BLACKDICE HALO PRODUCT PORTFOLIO

Cyber defence
at network scale.

Three deployment tiers from lightweight DNS to full carrier-grade intelligence sharing one underlying AI engine. Start where your infrastructure is. Scale when you're ready.

NETWORK INTELLIGENCE LIVE LIVE
DNS exfiltration, IoT device, Subscriber #4471821 HIGH BLOCKED
Behavioural anomaly new device, 3am traffic spike MED MONITORING
C2 callback attempt, ZeroDay variant detected HIGH NEUTRALISED
Remote access app active during banking session HIGH BLOCKED
Standard session device integrity clear LOW CLEAR
THREE DEPLOYMENT TIERS

The same intelligence engine. Three paths to it.

Every tier shares BlackDice IQ the same federated AI engine and upgrades without re-platforming.

Mobile SDK
TIER 01

Security and fraud signals embedded into your application

Real-time behavioural intelligence, session risk scoring, scam detection and device integrity signals, delivered via API directly into your existing mobile app. No infrastructure ownership. No subscriber friction.

Financial services Retail banks Mobile operators Fintech
DNS Protect
TIER 02

Rapid-deploy DNS security with zero hardware dependency

Network-level domain blocking across your full subscriber base including IoT devices powered by the same BlackDice IQ threat intelligence as the full CPE platform. Deployable in days.

ISPs MVNOs Regional telcos
Halo CPE
TIER 03

Full carrier-grade cyber defence embedded at the network edge

A lightweight firmware agent embedded directly into your existing CPE via TR-069/369 or containerised deployment. Full DPI, all-device IoT protection, zero-day behavioural detection. Zero hardware changes.

Tier-1 operators National ISPs CPE vendors
HOW EACH TIER MAPS TO THE THREE PILLARS
Confidence while connectedSDK: subscriber-level fraud prevention builds trust at every interaction, banking, payments, communications
Security of experienceDNS: uninterrupted digital experience through domain-level blocking across all devices with no subscriber friction
Security of economicsCPE: full behavioural intelligence reduces support cost, churn and regulatory exposure while monetising the router estate

How the tiers compare

Capability MOBILE SDK DNS PROTECT HALO CPE
Encrypted traffic visibilityApp layer onlyNoFull DPI
Unmanaged IoT protectionNoDNS blocking onlyAll devices, all traffic
Mobile fraud signalsFull session + deviceNoVia mobile SDK layer
Zero-day behavioural detectionSession-level signalsIQ threat intelligenceFull behavioural AI
Hardware requiredNoneNoneExisting CPE no changes
Deployment timelineDaysDays to weeksWeeks to months
Operator Retina consoleNoYesFull carrier-grade analytics
Subscriber app (Angel)Embedded in host appWhite-label AngelFull white-label Angel
MOBILE SDK FINANCIAL SERVICES

Fraud prevention that works at the session level

For banks, fintechs and mobile operators who need on-device intelligence without owning network infrastructure. Integrate in days. Reduce APP fraud liability now.

DNS PROTECT OPERATORS & ISPs

The fastest path to a live security proposition

No hardware dependency. No CPE procurement cycle. Deploy across your full subscriber base in days and start delivering measurable security value immediately.

HALO CPE TIER-1 OPERATORS

Carrier-grade cyber defence at subscriber scale

Full DPI, all-device IoT protection, zero-day behavioural detection. The complete platform embedded in your existing CPE estate with no hardware changes.

BLACKDICE MOBILE SDK FINANCIAL SERVICES

Real-time fraud signals.
Embedded in
your application.

The BlackDice Mobile SDK brings behavioural intelligence directly into your app. Session risk scoring, device integrity signals and scam detection, delivered in real time, with no infrastructure investment and no subscriber friction.

REAL-TIME SIGNAL FEED LIVE SCORING
Remote access app detected during banking session HIGH BLOCKED
Incoming call known scam number pattern HIGH FLAGGED
Device integrity no anomalies detected LOW CLEAR
Network switch: Wi-Fi → cellular (rogue AP adjacent) MED MONITORING
BUILT FOR
Retail banks Digital-first banks & fintech Mobile operators with FS exposure Insurance providers Payment platforms
THREE PROBLEMS IT SOLVES TODAY

Fraud has evolved beyond what authentication alone can detect.

The BlackDice SDK adds a behavioural intelligence layer that sees what authentication cannot what is happening on and around the device at the moment of risk.

