Phosphorus Cybersecurity
AcquiredNashville, US · Founded 2017 · Delaware corporation · 30 employees on LinkedIn · 9 known investors
Find your way into Phosphorus Cybersecurity
107 people in our graph share verified history with the Phosphorus Cybersecurity team — schools, employers, funds. One of them is your warm intro.
Phosphorus provides a cybersecurity remediation platform for Internet of Things (xIoT) devices in enterprise environments, offering visibility, patching, and compliance capabilities that integrate with existing security tools. The platform targets enterprises seeking to secure IoT devices that increasingly outnumber traditional endpoints in their infrastructure.
Also known as Phosphorus · Phosphorus Cybersecurity Inc. · Phosphorus Cybersecurity®
Founders & leadership
Phosphorus Cybersecurity was founded in 2017 by Chris Rouland.

Board
Investors · 9
Also in the syndicate · 1
Funding
SEC filings, press & company announcements$27M disclosed across 1 of 3 rounds · 2022–2023
- Undisclosed amountSeries AFeb 2022
MassMutual Ventures (lead), SYN Ventures (lead), Atypical Ventures, General Advance
Source ↗
▶$27MraisedDec 2023 · 5 investors · Other TechnologyRule 506(b)
- JR SmithDirector
- Christopher RoulandExecutive Officer, Director
- Earle AdyExecutive Officer, Director
- Charles AndrosDirector
- Arthur Coviello, Jr.Director
- Martin LeRoyExecutive Officer
- Offering amount
- $27.5M
- Amount sold
- $27M
- First sale
- Dec 2023
- Incorporated
- Corporation, Delaware
- Federal exemptions
- 06b
Source: SEC EDGAR Form D. Amounts as filed; amended filings shown once at their latest values.
Company profile
researched Aug 2026Phosphorus Cybersecurity Inc. is a Nashville, Tennessee-based provider of security and management software for the extended Internet of Things (xIoT) — the combined population of IoT, OT, IIoT, and Internet of Medical Things (IoMT) devices in enterprise environments. The platform discovers and classifies connected devices, assesses and prioritizes their vulnerabilities, and then performs remediation actions directly on the devices: rotating default and weak passwords, upgrading or downgrading firmware, managing and renewing certificates, disabling unnecessary network services such as Telnet or FTP, monitoring for device drift, and retrieving device logs for analysis. A prohibited-device capability discovers and remotely disables equipment banned under U.S. NDAA Section 889, including Huawei, Dahua, Hikvision, ZTE, and Hytera hardware and devices running their OEM firmware.
The company positions the product as going beyond visibility-only tooling by acting on devices in their native protocols. Deployment is agentless and does not require SPAN ports, TAPs, packet brokers, or network re-architecture; it can run on-premises as a virtual appliance, in AWS, Azure, or GCP, or in hybrid form, with an optional siteManager/zoneWorker component for segmented, DMZ, or air-gapped networks. The company states initial deployment takes hours, first discovery results minutes, and full environment visibility typically the same day. Integrations extend existing security and IT investments, including Check Point, ServiceNow, CyberArk, Axonius, Microsoft Sentinel, Qualys, Forescout, and Milestone XProtect.
Phosphorus serves data centers and colocation, manufacturing and industrial OT/ICS, healthcare, financial services, hospitality and retail, critical infrastructure and energy, and federal and public sector customers, and maps its capabilities to frameworks and directives such as CISA Binding Operational Directive 26-02, CISA Zero Trust guidance, and 33 CFR Part 101 Subpart F. In June 2026 the company announced it had been acquired by and joined Dragos, combining device-level xIoT security with Dragos's OT network security.
Founding story
Phosphorus was founded in 2017 by Chris Rouland, Rebecca Rouland, and Earle Ady. Rouland, who previously founded Endgame and Bastille and established X-Force at IBM, came out of an attempted retirement after his third exit when he encountered a University of Wisconsin research paper analyzing a large-scale IoT-based DDoS attack; the researchers found the average "half-life" for IoT firmware updates was seven years, meaning most connected devices ran vulnerable software long after exploits were known. Early customer engagements revealed a consistent pattern of missing device inventory, widespread default credentials, and unmanaged firmware, certificates, and configurations, leading to a founding premise that organizations cannot secure what they cannot see or fix what they cannot control.
