290+Alliance & CTA contributors
166+Firewall, cloud & SIEM integrations
STIX 2.1Native delivery format
Multi-TenantBuilt for MSSP scenarios
A Live Analysis, Not a Sales Deck

What one 24-hour window showed behind an existing firewall estate

This is the kind of report a Live Analysis produces — and it's the kind of artefact an MSSP can hand its own client, not just read internally. One recent anonymised run, against a real mixed Check Point and Fortinet estate, over a single 24-hour period:

22,053

Events parsed in 24 hours

20.5%

Already blocked by the client's own firewall

+6.7%

Additionally blocked by the alliance feed, same window

1,845

Distinct threat actors found inside "permitted" traffic

Of the 72.8% of traffic the client's own stack had already waved through, 12.1% — 1,939 events — came from addresses with a known history of malicious activity elsewhere in the alliance. 458 of those were scored critical. None of that required replacing the Check Point or Fortinet gateways already doing the first pass; it required a second opinion they didn't have.

OneFirewall threat actor profile for a single IP, showing Crime Score, first/last seen, and its connection history across multiple Check Point and Fortinet gateways
Why a Single Vendor's View Isn't Enough

Breadth is the product, not the feature

  • A single vendor's telemetry is bounded by its own customer base. Point solutions, even very good ones, only see what their own install base generates. A heterogeneous alliance sees what no single vendor's customer list can.
  • MSSPs pay for the same indicators twice. Running multiple threat-intel vendors to cover gaps means paying repeatedly for heavily overlapping, inconsistently fresh data instead of one well-correlated feed.
  • CTA membership extends reach beyond the alliance itself. CTA membership extends OneFirewall's telemetry reach beyond the alliance's own 290+ members into a wider global threat-sharing ecosystem. A technique first seen by a CTA member on the other side of the world still reaches every alliance member's firewall.
  • Critical national infrastructure needs the same model. PSN, which hosts public-administration and health-authority data on Italy's national strategic cloud, sits inside the same alliance as organisations with very different network footprints. That's proof the model scales from a single MSSP's client base all the way up to national infrastructure.
Built for Multi-Customer Operations

Designed around separation of duties from day one

OneFirewall's multi-tenant architecture explicitly targets organisations that need logical separation across business units or customers, including MSSP scenarios serving multiple clients with distinct policies and confidentiality requirements. Each tenant's users, feeds, crime scores, and WCF installations stay isolated; only the threat intelligence itself is shared.

OneFirewall threat actor profile showing Crime Score gauge, trend history, CTI points, members and reports
Security & critical-infrastructure organisations inside the alliance
Cyber Threat Alliance PSN Cy4Gate DSIT
How It Fits

A vendor-neutral layer across a heterogeneous client stack

  • Crime Score as a common prioritisation layer. Every indicator carries a consistent score regardless of which member or feed reported it first, a shared language across a client base running different vendors.
  • STIX/TAXII re-ingestion. Native STIX 2.1 / TAXII 2.1 delivery drops directly into an MSSP's own multi-tenant SIEM/SOAR stack without custom parsing per client.
  • Federated XDR across heterogeneous environments. Coordinated enforcement instructions flow across firewalls, endpoint security, and cloud providers, matching the mixed-vendor reality of most MSSP client portfolios.
Two Partnerships That Prove the Model

Why CTA, and why BondMesh

Neither partnership is a logo swap. Both exist because a cybersecurity vendor or MSSP reading this page needs proof that OneFirewall's intelligence is wide enough and sharp enough to matter.

Cyber Threat Alliance Cyber Threat Alliance

CTA was founded in 2014 by Check Point, Cisco, Fortinet, McAfee, Palo Alto Networks and Symantec — the incumbent vendors every MSSP already works with. It's headquartered in Arlington, Virginia, and today counts member companies across more than a dozen countries. OneFirewall's CTA membership means our alliance's 290+ members aren't a closed pool: a technique first seen by a CTA member on the other side of the world reaches every OneFirewall member's firewall too. For a vendor evaluating whether to plug into our feed, that's the difference between adopting another isolated data source and adopting one that's already interoperating with the vendors in your stack.

BondMesh BondMesh

BondMesh, based in Belgrade, Serbia, built what it calls the world's first autonomous AI Security Analyst — a system designed to detect, reason about, and act on threats in real time, without a human bottleneck, built for ransomware, APTs, and nation-state attacks. BondMesh is explicit that its platform is backed by the OneFirewall Alliance, alongside AquilaX and Moonstruck. That's a live proof point for this audience specifically: OneFirewall's intelligence is already structured and scored cleanly enough to drive an autonomous system's decisions, not just populate another analyst's dashboard.

Questions We Get From MSSPs and Vendors

The questions behind the questions

Will this compete with the threat-intel feeds we already resell?

It's built to sit alongside them, not replace them — the CTA and BondMesh relationships exist precisely because OneFirewall plays inside a multi-vendor stack rather than demanding exclusivity from the vendors or MSSPs that adopt it.

We manage 50+ client networks. How does billing and access stay separated?

The multi-tenant architecture is explicitly designed for this: each client's users, feeds, Crime Scores, and WCF installations stay logically isolated, while only the underlying threat intelligence is shared across the pool.

We already run STIX/TAXII tooling — is this extra integration work?

Minimal. Intelligence is delivered via a native STIX 2.1 / TAXII 2.1 server built for discovery, collections, pull, and push — it's designed to drop into MISP, OpenCTI, Anomali, ThreatConnect, or any TAXII-compatible platform you already run.

Running security for other people's networks?

See what alliance-wide correlation adds across a multi-client portfolio.

Start a Proof of Value