
By Sotiraki Sima, Chief Information Security Officer, OneFirewall Alliance
When we started OneFirewall, the idea was straightforward: block bad traffic before it hits your network. IPs, domains, URLs, file hashes—if it’s known to be malicious, kill the connection in real time. No waiting for a SOC analyst to review an alert at 3am. No hoping someone notices the C2 callback buried in logs.
We built our own intelligence network from the ground up. Our alliance members—now over 210 organizations—share what they see, and we push vetted indicators to everyone’s perimeter devices within milliseconds. It works. But by 2020, we’d hit a ceiling.
The Problem With Going It Alone
Here’s what we were running into:
There’s only so much you can see from your own network. We had solid coverage in certain sectors and geographies, but blind spots in others. Threat actors weren’t politely limiting themselves to our field of view.
We also needed better context. An IP address by itself tells you almost nothing. Is it a bulletproof hosting provider? A compromised VPS that’ll be gone tomorrow? Part of a known APT campaign? That context matters when you’re making automated blocking decisions at scale.
And then there’s the zero-day problem. By definition, we can’t see threats that haven’t touched our network yet. But somebody else might be seeing them right now.
Enter CTA

We’d been aware of the Cyber Threat Alliance for a while—hard not to be when their membership reads like a who’s who of security vendors. Cisco, Fortinet, Palo Alto, Sophos, Check Point… these aren’t companies that share data lightly.
What caught our attention was their model. CTA isn’t a pay-for-feeds arrangement. It’s reciprocal. You contribute what you see, you get access to what everyone else sees. The quality bar is high because everyone’s reputation is on the line.
We started talking to them in 2020. There was a proper vetting period—they wanted to see that our data was accurate and useful, and frankly we wanted the same assurance about theirs. After several months of testing, we joined as a Contributing Member.
How We’ve Expanded the Integration
We didn’t try to boil the ocean on day one. We started with IPv4 indicators only. Get the plumbing right, validate the data quality, make sure our blocking logic handles the new feed gracefully.
Three years later (around 2023), we expanded to domains, URLs, and file signatures. Same careful approach—integrate, validate, tune.
Earlier this year we added IPv6. Not glamorous work, but necessary. The world’s finally moving to v6 whether we like it or not, and threat actors aren’t waiting around.
What CTA Actually Provides (And What We Provide Back)
Let me be clear about something: OneFirewall is not a threat intelligence company. We’re a prevention system. Our job is to sit inline—or feed your firewalls, routers, IPS boxes, WAFs—and block traffic that shouldn’t be there.
To do that well, we need intel we can trust enough to block on automatically. No human in the loop. That’s a high bar.
CTA gives us volume we couldn’t achieve alone, but more importantly, they give us context. Over 90% of our STIX 2.1 data now comes through CTA. That means we’re not just getting raw indicators—we’re getting the “why.” What campaign is this associated with? What TTPs? What’s the confidence level?
On our end, we push them to see everything we’re seeing that they’re not. That’s the deal, and it works because everyone keeps up their end.
Disclaimer: OneFirewall Alliance does not share member identities, raw intelligence, or logs with CTA or any other external organization. What we contribute to the Cyber Threat Alliance is a processed Crime Score—an aggregated risk value calculated after internal submission and validation. No individual alliance member is ever exposed or identifiable through our CTA participation. Our members’ data stays with us; only the distilled, anonymized output leaves our network.
Six Years In: What’s Changed
The technical integration has obviously matured, but the bigger shift is how we think about CTA organizationally.
They’ve essentially become an extended threat hunting team for us. When something new surfaces in their community, we hear about it. When we spot something weird, we have a room full of experts to bounce it off. That kind of collaborative relationship takes years to build.
By the numbers: about 78% of our high-criticality indicators are now enriched with CTA data. For context and attribution—the stuff that tells you why something is bad—they’re our primary source.
The Honest Truth About Collective Defense
Cyber criminals figured out years ago that collaboration makes them more effective. Ransomware-as-a-service, initial access brokers, shared infrastructure—they’re not operating as isolated individuals anymore.
Meanwhile, most defenders are still going it alone. That’s a losing strategy.
Joining CTA was one of the better decisions we’ve made. Not because it’s a magic bullet—there isn’t one—but because it fundamentally changed what we can see and how fast we can act on it.