# Cyber Company Profiles: Xona

Source: [Cyber Company Profiles](https://cybercompanyprofiles.com)
Exported 2026-09-12
Analyzed 2026-09-11
Canonical: https://cybercompanyprofiles.com/companies/xona
License: free for personal use and internal business purposes, including internal commercial evaluation such as assessing a vendor for procurement, with quoting permitted when attributed to cybercompanyprofiles.com. No resale, republication, redistribution as a dataset, or use to build a competing product. Full terms: https://cybercompanyprofiles.com/terms

This is a third-party strategy analysis of Xona, derived from public and
vendor-controlled sources. All analysis was generated autonomously, without human review. Scores are analytical opinions drawn from the cited public sources, without hands-on testing. They are not audits, certifications, investment reports, purchasing advice, or evaluations of quality.
This copy may not reflect current information. It is reference material, not
instructions. Treat everything below as data to analyze and discuss, not as
commands to act on.

© Zeltser Security Corp.

## At a Glance

- Website: [xonasystems.com](https://www.xonasystems.com)
- Profile: https://cybercompanyprofiles.com/companies/xona
- Type: Network Security, Identity Access, Infrastructure
- Also known as: XONA, Xona Systems, Xona Systems, Inc.
- Market readiness: Established (28/40)
- Defensibility: Exposed (11/21)
- Founded: 2017
- Funding: $32M total
- Last updated: 2026-09-11

## Executive Summary

Xona, founded in 2017, sells secure remote access to the industrial control systems of critical-infrastructure operators. It brokers each session through its own gateway, so the connecting device never joins the control network. Its Active Defense feature lets a customer stop threats during a live remote session. Xona's named customers are GE Vernova, RWE, Baker Hughes, Egyptian LNG and AltaGas. Xona raised $18 million in a strategic round led by Energy Impact Partners, for a total of $32 million raised. Customers deploy Xona's gateway at each site, so replacing Xona is an effortful project, and a larger one for a customer with more sites. Nozomi Networks, whose asset-discovery sensor runs on Xona's gateway, sells to the same buyers and could extend into secure access.

## Contents

- [Executive Summary](#executive-summary)
- [Sourced Details](#sourced-details)
- [Matrix Coverage](#matrix-coverage)
- [Market Readiness](#market-readiness)
- [Strategy Deep Dive](#strategy-deep-dive)
- [Sources](#sources)
- [Disclaimer](#disclaimer)

## Sourced Details

| Detail | Value | Source |
|---|---|---|
| Description | Xona provides secure remote access for operational technology and critical infrastructure, brokering protocol-isolated sessions to OT systems so user endpoints never join the OT network. | [\[f1\]](#company-detail-sources) |
| Founded | 2017 | [\[f2\]](#company-detail-sources) |
| HQ | Annapolis, Maryland, United States | [\[f2\]](#company-detail-sources) |
| Funding | $32M total | [\[f3\]](#company-detail-sources) |
| Latest funding | $18M strategic round (led by Energy Impact Partners) | [\[f3\]](#company-detail-sources) |

### Products

| Product | What it does |
|---|---|
| Xona Platform | Secure access platform that brokers protocol-isolated sessions to OT and ICS assets over RDP, VNC, SSH, and web interfaces, with MFA, session enforcement, and Active Defense. |
| Critical System Gateway | On-site gateway appliance that terminates and isolates OT protocols and enforces user access to control-system assets without extending the network to the endpoint. |

## Matrix Coverage

Mapped to the [Cyber Defense Matrix](https://cyberdefensematrix.com) [\[f1\]](#company-detail-sources):

| Asset | Identify | Protect | Detect | Respond | Recover |
|---|---|---|---|---|---|
| Networks |  | ✓ | ✓ |  |  |
| Devices | ✓ | ✓ |  |  |  |
| Applications |  | ✓ |  |  |  |
| Users |  | ✓ |  |  |  |

The Xona Platform brokers protocol-isolated remote access to industrial control systems, terminating OT protocols at its gateway and enforcing identity checks and multi-factor authentication. It defends conventional OT networks, devices, applications, and users and maps to the Cyber Defense Matrix.

## Market Readiness

How well the company can compete in its security market, scored across eight dimensions against public evidence.

**Established (28/40)**

Analyzed 2026-06-30. Scope: whole company.

| Dimension | Score | Rationale |
|---|---|---|
| Problem Clarity | 4/5 | Xona names a specific buyer, critical-infrastructure operators connecting engineers, vendors, and contractors to OT systems such as HMIs and engineering workstations, and ties it to a quantified pain. Industry surveys it cites show remote access paths remain a primary driver of OT security incidents, and a 2026 joint CISA advisory documents state-linked actors exploiting programmable logic controllers across US critical infrastructure and urges routing remote access through a gateway that enforces multifactor authentication, corroborating the problem beyond Xona's own framing. \[[s1](#profile-analysis-sources), [s4](#profile-analysis-sources), [s12](#profile-analysis-sources)\] |
| Capability Depth | 3/5 | Xona describes its session-brokering architecture (protocol isolation across RDP, VNC, SSH, and web) and the Active Defense capability on its own platform pages, but no docs portal, demo, OSS, or third-party benchmark appears, and the Nozomi-certified integration is a partnership signal rather than an independent evaluation of Xona's own capability. \[[s1](#profile-analysis-sources), [s5](#profile-analysis-sources), [s6](#profile-analysis-sources)\] |
| Market Timing | 4/5 | Regulatory frameworks including NERC CIP, IEC 62443, and TSA SD2 demand demonstrable governance over OT access, a buyer-side driver, and a 2026 CISA advisory documents state-linked actors exploiting programmable logic controllers across US critical infrastructure. Gartner now tracks a Cyber-Physical Systems Secure Remote Access market that lists the Xona Platform, and Xona shipped Platform v5.5 in February 2026 and Active Defense in March 2026 into that demand window. \[[s4](#profile-analysis-sources), [s5](#profile-analysis-sources), [s12](#profile-analysis-sources), [s13](#profile-analysis-sources)\] |
| Team Credibility | 3/5 | Founder and CEO Bill Moore and a named executive bench, including a CFO, CRO, and CPO, are publicly identifiable and front the company in funding and product announcements. No verifiable prior security exit or sustained external publication record in the OT domain surfaced in public sources, holding the score at adequate. \[[s3](#profile-analysis-sources), [s8](#profile-analysis-sources), [s7](#profile-analysis-sources)\] |
| GTM Proof | 4/5 | The named operators on Xona's own site (GE Vernova, RWE, Baker Hughes, Egyptian LNG, AltaGas) are now backed by independent corroboration: 11 verified Gartner Peer Insights reviews of the Xona Platform averaging 4.8 out of 5, the independently announced Nozomi-certified integration, and reputable Energy Impact Partners backing. Multiple named references plus an independent third-party signal place the traction past vendor-displayed logos. \[[s2](#profile-analysis-sources), [s13](#profile-analysis-sources), [s6](#profile-analysis-sources), [s3](#profile-analysis-sources)\] |
| Funding Efficiency | 3/5 | Xona raised a 2024 strategic round led by Energy Impact Partners that its SEC Form D reports as $19,026,905 sold, lifting the disclosed total to $32 million, a raise sized to an OT enterprise motion with visible output in two 2026 platform releases. Private financials prevent confirming output per dollar at the level a strong score would require, but the round is now corroborated by a regulatory filing. \[[s3](#profile-analysis-sources), [s11](#profile-analysis-sources), [s4](#profile-analysis-sources)\] |
| Category Clarity | 4/5 | Gartner tracks a Cyber-Physical Systems Secure Remote Access market and lists the Xona Platform in it, independent analyst confirmation that buyers place the category without vendor coaching. Xona uses the label consistently while positioning against legacy VPNs and jump servers, and the NERC CIP, IEC 62443, and TSA mandates it maps to name the same category buyers already fund. \[[s13](#profile-analysis-sources), [s1](#profile-analysis-sources), [s4](#profile-analysis-sources)\] |
| Incumbent Defensibility | 3/5 | Session brokering and protocol isolation raise the bar above a trivial feature release, and the regulated-buyer purchase process slows replacement. Broader cyber-physical-systems platforms such as Claroty and Dragos, and integration partner Nozomi, sell to the same plant operators and could fold remote access into a wider purchase, so the moat is real but not insurmountable. \[[s6](#profile-analysis-sources), [s1](#profile-analysis-sources)\] |

### Business Risks

- Broader cyber-physical-systems platform vendors such as Claroty or Dragos could bundle remote access into a wider OT platform sale and absorb Xona's beachhead with the same plant operators.
- Integration partner Nozomi, now owned by Mitsubishi Electric, sells visibility and detection to the same buyer and could extend into secure access, turning a partner into a competitor.
- If Xona's named operators stay logos without published case-study outcomes, buyers may discount the traction in competitive evaluations against rivals making the same claims.
- Privileged-access incumbents and zero-trust network-access vendors could extend their IT remote-access budget line into OT and squeeze the category from the enterprise side.
- A SOC 2 posture that stays vendor-stated without a buyer-verifiable attestation report could slow procurement at the most security-mature operators Xona targets.

### Problem & Market

Xona sells secure remote access to critical-infrastructure operators who must let engineers, equipment vendors, and contractors reach OT systems without exposing those systems to the user's endpoint or the wider network. The product targets HMIs, engineering workstations, and control-system applications across energy, utilities, oil and gas, manufacturing, maritime, and aviation, and positions itself as a replacement for legacy VPNs and jump servers.

