Cyber resilience for the unknown
Resilience before the patch.
StormFox is developing Hardpoint — a new security device intended to limit the impact of unknown and unpatched vulnerabilities—helping important systems remain resilient while conventional defences catch up.
Currently engaging a small number of organisations with high-consequence, hard-to-patch systems.
A conceptual timeline of a vulnerability. A vulnerability exists, then exploitation becomes possible, then the vulnerability is discovered, then a patch becomes available, and finally the patch is safely deployed. The interval from exploitation becoming possible until the patch is safely deployed is the exposure interval. Hardpoint is intended to act as an additional layer of resilience across that interval.
Conceptual illustration of the exposure interval. Intervals are not to scale and do not represent measured data.
The dangerous interval
Security controls become more effective once a vulnerability is recognised, understood and incorporated into detection, remediation and patching processes. Critical systems can remain exposed during the interval before that happens—and patching may itself take days, weeks or months.
01
Unknown
Defenders may have no signature, indicator or published remediation when exploitation first becomes possible.
02
Unpatched
Even after disclosure, operational constraints can delay testing and deployment of a patch.
03
Operationally exposed
For systems that cannot simply stop, the cost of emergency remediation may rival the risk being addressed.
The question is not only whether an attack can be detected. It is how much of the system remains dependable when existing assumptions fail.
A different layer of resilience
Hardpoint is being designed as an economical additional layer for systems where unknown vulnerabilities and delayed remediation create unacceptable exposure. Its purpose is to reduce the consequences of compromise within a defined threat model, without pretending to replace the rest of the security stack.
01
Bounded and testable
Every claim should be tied to an explicit threat model, measurable conditions and known limitations.
02
Operationally compatible
Resilience is useful only if it can be introduced without creating unacceptable performance or availability risk.
03
Complementary
Hardpoint is intended to work alongside patching, identity controls, segmentation, monitoring and endpoint protection.
04
Economically deployable
The architecture is being developed with unit cost and broad deployment in mind.
How Hardpoint fits
Existing security controls
Patching, identity, segmentation, monitoring, endpoint protection
Hardpoint resilience layer
Intended to reduce the consequences of compromise within a defined threat model
Critical system or workload
The capability the organisation must keep dependable
What Hardpoint is not
Stating the boundaries of a security claim is part of the claim.
- It is not a replacement for patching.
- It is not a substitute for identity or access control.
- It does not claim to prevent every form of compromise.
- It will not be marketed on an unbounded promise of zero-day protection.
Where the risk is hardest to tolerate
We are initially speaking with organisations for which patching is operationally difficult and the consequences of compromise are unusually high.
Critical and operational systems
Environments where availability, safety or lengthy equipment lifecycles make rapid remediation difficult.
High-consequence digital infrastructure
Systems supporting regulated, sensitive or economically important operations.
Platforms and security ecosystems
Technology providers and integrators exploring an additional resilience capability for customer environments.
These are initial customer hypotheses, not claims of current deployment. Design-partner conversations will determine the first commercial focus.
Evidence before assertion
A claim about resilience against unknown vulnerabilities must be demonstrated under controlled, adversarial and operationally realistic conditions. Hardpoint’s validation process will be designed with prospective users and independent specialists.
What we expect to measure
01
Behaviour under defined exploit classes
02
Prevention or containment outcome
03
Reduction in affected system scope
04
Availability and fail-safe behaviour
05
Latency and throughput impact
06
Deployment and operational workload
07
Compatibility with existing controls
08
Repeatability of results
Current stageForming design partnerships and defining representative evaluations.
Help define a credible standard of proof
We are looking for a small number of organisations that operate high-consequence or hard-to-patch systems and are prepared to help define how Hardpoint should be evaluated.
A suitable design partner may provide
- A named security or technical sponsor.
- A representative non-production environment or cyber range.
- Realistic operational requirements and constraints.
- Input into the threat model and success criteria.
- Candid commercial and procurement feedback.
Hardpoint will provide
- A structured, confidential technical discussion.
- A jointly defined evaluation plan.
- Early visibility of the product direction.
- Direct access to the founding team.
- A documented assessment of outcomes and limitations.
No confidential system details are required in an initial conversation.
Built from operational cyber insight
StormFox Hardpoint began with an observation formed through experience developing advanced cyber capabilities: systems may require a different form of resilience when defenders cannot rely on prior knowledge of the vulnerability. The company is now turning that observation into a bounded, testable and economically deployable product.
Hardpoint is at the customer-discovery and design-partner stage. It is not a generally available or independently certified product.
For investors and strategic partners
StormFox is currently focused on validating customer demand, deployment requirements and a rigorous technical test programme. Specialist investors and strategic partners can request a non-confidential company briefing.
Request a company briefingCommon questions
Does Hardpoint replace existing cybersecurity controls?
No. Hardpoint is intended to complement established controls, including patching, identity management, segmentation, monitoring and endpoint protection.
Does Hardpoint protect against every zero-day vulnerability?
No responsible security product should make that claim. Hardpoint is being developed and evaluated against a defined threat model, with explicit conditions and limitations.
Is Hardpoint commercially available?
Hardpoint is currently at the customer-validation and design-partner stage. General availability has not yet been announced.
What is involved in becoming a design partner?
Initial participation begins with a non-confidential discussion about the organisation’s systems, operational constraints and validation requirements. Any detailed technical exchange would be governed by an appropriate confidentiality process.
Can investors receive more information?
Yes. Specialist investors and strategic partners can request a non-confidential briefing through the contact form.
Can we discuss the underlying technology?
Technical information is shared selectively and in stages. The initial conversation focuses on the customer problem, intended outcome and appropriate validation conditions.
Start a conversation
Tell us a little about your organisation and what you would like to discuss. Please do not include confidential system details, network information or security findings in this form.
- Response
- Enquiries are reviewed by the founding team.
- Data handling
- We store only what you submit here, use it solely to respond, and never share it with advertisers. Privacy notice.