Built for the networks that can't afford to be the first to know.
Defense and national-security networks are the most persistently targeted environments in cyberspace — probed daily by nation-state operators who have the patience to wait months before they act. OneFirewall was built on a simple premise: no single agency, command, or vendor firewall sees enough of the picture alone. The alliance model exists to close exactly that gap.
Espionage, not opportunism
- Nation-state patience, not smash-and-grab. Defense and intelligence networks are targeted by operators whose objective is long-term access and collection, not a quick payout — reconnaissance can run for months before anything resembling an "incident" occurs.
- Multi-domain attack surface. Land, air, sea, space, and cyber commands increasingly share logistics, communications, and administrative networks — a foothold in one domain's lowest-classification system can be the path toward a higher-value target.
- Classified and air-gapped by necessity. Large parts of the network legitimately cannot touch the public internet, which rules out most cloud-only threat intelligence platforms before the conversation even starts.
- NATO and allied interoperability. Since NATO's 2016 Warsaw Summit declaration of cyberspace as an operational domain, allied forces have operated under growing expectations to share indicators and coordinate defence — in formats allied systems can actually ingest.
- Procurement that outlives any single threat. Defense acquisition cycles are measured in years, not sprints — which means intelligence has to layer onto programmes of record already in place, not demand a new one.
No single command sees the whole threat
A single service's SOC, however well resourced, only ever sees what has already hit its own networks. OneFirewall was built on the position that a single-vendor firewall — however capable — cannot protect an organisation alone, because it cannot see what a heterogeneous alliance of independent SOCs sees together. For defense and national-security networks specifically, that gap is the whole problem: the indicator that would have told you this was a coordinated campaign, not a random scan, was sitting in another command's logs the entire time.
Comando per le Operazioni in Rete (COR)
Italian Ministry of Defence
A military cyber command, not a case study
COR is the Italian Ministry of Defence's cyber operations command — structured across a C4 Department, a Security and Cyber Defence Department, and a Cyber Operations Department, and built into a credible interlocutor both nationally and within NATO since it was stood up during the early days of the COVID-19 pandemic. It has been part of the OneFirewall Alliance since early in the alliance's history, longer than almost every commercial name elsewhere on this site. We don't publish the specifics of that relationship, for the same reason a military command doesn't publish its own — but its presence in the alliance is, on its own, a different order of validation than a vendor testimonial.
Discretion is the point, not a gap in the story
We won't describe a specific defense engagement, name a unit's internal tooling, or characterise an active threat against any member — not because there's nothing to say, but because that discretion is exactly what a defense buyer should expect from a partner, not just from themselves. What we will say: the mechanics on this page — multi-tenant separation, on-prem and air-gapped deployment, STIX/TAXII-native delivery, 290+ members' worth of pooled telemetry — are the same mechanics already running inside a NATO member's defence establishment today.
Deployment that matches the classification, not the other way round
- On-prem, private cloud, or fully air-gapped. OneFirewall Server is one instance that can run entirely disconnected from the public internet where policy requires it — the deployment model follows your classification level, not a vendor's hosting preference.
- Multi-tenant separation across commands. Each unit, command, or service branch keeps its own logically isolated users, feeds, and configuration — a structural fit for a ministry of defence with multiple branches operating under one overarching security function.
- STIX/TAXII native, NATO-compatible. Intelligence is delivered in STIX 2.1 / TAXII 2.1, the standard already used across NATO and allied information-sharing frameworks — an auditable record for every decision, not a proprietary format someone has to translate by hand.
- Enterprise-grade reliability. A three-node clustered deployment can push availability toward eight nines for environments where a standard commercial SLA isn't the bar you're measured against.
Before this gets anywhere near a classified network
Can this run fully disconnected from the internet?
Yes. OneFirewall Server runs as a single instance that can be deployed entirely air-gapped, with threat feed updates brought in through whatever controlled transfer process your accreditation already requires — the platform doesn't assume permanent outbound connectivity.
Does any telemetry leave our network back to OneFirewall?
Only what your organisation chooses to contribute. The multi-tenant model keeps every organisation's own users, feeds, and configuration logically separated — participation in the shared intelligence pool is a deliberate choice, not a default.
What does accreditation actually involve?
We work within your existing accreditation and assurance process rather than asking you to adopt ours — the WCF Agent integrates with firewalls and infrastructure already in place, so the security case is built around what's already been assessed, not a new black box.
