Skip to content
Client Focus

Solutions

Secure

C'ROC is the Client Focus blockchain security operations center. It monitors Ethereum, Solana, BNB Chain, Avalanche, Polygon, Arbitrum, Optimism, Base and Sonic (formerly Fantom) continuously, validates every alert with a trained analyst, and notifies named client contacts on a published clock.

The case for continuous security operations

According to Chainalysis, approximately $3.4 billion was stolen in cryptocurrency-related hacks in 2025 (Chainalysis, 2026 Crypto Crime Report). Settlement on a public blockchain is final, so the interval between an event and a decision determines the outcome more than any control applied afterwards.

Notification within 10 minutes of detection; client acknowledgment within 15 minutes (targets stated in the client's service description).

A shift lead briefing analysts in front of a wall screen on the security operations floor

Continuous on-chain security operations for a Tier-1 global bank

Client Focus operates the public blockchain security operations function for a Tier-1 global bank. The engagement covers multi-chain coverage across Layer 1 and Layer 2 networks including Ethereum and Base, continuous transaction monitoring, smart contract runtime security and invariant alerting, custody and treasury wallet surveillance, sanctions screening and Travel Rule integration, bridge and cross-chain monitoring, and regulatory reporting feeds with forensic case support. Alerts are delivered into the bank's existing security stack under banking service levels, 24/7/365.

Client identity is withheld under confidentiality. References are available under non-disclosure agreement.

Watch Officers on the Client Focus operations floor with the C'ROC Threat Intelligence Map on the wall display

What the practice delivers

C'ROC security operations center

Blockchain security operations delivered 24/7. Automated detection raises events from live chain data, and Watch Officers validate each one before notification.

Security assessments

Contract, key management and infrastructure reviews, mapped to the controls that auditors and supervisors test.

Incident response

Containment support, evidence capture, counterparty notification and post-incident review with corrective actions.

What Chain Monitor, the C'ROC detection engine, looks for

Detection runs continuously across the monitored networks and is tuned to client policy.

  • CAT-01

    Exploit-related fund movement

    Outflows matching known exploit signatures and abnormal contract drains.

  • CAT-02

    Laundering and mixer interactions

    Exposure to mixers, chain hopping and structured layering patterns.

  • CAT-03

    Sanctions and high-risk venue exposure

    Counterparties on sanctions lists and deposits to high-risk exchanges.

  • CAT-04

    Rug pulls and scam patterns

    Liquidity removal, privileged mint activity and honeypot behavior.

  • CAT-05

    Suspicious wallet behavior

    Dormant wallet reactivation, approval abuse and anomalous transaction velocity.

How Chain Monitor works

Chain Monitor is the detection layer inside C'ROC. It is operated as a controlled service rather than a set of standing alerts.

Step 1

Data ingestion

Chain data is ingested from full nodes operated by Client Focus and from RPC providers across the monitored networks.

Step 2

Versioned policy

Detection rules are expressed as versioned, change-controlled policy per client, so every change to what is watched has an author, a date and an approver.

Step 3

Behavioral baselines

Baselines are held per wallet, contract and counterparty, so deviation from established activity is measurable rather than assumed.

Step 4

Alert enrichment

Each alert is enriched with address history, counterparty context, sanctions and high-risk venue exposure before an officer reviews it.

Step 5

Validation queue

Enriched alerts enter a Watch Officer validation queue. No alert reaches a client without an officer confirming it.

Step 6

Evidence store

Detection, validation, notification and escalation are recorded in an evidence store with hop-by-hop timestamps and named owners.

Step 7

Client integrations

Integrations are available to client SIEM, ticketing and paging tools, including Splunk, Microsoft Sentinel, ServiceNow and PagerDuty.

Escalation ladderFour escalation steps: L1 Watch Officer, L2 Shift Lead, L3 Operations Manager, L4 Director. Each step has a named owner.L1Watch Officer

Validates, classifies and notifies

L2Shift Lead

Coordinates response across the watch

L3Operations Manager

Owns the incident and client updates

L4Director

Accountable for outcome and review

Detection engine

The engine that classifies each event is operated by Client Focus inside an agreed boundary.

