A leading insurance company with over 4 million customers was facing frequent, damaging DDoS attacks that led to disruptions and downtime. Their customers experienced repetitive connection issues when using the company’s online services. Despite deploying DDoS mitigation solutions and conducting periodic DDoS testing, the company remained vulnerable, and the customer experience was impacted. The company suffered from repetitive DDoS downtime, service degradation, and operational and reputational damage.
The company sought to:
All industry-leading DDoS mitigation providers begin with standard protection policies designed for broad compatibility and minimal business disruption. These baseline configurations are intentionally conservative and require environment-specific tuning to achieve optimal protection. RADAR identified configuration gaps that are common in initial deployments and enabled precise remediation aligned to the customer’s traffic patterns and risk profile.
Exposure Discovery & Visibility
MazeBolt worked together with our Preferred Remediation Technology Alliance partner, F5, to give the company full DDoS visibility. Industry-leading vendors like F5 provide extremely powerful DDoS mitigation platforms. For this customer, the deployed policy was generic, and the initial RADAR test showed 86% configuration exposure under standard deployment conditions, i.e., prior to tuning.
RADAR™ by MazeBolt provided the company with detailed configuration data and generated a full remediation report.
Automated Protection & Remediation
F5’s SOC team incorporated the data that they received from RADAR. They successfully configured F5’s XC DDoS protection for optimal protection. This enabled the company to reduce its risk of damaging downtime at record speed.
Overall, with the full visibility and data provided by MazeBolt together with F5, customized configurations were possible that resulted in a reduction of DDoS exposure from 86% to 7%, representing a total risk reduction of approximately 92%. This risk reduction was achieved in days.
Improvement in DDoS Resilience with MazeBolt & F5
This reduction in the company’s DDoS exposure is particularly significant because research highlights a 550% increase in DDoS attacks on the Banking, Financial Services, and Insurance industry, year over year.
The work done jointly by MazeBolt’s Professional Services team and F5’s SOC teams enabled the company to achieve DDoS auto-protection: the data provided by RADAR testing allowed F5 XC protection to automatically prevent damaging DDoS attacks.
The findings indicated that continuous validation and environment-specific policy tuning must become a common industry-wide standard.
“The combination of RADAR by MazeBolt and F5’s XC DDoS Protection completely changed the way we manage DDoS risk. For the first time, we had clear visibility.”
– CISO at Insurance Company
Deployment Deep Dive
If one universal policy worked for every customer:
But in reality:
For these reasons, tuning actions were required:
To eliminate the company’s risk of DDoS downtime, the F5 XC Web Application and API Protection (WAAP) was optimized.
The work done by MazeBolt and F5 enabled the company to align itself fully with the Gartner® framework for Continuous Threat Exposure Management (CTEM), by providing a comprehensive solution that addresses all five steps of CTEM: