The inspection data on your network has changed owner
7 min read
Who inspected your network last year? If the answer is a drone and a crew of technicians, pause for a moment. That footage — cables seen up close, turbine blades, substations, pylons — and the analysis built on top of it does not sit on your own servers: it sits on a third-party supplier’s platform, and you have access to it, not control of it. What happens to that data if the company holding it changes owner overnight? Until two days ago, that was a theoretical question. As of yesterday, it has a written answer, filed with the Securities and Exchange Commission.
The facts, from the filing
The Form 8-K filed on 10 August 2026 (accession number 0001193125-26-341399) by Ondas Inc. (Nasdaq: ONDS) records, under Item 2.01, an acquisition completed the same day: Ondas completed its purchase of Cyberhawk Holdings Limited, “a private company limited by shares incorporated in England and Wales” — a British company specialising in drone inspection of critical infrastructure. The deal had been agreed under the Share Purchase Agreement dated 17 June 2026, and closed, verbatim, as follows: “the Company acquired 100% of the issued and outstanding share capital of Cyberhawk for (i) $118.2 million in cash and (ii) 581,732 shares of the Company’s common stock” — the entire share capital, for $118.2 million in cash plus 581,732 Ondas shares.
The shares issued to the sellers are locked up for one year; for the following eighteen months, the sellers may only sell within a daily cap equal to their pro rata share of 10% of the average daily trading volume of ONDS stock. The document is signed by Eric A. Brock, Chief Executive Officer.
What the filing does not contain — and it belongs in the record
Under Item 9.01, the same filing states, verbatim: “Financial statements are not required in connection with the Acquisition pursuant to Rule 3-05(b) of Regulation S-X” and “Pro forma financial information is not required in connection with the Acquisition pursuant to Article 11 of Regulation S-X.” A deal worth over a hundred million dollars closes without Cyberhawk’s own accounts entering the public filing. This is not an irregularity: it is the rule that applies when a transaction falls under certain size thresholds in Regulation S-X, and the filing names it by number. But for anyone outside, it is a transparency fact worth noting: Cyberhawk’s financial statements stay outside the public record.
The sentence that makes this a story
The same day, Ondas issued a press release — attached to the filing as Exhibit 99.1 — headlined “Ondas Completes Previously Announced Acquisition of Cyberhawk, a Leader in AI-Powered Critical Infrastructure Intelligence.” Ondas describes itself openly as “a leading provider of advanced autonomous systems and next-generation defense and security technologies and services”; in its “About” section, the company presents itself as a provider of “autonomous systems, robotics, and mission-critical technologies for defense, homeland security, public safety, critical infrastructure, and industrial markets,” with platforms built to support “intelligence, surveillance, reconnaissance, security, and operational missions.” Cyberhawk, for its part, is described as “a global leader in drone-enabled inspection, visual data management and AI-powered asset intelligence solutions for critical infrastructure operators,” with “decades of operational expertise serving utilities, energy, renewables, mining and industrial customers” and a “proprietary visual data management platform” — neither description contradicts the other.
The sentence that makes this a story sits in the quote from Eric Brock, Chairman and CEO, carried in the release: “As we integrate Cyberhawk with our broader platform, including the leveraging of our enterprise-wide Palantir Foundry deployment, we expect to unlock additional value through enhanced data integration, AI-enabled workflows and greater operational efficiency across the business.” The inspections of your lines, your wind farms, your substations — if you commissioned them from Cyberhawk — will flow into the enterprise-wide Palantir Foundry deployment already running inside Ondas. The same release records, alongside the deal, inducement awards to 47 newly-hired employees: 1,601,593 RSUs and 1,290,000 stock options with an exercise price of $9.11, under the Nasdaq Rule 5635(c)(4) exception.
See the service · Talk to an engineer
What we do not know, and do not claim
We do not know which European customers Cyberhawk holds, nor whether any of its inspection contracts run with Italian energy, utility or infrastructure operators: the filing does not say, and we have not verified it. We do not know whether Cyberhawk’s individual contracts contain a change-of-control clause covering exactly this scenario, nor in what format or for how long the data stays available to the client who commissioned the inspection. We are not asserting this: we are flagging it as the area the filing does not cover, and one only the signed contract — yours, or your own inspection supplier’s — can actually answer.
The question that matters, for you
There is nothing unlawful in this deal: an acquisition is legitimate, Ondas states openly where it will take the data, and the contract signed with Cyberhawk continues to hold on its own terms. The point is a different one. Did the contract you signed anticipate this case? Does it contain a change-of-control clause? Does it say where your network’s images physically reside, and under which jurisdiction they now sit, now that the supplier has come under the umbrella of a Nasdaq-listed company that describes itself as a provider of defence and national-security technologies? Does it say what happens to your data if you decide to end the relationship?
It is the same question we measured reading the internal audit that found no exit strategy from a critical data supplier, and the one facing anyone who has asked who really owns the ontology a supplier builds on top of a company’s data. The same distinction applies here that we isolated reading an acquisition where the press release said one thing and the filing said another: the release promises integration, the filing only discloses a transfer of share capital. Where your network’s data actually ends up, day to day, depends on a contract neither document publishes.
The two axes, applied
Comply. The register of suppliers holding data on your assets — inspections, measurements, images, analysis — stops being a folder of expired quotes and becomes a control running on the client’s contracts and systems: for each supplier, which data on your infrastructure it holds, where it resides, under which jurisdiction, what the contract says on change of control, subcontracting and data return on termination, in what format and within what timeframe — with a test export already run and dated. It is the same gap found in a supplier register that never said what a product actually did: the field exists, the row stays blank until someone fills it in. With the record ready to show an inspector or a board — the same question that, for an operator in the energy sector or a NIS entity, arrives anyway on supply-chain security.
Decide. The same system unifies contracts, supplier registers, inspections, measurements, archives and documents into a single operational model — the organisation’s data lake becoming one single thing — on which AI agents execute decisions with a human operator in command, for large enterprises, defence, the public sector and healthcare. The difference we claim: the images of your wind turbine blades, the measurements of your substations and the model that links them stay yours, because that is the layer you cannot buy back once the supplier that captured them changes owner. Always in two modes: on-premises, on self-contained machines that require no deep integration into your network, or a dedicated cloud with a data centre in Italy, always with shared management.
If tomorrow morning the company that inspects your network were bought by a defence-technology supplier, could you already say, under contract, who owns the images taken last year? For most readers, the answer is no.
From the first session, at no cost, comes the dated list of suppliers holding data on your assets: for each one, what data, where it resides, what the contract says on change of control and data return, and whether a test export has ever been run — including the boxes that stay blank. It stays with you even if we do not go on to work together. Talk to one of our engineers about it.