Skip to content

Defence Intelligence

Ottawa, Canada-based small independent DNS security vendor best known for discovering and helping dismantle the Mariposa botnet, now marketing an agentless DNS/firewall filtering product line.

Visit Website ↗ + Add to Compare
32/100Emerging / Unranked

Overview

Defence Intelligence, founded in 2008 by CEO Chris Davis and based in Ottawa, Ontario, is a network and DNS security vendor best known for discovering the Mariposa botnet in 2008-2009, at the time one of the largest botnets ever identified, spanning an estimated 8 to 12 million infected machines. The company helped the international Mariposa Working Group, alongside Panda Security, Neustar, Directi, and the Georgia Tech Information Security Center, coordinate its takedown, work that earned the company a Global Hero Award from the Digital Crimes Consortium.

The company’s current commercial product line, marketed as Nemesis and Valkyrie, is a DNS-layer security and firewall offering that identifies compromised systems and blocks command-and-control communication, phishing, and malware delivery by filtering DNS requests against continuously updated threat intelligence, a lightweight, network-level control that does not require endpoint agent deployment.

Defence Intelligence has stayed small and independent for 17-plus years, with employee estimates ranging from roughly 18 to 34 depending on source, and no disclosed venture or private equity funding found. That longevity without a growth-capital event suggests a niche, steady-state trajectory rather than a scaling product company, even though its botnet-research pedigree remains a genuine, independently documented credential.

Innovation Matrix Assessment

Innovation Velocity 2/10

No evidence found of active product releases, funding events, or public updates in recent years beyond a maintained website and blog.

Operational Value 4/10

DNS security product line is still marketed and presumably supported, but small team size suggests limited engineering capacity.

Market Momentum 2/10

No recent funding, acquisition, or customer-growth signals found; company's public/LinkedIn presence is small.

Category Disruption 3/10

The agentless, DNS-layer approach was notable at founding but DNS security is now a well-established category with larger competitors.

Real-World Efficacy 5/10

Independently documented, historically significant threat-research credential (the Mariposa botnet takedown) backs its technical credibility.

Enduring Relevance 3/10

DNS security remains a relevant control category, but this specific small independent vendor has limited visible current market relevance versus larger DNS security players.

Why CISOs Should Care

A small, independent DNS security vendor with a genuinely notable threat-research pedigree, offering agentless, DNS-layer compromise detection as a lightweight complement to endpoint tools.

What Makes It Different

Built its credibility on hands-on botnet takedown research rather than marketing; its DNS and firewall filtering approach avoids endpoint agent deployment.

The Matrix Verdict

32/100 — EMERGING / UNRANKED

A long-running, small independent niche vendor -- its relevance rests more on historical research credibility than current visible growth.

Editorial Note: Claims vs. Verified Findings

Employee counts vary widely by source (18 to 34); no funding rounds, investors, or recent (post-2020) public updates were found, so current scale and traction could not be independently verified beyond the maintained product website.

Sources