iDNA
iDNA (Groupe IDNA, encompassing IDNA and AURA iT) is a Paris-based cybersecurity consulting and engineering specialist with roughly forty experts, focused on protecting IT…
Visit Website ↗ + Add to CompareOverview
iDNA (Groupe IDNA, encompassing IDNA and AURA iT) is a Paris-based cybersecurity consulting and engineering specialist with roughly forty experts, focused on protecting IT systems for critical infrastructure, industrial (OT), and building-management environments. Its work spans cyber risk audit and consulting, cyber risk management, and securing cloud and IT/OT environments for clients where operational continuity and safety are inseparable from security.
NXO announced the acquisition of Groupe IDNA in February 2026 to strengthen its own cybersecurity offering, pairing NXO’s existing certifications and technical capabilities with IDNA’s audit, consulting, and OT/critical-infrastructure expertise into a more complete strategy-risk-governance offering. IDNA becomes a subsidiary of NXO and retains its identity and operational autonomy to continue serving existing clients while developing commercial synergies with the broader group.
Innovation Matrix Assessment
A steady, services-led consultancy rather than a fast-moving product company; growth is measured in acquisition and client relationships rather than release velocity.
Provides hands-on audit, risk management, and cloud/IT-OT security consulting directly applicable to critical-infrastructure operators' compliance and safety obligations.
Acquired by NXO in February 2026 specifically to fill out its strategy-risk-governance capability -- concrete strategic validation, though as a private consultancy no revenue or client-count figures were disclosed.
OT and critical-infrastructure security consulting is an established, well-populated services category; IDNA's value is depth and specialization rather than a novel approach.
Roughly 40 specialists and a going-concern consulting practice for critical-infrastructure clients suggest real operational track record, though no independent client outcome data is publicly available.
Regulatory pressure (NIS2 and similar) and rising OT-targeted attacks keep specialized critical-infrastructure security consulting durably in demand.
Why CISOs Should Care
Gives CISOs at industrial and critical-infrastructure organizations a specialist partner for OT and IT/OT-convergence risk -- a domain where generic IT security consultancies often lack the operational-technology depth to audit safely.
What Makes It Different
Concentrates specifically on critical infrastructure, industrial, and building-management security rather than offering generic enterprise IT security consulting, giving it deeper OT-specific audit and risk expertise than broader consultancies.
The Matrix Verdict
52/100 — INCREMENTAL INNOVATOR
An established, roughly 40-person French OT/critical-infrastructure security consultancy folded into a larger group to round out its strategy-risk-governance offering; Incremental Innovator as a specialized services acquisition rather than a product breakthrough.
Editorial Note: Claims vs. Verified Findings
The acquisition and IDNA's OT/critical-infrastructure focus are corroborated across NXO's own announcement, IDNA's own site, and independent French trade press (Global Security Mag, Solutions Numeriques); no financial terms were disclosed.
Sources
Alternatives to iDNA
Vanta
Continuous automated compliance monitoring platform that replaces manual audit evidence-gathering with live, integration-based control checks.
AuditBoard (rebranded Optro)
Connected-risk platform for audit, SOX, risk, and compliance, recently rebranded from AuditBoard to Optro under an AI-agent-driven repositioning.
Arcova
Cybersecurity advisory and managed services firm, rebranded from MorganFranklin Cyber, offering GRC, IAM, OT security, and a cloud-based…
Credo AI
AI governance platform that discovers, assesses, and continuously monitors enterprise AI systems and agents against regulations like the…
Level 6 Cyber
CISO ReviewedContinuous decision-intelligence platform (LISN) that replaces point-in-time security audits with a live digital twin of a CISO's program.
Drata
Continuous compliance automation platform, Vanta's closest direct competitor, covering SOC 2, ISO 27001/42001, HIPAA, PCI DSS, DORA, and…