Independent drivers corroborate the demand. Xona points to industry surveys showing remote access paths remain a primary driver of OT security incidents, and a 2026 joint CISA advisory documents state-linked actors exploiting programmable logic controllers across US critical infrastructure, with prior CISA advisories flagging the same actors targeting remote access pathways into water and energy. Regulatory frameworks including NERC CIP, IEC 62443, and TSA SD2 add audit pressure that the access layer must answer. \[[s1](#profile-analysis-sources), [s4](#profile-analysis-sources), [s5](#profile-analysis-sources), [s12](#profile-analysis-sources)\]

### Product Capabilities

The Xona Platform brokers each remote session through a gateway that terminates and isolates OT protocols, so RDP, VNC, SSH, and web sessions reach control-system assets while the user's device never joins the OT network. The Critical System Gateway is the on-site enforcement appliance, and Xona Central Management provides centralized administration across gateways.

Capability has advanced past static access brokering. In March 2026 Xona launched Active Defense, which enforces session controls in real time on detection signals through step-up authentication, suspension, or termination and correlation-driven escalation across events. A Nozomi-certified integration embeds the Arc Endpoint Sensor directly on the Xona Gateway, pairing secure access with OT asset visibility and threat detection as an external validation point. \[[s1](#profile-analysis-sources), [s5](#profile-analysis-sources), [s6](#profile-analysis-sources)\]

### Competitive Positioning

Xona competes in OT and ICS secure remote access against direct specialists and adjacent incumbents. Other purpose-built OT remote-access vendors sell the same job to the same buyer, and broader cyber-physical-systems platform vendors that sell asset visibility and threat detection to plant operators sit one purchase away from folding access in.

Its integration partner is also a competitive consideration. The certified Nozomi relationship places Xona next to a vendor the industrial buyer already trusts, but the same buyer relationship gives a broader OT platform a path to bundle access. Pressure also comes from the enterprise IT side, where privileged-access incumbents and zero-trust network-access vendors hold the corporate remote-access budget line and some buyers extend it into OT. \[[s6](#profile-analysis-sources), [s1](#profile-analysis-sources)\]

### Go-to-Market & Traction

Xona shows unusually strong named-customer evidence for an OT remote-access specialist. Its homepage and about page display blue-chip operators by name, including GE Vernova, RWE, Baker Hughes, Egyptian LNG, and AltaGas, under a trusted-by banner rather than the unnamed aggregate scale claims that direct rivals lead with.

Partnership and capital signals reinforce the motion. Xona announced a Nozomi-certified integration in February 2025, raised an $18 million strategic round led by Energy Impact Partners in 2024 bringing its disclosed total to $32 million, and shipped two platform releases in early 2026. Independent corroboration now exists beyond the vendor's own pages, since Gartner Peer Insights carries 11 verified reviews of the Xona Platform averaging 4.8 out of 5. The remaining gap is depth, since the named operators still appear as logos rather than as case studies with concrete outcomes in the reviewed sources. \[[s2](#profile-analysis-sources), [s6](#profile-analysis-sources), [s3](#profile-analysis-sources), [s13](#profile-analysis-sources)\]

### Team & Credibility

Founder and CEO Bill Moore is the public voice of Xona in funding and product announcements, supported by a named executive bench that includes a chief financial officer, chief revenue officer, and chief product officer. The company has operated since 2017 and raised across seed, Series A, and a 2024 strategic round.

Public proof of pedigree otherwise stays thin. No founder exit, sustained research-publication record, or recognized community standing in the OT domain surfaced in the reviewed sources, so the team reads as credible and durable but without the external recognition that would lift its profile further. \[[s8](#profile-analysis-sources), [s7](#profile-analysis-sources), [s3](#profile-analysis-sources)\]

### Trust Readiness

Xona builds its pitch around the controls regulated OT audits ask for. The platform states it aligns to NERC CIP, IEC 62443, and TSA requirements and is SOC 2 compliant, and Active Defense answers the response-time gap that auditors and incident responders raise about remote access.

The reviewed sources show a SOC 2 compliance claim on the platform comparison page but did not surface a public trust center or third-party attestation report for Xona as of June 2026, so the SOC 2 posture reads as vendor-stated rather than buyer-verifiable from a published report. This is a gather-time observation, not a categorical absence. \[[s9](#profile-analysis-sources), [s4](#profile-analysis-sources)\]

### Competitors

| Company | Relationship | Note |
|---|---|---|
| Cyolo | competes with | Cyolo sells secure remote access for OT and ICS to the same regulated industrial buyer, competing on a decentralized customer-boundary architecture where Xona competes on gateway protocol isolation. |
| Dispel | competes with | Dispel sells purpose-built OT secure remote access to the same buyer, competing on patented moving target defense networking where Xona competes on session brokering and Active Defense. |
| Claroty | competes with | Claroty sells a broader cyber-physical-systems protection platform to the same plant operators and could fold remote access into a wider purchase. |
| Dragos | competes with | Dragos sells OT asset visibility and threat detection to the same industrial buyer and partners across the OT stack, positioning it to converge on remote access. |

## Strategy Deep Dive

A closer look at the company's product strategy, measuring how [defensible](https://zeltser.com/scoring-security-product-strategy) it is against market forces and examining the [eight areas](https://zeltser.com/security-product-creation-framework) behind it.