USE CASE 01

Authorised push payment fraud

When a fraudster persuades a customer to initiate a payment themselves, authentication passes without friction. BlackDice detects the behavioural signals that precede APP fraud a scam call in progress, a remote access app active, an unusual payment sequence and surfaces a risk score before the transaction is confirmed.

Scam call detectionSession contextRemote access signals
USE CASE 02

Account takeover and credential compromise

Account takeover often begins with a compromised device. BlackDice identifies device integrity anomalies before the login attempt reaches your authentication layer enabling step-up challenges or session termination before compromise occurs.

Device integrityRooted device detectionMalware signals
USE CASE 03

Scam call interception and SMS phishing

The SDK identifies known scam number patterns, real-time call activity, and suspicious SMS behaviour enabling banks and operators to alert customers or suppress fraudulent interactions before they escalate.

Call risk scoringSMS phishingSocial engineering
FOUR SIGNAL DIMENSIONS

What the SDK reads and why correlation matters.

Each signal may appear benign in isolation. Together, they form the high-confidence risk picture that single-layer tools cannot produce.

A remote access application active during a banking session individually unremarkable. Combined with a scam call in progress and an unusual payment sequence, they indicate a probable social engineering attack. BlackDice surfaces this composite risk score in real time, enabling your app to challenge or block before funds move.

01

Application behavioural signals

App usage patterns, session context and interaction behaviours. Detects anomalous co-occurrence remote access tools or screen recorders running simultaneously with banking sessions.

02

Fraud and scam indicators

Real-time risk scoring for incoming communications. Identifies known scam call patterns, phishing SMS and social engineering signatures flagged before the subscriber acts.

03

Device integrity signals

Detection of jailbroken or rooted devices, anomalous system behaviour, unauthorised accessibility service usage and indicators of device compromise surfaced at session initiation.

04

Network context signals

Wi-Fi vs. cellular switching, rogue access point proximity, network-level threat exposure and connectivity anomalies that indicate risk without requiring network infrastructure access.

REGULATORY ALIGNMENT

The compliance landscape has shifted. The SDK positions you ahead of it.

UK FRAUD STRATEGY 2026 2029

Telecoms and FS as critical control points

The UK Fraud Strategy 2026 2029 names telecoms operators and financial institutions as critical control points in the national fraud response for the first time. The BlackDice SDK provides the auditable, real-time fraud signal data to demonstrate compliance.

PSD2 / STRONG CUSTOMER AUTHENTICATION

Behavioural intelligence as a SCA factor

PSD2 SCA requirements demand risk-based authentication. The SDK provides a real-time behavioural risk signal that informs dynamic authentication decisions reducing friction for low-risk sessions while increasing scrutiny where signals indicate elevated risk.

FCA CONSUMER DUTY

Demonstrable action on fraud vulnerability

Consumer Duty requires firms to demonstrate they are actively protecting vulnerable customers from foreseeable harm. The SDK provides the evidential layer: logged risk signals, intervention triggers and outcome data that supports FCA reporting.

DEPLOYMENT IN DAYS, NOT MONTHS

No infrastructure ownership required.

The SDK integrates into your existing mobile application. It does not require network access agreements or operator partnerships to deliver value from day one.

01

SDK integration

Android and iOS packages delivered via standard package management. Integration into your existing application in days via documented APIs.

02

Signal configuration

Configure which signal categories to activate fraud indicators, device integrity, session risk, network context based on your risk appetite and use case.

03

Risk score integration

Real-time risk scores delivered via API. Integrate with your existing fraud decisioning engine, step-up authentication or transaction monitoring system.

04

Go live

No subscriber-facing changes required. Protection is active from the moment the updated app reaches your users.

TECHNICAL SPECIFICATIONS
Android, iOS
SDK + REST API
Real-time, <50ms latency
Operator environment no third-party cloud
Anonymised signals, no PII transmitted
Days to integration, weeks to production
NLB Bank (Slovenia) · BSNL Mobile (India)

APP fraud is not a technology problem. It is an intelligence gap.

Most fraud prevention tools authenticate the customer. The BlackDice SDK understands the context surrounding the customer and that is where fraud actually begins.

BLACKDICE HALO CPE CARRIER-GRADE DEPLOYMENT

Industrial-grade
cyber defence.
Zero hardware changes.

