Contact

← Back to use cases

Use case #04

Cybersecurity and GDPR: protect without breaking search visibility

An attack of more than 2 billion requests blocked, a reduced attack surface, trackers that wait for consent, and legitimate crawlers getting through.

Context

Large international B2B group, subject to GDPR and NIS2. A classic setup: CDN and WAAP in front of public sites, identity federation with strong authentication, a consent management platform, a dedicated security team. Public sites must stay fast, indexable and compliant.

Diagram: internal editing CMS, static generation, origin storage, WAAP and CDN, visitors

What I did, step by step

1. Block the attack

A denial-of-service attack of more than 2 billion requests was blocked by the WAAP, with no visible outage for visitors. Volumetric protection is prepared before the attack, not during.

2. Untangle security and performance

A WAF/CDN setting caused authentication loops and prevented caching. Cache and session rules were fixed with the security team, without weakening application protection.

3. Reduce what is exposed

Target architecture: editing back office off the public internet, static public site behind a load balancer, WAAP and CDN, admin access through strong authentication rather than IP filtering.

4. Make consent real

Verification that no analytics tracker or third-party tag fires before explicit consent, through the consent platform and advanced consent mode.

5. Let legitimate crawlers through

Anti-bot rules were also blocking search engines. Coordination between security, agency and marketing to allow them without opening the door to the rest.

6. Apply a standard

Mandatory strong authentication and SSO, CMS hardening, centralized secret management, HTTP security headers, protection against injection and XSS, regular testing.

Pitfalls and decisions

  • IP filtering does not replace access control: it fails as soon as someone connects from another place or network.
  • A WAF rule added in a rush in production, untested, creates the next incident.
  • A badly connected consent banner lets data leave before the visitor agrees. The defect only shows when you inspect network requests.

Outcome

Reduced attack surface, caching restored, verifiable consent, indexing unblocked. Protection and search visibility stop fighting each other. Want to know more? Get in touch.

Stack and methods

Akamai (CDN/WAAP)
Google Cloud Armor
SSO / MFA
CMP
Consent Mode v2
GDPR
NIS2
← Previous case: CMS overhaul: from optimized CMS to static site → Next case: MarTech and data: measure correctly, within the rules

Facing something similar?

Get in touch