An attack of more than 2 billion requests blocked, a reduced attack surface, trackers that wait for consent, and legitimate crawlers getting through.
Large international B2B group, subject to GDPR and NIS2. A classic setup: CDN and WAAP in front of public sites, identity federation with strong authentication, a consent management platform, a dedicated security team. Public sites must stay fast, indexable and compliant.
A denial-of-service attack of more than 2 billion requests was blocked by the WAAP, with no visible outage for visitors. Volumetric protection is prepared before the attack, not during.
A WAF/CDN setting caused authentication loops and prevented caching. Cache and session rules were fixed with the security team, without weakening application protection.
Target architecture: editing back office off the public internet, static public site behind a load balancer, WAAP and CDN, admin access through strong authentication rather than IP filtering.
Verification that no analytics tracker or third-party tag fires before explicit consent, through the consent platform and advanced consent mode.
Anti-bot rules were also blocking search engines. Coordination between security, agency and marketing to allow them without opening the door to the rest.
Mandatory strong authentication and SSO, CMS hardening, centralized secret management, HTTP security headers, protection against injection and XSS, regular testing.
Reduced attack surface, caching restored, verifiable consent, indexing unblocked. Protection and search visibility stop fighting each other. Want to know more? Get in touch.