Business model
Phosphorus sells its platform as an annual subscription, with pricing based on the number of devices managed and the features employed. The subscription covers continuous discovery and inventory, risk assessment and enrichment, automated remediation capabilities, and ongoing device support and updates, with support for new device types added over time as part of the subscription.
Recurring annual software subscription revenue, priced by managed device count and feature set.
Traction
The company reports assessing more than one billion enterprise IPs to date and helping customers assess over 50 million new IPs each week, with a device network spanning more than 600 IoT, OT, IIoT, and IoMT manufacturers and over one million unique device models. It reports customers updating firmware 24x more often and rotating passwords 110x more often than in prior years. Phosphorus doubled its workforce in the year preceding its February 2022 Series A and committed to adding 50 new jobs by 2024, mostly in software engineering; a third-party profile lists 125 employees. Published case studies cover healthcare, hospitality, data center, and manufacturing deployments.
Latest developments
On June 1, 2026, Phosphorus announced that it had been acquired by and joined Dragos, with the stated aim of pairing device-level xIoT security with Dragos's OT network security across the full xOT environment. Earlier in 2026 the company introduced the Phosphorus xIoT Compliance Report, which shifts compliance from documentation to enforceable device-level evidence, published guidance mapping its platform to CISA Binding Operational Directive 26-02 on unsupported edge devices, and was named a finalist in the SC Awards for both innovation and leadership.
▸Full profile — market position, technology, go-to-market, geography, history
Market position
Phosphorus describes itself as creating and leading a category it calls Unified xIoT Security Management, differentiated from discovery-only tools by its ability to remediate. Its platform was included as a Representative Vendor in the 2023 Gartner Market Guide for CPS Protection Platforms, and the company was named a finalist in the SC Awards for both innovation and leadership in 2026. Its $38 million Series A was described at announcement as one of the largest early-stage funding rounds for a cybersecurity company.
The company's stated differentiation is action rather than observation: where competing approaches stop at discovery, Phosphorus automatically remediates credentials, firmware, certificates, and configurations across IoT, OT, IIoT, and IoMT devices. Supporting differentiators cited include deterministic (not inferred) discovery via native device protocols, agentless deployment without SPAN ports, TAPs, or hardware, operation in segmented and air-gapped networks, same-day time to visibility, and remote disablement of NDAA Section 889-prohibited devices.
Technology
The platform is built on a patented Intelligent Active Discovery (IAD) engine that communicates with devices in their native protocols rather than relying on aggressive scanning or passive traffic inspection, dynamically adjusting probe behavior to limit network impact and device disruption in sensitive OT, ICS, and healthcare environments. The company reports the engine discovers and assesses cyber-physical assets up to 16x faster than traditional passive scanners and with up to 95% better efficiency than legacy active scanners, and covers well over one million unique xIoT device models across more than 600 device manufacturers. Remediation modules handle credentials, firmware, certificates, and configuration hardening; deployment requires only outbound HTTPS (TCP 443) plus access to device communication ports, with no agents or hardware dependencies.
Go-to-market
Direct enterprise sales supported by demo requests on the company website, a resource center of white papers, solution and integration briefs, case studies, and data sheets, and presence at industry conferences such as S4X24 and RSAC. Technology integrations with incumbent security and IT vendors (Check Point, ServiceNow, CyberArk, Axonius, Microsoft Sentinel, Qualys, Forescout, Milestone XProtect) serve as a channel to extend existing customer deployments. Series A proceeds were directed largely to engineering hiring, with self-service demos and deployment planned for 2022; Series A2 proceeds were earmarked for R&D and go-to-market expansion.
Large enterprises and government organizations, typically with 10,000+ employees or large distributed environments, thousands to hundreds of thousands of connected devices, and requirements for high-fidelity asset visibility and automated remediation in regulated or mission-critical settings. Named verticals include data centers and colocation, manufacturing and industrial OT/ICS, healthcare (IoMT), financial services, hospitality and retail, critical infrastructure and energy, and federal and public sector. The company describes its customers as including large financial institutions, Fortune 500 companies, and government agencies.
