No single vendor sees everything. Not even the one selling you its own firewall.
The Cyber Threat Alliance (CTA) and the Polo Strategico Nazionale (PSN), Italy's national strategic cloud hub for public administration, are both members of the OneFirewall Alliance, sitting alongside security vendors and MSSPs whose businesses depend on visibility that no single customer base can provide on its own.
What one 24-hour window showed behind an existing firewall estate
This is the kind of report a Live Analysis produces — and it's the kind of artefact an MSSP can hand its own client, not just read internally. One recent anonymised run, against a real mixed Check Point and Fortinet estate, over a single 24-hour period:
22,053
Events parsed in 24 hours
20.5%
Already blocked by the client's own firewall
+6.7%
Additionally blocked by the alliance feed, same window
1,845
Distinct threat actors found inside "permitted" traffic
Of the 72.8% of traffic the client's own stack had already waved through, 12.1% — 1,939 events — came from addresses with a known history of malicious activity elsewhere in the alliance. 458 of those were scored critical. None of that required replacing the Check Point or Fortinet gateways already doing the first pass; it required a second opinion they didn't have.
Breadth is the product, not the feature
- A single vendor's telemetry is bounded by its own customer base. Point solutions, even very good ones, only see what their own install base generates. A heterogeneous alliance sees what no single vendor's customer list can.
- MSSPs pay for the same indicators twice. Running multiple threat-intel vendors to cover gaps means paying repeatedly for heavily overlapping, inconsistently fresh data instead of one well-correlated feed.
- CTA membership extends reach beyond the alliance itself. CTA membership extends OneFirewall's telemetry reach beyond the alliance's own 290+ members into a wider global threat-sharing ecosystem. A technique first seen by a CTA member on the other side of the world still reaches every alliance member's firewall.
- Critical national infrastructure needs the same model. PSN, which hosts public-administration and health-authority data on Italy's national strategic cloud, sits inside the same alliance as organisations with very different network footprints. That's proof the model scales from a single MSSP's client base all the way up to national infrastructure.
Designed around separation of duties from day one
OneFirewall's multi-tenant architecture explicitly targets organisations that need logical separation across business units or customers, including MSSP scenarios serving multiple clients with distinct policies and confidentiality requirements. Each tenant's users, feeds, crime scores, and WCF installations stay isolated; only the threat intelligence itself is shared.
A vendor-neutral layer across a heterogeneous client stack
- Crime Score as a common prioritisation layer. Every indicator carries a consistent score regardless of which member or feed reported it first, a shared language across a client base running different vendors.
- STIX/TAXII re-ingestion. Native STIX 2.1 / TAXII 2.1 delivery drops directly into an MSSP's own multi-tenant SIEM/SOAR stack without custom parsing per client.
- Federated XDR across heterogeneous environments. Coordinated enforcement instructions flow across firewalls, endpoint security, and cloud providers, matching the mixed-vendor reality of most MSSP client portfolios.
Why CTA, and why BondMesh
Neither partnership is a logo swap. Both exist because a cybersecurity vendor or MSSP reading this page needs proof that OneFirewall's intelligence is wide enough and sharp enough to matter.
Cyber Threat Alliance
CTA was founded in 2014 by Check Point, Cisco, Fortinet, McAfee, Palo Alto Networks and Symantec — the incumbent vendors every MSSP already works with. It's headquartered in Arlington, Virginia, and today counts member companies across more than a dozen countries. OneFirewall's CTA membership means our alliance's 290+ members aren't a closed pool: a technique first seen by a CTA member on the other side of the world reaches every OneFirewall member's firewall too. For a vendor evaluating whether to plug into our feed, that's the difference between adopting another isolated data source and adopting one that's already interoperating with the vendors in your stack.
BondMesh
BondMesh, based in Belgrade, Serbia, built what it calls the world's first autonomous AI Security Analyst — a system designed to detect, reason about, and act on threats in real time, without a human bottleneck, built for ransomware, APTs, and nation-state attacks. BondMesh is explicit that its platform is backed by the OneFirewall Alliance, alongside AquilaX and Moonstruck. That's a live proof point for this audience specifically: OneFirewall's intelligence is already structured and scored cleanly enough to drive an autonomous system's decisions, not just populate another analyst's dashboard.
The questions behind the questions
Will this compete with the threat-intel feeds we already resell?
It's built to sit alongside them, not replace them — the CTA and BondMesh relationships exist precisely because OneFirewall plays inside a multi-vendor stack rather than demanding exclusivity from the vendors or MSSPs that adopt it.
We manage 50+ client networks. How does billing and access stay separated?
The multi-tenant architecture is explicitly designed for this: each client's users, feeds, Crime Scores, and WCF installations stay logically isolated, while only the underlying threat intelligence is shared across the pool.
We already run STIX/TAXII tooling — is this extra integration work?
Minimal. Intelligence is delivered via a native STIX 2.1 / TAXII 2.1 server built for discovery, collections, pull, and push — it's designed to drop into MISP, OpenCTI, Anomali, ThreatConnect, or any TAXII-compatible platform you already run.