Chain Monitor is powered by a detection engine operated by Client Focus and hosted within Client Focus infrastructure or the client's designated environment. No client data leaves the agreed boundary.

The engine uses open-weight models fine-tuned on labeled exploit patterns, malware corpora, identity attack signatures and MITRE ATT&CK techniques, with alert classification at sub-second latency under production load.

Each detection is paired with a generated standard operating procedure for analyst response, escalation and client notification at the moment the alert is raised. Model lineage is versioned and available for technical review under non-disclosure agreement.

Four layers before a decision

Every event passes through four layers of analysis before an officer determines what it is.

  1. Layer 1

    Blockchain data

    Live transaction data checked against security rules and client-specific operational policy.

  2. Layer 2

    Behavioral analysis

    Baselines of normal activity per wallet, contract and counterparty, so deviation is measurable.

  3. Layer 3

    Risk intelligence

    Known-bad addresses, mixers, sanctioned entities and high-risk exchange exposure.

  4. Layer 4

    Rule-based detection

    Privileged actions such as role grants and configuration flag changes, plus threshold and timing rules.

Custody position

Client Focus does not take custody of client assets and does not hold client signing keys. Key generation, storage and signing remain within the client's or its qualified custodian's environment. Client Focus operates with monitoring and alerting rights and, where contracted, proposes actions that the client's authorized approvers execute.

Three tiers of severity

S1 Critical

Activity that is new, unfamiliar or unexplained, and privileged actions such as role grants or configuration flag changes.

Notification within 10 minutes of detection. Escalation continues up the chain if client acknowledgment does not follow within 15 minutes (targets stated in the client's service description).

S2 High

Known event types occurring outside the established daily pattern, or at unusual volume or timing.

Notified within the published service window and tracked to closure.

S3 Informational

Routine expected operational activity, recognized wallets, and standard issuance and transfer flows.

Logged and summarized in the daily report.

Detection and notification timelineA single line with five points: detection at T0, validation at T plus five minutes, notification at T plus ten minutes, client acknowledgment at T plus fifteen minutes, and escalation from L1 to L4 with each hop timestamped.T0Detection

Automated analysis raises an event

T+5Validation

Watch Officer confirms and assigns severity

T+10Notification

Client contacts notified on the published clock

T+15Acknowledgment

Named client contact confirms receipt

ThenEscalation

L1 to L4, each hop timestamped

Named accountability from L1 to L4

Each level has a defined responsibility and a named individual on duty, recorded with hop-by-hop timestamps.

L1

Watch Officer

Monitors the queue, validates alerts and discards false positives.

L2

Senior analyst

Investigates confirmed indicators, traces flows and opens the incident.

L3

Incident manager

Owns containment, client communication and the response timeline.

L4

Operations lead

Holds named accountability, regulator-facing reporting and post-incident review.

Escalation ladderFour escalation steps: L1 Watch Officer, L2 Shift Lead, L3 Operations Manager, L4 Director. Each step has a named owner.L1Watch Officer

Validates, classifies and notifies

L2Shift Lead

Coordinates response across the watch

L3Operations Manager

Owns the incident and client updates

L4Director

Accountable for outcome and review

Sample severity and response targets

Illustrative values, not contractual
S1Critical: new, unexplained or privileged actionNotification within 10 minutes of detection, escalation continues without acknowledgment within 15 minutes24/7/365
S2High: known event outside the daily patternPublished service window24/7/365
S3Informational: routine expected activityDaily report24/7/365 monitoring
IRIncident response engagement1 hour to incident manager24/7/365

Illustrative values shown. Final severity definitions and response targets are agreed for each engagement.

Continue reading

Digital asset operations glossary

Definitions of the detection, escalation and custody terms used across these pages.

Run

The Digital Asset NOC holds availability to the targets set out in the client's service description under ITIL-based managed operations.

Support

Instructions for existing clients reporting an active incident, with direct phone and email channels.

Put your assets under watch.

Discuss continuous security operations for your on-chain activity with the team that runs the C'ROC. Every request is reviewed by a principal of the firm.