BlackDice Halo embeds directly into your existing CPE estate via firmware, TR-069/369 or containerised deployment. Full DPI, all-device IoT protection and zero-day behavioural detection at subscriber scale, with no latency impact and no user friction.

5
DATA LAYERS VISIBLE
SIMULTANEOUSLY
<2ms
EDGE ENFORCEMENT
LATENCY
0
HARDWARE CHANGES
REQUIRED
100%
IoT DEVICE COVERAGE
NO CLIENT SOFTWARE
PLATFORM ARCHITECTURE

How the platform is built.

BlackDice Halo operates as a layered intelligence architecture. Each layer adds a dimension of visibility and control together they create a detection capability that no single-layer approach can replicate.

EDGE

Edge agent embedded in CPE firmware

A lightweight software agent deployed directly into the router via TR-069/369, firmware SDK or containerised environment. Operates inline at the packet inspection layer, enforcing protection locally even when cloud connectivity is interrupted. Observes all traffic from all devices from the moment they connect.

TR-069 / 369Firmware SDKContainerisedHardware-agnosticLocal enforcement
INTELLIGENCE

BlackDice IQ™ federated AI engine

Aggregates anonymised telemetry from across all deployments, applies behavioural analysis via federated machine learning, and generates risk assessments and policy decisions. Continuously learns without centralising raw subscriber data. Detects zero-day threats by identifying deviation from established behavioural baselines not by waiting for signature database updates.

Federated learningZero-day detectionBehavioural baselinesNo raw data centralisation
OPERATOR

BlackDice Retina™ carrier-grade operator console

Translates raw network telemetry into actionable business intelligence. Real-time threat visibility across routers and devices, network and security telemetry linked to QoE and churn indicators, actionable insights for segmentation, monetisation and policy control. Built at operator scale not adapted from enterprise tools.

Real-time threat visibilityQoE linkageChurn indicatorsPolicy control
SUBSCRIBER

BlackDice Angel™ subscriber-facing application

A white-labelled consumer application giving families and businesses intuitive control over their digital security. Clear security scores, plain-language explanations of threats blocked, one-tap remediation and family controls. Turns security from an invisible service into something subscribers can see, value and stay for.

White-labelSecurity scoresOne-tap remediationFamily controls
FIVE DATA LAYERS SIMULTANEOUSLY

The only platform with visibility across all five layers at deployment.

This is not an architectural aspiration it is the production reality of every CPE deployment.

LAYER 01

DNS query streams

Every domain resolution request from every device including IoT devices, smart TVs and gaming consoles with no user-facing interface. Intent signals at source.

Visible to DNS-only solutions, but this is where their visibility ends.

LAYER 02

Deep packet inspection metadata

Protocol-level traffic classification including encrypted service identification, without decrypting payload content. Identifies application behaviour patterns completely invisible to DNS-only solutions.

Not visible to DNS-only competitors. This is the first differentiating layer.

LAYER 03

Device fingerprinting

Identification and classification of every connected device using behavioural signatures rather than MAC addresses. Type, manufacturer, firmware version and anomalous behaviour without any client-side software.

Covers unmanaged IoT the fastest growing threat surface with zero existing visibility.

LAYER 04

Traffic flow analysis

Volumetric and temporal patterns across the entire home network. Detects data exfiltration, command-and-control communication and lateral movement between devices.

Enables detection of botnet activity, C2 callbacks and slow-burn exfiltration.

LAYER 05

Behavioural session correlation

The multi-layer intelligence that transforms raw data into actionable insight. A DNS query alone is benign. Combined with unusual traffic volume at 3am from a new device, it becomes a high-confidence threat signal.

This is the layer that detects zero-day and polymorphic threats other platforms miss.

ARCHITECTURE

Why this position is defensible

The agent operates inside operator-managed infrastructure at firmware level. This requires a direct commercial relationship with the telecom operator and cannot be replicated by over-the-top applications. There is no self-serve path to this data position.

Protected by granted patents: EP3231153B1 · GB2533101 · AU2015359182

WHAT THIS MEANS VERSUS DNS-ONLY

DNS filtering is the entry point. Not the destination.

DNS-based solutions block known threats. BlackDice Halo detects unknown ones. That distinction defines the difference between reactive and proactive security at operator scale.

Encrypted traffic seen, not blockedDPI metadata classification identifies application behaviour in encrypted streams without decrypting content.

