Collective Defence
Newly combined managed-detection and collective-threat-sharing security firm formed from the February 2026 merger of MSSP ITC Secure and network-detection pioneer IronNet, targeting nation-state and critical-infrastructure threats.
Visit Website ↗ + Add to CompareOverview
Collective Defence was formed in February 2026 through the combination of ITC Secure, a UK-based managed security services provider (MSSP) running 24/7 SOC operations since 1995, and IronNet, the network detection and ‘collective defense’ technology pioneer founded in 2014 by former NSA director Gen. Keith Alexander. The combined offering pairs ITC Secure’s managed detection and response (MDR) services with IronNet’s anonymized threat-sharing technology, which lets threat indicators observed in one customer’s environment inform defensive tuning across other participants in near-real time, plus Microsoft Security Copilot integration for AI-assisted SOC analysis.
IronNet’s own path was turbulent: it went public via SPAC in 2021, struggled financially as a standalone public company, and filed for Chapter 11 bankruptcy in October 2023 before its technology and remaining assets were carried forward. Combining that technology with ITC Secure’s established MSSP delivery organization and customer base is, in effect, a rescue-and-relaunch of the collective-defense concept under new commercial packaging, headquartered in Luxembourg with operations in the US, UK, and Singapore, led by CEO Arno Robbertse and Chairman Andre Pienaar.
The core idea — that anonymized cross-customer threat sharing can catch novel attacks faster than any single organization’s telemetry alone — remains a genuinely differentiated concept in a market dominated by single-tenant MDR and SIEM offerings, but the new entity has no independent operating track record yet, and IronNet’s prior bankruptcy is a real caution flag on execution risk that the ITC Secure combination has not yet had time to resolve.
Innovation Matrix Assessment
The February 2026 merger itself is a significant structural move combining MDR delivery with collective-defense technology and Microsoft Security Copilot integration, but there is no post-merger product release history yet to judge ongoing pace.
ITC Secure brings a genuine 24/7 SOC and decades of MSSP delivery experience, and IronNet's anonymized cross-customer threat-sharing technology is functionally distinct from typical single-tenant MDR, but the two have not yet operated together long enough to confirm integration is complete.
This is a brand-new combined entity as of February 2026 with no independent financial or growth track record; IronNet's immediate predecessor history includes a 2023 Chapter 11 bankruptcy, which is a significant negative momentum signal even though ITC Secure itself was an established, ongoing business.
Anonymized, cross-organization threat-sharing at the core of IronNet's original technology is a genuinely different model than single-tenant SIEM/MDR, addressing hybrid state-sponsored threats in a way most MSSPs do not attempt.
No independent, named customer results or third-party evaluation of the combined offering exist yet; IronNet's pre-bankruptcy public financial disclosures showed the business struggling to convert its technology into sustainable revenue, which tempers confidence until the new combination proves otherwise.
Hybrid warfare and state-sponsored threats to critical infrastructure (energy, telecom, financial services) are a growing, well-funded government and enterprise priority, which is squarely the market this combination targets.
Why CISOs Should Care
Offers a combination of established 24/7 managed detection and response delivery with a genuinely different cross-customer threat-sharing model aimed specifically at nation-state and critical-infrastructure threats.
What Makes It Different
Built around anonymized, real-time threat-indicator sharing across customers (IronNet's original 'collective defense' concept) layered onto an established MSSP's SOC delivery, rather than a single-tenant detection stack.
The Matrix Verdict
47/100 — EMERGING / UNRANKED
A conceptually strong combination pairing a proven MSSP with a technically differentiated but financially troubled predecessor technology; promising on paper, but too new post-merger to have earned trust on execution, and IronNet's 2023 bankruptcy is a real risk factor to watch.
Editorial Note: Claims vs. Verified Findings
The February 2026 merger, leadership names, and Luxembourg headquarters are independently reported via multiple wire services (BusinessWire, Yahoo Finance, National Security News). IronNet's 2021 SPAC IPO and 2023 Chapter 11 bankruptcy are independently documented matters of public record. Specific claims about detection performance and customer outcomes for the combined Collective Defence offering are not yet independently verifiable given how recently the entity was formed.
Sources
Alternatives to Collective Defence
Abnormal AI
AI-native behavioral security platform that analyzes sender identity and communication patterns, rather than message content alone, to stop…
Palo Alto Networks Cortex XSIAM
Palo Alto Networks' AI-driven 'autonomous SOC' platform that unifies SIEM, EDR, SOAR, and attack-surface data into a single…
Fenix24
Chattanooga-based ransomware recovery specialist that has restored operations after 500+ real-world incidents, including 30 Fortune 500 companies.
Torq
AI-native hyperautomation platform positioning itself as an 'agentic SOC,' using a multi-agent system to autonomously execute large volumes…
ReliaQuest
ReliaQuest operates GreyMatter, a security operations platform that unifies detection, investigation, and response across a customer's existing security…
Tines
No-code security automation platform letting SOC teams build and share automated workflows ('Stories') without proprietary scripting or vendor…