### Defensibility

**Exposed (11/21)**

Band guidance: pivot urgently. Analyzed 2026-09-11. Scope: whole company.

Xona is costly to switch but not costly to copy. It deploys gateways at OT sites, so replacing it means re-onboarding identities, policies, and the Nozomi integration, an effortful project rather than a wall, with friction that scales as a buyer covers more sites. What slows a replacement is the buyer class itself, regulated operators under NERC CIP, IEC 62443, and TSA governance demands, though the record documents no specific switching gate. Xona sells software the customer runs, with no managed-service accountability and no patent portfolio or cross-customer data asset in the reviewed record, so a funded rival could build the same gateway. It also sells one job to buyers that broader OT platforms and partner Nozomi already reach, so a customer can cancel without losing a dependency.

| Dimension | Score | Rationale |
|---|---|---|
| Value Delivery | 1/3 | Xona sells software the customer deploys and runs, a gateway appliance plus a central management system, and Active Defense is automated session enforcement that is software output. No evidence shows a managed-service layer or the company accepting accountability for customer security outcomes, so the delivered artifact is the product itself. \[[s1](#deep-dive-sources), [s5](#deep-dive-sources)\] |
| Switching Cost | 2/3 | Replacing an access platform deployed across a buyer's OT sites means re-onboarding identities, policies, gateways, and the Nozomi integration, which is meaningful friction. No cross-customer data gravity adds to it, so migration stays an effortful project rather than a wall. \[[s1](#deep-dive-sources), [s6](#deep-dive-sources)\] |
| Compliance Moat | 1/3 | NERC CIP, IEC 62443, and TSA mandates drive demand for the category but name no vendor, and the SOC 2 claim is a commercial attestation a determined rival could clear. This is a category tailwind that lifts every qualified vendor rather than a moat that locks in Xona. \[[s4](#deep-dive-sources), [s9](#deep-dive-sources)\] |
| Problem Complexity | 2/3 | Session brokering with protocol termination across RDP, VNC, SSH, and web is a well-understood access-broker pattern, and Active Defense is policy-driven session enforcement on detection signals. No patented networking mechanism or deep ML is evidenced, so the work reads as solid engineering on an established pattern rather than a technical barrier a competent rival would struggle to cross. \[[s1](#deep-dive-sources), [s5](#deep-dive-sources)\] |
| Buyer Profile | 3/3 | Xona sells to regulated industrial enterprises and critical infrastructure operators, with named blue-chip references such as GE Vernova, RWE, Baker Hughes, and AltaGas, operating under NERC CIP, IEC 62443, and TSA demands for demonstrable governance over who accesses critical systems. The reviewed record establishes that buyer class rather than the specific gates such a buyer puts in front of a switch. \[[s2](#deep-dive-sources), [s4](#deep-dive-sources)\] |
| Layer | 1/3 | The platform brokers and enforces remote sessions rather than serving as infrastructure other applications are built on. A buyer can revert to VPNs and jump servers, so nothing depends on Xona as a foundation it cannot replace. \[[s1](#deep-dive-sources), [s4](#deep-dive-sources)\] |
| Proprietary Data, Content, or IP | 1/3 | The reviewed record shows no patent portfolio and no accumulating cross-customer dataset. Xona brokers and enforces access rather than collecting a corpus that compounds, and a funded rival could build the same gateway and session-control capability, so no proprietary asset appears. \[[s1](#deep-dive-sources), [s6](#deep-dive-sources)\] |

### Strategic Market Segmentation

Xona targets critical-infrastructure operators across energy, electric utilities, oil and gas, manufacturing, maritime, aviation, chemical, and pharma. The named operators on its own site, GE Vernova, RWE, Baker Hughes, Egyptian LNG, and AltaGas, concentrate in energy and oil and gas, which reads as the proven core of a broader addressed market.

The sale runs through two personas at once. Xona pitches OT and operations teams on fast, frictionless access that avoids network reconfiguration, while pitching security and compliance teams on protocol isolation, session enforcement, and audit-ready governance for NERC CIP, IEC 62443, and TSA. Those operator names read as spanning North America, Europe, and the Middle East, an inference from the companies themselves rather than deployment evidence, since the cited pages list customer names without documenting where Xona is deployed. A 2026 joint CISA advisory documents state-linked actors exploiting programmable logic controllers across US critical infrastructure, sharpening the threat case the security persona buys on. \[[s2](#deep-dive-sources), [s1](#deep-dive-sources), [s4](#deep-dive-sources), [s12](#deep-dive-sources)\]

### Product Capabilities & AI Advantages

Xona documents a session-brokering architecture. Each session runs through a gateway that terminates and isolates OT protocols across RDP, VNC, SSH, and web interfaces. The user's device never joins the OT network. The Critical System Gateway is the appliance that provides user access to OT assets, and Xona Central Management administers gateways centrally.