Unmanaged IoT fully coveredEvery device joining the network is visible from the moment of connection. No client software required on any device.

Zero-day threats detected behaviourallyBlackDice IQ predicts malicious behaviour by detecting deviations from established baselines not by checking a signature database.

Local enforcement no cloud dependencyProtection remains active even when cloud connectivity is interrupted. Security does not degrade during outages.

CAPABILITY COMPARISON HALO CPE VS DNS-ONLY
BD

Encrypted traffic visible via DPI metadata, behavioural patterns identified without payload decryption

DNS

Encrypted traffic not visible DNS sees only the domain query, not what the session contains or does

BD

Zero-day detection via behavioural anomaly threats identified before signatures exist

DNS

Known domain blocking only reacts after a threat has been catalogued and added to the blocklist

BD

All unmanaged IoT devices covered no client software required on any device

DNS

IoT covered via DNS only device-level behaviour, compromise and lateral movement not visible

BD

Local enforcement protection active independent of cloud connectivity

DNS

Cloud-dependent resolution latency and uptime affect enforcement capability

LIVE AND IN DEPLOYMENT

In production at scale. Today.

🇮🇳

BlueCloud / BSNL

INDIA FIXED WIRELESS ACCESS
5M
Addressable subscribers, 15 Indian states

Integration into BSNL 5G Fixed Wireless Access rollout. Multi-year agreement covering a potential population exceeding 500 million. Acceptance certificate signed February 2026.

ACCEPTED SCALING
🇮🇩

CBN Indonesia

INDONESIA ZTE ROUTER INTEGRATION
450K
Subscribers, growing 12,000/month

Direct integration into ZTE routers. Year 1 positioned as value-added security service. Full tariff rollout in Year 2. 90%+ pipeline probability.

CONTRACTING Q2 2026
🇹🇷

Turkcell

TURKEY TP-LINK ROUTER DEPLOYMENT
3.3M
Fixed broadband subscribers

Deployment across Turkcell's fixed broadband estate via TP-Link routers. Pilot commencing May 2026, linked to 5G network rollout progression.

PILOT MAY 2026

The router is not just CPE. It is your most under-leveraged strategic asset.

Every router in your estate has the potential to be an intelligent security edge generating new revenue, reducing support costs and protecting your subscriber base from threats that DNS-only tools cannot see.

BLACKDICE FOR TELECOMS OPERATORS

Trusted connectivity
is the new
competitive edge.

Speed and price are table stakes. The operators who lead commercially over the next five years will be those who can deliver something more valuable: a trusted digital environment for every subscriber. BlackDice makes that possible embedded in your existing infrastructure, at network scale, with no hardware changes.

NETWORK INTELLIGENCE OPERATOR VIEW LIVE
DNS exfiltration, IoT device, Subscriber #4471821 HIGH BLOCKED
Behavioural anomaly new device, 3am traffic spike MED MONITORING
C2 callback attempt ZeroDay variant HIGH NEUTRALISED
Encrypted scam call known fraud pattern match HIGH ALERTING

"The UK Fraud Strategy 2026 2029, the EU's NIS2 Directive, and Singapore's expanded Cybersecurity Act obligations all point in the same direction: operators are now accountable for the quality of the digital environment they create not just the speed of the connection they provide."

BLACKDICE MAY 2026 →
THREE OUTCOMES

The three things that determine whether your subscribers trust you or merely use you.

These are not features. They are the three things that determine whether a telecoms operator is genuinely trusted by its subscribers, or merely tolerated until a better offer comes along.

SUBSCRIBER OUTCOME

Confidence while connected

THE EMOTIONAL ANCHOR

Confidence is not the absence of threats threats are constant and growing. It is the knowledge that your network is detecting and managing them continuously, without requiring anything from the subscriber. No app to install. No settings to configure. No decision to make.

When confidence exists, subscribers stay, upgrade, and recommend. Safe banking. Protected families. SME continuity.

Reduced churn from security-related dissatisfaction
Higher NPS and subscriber satisfaction scores
Premium security tier upsell potential
Brand differentiation in a commoditised market
OPERATIONAL CAPABILITY

Security of experience

TECHNICAL CREDIBILITY

The digital experience your subscribers rely on banking, healthcare, remote work, communication must remain uninterrupted regardless of the threats targeting it at any moment. A single security incident that disrupts a subscriber's digital experience costs more in churn and support than the entire annual security budget for most operators.

