The customer is a leading European payment platform services company. Like most payment providers, its business depends on uninterrupted uptime, since even a brief outage can disrupt millions of daily transactions, damage merchant trust, and expose the company to regulatory scrutiny. That dependency became clear when a damaging DDoS attack disrupted the company’s online services, despite having a DDoS mitigation solution already in place.
The company first engaged MazeBolt after a damaging DDoS attack disrupted its online services, bringing customer transactions to a standstill despite already having a DDoS mitigation stack in place. The incident made clear that deploying protection and knowing it works are two different things. The security team needed continuous, nondisruptive visibility into whether its defenses, including its scrubbing center, customer premises equipment (CPE), and web application firewall (WAF), would actually hold against real attacks. The company deployed RADAR as an independent, nondisruptive DDoS validation layer.
At the time of initial deployment, RADAR found that the company’s deployed DDoS mitigation stack carried more than 52% exposure. In other words, against a real attacker, more than 5 out of 10 tested attack vectors would have succeeded.
RADAR gave the security team the specific DDoS vulnerability data needed to remediate misconfigurations across the stack, rather than relying on assumptions about where the gaps were. Instead of a one-time assessment, RADAR continuously re-tested the environment, showing measured improvement over time and confirm that fixes held as the environment evolved.
By using RADAR, the company was able to reduce its vulnerability gap from 52% to 18.2% thus far. In the last six months alone, RADAR ran 778 different DDoS attack simulations against the company’s production network. The company has a highly organized and competent security team, which has been working closely together with MazeBolt to remediate the vulnerabilities and misconfigurations that were identified. To date, approximately 50% of the findings that were surfaced by RADAR have been remediated. The process is unusually complex because of the extensive changes to the company’s infrastructure that are being implemented in parallel.
With clear, continuous visibility into its DDoS exposure, the company moved from reacting to a damaging attack to proactively validating its defenses on an ongoing basis. Continuous validation of the environment gives the security team full visibility into DDoS exposure across OSI Layers 3, 4, and 7 as workloads shift and defense configurations change.
The results were strong enough that the company signed a renewal agreement that extended RADAR beyond its original on-premises deployment into a new Google Cloud Platform (GCP) environment as part of a broader infrastructure re-architecture.