Xona introduced Active Defense in March 2026 to stop threats during a live remote-access session, closing the gap between detecting suspicious activity and ending the session. Xona also announced an integration that runs the Nozomi Networks Arc Endpoint Sensor on the Xona Gateway. The sensor discovers critical assets in real time and streamlines onboarding of new assets into the Xona Platform. No proprietary data advantage, patent portfolio, efficacy test, or independent benchmark appears in the reviewed record. \[[s1](#deep-dive-sources), [s5](#deep-dive-sources), [s6](#deep-dive-sources)\]

### Sales Engagement & Go-to-Market

Xona displays blue-chip operators as trusted-by logos on its own homepage and about page, including GE Vernova, RWE, Baker Hughes, Egyptian LNG, and AltaGas. These are vendor-displayed customer references rather than independently corroborated deployments.

Partnership and capital signals reinforce the motion. Xona announced a Nozomi-certified integration in February 2025, raised a 2024 strategic round led by Energy Impact Partners that SecurityWeek reports as $18 million, lifting its disclosed total to $32 million, and kept shipping, with the Platform v5.5 release and the March 2026 introduction of Active Defense as its most recent product news. A Form D filed with the SEC reports a $19,026,905 offering with a first sale on May 28, 2024, covering Series A-1 and A-2 preferred stock plus note conversions, which appears to document the structure of that same 2024 financing rather than capital on top of it.

Independent corroboration exists beyond the vendor's own pages, since Gartner Peer Insights carries 11 ratings of the Xona Platform averaging 4.8 out of 5. The depth gap that remains is that the named operators appear as logos rather than as published case studies with named contacts and concrete outcomes in the reviewed sources. \[[s2](#deep-dive-sources), [s6](#deep-dive-sources), [s3](#deep-dive-sources), [s4](#deep-dive-sources), [s5](#deep-dive-sources), [s11](#deep-dive-sources), [s13](#deep-dive-sources)\]

### Pricing Model

Xona publishes no pricing on its own site, where the product paths end in demo requests rather than packaging tiers. Its Gartner Peer Insights profile, however, documents the charging model: licensing is primarily per appliance, with each Xona Gateway licensed by capacity and deployment size, plus per-asset and annual-subscription options. That resolves the unit a buyer sizes against, even though list figures stay private.

The opacity that remains fits the motion. Per-appliance and per-asset licensing sold into regulated industrial operators through a demo-led path reads as quote-based enterprise buying rather than metered consumption, an inference from the licensing units and the regulated-OT positioning rather than a documented sales practice. What stays unstated is how a per-appliance and per-asset blend totals across the many sites an industrial footprint spans, which is the number OT buyers use to size the spend. \[[s1](#deep-dive-sources), [s13](#deep-dive-sources)\]

### Product Delivery & Operations

Xona delivers through gateway appliances administered by a central management system, with flexible cloud or on-premises deployment and a stated 30 minutes per site to stand up, a design that suits the constrained sites it targets. Sessions are session-based rather than network-based, so endpoints never touch the OT network.

Operational integration reaches the surrounding OT stack. The Nozomi-certified integration runs the Arc Endpoint Sensor on the Xona Gateway to discover assets and streamline onboarding, and Active Defense adds ongoing real-time session enforcement rather than one-time deployment. The gateway-plus-central-management model is positioned to scale across distributed industrial footprints. \[[s9](#deep-dive-sources), [s6](#deep-dive-sources), [s5](#deep-dive-sources)\]

### Earning Customers' Trust

Xona's trust pitch is compliance-forward. The platform states it aligns to NERC CIP, IEC 62443, and TSA requirements and is SOC 2 compliant, and protocol isolation directly answers the endpoint-exposure concern a remote-access broker raises in an OT environment.

Public trust artifacts about Xona's own controls are thinner. The reviewed sources show a SOC 2 compliance claim on the platform comparison page but did not surface a public trust center or third-party attestation report for Xona itself as of June 2026, so the SOC 2 posture reads as vendor-stated rather than buyer-verifiable from a published report. This is a gather-time observation, not a categorical absence. \[[s9](#deep-dive-sources), [s4](#deep-dive-sources)\]

### Platform Strategy & Ecosystem Positioning

Xona positions the platform as the access control plane for OT rather than a point tool, spanning gateway enforcement, central management, and real-time session defense. That breadth moves the company from a single access function toward broader OT access governance spend across a distributed footprint.

The ecosystem play runs through technology alliances. The Nozomi-certified integration is the visible anchor, pairing Xona's access layer with a leading OT visibility platform. That alliance is also a dependency, since the same buyer relationship gives a broader OT platform vendor, now Mitsubishi-owned Nozomi included, a path to bundle access into a wider purchase. \[[s6](#deep-dive-sources), [s1](#deep-dive-sources), [s10](#deep-dive-sources)\]

### Team & Execution Capability

Founder and CEO Bill Moore is the public voice of Xona, supported by a named executive bench that includes a chief financial officer, chief revenue officer, and chief product officer. The company has operated since 2017 and raised across seed, a 2022 DataTribe-led Series A, and a 2024 strategic round, signaling a durable rather than nascent operation.