Reduced incident fallout and fewer escalations
Improved network resilience and QoE linkage
Full unmanaged IoT device coverage
NIS2 and Cyber Resilience Act alignment
COMMERCIAL IMPACT

Security of economics

THE COMMERCIAL CONTROL LAYER

The broadband router is already deployed capital. The question is whether it remains a pass-through device, or becomes an intelligent edge control layer that protects margin. Every avoided compromise is one less call, one less complaint, one less churn event. That is measurable OPEX reduction.

Fewer support calls and truck rolls
Reduced average handling time
Premium security tier monetisation
Fraud and reputational risk reduction
WHY THE MARKET HAS REACHED THIS INFLECTION POINT

Speed and price are table stakes.
Trust is the new battleground.

Speed and price have become table stakes. Coverage is assumed. The competitive battle has shifted to a different question: how safe is the digital environment you deliver to your subscribers?

"The operators who lead commercially over the next five years will be those who can deliver something more valuable than fast, cheap connectivity: a trusted digital environment for every subscriber."

Ransomware attacks on telecoms operators since 2022

Operators are no longer passive victims they are direct targets of increasingly sophisticated attacks on critical infrastructure.

2%

Maximum NIS2 fine as a share of global turnover

EU NIS2 introduces board-level accountability and material financial penalties for non-compliance. Inaction is no longer a neutral position.

1st

Year telecoms named as critical fraud control points

The UK Fraud Strategy 2026 2029 names telecoms operators as critical control points in the national fraud response for the first time.

THE PLATFORM BEHIND ALL THREE OUTCOMES

Three proprietary components, operating as one unified system.

BlackDice Halo integrates into existing routers via SDK, TR-069/369 or containerised deployment. No hardware changes required.

BLACKDICE IQ™

Federated AI engine

A self-learning AI engine using federated machine learning to analyse device behaviour and neutralise zero-day threats in real time. Predicts malicious behaviour by detecting deviations from established behavioural baselines not by waiting for signature database updates.

Federated learningZero-day detectionBehavioural AI
BLACKDICE RETINA™

Operator intelligence console

Carrier-grade analytics translating raw network telemetry into actionable business intelligence. Real-time threat visibility, telemetry linked to QoE and churn indicators, policy control. Built for operator scale not adapted from enterprise tools.

Real-time visibilityQoE linkageChurn indicators
BLACKDICE ANGEL™

Subscriber application

A white-labelled consumer application giving families and businesses intuitive control over their digital security. Turns security from an invisible service into something subscribers can see, value, and stay for. Strengthens the operator-subscriber relationship at every interaction.

White-labelSecurity scoresFamily controls
THE REGULATORY LANDSCAPE HAS CHANGED

Inaction is no longer a neutral position.

Operators are now accountable for whether their networks are fast and whether their subscribers' digital environments are safe. These are current obligations, not future ones.

EU NIS2 DIRECTIVE

Board-level accountability and material penalties

NIS2 expanded cybersecurity obligations for digital infrastructure and telecom operators introducing stronger enforcement powers, board-level accountability, and fines of up to 2% of global turnover for non-compliance.

UK FRAUD STRATEGY 2026 2029

Telecoms as critical fraud control points

For the first time, the UK Fraud Strategy names telecoms operators as critical control points in the national fraud response. Demonstrable proactive controls are now expected and the absence of them is becoming a regulatory and reputational liability.

EU CYBERSECURITY ACT

Router security is now a national security issue

US regulators enacted sweeping restrictions on foreign-manufactured consumer routers in March 2026. The EU Cybersecurity Act mandates infrastructure security refresh. Router security has been elevated from an IT concern to a national security priority.

START WHERE YOUR INFRASTRUCTURE IS

Scale when you're ready. No re-platforming required.

All three deployment tiers share the same underlying intelligence engine and upgrade without re-platforming.

DNS Protect
FASTEST TO DEPLOY

Network-level DNS security deployable in days, zero hardware dependency

Blocks malicious domains, phishing infrastructure and scam traffic across the full subscriber base. No router changes. No CPE dependency. Powered by the same BlackDice IQ threat intelligence as the full platform. The fastest path to a live security proposition.

