290+Alliance Members
166+Firewall, WAF & SIEM Integrations
GDPRCompliance-bounded by design
On-Prem or CloudDeployment flexibility
What a 24-Hour Live Analysis Actually Shows

The traffic your firewall already let through

A risk team doesn't need another dashboard — it needs to know what already got past the controls it has. One recent anonymised Live Analysis, run against a real mixed Check Point and Fortinet estate over a single day:

22,053

Events analysed in 24 hours

72.8%

Permitted by the existing firewall

1,939

Of those, flagged as malicious by alliance intelligence

458

Scored critical — immediate blocking recommended

That's 1,845 distinct addresses with a known history of malicious activity elsewhere in the alliance, sitting inside traffic a well-configured firewall had already called clean — the exact gap a fraud or risk team can't see from inside its own logs alone.

OneFirewall threat actor profile showing a Crime Score of 546, CTI points, reporting members, and the ASN/ownership record for a flagged IP address
The Pattern Only Pooled Data Reveals

A single IP, eight sectors, five countries

A documented case from inside the Alliance: a single malicious IP address was independently reported by members across automotive, logistics, cybersecurity, threat intelligence, financial services, cloud infrastructure, software development, and GenAI security, spanning the Netherlands, UK, Germany, Italy and Serbia.

Seen in isolation

Evaluated individually, each sighting looked like routine background scanning — the kind of noise every SOC deprioritises daily.

Correlated across the alliance

Pooled, the sightings described a single actor working through unrelated targets across five countries. The financial services member had flagged the address days before most of the others got there.

Why This Matters for Financial Services

Fraud rings don't respect a bank's perimeter

Credential-stuffing botnets and account-takeover infrastructure are rotated across many institutions in parallel, specifically to stay below any single fraud team's detection threshold. A lookup against alliance-wide intelligence — not just one institution's own logs — is what turns an isolated login anomaly into a known, scored, already-active threat.

Relationship graph showing a single malicious IP connected to alliance members across eight sectors and five countries, each flagged independently
Alliance Member

Cassa Depositi e Prestiti (CDP)

Cassa Depositi e Prestiti manages a large share of Italy's state investment activity, which makes it precisely the kind of target fraud rings and state-adjacent actors probe first. It draws on the same intelligence pool as the alliance's telecom, defence, energy, and technology members, and feeds its own observations back into it.

Financial infrastructure inside the alliance
CDP PSN Cyber Threat Alliance
How It Fits

Built for regulated, heterogeneous environments

  • DORA-era third-party risk. As EU operational-resilience rules push financial institutions to document control over third-party and supply-chain risk, a blocking decision backed by alliance intelligence is easier to justify to an auditor than one based on a single institution's own guesswork.
  • GDPR-bounded by design. OneFirewall's federated model is built to operate within GDPR, HIPAA, and similar compliance boundaries, using anonymisation and zero-trust principles rather than raw data pooling.
  • Fits around core banking, not instead of it. The WCF Agent pushes enforcement into the firewalls, WAFs, and SIEM/SOAR platforms already in place — no replacement of legacy core-banking-adjacent infrastructure required.
  • On-prem or private cloud available. OneFirewall can run on-prem, in a private cloud, or in the public cloud, with logical separation between organisations' users, feeds, and configurations. That matters for institutions that can't relax their own data-control policy just to get better intelligence.
Questions We Get From Risk & Compliance Teams

Before you talk to a vendor, talk to your own policy

Does customer or transaction data ever leave our perimeter?

No. A Proof of Value runs on a containerized VM inside your own infrastructure, with access credentials scoped to that VM. The only outbound connection is port 443 to pull threat feeds — no transaction data, account data, or customer records are ever transmitted out.

How does this sit alongside our existing fraud and SIEM stack?

It doesn't replace it. The WCF Agent pushes Crime Score-based blocking into the firewalls and WAFs you already run, and intelligence is delivered natively in STIX 2.1 / TAXII 2.1 for direct ingestion into whatever SIEM or fraud platform your team already uses.

What do we actually get at the end of a trial?

Three reports: an installation report documenting setup, a traffic analysis report showing detected threats by type/source/frequency, and an evaluation report on detection accuracy and responsiveness — evidence for a board, not a sales deck.

See what alliance-wide correlation surfaces in your own traffic.

Run a free Proof of Value against your own traffic — nothing leaves your perimeter.

Start a Proof of Value