Dossier · Acquired asset · 1 independent source

Radiflow

Cybersecurity Acquired asset Dual-Use Technology Founded 2009

Last updated: Jul 31, 2026

Radiflow is an Israeli industrial cybersecurity company that provides passive OT/ICS visibility, anomaly and threat detection, risk assessment, and compliance-oriented security management for critical infrastructure and industrial operators. Its products are designed to improve cyber resilience without interrupting safety- and uptime-sensitive operations.

Visit Website

Company Overview

Radiflow develops a purpose-built OT and ICS security platform rather than a general enterprise endpoint product. Its current product materials describe iSID for passive asset discovery, network visualization, behavioral baselining, and anomaly or threat detection; CIARA for data-driven OT risk assessment, breach-and-attack simulation, mitigation prioritization, and reporting; iCEN for centralized management across multiple sites; and Active Scanner for deeper, targeted asset queries. The architecture is relevant to industrial environments because it can ingest mirrored traffic and operate without treating production systems like ordinary IT endpoints. Radiflow also describes Smart Collectors and secure gateways for distributed or remote sites. These capabilities address a persistent visibility problem: operators often have incomplete inventories, legacy controllers, proprietary protocols, and limited tolerance for active testing or downtime.

The commercial buyer set includes utilities, energy and oil-and-gas operators, manufacturing, transportation or maritime environments, and managed security service providers that need to monitor multiple industrial customers. The product is positioned for CISOs, OT or plant managers, SOC teams, auditors, and service providers. Its APIs and documented integrations with SIEM, identity, network-security, asset-management, and industrial-platform partners can reduce adoption friction, although integration breadth is not the same as independently verified customer depth. Radiflow says its solutions are deployed at more than 8,000 sites on its product and company pages, while its homepage currently markets 20,000 sites globally. The discrepancy should be resolved in diligence before using deployment scale as a hard traction metric; either figure indicates an established installed base, but neither page provides a customer-by-customer reconciliation or recurring-revenue disclosure.

The market is attractive but crowded. OT security demand benefits from industrial digitization, ransomware and sabotage concerns, regulatory pressure, and the operational cost of outages. Radiflow competes with specialist vendors such as Claroty, Dragos, Nozomi Networks, and Microsoft Defender for IoT, as well as broader security and networking suppliers including Cisco, Fortinet, Palo Alto Networks, and Armis. Its differentiating thesis is a combined workflow from asset visibility and detection to quantified risk, digital-twin simulation, compliance reporting, and budget-aware mitigation planning. That can be valuable for operators that need to explain technical exposure to business owners, regulators, and boards. It is not a moat by itself: competitors increasingly combine discovery, vulnerability context, threat intelligence, exposure management, and response, and large platform vendors can bundle adjacent capabilities into existing contracts.

Radiflow was founded in 2009 and continues to present itself as an independent operating brand with a Tel Aviv base and international offices or partners. Sabancı Holding disclosed that its technology investment vehicle DxBV acquired 51% of Radiflow on May 30, 2022, making Radiflow a subsidiary; this is more reliable current ownership information than the record’s prior Series C label. The acquisition provides a strategic parent and potential access to industrial, energy, and infrastructure relationships, but public sources do not establish current revenue, margins, renewal rates, customer concentration, or the terms of any later ownership change. LinkedIn still lists Radiflow as privately held, with 51–200 employees and a Tel Aviv headquarters, but directory ranges are not audited headcount. The company’s continued product updates, partner activity, and 2026 public marketing indicate ongoing commercialization, while the limited financial disclosure warrants a moderate team and traction score rather than an assumption of venture-scale growth.