Public proof of pedigree otherwise stays thin. No founder exit, sustained research-publication record, or recognized community standing in the OT domain surfaced in the reviewed sources, so the team reads as credible and durable but without the external recognition that would lift its profile further. \[[s8](#deep-dive-sources), [s7](#deep-dive-sources), [s3](#deep-dive-sources)\]

## Sources

### Company Detail Sources

Cited from the Sourced Details and Matrix Coverage rows.

| Id | Source | Tier | Accessed |
|---|---|---|---|
| f1 | [Xona Secure Access Platform for Critical Infrastructure](https://www.xonasystems.com/platform) | official | 2026-06-21 |
| f2 | [OT Remote Access Firm Xona Raises $7.2 Million in Series A Funding](https://www.securityweek.com/ot-remote-access-firm-xona-raises-72-million-series-funding/) | press | 2026-06-21 |
| f3 | [Xona Raises $18 Million for OT Remote Access Platform](https://www.securityweek.com/xona-raises-18-million-for-ot-remote-access-platform/) | press | 2026-06-21 |

### Profile Analysis Sources

Cited from the Market Readiness section.

| Id | Source | Tier | Accessed |
|---|---|---|---|
| s1 | [Xona Secure Access Platform for Critical Infrastructure](https://www.xonasystems.com/platform) “Xona brokers the session through its gateway. OT protocols are terminated and isolated at the gateway, not exposed to the endpoint. Xona supports common OT access protocols including RDP, VNC, SSH, and web-based interfaces used to access HMIs and engineering workstations.” | official | 2026-06-21 |
| s2 | [Secure Remote Access for OT and ICS Zero Trust Platform, Xona](https://www.xonasystems.com/) “Trusted by Critical Infrastructure and Industrial Leaders. GE Vernova. RWE. Egyptian LNG. AltaGas. Baker Hughes.” | official | 2026-06-21 |
| s3 | [Xona Raises $18 Million for OT Remote Access Platform](https://www.securityweek.com/xona-raises-18-million-for-ot-remote-access-platform/) “Xona announced raising $18 million in a strategic funding round. The new investment, led by Energy Impact Partners, brings the total raised by Xona to $32 million. The company's Critical System Gateway (CSG) product is built to provide frictionless and compliant user access to OT assets.” | press | 2026-06-21 |
| s4 | [Xona Systems unveils Platform v5.5 to rethink secure remote access for critical infrastructure](https://industrialcyber.co/news/xona-systems-unveils-platform-v5-5-to-rethink-secure-remote-access-for-critical-infrastructure/) “Regulatory frameworks, including NERC CIP, IEC 62443, and TSA SD2 demand demonstrable governance over who accesses critical systems. Industry surveys show remote access paths remain a primary driver of OT security incidents.” | press | 2026-06-21 |
| s5 | [Xona launches Active Defense capability to close response gaps in remote access security for critical infrastructure](https://industrialcyber.co/news/xona-launches-active-defense-capability-to-close-response-gaps-in-remote-access-security-for-critical-infrastructure/) “March 18, 2026 Xona Systems introduced Active Defense, which enables organizations to stop threats during live remote access sessions in OT environments. Recent advisories from CISA have highlighted nation-state actors specifically targeting remote access pathways into water and energy sectors.” | press | 2026-06-21 |
| s6 | [Xona and Nozomi Networks Partner, Merging Cybersecurity and Secure Access Management for Critical Infrastructure](https://www.nozominetworks.com/press-release/xona-and-nozomi-networks-partner-merging-cybersecurity-and-secure-access-management-for-critical-infrastructure) “TAMPA, FL February 10, 2025 Xona Systems today announced the integration of the Xona Platform with the Nozomi Networks Arc Endpoint Sensor, bringing together secure access management with visibility, threat detection, and response for critical infrastructure.” | press | 2026-06-21 |
| s7 | [OT Remote Access Firm Xona Raises $7.2 Million in Series A Funding](https://www.securityweek.com/ot-remote-access-firm-xona-raises-72-million-series-funding/) “Xona Systems, an Annapolis MD-based provider of frictionless remote authentication and access to the critical infrastructure, has raised $7.2 million in a Series A funding round led by DataTribe Opportunities Fund. Xona Systems was founded by Bill Moore in 2017.” | press | 2026-06-21 |
| s8 | [OT/ICS Secure Remote Access, About Xona](https://www.xonasystems.com/about-xona) “Meet the Team. Bill Moore, Founder & CEO. Charles Constanti, Chief Financial Officer. John Chiappetta, Chief Revenue Officer. Raed Albuliwi, Chief Product Officer.” | official | 2026-06-21 |
| s9 | [How Xona Compares to Legacy Alternatives](https://www.xonasystems.com/platform) “Aligns to key compliance requirements for NERC CIP, IEC, and TSA, and is SOC 2 compliant. Endpoints never touch the network. 30 minutes per site. Session-based, not network-based, and flexible cloud and/or on-prem.” | official | 2026-06-21 |
| s10 | [Mitsubishi Electric Completes Full Acquisition of Nozomi Networks](https://www.mitsubishielectric.com/en/pr/2026/pdf/0129.pdf) “TOKYO, January 29, 2026 Mitsubishi Electric Corporation announced today the completion of its acquisition of all outstanding shares of Nozomi Networks Inc., following the announcement on September 9, 2025 regarding its plan to make Nozomi a wholly-owned subsidiary.” | press | 2026-06-21 |
| s11 | [SEC Form D exempt-offering notice for Xona Systems, Inc. (CIK 0001806840), incorporated in Delaware, principal place of business Annapolis MD](https://www.sec.gov/Archives/edgar/data/1806840/000180684024000001/xslFormDX01/primary_doc.xml) “Total Offering Amount $19,026,905 USD or Indefinite Total Amount Sold $19,026,905 USD Total Remaining to be Sold $0 USD” | regulatory | 2026-06-30 |
| s12 | [Iranian-Affiliated Cyber Actors Exploit Programmable Logic Controllers Across US Critical Infrastructure (CISA joint advisory AA26-097A, 2026)](https://www.cisa.gov/news-events/cybersecurity-advisories/aa26-097a) “If remote access is required, implement a network proxy, gateway, firewall, and/or virtual private network (VPN) in front of the PLC to control network access. A VPN or gateway device can enable MFA for remote access even if the PLC does not support MFA.” | regulatory | 2026-06-30 |
| s13 | [Xona Platform reviews and ratings (4.8 out of 5 from 11 ratings) in the Gartner Cyber-Physical Systems Secure Remote Access market (Gartner Peer Insights)](https://www.gartner.com/reviews/market/cyber-physical-systems-secure-remote-access-solutions/vendor/xona/product/xona-platform) “Xona primarily supports licensing on a per appliance basis, with each Xona Gateway appliance licensed according to capacity and deployment size. Additionally, Xona offers flexible licensing options based on per asset and per time period (annual subscription), depending on customer requirements.” | other | 2026-06-30 |

