SOC-to-SOC Threat Intelligence Alliance · 290+ Members Worldwide

Global threat intelligence. Shared in real time. Enforced automatically.

OneFirewall Alliance is a UK cyber threat intelligence company. It connects the Security Operations Centres of independent organisations into one real-time defence network, so every member firewall can learn from every attack, anywhere in the alliance.

A single-vendor firewall, however capable, only ever sees its own customers. It cannot see what a heterogeneous alliance of independent SOCs sees together — and that gap is exactly what OneFirewall closes.

Diagram showing the Global Security Alliance Network and Central Cluster Score Algorithm feeding the OneFirewall Crime Feed Sensor, which pushes rules to Intrusion Prevention and Intrusion Detection Modules across firewalls, cloud, and SIEM platforms

“Independent organisations shouldn't have to fight alone. OneFirewall exists so yours doesn't have to.”

OneFirewall Alliance · Global Cyber Threat Intelligence
290+Alliance Members
<30sDetection to Enforcement
220M+Live CTI Records
166+Firewall & IPS Integrations
Trusted by leading telecoms, energy, financial, government and defence organisations
Leonardo logo TIM logo Terna logo Telepass logo Cy4Gate logo Olidata logo Exprevia logo Almaviva logo Cassa Depositi e Prestiti (CDP) logo Department for Science, Innovation and Technology (DSIT) logo Polo Strategico Nazionale logo COR - Comando per le Operazioni in Rete, Italian Ministry of Defence
One Alliance, Three Disciplines

A single platform for intelligence, enforcement, and assurance

Most vendors sell you one layer of defence. OneFirewall was built by combining all three — because collective intelligence is only as useful as your ability to act on it, and to prove it's working.

OneFirewall Alliance logo

Collective Intelligence

IOC and CTI feeds crowd-sourced from 290+ alliance members, enriched with Crime Scores and MITRE ATT&CK mapping, delivered natively in STIX 2.1 / TAXII 2.1.

Explore Threat Intelligence →
OneFirewall WCF Agent logo

Automated Enforcement

The WCF Agent pushes validated block-rules directly to your firewall, IPS, WAF or SIEM — no manual playbooks, no ticket queues, detection to enforcement in under 30 seconds.

Explore the Platform →
Vulnix0 logo

Security Assurance

Penetration testing, OpenSAMM maturity assessments, threat modeling and phishing simulation — validating that your defences hold up against a real adversary, not just a scanner.

Explore Security Assurance →
Global Threat-Sharing Ecosystem

Connected to the threat-sharing circle that already protects critical infrastructure Cyber Threat Alliance

OneFirewall is a member of the Cyber Threat Alliance — the vetted group founded in 2014 by Fortinet, Palo Alto Networks, Symantec and McAfee to share threat intelligence across an entire industry, not just inside one vendor's customer base. Check Point and Cisco joined in 2017. CTA membership means OneFirewall's own alliance taps directly into that wider ecosystem.

Cyber Threat Alliance member grid with OneFirewall highlighted alongside Check Point, Cisco, Fortinet, McAfee, Palo Alto Networks, Sophos, Symantec and other members

What is OneFirewall Alliance?

OneFirewall Alliance is a UK-based cybersecurity company, founded in 2018 in London, that operates a SOC-to-SOC alliance: a crowd-sourced Cyber Threat Intelligence platform connecting 290+ independent organisations worldwide. Members share real-world attack observations, which are validated and enriched with a Crime Score (0–1000), MITRE ATT&CK mapping and STIX 2.1 / TAXII 2.1 formats, then enforced automatically across firewalls, IPS, WAF, SIEM and cloud controls in under 30 seconds. The platform integrates with 166+ firewall and security products.

How It Works

Every data center, one shared nervous system

Each data center keeps running its own security products. The OneFirewall Agent sits alongside them, feeding intrusion data into a central rating engine — so a threat detected at Data Center A becomes a blocking rule at Data Center B, automatically.

Diagram showing two data centers feeding intrusion data through OneFirewall Agents into a central scoring server that pushes prevention rules back to both data centers
290+Alliance members across finance, telecom, government & cloud
0–1000Crime Score risk scale
166+Firewall, cloud & SIEM integrations
STIX 2.1Native intelligence format
Case Study · Global B2B SaaS Platform

35,000 daily attacks before deployment. Latency down 28% in 24 hours (client-reported).

A global SaaS platform running across Azure, DigitalOcean and GCP was absorbing 35,000 attacks a day, with nearly a quarter of all inbound traffic malicious. After deploying OneFirewall, unauthorised traffic dropped to zero while performance improved — the same alliance-wide defence network every member plugs into on day one.

Read the Full Case Study →

35,000

Daily attacks before deployment (client-reported)

28%

Latency reduction

24h

Time to full resolution

12,000+

Daily feeds contributed back

Juan Rivera, Executive Director of OneFirewall Alliance
Leadership
“Every threat we identify collectively is an opportunity to protect another organisation.”

Juan Rivera, Executive Director, OneFirewall Alliance. Joined the company in 2024. LinkedIn profile

Global Presence

Headquartered in London, with partners across Europe, Asia and Latin America.

Alliance members and delivery partners spanning Europe, South Asia, Southeast Asia and Latin America.

Headquarters

London, UK

OneFirewall Alliance LTD

Founded 2018

Partner

New Delhi, India

Cybosecure Networks Pvt. Ltd

Partner

Southeast Asia

Skylabs Solution India Pvt

Partner

Peru · Ecuador · Colombia

VLATAM

FAQ

Frequently asked questions about OneFirewall Alliance

What is OneFirewall Alliance?

A UK cyber threat intelligence company. It runs a crowd-sourced alliance of 290+ independent organisations that share validated threat intelligence, enforced automatically on firewalls, IPS, WAF and SIEM platforms.

How fast is threat intelligence enforced?

According to OneFirewall's platform specifications, detection to enforcement takes under 30 seconds once an indicator is validated by the alliance.

Which firewalls and security platforms are supported?

OneFirewall lists 166+ firewall, cloud, WAF and SIEM integrations, including Check Point, Fortinet FortiGate, Palo Alto Networks, Sophos, AWS WAF, Google Cloud Platform, IBM QRadar and Splunk.

What is a Crime Score?

The Crime Score is a 0 to 1000 risk value assigned to IPs, domains, URLs and file hashes. It rises when several independent alliance members confirm the same threat, so volume from one reporter alone never triggers a block.

How is the intelligence shared in a standard format?

Intelligence is available as STIX 2.1 over a TAXII 2.1 server. STIX and TAXII are OASIS standards, so tools such as MISP and OpenCTI can consume it directly.

How do organisations get started?

Request a free Proof of Value, a risk-free assessment against your own infrastructure, or talk to our sales team. Data handling and certifications are set out on the Trust & Security page.

See what collective defence looks like in your environment.

Start a free Proof of Value and connect your perimeter to the alliance in days, not months.

Get Started