The national-security relevance is credible through infrastructure dependency, not because public sources establish military deployments. Electricity, water, manufacturing, transport, communications, and defense supply chains all rely on cyber-physical environments whose compromise can create physical, economic, or safety consequences. Passive monitoring, asset inventory, threat detection, risk prioritization, and simulation can therefore support resilience programs used by civilian critical infrastructure and defense-adjacent industrial suppliers. The strongest diligence question is whether Radiflow can translate technical capability into measurable reduction in outage risk and response time across heterogeneous legacy environments. Other important questions include independent validation of detection performance, false-positive rates, protocol coverage, deployment effort, cloud versus on-premises economics, product security, and the extent to which the Sabancı ownership structure changes channel access, governance, and strategic optionality.

Dual-Use Assessment

Military & Commercial Applications

Radiflow has substantive dual-use applicability because the same OT visibility, anomaly detection, risk assessment, and resilience workflows can protect civilian critical infrastructure, industrial facilities, and defense-adjacent production or logistics networks. The public evidence supports infrastructure-security relevance, but does not establish military customers or classified deployments; the defense case should therefore be framed as an infrastructure and supply-chain resilience adjacency rather than as a proven defense program.

Strategic Fit Assessment

Radiflow is strategically relevant, but strategically relevant is set to false as a legacy priority-signal flag because the company is a majority-owned subsidiary rather than an ordinary independent startup opportunity. Its underlying diligence case is supported by a long operating history, a specialized OT product suite, ongoing public commercialization, and a market with high operational consequences. The main positive questions are whether the platform produces defensible detection and risk-reduction outcomes, whether its installed base converts into durable recurring revenue, and whether Sabancı ownership accelerates distribution across energy and industrial relationships. The main constraints are sparse public financial data, unverified customer and revenue concentration, fierce competition from better-capitalized specialists and platform vendors, and limited visibility into ownership terms and strategic exit pathways. This assessment is a strategic diligence signal, not an investment recommendation.

Strategic Value to U.S.-Israel Alliance

Radiflow can contribute to national and allied resilience by helping operators discover and monitor industrial assets that cannot be patched, scanned, or taken offline like conventional IT systems. Its strongest strategic value is defensive: improving visibility, prioritizing remediation, and supporting continuity in utilities, manufacturing, energy, and critical suppliers. Sabancı ownership may create useful industrial and infrastructure adjacency, but public evidence does not demonstrate government contracts, military adoption, or a unique sovereign capability. Strategic evaluation should focus on independently measured detection efficacy, coverage of locally relevant industrial protocols, deployment in geographically distributed environments, secure product lifecycle practices, and the company’s ability to support operators during an active incident.

Key Technologies

  • Passive ICS and OT asset discovery
  • Industrial network topology and behavioral baselining
  • OT anomaly and threat detection across legacy and proprietary protocols
  • CIARA risk scoring and mitigation prioritization
  • Digital-twin breach-and-attack simulation
  • Centralized multi-site iCEN management and MSSP tenancy
  • Smart Collectors, secure gateways, and targeted active asset scanning

Use Cases & Applications

  • Continuous visibility for electric, water, energy, and other utility networks
  • Threat detection and anomaly monitoring in manufacturing plants
  • Multi-site OT monitoring by enterprise SOCs and managed security providers
  • Risk-based remediation planning for NIS2, IEC 62443, NIST CSF, and related controls
  • Remote-site and substation monitoring where bandwidth and uptime are constrained
  • Cyber-resilience assessment for defense suppliers and other critical industrial contractors
  • Asset inventory and exposure analysis for legacy SCADA and ICS environments

Sources and verification

This profile is based on public-source research, Claw & Talon curation, and editorial judgment. Inclusion does not imply endorsement, partnership, investment, or a recommendation to transact. Readers should still confirm current status, customers, funding, and product claims before relying on this profile. The editorial policy explains how profiles are researched, where automated drafting is used, and how corrections work; the research methodology documents how evidence is graded, what counts as an independent source, and why some profiles are excluded from search indexing.

This record lists 6 public references used for company identity, status, positioning, or material-claim review.

Public sources

The links below are visible public references used for source discipline around company identity, status, funding, customer, acquisition, public-company, or other material claims where available.

Related sector

See the Cybersecurity sector page for market context, related subcategories, and other Israeli companies in this part of the database.