition, January 28, 2026 | official | 2026-08-15 |
| f3 | SDxCentral: Nozomi Networks crowns co-founder Andrea Carcano as CEO | press | 2026-08-15 |
| f4 | Nozomi Networks contact page: corporate headquarters address | official | 2026-08-15 |
| f5 | SecurityWeek: Nozomi Networks raises $100 million, total raised to date | press | 2026-08-15 |
| f6 | Nozomi Networks platform overview: managers, sensors and add-on analysis modules | official | 2026-08-15 |
This site is an experimental research aid created by Zeltser Security Corp. All its data gathering and analysis was performed autonomously without human review, and it can contain errors of fact, interpretation, and judgment that a human reviewer might catch.
The analyses are statements of opinion, not statements of fact. Machine analysis produced the scores, summaries, and matrix placements by weighing the public sources each page cites, and reasonable people can weigh the same sources differently. Where a page states a fact, it cites the public source and the date it was checked, and the statement is only as accurate as that source. Unless a profile expressly says otherwise, the analysis involves no hands-on testing and no independent validation of any company's products or services.
Nothing here is professional, security, legal, financial, investment, or purchasing advice, and nothing here is a recommendation to invest in, do business with, or avoid any company. Inclusion of a company is not an endorsement, and absence of a company is not a judgment about it. Reading this site creates no advisory or client relationship. Verify any detail you plan to act on against the vendor's current materials.
The content is provided "as is" and "as available," with all warranties disclaimed, express or implied, including merchantability, fitness for a particular purpose, accuracy, and non-infringement. No entry is warranted to be complete, current, or correct. Companies change, vendors update their claims, sources can be wrong, and automated analysis can misread them.
To the fullest extent permitted by law, the operator, Zeltser Security Corp, is not liable for any damages that arise from using this site or relying on its content, including direct, indirect, incidental, special, and consequential damages and lost profits, even if advised that such damages were possible. If you are dissatisfied with the site or disagree with these terms, your remedy is to stop using it.
Entries link to vendor pages, press coverage, and other external sites that Zeltser Security Corp does not control and is not responsible for. A link is not an affiliation with the destination or an endorsement of it. Product and company names and trademarks are the property of their owners, used here nominatively to identify the companies described. Short quotations from cited sources appear for identification and commentary.
Use, quotation, automated retrieval, and redistribution of the content are governed by the Terms of Use at cybercompanyprofiles.com/terms, which permit personal and internal business use with attribution and prohibit republication and resale.