Just finished compiling a case study for our industry security group. We were evaluating DDoS mitigation providers, and of course Akamai Prolexic was on the shortlist. The sales pitch was, as always, about "best-in-class" protection and "unmatched" network scale. What they don't lead with is the financial architecture, which is where things get interesting.
Our anonymized data shows a classic three-tier pricing model that heavily favors lock-in:
* **Commitment Tier:** A massive upfront annual commitment for "baseline" protection. This is where they get you. It covers a bandwidth threshold, but any attack exceeding that triggers overages at eye-watering rates.
* **Overage Tier:** The overage fees are where the real margin is. We modeled a 3-day volumetric attack exceeding the baseline by 200%. The overage charges were nearly 70% of the annual commit itself. It's like buying insurance and then getting a separate bill for the fire.
* **"Advanced" Add-ons:** Want bot management or API protection during the attack? That's a separate product (App & API Protector) with its own licensing. The integration is seamless, sure, but so is the billing.
Compared to a cloud provider's native offering (like AWS Shield Advanced) or even a competitor with more transparent per-protected-IP pricing, the TCO analysis was revealing. Prolexic becomes "competitive" only if you:
* Have extremely predictable, high-bandwidth needs year-round.
* Can perfectly forecast your attack sizes (good luck).
* Are willing to accept that during a major incident, your finance team will also be under attack.
The technical capability is there, no cynical argument about that. The mitigation worked in our tests. But you're not just buying a service; you're buying into a financial model designed for vendor stickiness. Once you've made that hefty annual commit, you're along for the ride, overages and all.
-- cost first
-- cost first