Gaming

Gamer Maintains Business Continuity

A global online gaming provider and digital entertainment publisher stopped DDoS attacks – remediating over 96% of their DDoS vulnerabilities.

The Customer

The customer is one of the leading, publicly traded companies in the gaming industry, with over 6,000 employees, hundreds of partners, and millions of gamers. They specialize in online casino games with integrated online solutions for gaming operators and partners. As a worldwide leader, the company drew the attention of threat actors and suffered from relentless DDoS attacks.

 

Following several weeks of intermittent service disruptions and downtime, their ability to function was impaired and they suffered from significant reputational damage. The company needed to uncover its true DDoS exposure to secure its online services. 

Key Takeaways

Customer Challenges

  • Several weeks of intermittent service disruptions  
  • Millions of dollars in lost revenue from users and in-game ads (per hour of downtime) 
  • High risk of customer churn – both partners and gamers 

Our Impact

  • Eliminating damaging DDoS downtime 
  • Insight and data to validate the effectiveness of their DDoS protection 
  • Reducing churn by improving the user experience 

The Challenge

With millions of Daily Active Users (DAU) and significant Average Revenue Per User (ARPU), every minute that the company is offline results in millions of dollars in losses. They made a significant investment in hybrid DDoS protection solutions from top-tier vendors, but they continued to suffer damaging DDoS downtime.  


Due to the nature of their 24/7 business, the company couldn’t allow maintenance windows to perform DDoS pen tests. They needed to maintain 100% uptime with zero disruption to gamers so looked for innovative solutions that could provide complete visibility into their DDoS security posture. The CISO was intrigued by the ability of MazeBolt RADAR™ to run continuous DDoS vulnerability assessments without service disruption or downtime. 

Our Solution

After a short Proof of Concept (POC) that exposed significant vulnerabilities, RADAR was deployed downstream to each of the company’s mitigation layers. Continuous simulations identified severe vulnerabilities in layers 3 and 4, with critical misconfigurations in the CPE (for the on-premises DDoS protection) and of the Scrubbing Center (for the cloud-based DDoS protection). 

RADAR helped the company identify the following: 

  • Their DDoS protection was vulnerable to 45% of attack vectors launched 
  • The mitigation solutions they deployed relied heavily upon reactive and manual protection procedures previously not disclosed to the company 
  • Over 190 DDoS vulnerabilities were uncovered 


After RADAR was deployed and provided the company with initial DDoS vulnerability data, MazeBolt’s Professional Services team established a new streamlined process with the company and its mitigation vendor. They created a prioritized remediation plan and made sure all online services were protected – without compromising the company’s crucial uptime and availability.
 

Over 120 vulnerabilities were closed within six weeks, during which time the company continued to be targeted by DDoS attacks. The company realized that they needed to prioritize improving their DDoS resilience as soon as possible. 

Customer Benefits

Working with MazeBolt’s Professional Services team and their DDoS mitigation vendor, the company developed an action plan for continuous remediation. The impact of RADAR on the company’s DDoS resilience included: 


  • Over 96% DDoS vulnerabilities remediated in less than 6 months, with zero downtime 
  • Fully automated DDoS protection integrated with RADAR vulnerability testing, allowing complete prevention of damaging DDoS attacks 
  • A move away from a reliance on “smart human processes” and reactive emergency response  
  • Expansion of their DDoS coverage to Layer 7 vulnerabilities 
  • Continuous RADAR simulations and a remediation plan with the necessary insight and data to validate the effectiveness of its DDoS protection