One financial institution spotted the pattern days before anyone else did.
Fraud infrastructure and account-takeover tooling gets reused across unrelated financial targets long before any single bank's SOC connects the dots. Inside the OneFirewall Alliance, a financial services member is sometimes the first to see an attacker working its way through completely unrelated industries. The pattern only becomes visible once everyone's observations are pooled.
The traffic your firewall already let through
A risk team doesn't need another dashboard — it needs to know what already got past the controls it has. One recent anonymised Live Analysis, run against a real mixed Check Point and Fortinet estate over a single day:
22,053
Events analysed in 24 hours
72.8%
Permitted by the existing firewall
1,939
Of those, flagged as malicious by alliance intelligence
458
Scored critical — immediate blocking recommended
That's 1,845 distinct addresses with a known history of malicious activity elsewhere in the alliance, sitting inside traffic a well-configured firewall had already called clean — the exact gap a fraud or risk team can't see from inside its own logs alone.
A single IP, eight sectors, five countries
A documented case from inside the Alliance: a single malicious IP address was independently reported by members across automotive, logistics, cybersecurity, threat intelligence, financial services, cloud infrastructure, software development, and GenAI security, spanning the Netherlands, UK, Germany, Italy and Serbia.
Evaluated individually, each sighting looked like routine background scanning — the kind of noise every SOC deprioritises daily.
Pooled, the sightings described a single actor working through unrelated targets across five countries. The financial services member had flagged the address days before most of the others got there.
Fraud rings don't respect a bank's perimeter
Credential-stuffing botnets and account-takeover infrastructure are rotated across many institutions in parallel, specifically to stay below any single fraud team's detection threshold. A lookup against alliance-wide intelligence — not just one institution's own logs — is what turns an isolated login anomaly into a known, scored, already-active threat.
Cassa Depositi e Prestiti (CDP)
Cassa Depositi e Prestiti manages a large share of Italy's state investment activity, which makes it precisely the kind of target fraud rings and state-adjacent actors probe first. It draws on the same intelligence pool as the alliance's telecom, defence, energy, and technology members, and feeds its own observations back into it.
Built for regulated, heterogeneous environments
- DORA-era third-party risk. As EU operational-resilience rules push financial institutions to document control over third-party and supply-chain risk, a blocking decision backed by alliance intelligence is easier to justify to an auditor than one based on a single institution's own guesswork.
- GDPR-bounded by design. OneFirewall's federated model is built to operate within GDPR, HIPAA, and similar compliance boundaries, using anonymisation and zero-trust principles rather than raw data pooling.
- Fits around core banking, not instead of it. The WCF Agent pushes enforcement into the firewalls, WAFs, and SIEM/SOAR platforms already in place — no replacement of legacy core-banking-adjacent infrastructure required.
- On-prem or private cloud available. OneFirewall can run on-prem, in a private cloud, or in the public cloud, with logical separation between organisations' users, feeds, and configurations. That matters for institutions that can't relax their own data-control policy just to get better intelligence.
Before you talk to a vendor, talk to your own policy
Does customer or transaction data ever leave our perimeter?
No. A Proof of Value runs on a containerized VM inside your own infrastructure, with access credentials scoped to that VM. The only outbound connection is port 443 to pull threat feeds — no transaction data, account data, or customer records are ever transmitted out.
How does this sit alongside our existing fraud and SIEM stack?
It doesn't replace it. The WCF Agent pushes Crime Score-based blocking into the firewalls and WAFs you already run, and intelligence is delivered natively in STIX 2.1 / TAXII 2.1 for direct ingestion into whatever SIEM or fraud platform your team already uses.
What do we actually get at the end of a trial?
Three reports: an installation report documenting setup, a traffic analysis report showing detected threats by type/source/frequency, and an evaluation report on detection accuracy and responsiveness — evidence for a board, not a sales deck.
