Skip to content
Client Focus

Secure

The Secure practice protects digital asset operations across their lifecycle: contract assurance before deployment, continuous security operations in production, and incident response when an event occurs. It is delivered through two Client Focus solutions, C'ROC and Smart Contract Guard 360, with assessment and response services around them.

Security assessments and contract assurance through Smart Contract Guard 360

C'ROC security operations, with every alert validated by a Watch Officer

Pre-agreed playbooks, evidence preserved hop by hop, and post-incident review

Security across the lifecycle

Each stage has an owner and produces evidence, so security is continuous from design to post-incident review rather than a single audit.

Secure practice lifecycleFive stages: assess at design, assure contracts before deployment with Smart Contract Guard 360, monitor in production with C'ROC, respond to incidents with pre-agreed playbooks, and review after each incident.DesignAssess

Architecture, keys and integrations reviewed against controls

Pre-deploymentAssure contracts

SCG360 analysis and a rule-based verdict

ProductionMonitor

C'ROC watches on-chain activity 24/7/365

IncidentRespond

Pre-agreed playbooks and evidence capture

AfterReview

Post-incident review and corrective actions

Finality

Settlement on a public blockchain is final. The interval between an event and a decision determines the outcome.

The case for a security practice built for finality

According to Chainalysis, approximately $3.4 billion was stolen in cryptocurrency-related hacks in 2025 (Chainalysis, 2026 Crypto Crime Report). A stolen key or an exploited contract cannot be reversed after settlement, so controls applied afterwards recover little.

The Secure practice combines the work that prevents loss before deployment with the operations that shorten the interval once a system is live, under one accountable model.

Two solutions at the core

The practice is delivered through two named Client Focus solutions, one for systems in production and one for contracts before they ship.

C'ROC security operations center

Chain Monitor detection across nine public blockchains, Watch Officer validation of every alert, and notification to named contacts on a published clock, 24/7/365.

Smart Contract Guard 360 (SCG360)

Automated contract analysis and continuous compliance monitoring inside the client environment, with reproducible, rule-based verdicts mapped to control frameworks.

What the practice delivers

Six services cover prevention, detection, response and the evidence that supervisors expect to see.

Security operations

Detection, analyst validation and notification on a published clock, 24/7/365, through the C'ROC security operations center.

Smart contract assurance

Automated analysis and continuous compliance monitoring of contracts inside the client environment, through Smart Contract Guard 360.

Security assessments

Architecture reviews, penetration tests of web, cloud and integration layers, red-team exercises on signing workflows and tabletop exercises, mapped to the controls that auditors and supervisors test.

Incident response

Pre-agreed playbooks for contract pause, key rotation and withdrawal freeze, with containment support, evidence capture, counterparty notification and post-incident review.

Threat intelligence

Tracking of active exploit campaigns, drainer kits and phishing infrastructure targeting the client's brand and signers, shared across the watch floor.

Regulatory evidence

Monitoring records, incident timelines and access logs packaged for examiner and auditor requests under DORA, MiCA and the GENIUS Act.

How the practice is held accountable

Named accountability from L1 to L4

Watch Officer, senior analyst, incident manager and operations lead, each with a defined responsibility and a named individual on duty.

Published notification clock

Notification within 10 minutes of detection; client acknowledgment within 15 minutes (targets stated in the client's service agreement).

Separable engineering and defense

Where a client or its supervisor requires separation of duties, the teams that build a system and the teams that monitor it operate under independent reporting lines, with separate access and separate change authority.

Custody position

Client Focus does not take custody of client assets and does not hold client signing keys. Key generation, storage and signing remain within the client's or its qualified custodian's environment. Client Focus operates with monitoring and alerting rights and, where contracted, proposes actions that the client's authorized approvers execute.

How Secure is engaged

Most clients combine a continuous service with a retainer for response.

Continuous services

C'ROC monitoring and Smart Contract Guard 360 run as continuous services under agreed service levels.

Annual retainer

Reserved capacity for incident response, advisory and assessment work, with guaranteed response levels.

Fixed-price project

Defined scope for security assessments, audits and compliance engagements.

Client Focus operates the public blockchain security operations function for a Tier-1 global bank. Client identity is withheld under confidentiality; references are available under non-disclosure agreement.

Continue reading

C'ROC security operations center

Detection categories, the Chain Monitor method, severity framework and escalation from L1 to L4.

Smart Contract Guard 360

Automated contract analysis and continuous compliance monitoring inside the client environment.

Cybersecurity

Key and custody controls, smart contract security, node hardening and assurance for digital asset operations.

Secure the full lifecycle.

Discuss security assessments, contract assurance, security operations and incident response. Every request is reviewed by a principal of the firm.