Mobile SDK
FOR MOBILE OPERATORS

Mobile behavioural intelligence fraud signals and scam detection in your app

Real-time mobile behavioural intelligence, session risk scoring, scam call and SMS detection, device integrity signals. Integrates into your existing subscriber-facing application in days. Particularly valuable for mobile operators with exposure to scam call and SMS phishing volumes.

Halo CPE
FULL PLATFORM

Industrial-grade carrier cyber defence embedded at the network edge, zero hardware changes

The complete BlackDice Halo platform embedded directly into your existing CPE estate. Full DPI, all-device IoT protection, zero-day behavioural detection and carrier-grade operator intelligence via BlackDice Retina. Protects all traffic from all devices, including encrypted streams and unmanaged IoT.

Security is no longer a feature. It is an economic control layer.

Talk to BlackDice to understand how the three outcomes confidence while connected, security of experience, and security of economics translate to your network, your subscriber base, and your commercial roadmap.

BLACKDICE FOR FINANCIAL SERVICES

Fraud prevention starts
before the
transaction begins.

Most fraud prevention tools authenticate the customer. The BlackDice Mobile SDK understands the context surrounding the customer and that is where fraud actually begins. Real-time behavioural intelligence, session risk scoring and scam detection, embedded directly into your existing application.

SESSION RISK INTELLIGENCE LIVE SCORING
Remote access app active during banking session high-risk co-occurrence HIGH BLOCKED
Incoming call known scam pattern, subscriber on banking app HIGH FLAGGED
Device integrity anomaly accessibility service active, not user-authorised HIGH CHALLENGE
Device clear standard session, no anomalous signals LOW CLEAR
BUILT FOR
Retail banks Digital-first banks & fintech Building societies Payment platforms Insurance providers Mobile operators with FS exposure
THE INTELLIGENCE GAP

Authentication passes.
The fraud still happens.

Authorised push payment fraud, social engineering and account takeover have one thing in common: they exploit the gap between a technically successful authentication and a genuinely safe transaction. The customer is real. The credentials are correct. The fraud happens anyway.

The signal that would have stopped the fraud was there a scam call in progress, a remote access app active, a compromised device but no tool was looking for it. BlackDice closes that gap by reading the context surrounding the session.

"APP fraud is not a technology problem. It is an intelligence gap. Most tools authenticate the customer. BlackDice understands what is happening around the customer at the moment of risk."
£bn

APP fraud costs the UK economy annually

Authorised push payment fraud has overtaken card fraud as the primary financial crime vector. The PSR reimbursement mandate makes this directly material to financial institution P&L.

76%

Of APP fraud involves a scam call or social engineering contact

The perpetrator is typically in voice or SMS contact with the victim at the moment the fraudulent payment is authorised. That signal is detectable without the right tooling, it is invisible.

85%

Of account takeover begins with device compromise

Jailbroken devices, accessibility service abuse and credential-harvesting malware create the conditions for account takeover before the first login attempt.

100%

Reimbursement obligation under PSR mandate

Financial institutions are now required to reimburse APP fraud victims in most cases. The cost of a missed signal is now a direct liability.

THREE PROBLEMS THE SDK SOLVES TODAY

Fraud patterns have evolved beyond what authentication layers alone can detect.

PROBLEM 01

Authorised push payment and social engineering fraud

When a fraudster persuades a customer to initiate a payment themselves, traditional authentication passes without friction the customer is real, the credentials are correct. BlackDice detects the behavioural context that precedes APP fraud before the transaction is confirmed.

Scam call detectionSession contextRemote access signals
PROBLEM 02

Account takeover and credential compromise

Account takeover often begins with a compromised device. BlackDice identifies device integrity anomalies before the login attempt reaches your authentication layer enabling step-up challenges or session termination before compromise occurs, not retrospective investigation after it already has.

Device integrityRooted device detectionAccessibility service abuse
PROBLEM 03

Scam call, SMS phishing and social engineering at scale

Scam calls and phishing SMS remain the primary first contact in social engineering attacks on banking customers. The SDK identifies known scam number patterns, real-time call activity correlated with active banking sessions, and suspicious SMS behaviour.

Call risk scoringSMS phishing detectionPattern matching
REGULATORY ALIGNMENT

The compliance landscape has shifted.
The SDK positions you ahead of it.

UK FRAUD STRATEGY 2026 2029

Telecoms and FS as critical control points

For the first time, the UK Fraud Strategy names financial institutions and telecoms operators as critical control points in the national fraud response. The SDK provides the auditable, real-time fraud signal data to demonstrate compliance.

