Skip to content

Cyber resilience for the unknown

Resilience before the patch.

StormFox is developing Hardpoint — a new security device intended to limit the impact of unknown and unpatched vulnerabilities—helping important systems remain resilient while conventional defences catch up.

Currently engaging a small number of organisations with high-consequence, hard-to-patch systems.

Vulnerability timelineThe exposure interval

A conceptual timeline of a vulnerability. A vulnerability exists, then exploitation becomes possible, then the vulnerability is discovered, then a patch becomes available, and finally the patch is safely deployed. The interval from exploitation becoming possible until the patch is safely deployed is the exposure interval. Hardpoint is intended to act as an additional layer of resilience across that interval.

Conceptual illustration of the exposure interval. Intervals are not to scale and do not represent measured data.

The dangerous interval

Security controls become more effective once a vulnerability is recognised, understood and incorporated into detection, remediation and patching processes. Critical systems can remain exposed during the interval before that happens—and patching may itself take days, weeks or months.

  • 01

    Unknown

    Defenders may have no signature, indicator or published remediation when exploitation first becomes possible.

  • 02

    Unpatched

    Even after disclosure, operational constraints can delay testing and deployment of a patch.

  • 03

    Operationally exposed

    For systems that cannot simply stop, the cost of emergency remediation may rival the risk being addressed.

The question is not only whether an attack can be detected. It is how much of the system remains dependable when existing assumptions fail.

A different layer of resilience

Hardpoint is being designed as an economical additional layer for systems where unknown vulnerabilities and delayed remediation create unacceptable exposure. Its purpose is to reduce the consequences of compromise within a defined threat model, without pretending to replace the rest of the security stack.

  • 01

    Bounded and testable

    Every claim should be tied to an explicit threat model, measurable conditions and known limitations.

  • 02

    Operationally compatible

    Resilience is useful only if it can be introduced without creating unacceptable performance or availability risk.

  • 03

    Complementary

    Hardpoint is intended to work alongside patching, identity controls, segmentation, monitoring and endpoint protection.

  • 04

    Economically deployable

    The architecture is being developed with unit cost and broad deployment in mind.

How Hardpoint fits

Existing security controls

Patching, identity, segmentation, monitoring, endpoint protection

Hardpoint resilience layer

Intended to reduce the consequences of compromise within a defined threat model

Critical system or workload

The capability the organisation must keep dependable

Hardpoint is intended to add resilience to an existing security architecture rather than require customers to abandon established controls.

What Hardpoint is not

Stating the boundaries of a security claim is part of the claim.

  • It is not a replacement for patching.
  • It is not a substitute for identity or access control.
  • It does not claim to prevent every form of compromise.
  • It will not be marketed on an unbounded promise of zero-day protection.

Where the risk is hardest to tolerate

We are initially speaking with organisations for which patching is operationally difficult and the consequences of compromise are unusually high.

  • Critical and operational systems

    Environments where availability, safety or lengthy equipment lifecycles make rapid remediation difficult.

  • High-consequence digital infrastructure

    Systems supporting regulated, sensitive or economically important operations.

  • Platforms and security ecosystems

    Technology providers and integrators exploring an additional resilience capability for customer environments.

These are initial customer hypotheses, not claims of current deployment. Design-partner conversations will determine the first commercial focus.

Evidence before assertion

A claim about resilience against unknown vulnerabilities must be demonstrated under controlled, adversarial and operationally realistic conditions. Hardpoint’s validation process will be designed with prospective users and independent specialists.

What we expect to measure

  • 01

    Behaviour under defined exploit classes

  • 02

    Prevention or containment outcome

  • 03

    Reduction in affected system scope

  • 04

    Availability and fail-safe behaviour

  • 05

    Latency and throughput impact

  • 06

    Deployment and operational workload

  • 07

    Compatibility with existing controls

  • 08

    Repeatability of results

Current stageForming design partnerships and defining representative evaluations.

Help define a credible standard of proof

We are looking for a small number of organisations that operate high-consequence or hard-to-patch systems and are prepared to help define how Hardpoint should be evaluated.

A suitable design partner may provide

  • A named security or technical sponsor.
  • A representative non-production environment or cyber range.
  • Realistic operational requirements and constraints.
  • Input into the threat model and success criteria.
  • Candid commercial and procurement feedback.

Hardpoint will provide

  • A structured, confidential technical discussion.
  • A jointly defined evaluation plan.
  • Early visibility of the product direction.
  • Direct access to the founding team.
  • A documented assessment of outcomes and limitations.
Discuss a design partnership

No confidential system details are required in an initial conversation.

Built from operational cyber insight

StormFox Hardpoint began with an observation formed through experience developing advanced cyber capabilities: systems may require a different form of resilience when defenders cannot rely on prior knowledge of the vulnerability. The company is now turning that observation into a bounded, testable and economically deployable product.

Hardpoint is at the customer-discovery and design-partner stage. It is not a generally available or independently certified product.

For investors and strategic partners

StormFox is currently focused on validating customer demand, deployment requirements and a rigorous technical test programme. Specialist investors and strategic partners can request a non-confidential company briefing.

Request a company briefing

Common questions

Does Hardpoint replace existing cybersecurity controls?

No. Hardpoint is intended to complement established controls, including patching, identity management, segmentation, monitoring and endpoint protection.

Does Hardpoint protect against every zero-day vulnerability?

No responsible security product should make that claim. Hardpoint is being developed and evaluated against a defined threat model, with explicit conditions and limitations.

Is Hardpoint commercially available?

Hardpoint is currently at the customer-validation and design-partner stage. General availability has not yet been announced.

What is involved in becoming a design partner?

Initial participation begins with a non-confidential discussion about the organisation’s systems, operational constraints and validation requirements. Any detailed technical exchange would be governed by an appropriate confidentiality process.

Can investors receive more information?

Yes. Specialist investors and strategic partners can request a non-confidential briefing through the contact form.

Can we discuss the underlying technology?

Technical information is shared selectively and in stages. The initial conversation focuses on the customer problem, intended outcome and appropriate validation conditions.

Start a conversation

Tell us a little about your organisation and what you would like to discuss. Please do not include confidential system details, network information or security findings in this form.

Response
Enquiries are reviewed by the founding team.
Data handling
We store only what you submit here, use it solely to respond, and never share it with advertisers. Privacy notice.

Please keep this non-confidential.