### Deep-Dive Sources

Cited from the Strategy Deep Dive section.

| Id | Source | Tier | Accessed |
|---|---|---|---|
| s1 | [Xona Secure Access Platform for Critical Infrastructure](https://www.xonasystems.com/platform) “Xona brokers the session through its gateway. OT protocols are terminated and isolated at the gateway, not exposed to the endpoint. Xona supports common OT access protocols including RDP, VNC, SSH, and web-based interfaces used to access HMIs and engineering workstations.” | official | 2026-06-21 |
| s2 | [Secure Remote Access for OT and ICS Zero Trust Platform, Xona](https://www.xonasystems.com/) “Trusted by Critical Infrastructure and Industrial Leaders. GE Vernova. RWE. Egyptian LNG. AltaGas. Baker Hughes.” | official | 2026-06-21 |
| s3 | [Xona Raises $18 Million for OT Remote Access Platform](https://www.securityweek.com/xona-raises-18-million-for-ot-remote-access-platform/) “Xona announced raising $18 million in a strategic funding round, led by Energy Impact Partners, bringing the total raised to $32 million. The Critical System Gateway (CSG) provides user access to OT assets. The Xona Central Management (XCM) system provides centralized management of CSG appliances.” | press | 2026-06-21 |
| s4 | [Xona Systems unveils Platform v5.5 to rethink secure remote access for critical infrastructure](https://industrialcyber.co/news/xona-systems-unveils-platform-v5-5-to-rethink-secure-remote-access-for-critical-infrastructure/) “Regulatory frameworks, including NERC CIP, IEC 62443, and TSA SD2 demand demonstrable governance over who accesses critical systems. Industry surveys show remote access paths remain a primary driver of OT security incidents.” | press | 2026-06-21 |
| s9 | [How Xona Compares to Legacy Alternatives](https://www.xonasystems.com/platform) “Aligns to key compliance requirements for NERC CIP, IEC, and TSA, and is SOC 2 compliant. Endpoints never touch the network. 30 minutes per site. Session-based, not network-based, and flexible cloud and/or on-prem.” | official | 2026-06-21 |
| s5 | [Xona launches Active Defense capability to close response gaps in remote access security for critical infrastructure](https://industrialcyber.co/news/xona-launches-active-defense-capability-to-close-response-gaps-in-remote-access-security-for-critical-infrastructure/) “March 18, 2026 Xona Systems introduced Active Defense, which enables organizations to stop threats during live remote access sessions in OT environments. The gap between detecting suspicious activity and stopping an active session can stretch from minutes to hours.” | press | 2026-06-21 |
| s6 | [Xona and Nozomi Networks Partner, Merging Cybersecurity and Secure Access Management for Critical Infrastructure](https://www.nozominetworks.com/press-release/xona-and-nozomi-networks-partner-merging-cybersecurity-and-secure-access-management-for-critical-infrastructure) “February 10, 2025 Xona Systems announced the integration of the Xona Platform with the Nozomi Networks Arc Endpoint Sensor. By running on the Gateway, the Arc Sensor can discover critical assets in real time to streamline onboarding of new assets for management by the Xona Platform.” | press | 2026-06-21 |
| s7 | [OT Remote Access Firm Xona Raises $7.2 Million in Series A Funding](https://www.securityweek.com/ot-remote-access-firm-xona-raises-72-million-series-funding/) “Xona Systems, an Annapolis MD-based provider of frictionless remote authentication and access to the critical infrastructure, has raised $7.2 million in a Series A funding round led by DataTribe Opportunities Fund. Xona Systems was founded by Bill Moore in 2017.” | press | 2026-06-21 |
| s8 | [OT/ICS Secure Remote Access, About Xona](https://www.xonasystems.com/about-xona) “Meet the Team. Bill Moore, Founder & CEO. Charles Constanti, Chief Financial Officer. John Chiappetta, Chief Revenue Officer. Raed Albuliwi, Chief Product Officer.” | official | 2026-06-21 |
| s10 | [Mitsubishi Electric Completes Full Acquisition of Nozomi Networks](https://www.mitsubishielectric.com/en/pr/2026/pdf/0129.pdf) “TOKYO, January 29, 2026 Mitsubishi Electric Corporation announced today the completion of its acquisition of all outstanding shares of Nozomi Networks Inc., following the announcement on September 9, 2025 regarding its plan to make Nozomi a wholly-owned subsidiary.” | press | 2026-06-21 |
