How It Started

One server, one question

A client needed their server secured. We ran the usual playbook — hardening, monitoring, blocklists of known-bad IPs. Then came the question that mattered: what about the IPs we personally know are bad, the ones caught trying to break in, but that nobody else has flagged yet? That was the seed of private, first-hand threat intelligence.

We were running multiple servers at the time, each logging attacks in isolation — a security guard who never talks to the guard next door. The obvious next question followed: what if they shared what they knew? What if the whole network acted as one? Coordinating threat data across machines, pooling knowledge, making the network smarter than any single node — that idea became the company.

No product had done this before: bring the Security Operations Centres of separate, independent organisations into a single alliance, sharing what each was seeing in real time. A single vendor's firewall — no matter how well engineered — only ever sees its own customers. It took a genuine alliance of heterogeneous SOCs, each watching a different slice of the internet, to see the whole picture. That's the gap OneFirewall was built to close.

The Name

From "Firewall Trust Alliance" to OneFirewall

The working name was FTA — Firewall Trust Alliance. Solid concept, forgettable name. In one of the late meetings where the concept was being argued over again, someone put it simply: "it's like they're all one firewall." The name stuck, the concept grew into a company, and OneFirewall Alliance was incorporated in England.

What followed was a longer argument, inside the company, about identity: was this simply a CTI vendor competing against much larger marketing budgets? The answer that stuck was that intelligence sitting unused in a report protects nothing. What matters is whether it's actionable — not "here's a list of bad IPs, good luck," but a firewall that has already blocked them, automatically, in real time.

Milestones

From a whiteboard to a global alliance

2018 · London

OneFirewall Alliance incorporated

Founded in England after outgrowing a proof of concept built to solve one client's perimeter security problem.

Early Growth

From CTI feed to enforcement platform

The mission narrowed to one word: actionable. Intelligence was rebuilt around automated enforcement, not static reports.

Scaling the Alliance

Global members and government partners

The network grew to include telecoms, financial institutions, and government bodies — including Telecom Italia, the Italian Ministry of Defence, Leonardo, AlmavivA, and the Cyber Threat Alliance.

Recognition

Accelerator cohorts & industry recognition

Selected for Plexal's Cyber Runway Scale programme and the Barclays Eagle Lab Cyber Bridge cohort; named among Beauhurst's Top 27 funded cybersecurity startups in the UK.

2026

Strategic partnership with BondMesh

Joined forces with BondMesh, creator of the world's first autonomous AI security analyst, connecting alliance-wide threat data directly into autonomous detection-to-remediation workflows.

Key Numbers

Eight years in, the numbers behind the platform

8

Years of platform development

280M

Malicious sources, live

998M

Public actors tracked · ~23% of the internet

26

Plug-ins developed

51

Attack types intercepted and blocked

96

Public and private sources

290+

Organisations in the Alliance

<30s

From report to protection of all members

Where We Are Now

290+ organisations, one collective defence network

Governments, telecoms, financial institutions, and security partners who take collective defence as seriously as we do.

Telecom Italia (TIM) Leonardo AlmavivA Cyber Threat Alliance Terna

Including a long-standing relationship with the Ministry of Defence, Italy.

Join the alliance.

See how collective defence works inside your own environment.

Get Started