Geography
Headquartered in Nashville, Tennessee, United States. The platform supports distributed environments across regions and business units, and the company has a Middle East and Africa presence, with Osama Al-Zoubi serving as Vice President, MEA.
History
Founded in 2017 in Nashville, the company raised a $38 million Series A led by SYN Ventures and MassMutual Ventures in February 2022, at which point it was focused on automated "Security of Things" protection for enterprise and government customers. In December 2023 it extended that round with a $27 million Series A2 led by Evolution Equity Partners, positioning itself around Unified xIoT Security Management and Cyber-Physical Systems protection. The company subsequently expanded its platform with compliance reporting, certificate and configuration management, and a broad integration ecosystem, and appointed Brett Raphael as Chief Revenue Officer. In June 2026 Phosphorus announced it had been acquired by Dragos and now operates as a Dragos company.
Compiled by commissioned research from 8 cited public sources — announcements, filings, and press listed under research sources below.
Key figures
latest reportedCompany-reported or press-reported figures, each dated to when it was claimed — not independently audited.
Competitors · 3
by search overlapCompanies competing with Phosphorus Cybersecurity for the same Google search keywords, organic and paid, via search-intersection analysis.
Non-dilutive funding · 2 SBIR/STTR awards
Federal grants — no equity taken| Agency | Phase | Year | Amount |
|---|---|---|---|
| U.S. Air ForceAir Force | Phase I | 2021 | $48.5K |
| U.S. Air ForceAir Force | Phase I | 2020 | $50K |
Source: SBIR.gov award data (U.S. Small Business Administration). SBIR/STTR awards are competitive federal R&D grants and contracts — non-dilutive capital alongside any venture rounds above.
Timeline · 7
launches, deals, and filingsDragos acquired Phosphorus to bring OT-native cybersecurity to the full xOT environment; Phosphorus now operates as a Dragos company, combining device-level xIoT security with Dragos's network-level OT security.
Phosphorus announced it had been named a finalist in the SC Awards in both innovation and leadership categories.
Phosphorus introduced the xIoT Compliance Report, a capability intended to move connected-device compliance from documentation to enforceable, evidence-based reporting.
Phosphorus announced an additional $27 million in Series A2 funding led by Evolution Equity Partners, extending its 2022 Series A, to expand R&D and go-to-market initiatives for its Cyber-Physical Systems Protection Platform.
$27M source ↗
Phosphorus announced the completion of a $38 million Series A led by SYN Ventures and MassMutual Ventures, with proceeds directed mainly to engineering talent, platform development including extended device coverage and security-platform integrations, and self-service demos and deployment planned for 2022.
$38M source ↗
Phosphorus announced the promotion of Brett Raphael to Chief Revenue Officer.
Dated company events from announcements, filings, and press; legal rows summarize public dockets and regulator releases.
Legal entities · 1
corporate structureIn the news
▸Research sources · 8
primary sources listed
- Phosphorus Cybersecurityphosphorus.io · web
8 public sources were cited for this profile; the first-party ones are listed here.
Frequently asked questions
- What does Phosphorus Cybersecurity do?
- Phosphorus, now a Dragos company, sells an xIoT platform that discovers, hardens, remediates, and monitors connected devices.
- Who founded Phosphorus Cybersecurity?
- Phosphorus Cybersecurity was founded by Chris Rouland in 2017.
- Who are Phosphorus Cybersecurity's investors?
- Phosphorus Cybersecurity's investors include Evolution Equity Partners, FirstMark Capital, MassMutual Ventures, Neva Sgr., Service Provider Capital, Syn Ventures Seed Management Llc, General Advance, SYN Ventures.
- How much funding has Phosphorus Cybersecurity raised?
- Phosphorus Cybersecurity has disclosed $27M raised across 1 of its 3 known rounds.
- Where is Phosphorus Cybersecurity headquartered?
- Phosphorus Cybersecurity is headquartered in Nashville, US.