Proactive
compliance posture from day one
PSD2 / STRONG CUSTOMER AUTHENTICATION

Behavioural intelligence as a SCA factor

PSD2 SCA requirements demand risk-based authentication. The BlackDice SDK provides a real-time behavioural risk signal that informs dynamic authentication decisions reducing friction for low-risk sessions while increasing scrutiny where signals indicate elevated risk.

↓ Friction
for low-risk sessions, without compromising security
FCA CONSUMER DUTY

Demonstrable action on fraud vulnerability

Consumer Duty requires firms to demonstrate they are actively protecting vulnerable customers from foreseeable harm including fraud. The BlackDice SDK provides the evidential layer: logged risk signals, intervention triggers and outcome data that supports regulatory examination.

Auditable
evidence trail for FCA reporting

APP fraud is not a technology problem. It is an intelligence gap.

Most fraud prevention tools authenticate the customer. The BlackDice SDK understands the context surrounding the customer and that is where fraud actually begins. Talk to our financial services team to understand how the SDK maps to your specific risk environment.

WHY BLACKDICE?

A world where being
connected means
being protected.

We believe everyone deserves a safe, trusted digital environment. BlackDice was built to make that a reality embedded in the networks people already rely on, protecting them automatically, at scale.

25+
CONNECTED DEVICES
PER HOUSEHOLD
82%
PARENTS WILLING TO
PAY FOR PROTECTION
45%
CYBERATTACKS
TARGET SMBs
$2T
TOTAL MARKET
OPPORTUNITY
OUR VISION

The internet has become the foundation of daily life. Security should be too.

The internet has become the foundation of daily life for families, businesses, healthcare, and communities. Yet the infrastructure that delivers connectivity has never been built with security at its core.

BlackDice changes that. We embed intelligence and protection directly into the network layer, so every subscriber is defended from the moment they connect without downloading an app, configuring settings, or thinking about it at all.

"Telecoms operators sit at the point of presence for billions of people. BlackDice gives them the tools to turn that position into protection."
PILLAR 01

Confidence while connected

Every subscriber feels safe, whatever they do online. Threats are neutralised before they cause harm, without any disruption to the experience.

PILLAR 02

Security of experience

Banking, remote work, healthcare all protected from disruption caused by threats or fraud. The digital services subscribers rely on remain uninterrupted.

PILLAR 03

Security of economics

Financial harm from cybercrime is prevented at the network level. Scams, fraud, ransomware stopped before they reach the subscriber's bank account.

WHO WE WORK WITH

Built for the organisations that connect the world.

BlackDice works with telecoms operators, managed service providers, and hardware vendors who want to deliver security as a native capability not an add-on.

TELECOMS OPERATORS

Fixed and mobile operators

Deploying BlackDice Halo within their infrastructure to protect millions of subscribers at scale, with zero hardware changes and full carrier-grade analytics.

MANAGED SERVICE PROVIDERS

MSPs and connectivity resellers

Embedding BlackDice into managed connectivity services for business subscribers, adding a security layer without rebuilding infrastructure.

HARDWARE VENDORS

CPE and router manufacturers

Integrating the BlackDice edge agent at device level, enabling security to ship as a standard feature in every router that leaves the factory.

Ready to see BlackDice Halo in action?

Talk to our team about how BlackDice deploys within your infrastructure to protect your subscribers from day one.

NEWSROOM

The latest news, announcements and insights from BlackDice.

NEWS 28 Apr 2026

BlackDice partners with leading APAC telecoms operator to deploy Halo platform

Strategic partnership extends BlackDice's footprint across South-east Asia, protecting millions of additional subscribers at network edge.

Read more →
INSIGHTS 14 Apr 2026

The regulatory moment: why NIS2 and the UK Fraud Strategy are reshaping telecoms obligations

European and UK regulation is moving operators from passive connectivity providers to active participants in digital safety. Here's what that means in practice.

Read more →
PRESS 2 Apr 2026

BlackDice named in Gartner Cool Vendor report for network security

Recognition highlights BlackDice's approach to behavioural intelligence and telco-native deployment as differentiated in a crowded market.

Read more →
INSIGHTS 18 Mar 2026

Behavioural intelligence: moving telecoms security from reactive to predictive

Static signatures and known threat lists are no longer sufficient. We explore why the future of network security is behavioural, not binary.

