A blind spot at one substation is a blind spot for the whole grid.
Terna runs Italy's national electricity transmission grid, which is precisely the kind of target that rewards a long, patient reconnaissance campaign over a quick smash-and-grab. It's part of the same OneFirewall intelligence pool as the alliance's telecom, finance, defence, and technology members.
Nation-state patience meets distributed infrastructure
- Designated as essential by NIS2. EU energy operators are explicitly in scope for NIS2's essential-entities rules. Mandatory incident reporting and board-level accountability aren't a voluntary best practice here, they're the law.
- IT/OT convergence widens the perimeter. As operational technology increasingly connects to IT networks, the attack surface extends well past what traditional firewall-only tooling was built to watch.
- Long-dwell reconnaissance. Energy-sector intrusions linked to nation-state actors are frequently characterised by extended reconnaissance before any disruptive action. That kind of pattern only stands out against a wide intelligence baseline, not a single operator's own logs.
- Distributed sites, not one perimeter. Substations and distribution sites are numerous and geographically spread, making centralised, consistent monitoring with point products difficult without a shared feed across all of them.
From 99.99% to eight nines when it matters
OneFirewall's standard architecture is built to a 99.99% SLI. For deployments with stricter requirements, an enterprise-grade three-node Kubernetes clustering architecture, with redundant compute, shared storage, and load-balanced access, is available to push availability toward four to eight nines. That's the range critical-infrastructure operators typically need to satisfy regulators and boards.
One feed, consistently applied across every site
- Consolidates distributed sites into one feed. The WCF Agent pushes the same enforcement-ready intelligence into firewalls at every site, substation, distribution centre, or head office, instead of relying on each location to maintain its own threat list.
- On-prem or private cloud for OT-adjacent environments. OneFirewall Server can run on-prem or in a private cloud, keeping intelligence processing in-country or in-network where OT-adjacent policy requires it.
- STIX/TAXII for existing SOC tooling. Intelligence is delivered natively in STIX 2.1 / TAXII 2.1, dropping into SIEM and SOAR platforms energy-sector SOCs already run.
What this does and doesn't touch
Does this reach into our OT/ICS network?
No. OneFirewall operates at the IT-facing perimeter — the firewalls, routers, and WAFs the WCF Agent connects to — not as an OT/ICS protocol-aware tool. It's a complementary intelligence layer in front of IT infrastructure, not a replacement for dedicated OT security controls.
How do dozens of substations report in without becoming one big attack surface?
Each site keeps its own logically separated feed, users, and configuration under the multi-tenant model — only the threat intelligence itself is pooled, consolidated into one consistent feed pushed back out to every site's existing firewall.
What's the actual uptime commitment?
99.99% SLI on the standard architecture. For deployments that need more, a three-node Kubernetes clustering option is available, pushing availability toward four to eight nines.