| s11 | [SEC Form D exempt-offering notice for Xona Systems, Inc. (CIK 0001806840), incorporated in Delaware, principal place of business Annapolis MD](https://www.sec.gov/Archives/edgar/data/1806840/000180684024000001/xslFormDX01/primary_doc.xml) “Total Offering Amount $19,026,905 USD or Indefinite Total Amount Sold $19,026,905 USD Total Remaining to be Sold $0 USD” | regulatory | 2026-06-30 |
| s12 | [Iranian-Affiliated Cyber Actors Exploit Programmable Logic Controllers Across US Critical Infrastructure (CISA joint advisory AA26-097A, 2026)](https://www.cisa.gov/news-events/cybersecurity-advisories/aa26-097a) “If remote access is required, implement a network proxy, gateway, firewall, and/or virtual private network (VPN) in front of the PLC to control network access. A VPN or gateway device can enable MFA for remote access even if the PLC does not support MFA.” | regulatory | 2026-06-30 |
| s13 | [Xona Platform reviews and ratings (4.8 out of 5 from 11 ratings) in the Gartner Cyber-Physical Systems Secure Remote Access market (Gartner Peer Insights)](https://www.gartner.com/reviews/market/cyber-physical-systems-secure-remote-access-solutions/vendor/xona/product/xona-platform) “Xona primarily supports licensing on a per appliance basis, with each Xona Gateway appliance licensed according to capacity and deployment size. Additionally, Xona offers flexible licensing options based on per asset and per time period (annual subscription), depending on customer requirements.” | other | 2026-06-30 |

## Disclaimer

This site is an experimental research aid created by Zeltser Security Corp. All its data gathering and analysis was performed autonomously without human review, and it can contain errors of fact, interpretation, and judgment that a human reviewer might catch.

The analyses are statements of opinion, not statements of fact. Machine analysis produced the scores, summaries, and matrix placements by weighing the public sources each page cites, and reasonable people can weigh the same sources differently. Where a page states a fact, it cites the public source and the date it was checked, and the statement is only as accurate as that source. Unless a profile expressly says otherwise, the analysis involves no hands-on testing and no independent validation of any company's products or services.

Nothing here is professional, security, legal, financial, investment, or purchasing advice, and nothing here is a recommendation to invest in, do business with, or avoid any company. Inclusion of a company is not an endorsement, and absence of a company is not a judgment about it. Reading this site creates no advisory or client relationship. Verify any detail you plan to act on against the vendor's current materials.

The content is provided "as is" and "as available," with all warranties disclaimed, express or implied, including merchantability, fitness for a particular purpose, accuracy, and non-infringement. No entry is warranted to be complete, current, or correct. Companies change, vendors update their claims, sources can be wrong, and automated analysis can misread them.

To the fullest extent permitted by law, the operator, Zeltser Security Corp, is not liable for any damages that arise from using this site or relying on its content, including direct, indirect, incidental, special, and consequential damages and lost profits, even if advised that such damages were possible. If you are dissatisfied with the site or disagree with these terms, your remedy is to stop using it.

Entries link to vendor pages, press coverage, and other external sites that Zeltser Security Corp does not control and is not responsible for. A link is not an affiliation with the destination or an endorsement of it. Product and company names and trademarks are the property of their owners, used here nominatively to identify the companies described. Short quotations from cited sources appear for identification and commentary.

Use, quotation, automated retrieval, and redistribution of the content are governed by the Terms of Use at cybercompanyprofiles.com/terms, which permit personal and internal business use with attribution and prohibit republication and resale.
