Robert M. Lee: Defending Power Grids, Building Dragos
Robert M. Lee wrote a children's book about the computers that run power grids and factories, and the subtitle tells you who it was really for: A Book for Children and Management.
He also served as an Air Force officer assigned to the NSA, where he helped stand up the first mission dedicated to tracking threats to industrial infrastructure. Then he co-authored the autopsy of the first known blackout caused by hackers and co-founded Dragos, which grew into a heavyweight of industrial cybersecurity.
Along the way he made a habit of telling Washington and the industry to take the threats seriously and the hype apart. The harder test was building a company on that message.
Robert M. Lee at a Glance
- As a U.S. Air Force Cyber Warfare Operations Officer assigned to the NSA, Lee helped stand up the first mission dedicated to tracking and countering threats to industrial infrastructure.
- He wrote SCADA and Me: A Book for Children and Management, illustrated by Jeff Haas, and spun it into the weekly web comic Little Bobby.
- With Michael Assante he wrote the ICS Cyber Kill Chain in 2015, and he created ICS515, the industrial community's first dedicated monitoring and incident response class at SANS.
- He co-authored the E-ISAC/SANS analysis of the December 2015 attack that cut power to about 225,000 customers in Ukraine, the first known blackout caused by a cyberattack.
- He co-founded Dragos in 2016 with seed money from DataTribe, turning down investors who wanted him on the West Coast, and the company went on to analyze CRASHOVERRIDE, TRISIS and PIPEDREAM.
- Dragos hit a $1.7 billion valuation in 2021, then rode out a failed extortion attempt by a criminal gang and a round of layoffs in 2023.
- In 2026 Accenture took a majority stake in Dragos in a set of deals valued at about $4.175 billion, and Lee stayed on as CEO and became chairman.
The Life of Robert M. Lee
Lee Finds the Grid
Lee came up through the Air Force as a Cyber Warfare Operations Officer and was assigned to the National Security Agency. There, he helped stand up the first mission dedicated to tracking and countering threats to industrial infrastructure: the control systems that open breakers, run pumps and keep refineries running safely.
Lee also set out to explain the field to anyone who'd listen. He taught cybersecurity at Utica College, began a PhD in control system security at King's College London and wrote SCADA and Me, a picture book that walks managers through the plumbing of the power grid with a wink.
The book became a weekly Sunday web comic, Little Bobby, drawn by Jeff Haas.
The Ukraine Blackout
In October 2015 Lee and Michael Assante published The Industrial Control System Cyber Kill Chain, a SANS paper laying out, in two stages, how an attacker gets from a foothold in a company's network to an attack on the physical process itself.
Two months later someone did it for real. On December 23, 2015, attackers inside three regional Ukrainian power distribution companies opened breakers remotely with stolen credentials, wiped computers with KillDisk and cut power to about 225,000 customers in coordinated strikes within half an hour of each other.
Lee co-authored the E-ISAC and SANS analysis of the attack, which walked defenders through how it'd been done. He also built ICS515, the industrial community's first dedicated monitoring and incident response class at SANS, and became lead author of FOR578, the institute's cyber threat intelligence course.
Founding Dragos
Lee co-founded Dragos in 2016 and became its CEO. Its mission statement is grander than most: "to safeguard civilization from those trying to disrupt the critical infrastructure we depend on every day."
The seed money came from DataTribe, a Maryland "cyber foundry" that invests in and co-builds security startups. Lee rebuffed investors who wanted him to move to the West Coast, and in 2017 Dragos opened its headquarters in Hanover, Maryland, a short drive from the NSA's home at Fort Meade.
Dragos's leadership includes fellow intelligence veterans. Chief technology officer Jon Lavender once led a hand-selected NSA team hunting national-level intruders in US government and infrastructure networks, and chief data scientist Justin Cavinee built analytics in the intelligence community to catch threats to industrial networks.
Lee vs. the Hype
Lee also became known for pushing back on hype. On December 30, 2016, the day after DHS and the FBI released their GRIZZLY STEPPE report on Russian hacking, he picked it apart on his blog.
The report's written portion, he wrote, "has little to nothing to do with the intended purpose or the technical data released," and its indicators "will have a high rate of false positives for defenders that use them." What defenders needed, he argued, was context.
It set a pattern for his public voice: take the threats seriously, and take the hype apart.
CRASHOVERRIDE, TRISIS and PIPEDREAM
Dragos made its name on research. In June 2017 it published its analysis of CRASHOVERRIDE, malware built to disrupt grid operations that'd been used against Ukraine's power system in December 2016, a year after the first attack. A US government alert cited Dragos's and ESET's analysis, and the government later attributed the attack to Russian state actors.
Later that year Dragos dissected TRISIS, malware that'd targeted the safety instrumented systems of a petrochemical plant in Saudi Arabia, the equipment whose whole job is to shut a process down before it hurts someone.
In April 2022 Dragos disclosed PIPEDREAM, which it called the seventh known ICS-specific malware: a toolkit with modules for Schneider Electric and Omron gear and for widely used industrial protocols such as Modbus and OPC UA. Lee presented the findings himself as a keynote at the S4 conference that spring.
Boom, Bust and Blackmail
Investors noticed. On October 28, 2021, Dragos raised $200 million in a Series D led by Koch Disruptive Technologies and funds managed by BlackRock, at a $1.7 billion valuation.
Then things got harder. In May 2023 a criminal group compromised the personal email of a new sales hire, impersonated the employee during onboarding and got into SharePoint and a contract management system.
When the intruders failed to deploy ransomware or move deeper into the network, they switched to extortion, sending threatening messages to executives that referenced their family members. Dragos refused to pay and published the whole story to "help de-stigmatize security events."
A month later it announced it was cutting about 9 percent of its workforce amid a sales slowdown. That September it raised another $74 million, led by WestCap, bringing its total funding to roughly $440 million.
Lee Goes to Washington
Lee also kept showing up in Washington. He testified before a Senate committee on the cybersecurity of energy infrastructure in March 2018, before a House Homeland Security subcommittee on water systems in February 2024, and in July 2025 at a hearing titled "Fully Operational: Stuxnet 15 Years Later and the Evolution of Cyber Threats to Critical Infrastructure."
SC Media named him Security Executive of the Year in 2022, and in December 2023 DataTribe, his first investor, brought him back as a venture partner.
The Accenture Deal
The biggest news came on June 18, 2026, when Accenture agreed to take a majority stake in Dragos and to buy two other companies outright: runZero, the asset-discovery firm led by Metasploit creator HD Moore, and NetRise. Both would join Dragos, and the three deals carried a combined enterprise value of about $4.175 billion.
"Organizations need solutions, not a patchwork of software and services," Lee said in the announcement. Dragos would keep operating as an independent business, with him as CEO.
The deals closed on September 21, 2026, and Lee was named chairman of the board as well. In June, Dragos had also bought the xIoT security company Phosphorus.
Lee's message to asset owners hasn't softened. "If you start today," he told an interviewer in October 2026, "it will take you two to three years to have a really well-functioning OT security program, and that's if you're moving with purpose and a sense of urgency."
Robert M. Lee: Defense Is Doable
The attackers who cut Ukraine's lights and went after a Saudi plant's safety systems are real. So are the engineers who can see them coming, if someone teaches them how. Lee's whole message comes down to four words: "ICS defense is doable."
He still runs Dragos as CEO and chairman, teaches at SANS, holds a commission as a lieutenant colonel in the Army National Guard and sits on boards from the International Society of Automation to the National Cryptologic Foundation.
He even wrote a children's book to get the grown-ups to read about it.
QUOTE:
"Amateurs hack systems, professionals hack people."