Security operations
C'ROC security operations center
Chain Monitor detection across nine public blockchains, Watch Officer validation of every alert, and notification to named contacts on a published clock, 24/7/365.
The Secure practice protects digital asset operations across their lifecycle: contract assurance before deployment, continuous security operations in production, and incident response when an event occurs. It is delivered through two Client Focus solutions, C'ROC and Smart Contract Guard 360, with assessment and response services around them.
Before deployment
Security assessments and contract assurance through Smart Contract Guard 360
In operation
C'ROC security operations, with every alert validated by a Watch Officer
On incident
Pre-agreed playbooks, evidence preserved hop by hop, and post-incident review
Lifecycle
Each stage has an owner and produces evidence, so security is continuous from design to post-incident review rather than a single audit.
Settlement on a public blockchain is final. The interval between an event and a decision determines the outcome.
Context
According to Chainalysis, approximately $3.4 billion was stolen in cryptocurrency-related hacks in 2025 (Chainalysis, 2026 Crypto Crime Report). A stolen key or an exploited contract cannot be reversed after settlement, so controls applied afterwards recover little.
The Secure practice combines the work that prevents loss before deployment with the operations that shorten the interval once a system is live, under one accountable model.
Solutions
The practice is delivered through two named Client Focus solutions, one for systems in production and one for contracts before they ship.
Security operations
Chain Monitor detection across nine public blockchains, Watch Officer validation of every alert, and notification to named contacts on a published clock, 24/7/365.
Contract assurance
Automated contract analysis and continuous compliance monitoring inside the client environment, with reproducible, rule-based verdicts mapped to control frameworks.
Services
Six services cover prevention, detection, response and the evidence that supervisors expect to see.
Detection, analyst validation and notification on a published clock, 24/7/365, through the C'ROC security operations center.
Automated analysis and continuous compliance monitoring of contracts inside the client environment, through Smart Contract Guard 360.
Architecture reviews, penetration tests of web, cloud and integration layers, red-team exercises on signing workflows and tabletop exercises, mapped to the controls that auditors and supervisors test.
Pre-agreed playbooks for contract pause, key rotation and withdrawal freeze, with containment support, evidence capture, counterparty notification and post-incident review.
Tracking of active exploit campaigns, drainer kits and phishing infrastructure targeting the client's brand and signers, shared across the watch floor.
Monitoring records, incident timelines and access logs packaged for examiner and auditor requests under DORA, MiCA and the GENIUS Act.
Operating model
Watch Officer, senior analyst, incident manager and operations lead, each with a defined responsibility and a named individual on duty.
Notification within 10 minutes of detection; client acknowledgment within 15 minutes (targets stated in the client's service agreement).
Where a client or its supervisor requires separation of duties, the teams that build a system and the teams that monitor it operate under independent reporting lines, with separate access and separate change authority.
Boundary
Client Focus does not take custody of client assets and does not hold client signing keys. Key generation, storage and signing remain within the client's or its qualified custodian's environment. Client Focus operates with monitoring and alerting rights and, where contracted, proposes actions that the client's authorized approvers execute.
Engagement
Most clients combine a continuous service with a retainer for response.
C'ROC monitoring and Smart Contract Guard 360 run as continuous services under agreed service levels.
Reserved capacity for incident response, advisory and assessment work, with guaranteed response levels.
Defined scope for security assessments, audits and compliance engagements.
Client Focus operates the public blockchain security operations function for a Tier-1 global bank. Client identity is withheld under confidentiality; references are available under non-disclosure agreement.
Related
Detection categories, the Chain Monitor method, severity framework and escalation from L1 to L4.
Automated contract analysis and continuous compliance monitoring inside the client environment.
Key and custody controls, smart contract security, node hardening and assurance for digital asset operations.
Discuss security assessments, contract assurance, security operations and incident response. Every request is reviewed by a principal of the firm.