99.99%Standard SLI
Up to 8 ninesAvailable for critical deployments
NIS2Essential-entities sector
290+Alliance Members
Why Energy Is a Different Kind of Target

Nation-state patience meets distributed infrastructure

  • Designated as essential by NIS2. EU energy operators are explicitly in scope for NIS2's essential-entities rules. Mandatory incident reporting and board-level accountability aren't a voluntary best practice here, they're the law.
  • IT/OT convergence widens the perimeter. As operational technology increasingly connects to IT networks, the attack surface extends well past what traditional firewall-only tooling was built to watch.
  • Long-dwell reconnaissance. Energy-sector intrusions linked to nation-state actors are frequently characterised by extended reconnaissance before any disruptive action. That kind of pattern only stands out against a wide intelligence baseline, not a single operator's own logs.
  • Distributed sites, not one perimeter. Substations and distribution sites are numerous and geographically spread, making centralised, consistent monitoring with point products difficult without a shared feed across all of them.
Built for Critical-Infrastructure Uptime

From 99.99% to eight nines when it matters

OneFirewall's standard architecture is built to a 99.99% SLI. For deployments with stricter requirements, an enterprise-grade three-node Kubernetes clustering architecture, with redundant compute, shared storage, and load-balanced access, is available to push availability toward four to eight nines. That's the range critical-infrastructure operators typically need to satisfy regulators and boards.

OneFirewall logical architecture diagram
Grid operator inside the alliance
Terna
How It Fits

One feed, consistently applied across every site

  • Consolidates distributed sites into one feed. The WCF Agent pushes the same enforcement-ready intelligence into firewalls at every site, substation, distribution centre, or head office, instead of relying on each location to maintain its own threat list.
  • On-prem or private cloud for OT-adjacent environments. OneFirewall Server can run on-prem or in a private cloud, keeping intelligence processing in-country or in-network where OT-adjacent policy requires it.
  • STIX/TAXII for existing SOC tooling. Intelligence is delivered natively in STIX 2.1 / TAXII 2.1, dropping into SIEM and SOAR platforms energy-sector SOCs already run.
OneFirewall active protection statistic: over 230 high-critical attacks blocked per hour in real time across critical infrastructure environments
Questions an Operations Director Would Ask

What this does and doesn't touch

Does this reach into our OT/ICS network?

No. OneFirewall operates at the IT-facing perimeter — the firewalls, routers, and WAFs the WCF Agent connects to — not as an OT/ICS protocol-aware tool. It's a complementary intelligence layer in front of IT infrastructure, not a replacement for dedicated OT security controls.

How do dozens of substations report in without becoming one big attack surface?

Each site keeps its own logically separated feed, users, and configuration under the multi-tenant model — only the threat intelligence itself is pooled, consolidated into one consistent feed pushed back out to every site's existing firewall.

What's the actual uptime commitment?

99.99% SLI on the standard architecture. For deployments that need more, a three-node Kubernetes clustering option is available, pushing availability toward four to eight nines.

See what alliance-wide intelligence surfaces across your sites.

Run a free Proof of Value against your own network data. Nothing leaves your perimeter.

Start a Proof of Value