Read more →
EVENTS 5 Mar 2026

BlackDice at MWC Barcelona 2026: key conversations from the show floor

Our team shares what operators are telling us about their security priorities, and how the conversation has shifted since 2025.

Read more →
NEWS 12 Feb 2026

BlackDice closes strategic funding round to accelerate global operator expansion

New capital will fund expansion across APAC, MENA and Latin America, supporting operators navigating new cybersecurity regulations.

Read more →
View all articles on blackdice.ai →
INVESTOR HUB

AI-powered cybersecurity
for telecoms and their
subscribers.

BlackDice is addressing a $2 trillion market opportunity (McKinsey) with 90% of it still untapped. We give telecoms operators the infrastructure to deliver security as a native service, generating new recurring revenue at scale.

$2T
TOTAL MARKET
OPPORTUNITY
90%
UNTAPPED NETWORK
LAYER OPPORTUNITY
82%
WILLINGNESS TO
PAY FOR SECURITY
45%
CYBERATTACKS
TARGET SMBs
MARKET OPPORTUNITY

A $2 trillion market. 90% untapped.

The global cybersecurity market is enormous, but the network-layer, telecoms-native segment remains structurally underserved. Most security solutions are sold to enterprises not embedded in the infrastructure that connects consumers and SMBs.

BlackDice targets this gap: embedding security within operator infrastructure, creating a defensible recurring revenue model that scales with subscriber growth not deal-by-deal enterprise sales.

3

Proprietary platform components

BlackDice IQ (AI engine), Retina (operator console) and Angel (subscriber app) each defensible independently, exponentially stronger together.

3

Live operator deployments

BSNL India, CBN Indonesia and Turkcell Turkey with pipeline extending across APAC, MENA and Latin America.

3

Granted patents

EP3231153B1, GB2533101 and AU2015359182 protecting the core architectural position that competitors cannot replicate without a direct operator relationship.

THREE INTEGRATED COMPONENTS
ENGINE

BlackDice IQ

The AI-powered intelligence layer. Ingests signals from network, device, and behavioural sources. Continuously learning. Generates risk scores and threat intelligence that drives enforcement decisions in real time.

OPERATOR

BlackDice Retina

Full network visibility and control for operators. Real-time threat intelligence, subscriber analytics, and policy management from a single interface.

CONSUMER

BlackDice Angel

On-device telemetry, family protection controls, and real-time security awareness delivered as a white-label experience that operators brand as their own.

GROWTH MARKETS

Deploying where subscriber growth is fastest.

BlackDice is scaling into the markets with the fastest-growing subscriber bases, strongest regulatory tailwinds, and greatest unmet demand for network-level security.

🌏

Asia Pacific

Fastest growing 5G subscriber base globally, with emerging regulatory frameworks creating operator demand.

🌍

Middle East and Africa

Rapid mobile-first infrastructure build-out with governments driving digital trust mandates.

🌎

Latin America

Operators scaling connectivity as subscriber base expands, with significant unmet demand for security services.

"BlackDice is building the security infrastructure layer that telecoms operators have needed for a decade. The combination of edge enforcement, behavioural intelligence, and telco-native deployment is genuinely differentiated."

MARKO ELAZAR CEO, NOVA DEFENSE
INVESTOR ENQUIRIES

For investor relations, funding enquiries, or to request our investor deck:

invest@blackdice.ai →
CONTACT

Safeguard your
digital world.

Whether you're an operator, investor, or partner we'd love to hear from you.

GET IN TOUCH

How can we help?

OPERATORS AND PARTNERS

Request a demonstration

See BlackDice Halo in action. Our team will walk you through a live demonstration tailored to your infrastructure and subscriber base.

GENERAL ENQUIRIES

Send us a message

For general questions, press enquiries, or partnership opportunities:

info@blackdice.ai →
INVESTORS

Investor relations

For funding enquiries, investor deck requests, or strategic partnership discussions:

invest@blackdice.ai →
OUR OFFICE

Leeds, United Kingdom

📍
LEEDS, UNITED KINGDOM

BlackDice Cyber Ltd

17th Floor, The Pinnacle
67 Albion Street
Leeds LS1 5AA
United Kingdom

FOLLOW US
PRESS AND MEDIA

For press and media enquiries, including interview requests, bylines, or brand assets, please contact our communications team.

View our newsroom →