A ministry's network doesn't get to go down for a rebuild.
The Italian Ministry of Defence's cyber operations command, the Comando per le Operazioni in Rete (COR), has been part of the OneFirewall Alliance since early in its history, longer than most of the commercial names on this page.
Espionage-grade patience meets procurement-grade constraints
- Espionage over disruption. State and ministry networks are a priority target for long-dwell, intelligence-gathering operations rather than smash-and-grab attacks. That kind of activity only stands out against a wide intelligence baseline, not a single agency's own logs.
- Data can't leave the building. Classified and sensitive systems frequently cannot accept cloud-hosted tooling or send telemetry off-site, which rules out most SaaS-only threat-intelligence platforms by default.
- NATO and EU interoperability expectations. Defence and interior ministries increasingly operate under information-sharing expectations set at NATO or EU level, on top of domestic requirements.
- Procurement cycles resist rip-and-replace. Public-sector budgeting makes a single large infrastructure swap hard to justify, so intelligence has to layer onto what's already deployed rather than replace it.
On-prem when the policy says on-prem
OneFirewall Server is one instance that can run on-prem, in a private cloud, or in the public cloud. The multi-tenant architecture, with logical separation between organisations' users, feeds, crime scores, and configurations, stays the same regardless of where it's hosted. For a government body, that means intelligence sharing without a mandate to move data off a controlled network.
Separation of duties across departments and commands
- Multi-tenant separation of duties. Each organisational unit's users, feeds, and configurations stay logically isolated from every other member. That structural separation fits ministries with multiple departments or commands operating under one security function.
- STIX/TAXII native delivery. Intelligence arrives in STIX 2.1 / TAXII 2.1, built to drop into the SIEM and SOC tooling government security teams already standardise on.
- Enterprise-grade reliability. A three-node clustered deployment can push availability toward eight nines for environments where standard 99.99% isn't sufficient.
A defence command and a policy department
Government trust isn't one relationship — it's several different kinds, in different countries, for different reasons.
Comando per le Operazioni in Rete (COR)
The Italian Ministry of Defence's cyber operations command has been part of the OneFirewall Alliance since early in its history — a relationship that predates most of the commercial names elsewhere on this site.
DSIT
DSIT has held the UK Government's national cyber security policy brief since February 2023, having taken it over from DCMS — running programmes from the Cyber Essentials certification scheme to a monthly national cyber security newsletter. DSIT sits inside the OneFirewall alliance network, the same way it's listed among our alliance and technology partners.
Before this goes out to tender
Can this run fully on-prem, or even air-gapped, for a classified network?
Yes. OneFirewall Server is one instance that can run on-prem, in a private cloud, or in the public cloud — the deployment model follows your data-sovereignty policy, not the other way round.
How does this fit NATO or EU interoperability requirements?
Intelligence is delivered natively in STIX 2.1 / TAXII 2.1, the same standard used across NATO and EU information-sharing frameworks, giving you an auditable record for every decision rather than a proprietary format to translate.
Does this require a full platform replacement programme?
No. The WCF Agent integrates with the firewalls and routers already deployed — it's an incremental intelligence layer, not a multi-year procurement to rip out what's already in place.
