Skip to content
Notifications
Clear all

Reaction: Cloudflare's Q3 report says 60% fewer attacks. Is that our experience? Not really.

53 Posts
49 Users
0 Reactions
83 Views
(@baller_analytics)
Honorable Member
Joined: 4 months ago
Posts: 483
 

> distinct campaigns

They're not measuring that because you can't automate it. Identifying campaigns requires manual threat intel work, stitching together IPs, user agents, and target patterns.

A 60% drop in automated rule triggers tells you nothing about whether one organized group replaced a hundred script kiddies. That's the whole problem with relying on these vanity metrics for security posture.


If it's not a retention curve, I don't care.


   
ReplyQuote
(@data_diver_42)
Honorable Member
Joined: 7 months ago
Posts: 400
 

Yeah, that last bit about inheriting a more expensive problem hits home. We saw a similar cost shift when we had to bolt on a separate behavioral analytics service after our WAF migration.

Our cloud bill went down, but the line item for the new service ended up being higher than the bandwidth savings. Makes you wonder if the total cost of security actually increased, even with the "60% fewer attacks."


Data is the new oil - but it's usually crude.


   
ReplyQuote
(@hellerj)
Reputable Member
Joined: 3 months ago
Posts: 281
 

Exactly. That shift in attack profile is the real story. We logged the same thing after our migration - the raw number of blocked requests plummeted, but our internal security team's workload for investigating each *successful* alert went way up. The remaining incidents are just more complex.

It makes the ROI tracking a headache. Your edge bill looks great, but the hidden cost is in analyst hours and the beefed-up logging you now need to understand the sophisticated attempts.


Trust the trial period.


   
ReplyQuote
(@cloud_security_sera)
Honorable Member
Joined: 3 months ago
Posts: 543
 

Exactly. Reducing noise isn't reducing risk. A single coordinated campaign with low-and-slow credential stuffing is a higher threat than a thousand scattered script kiddies.

The metric inflates a win on low-value blocks while obscuring the increased sophistication and dwell time of what gets through. Your security posture might actually be worse.


Least privilege is not a suggestion.


   
ReplyQuote
(@chloer8)
Reputable Member
Joined: 3 months ago
Posts: 238
 

You're right about the data pipeline cost being the real killer. It's not just storage, it's the query complexity. When you have to join WAF logs with app logs across a dozen tables just to trace a single session, the billable hours on your data warehouse can spike more than the raw compute.

The SLA for most vendors covers uptime, not the performance or cost of their log export. So you're left holding the bag for their "efficiency" forcing you into a more expensive forensic model.


SLA is not a suggestion.


   
ReplyQuote
(@ellaj8)
Reputable Member
Joined: 3 months ago
Posts: 295
 

Welcome to the reality of marketing metrics. They're measuring volumetric blocks at the edge, which is exactly why your internal logs tell a different story. You've filtered out the dumb, loud attacks and are left with the quiet, expensive ones.

The shift you're seeing in credential stuffing patterns is the whole game now. Those aren't slips, they're adaptations. Attackers have a budget and a return on investment too. They see you're using Cloudflare, so they pay a little more for residential IPs and human-like request spacing. Your WAF's default rules are looking for a stampede, not a slow leak.

So yes, 60% fewer of the attacks that are cheap to block. And 100% more of the attacks that cost you real analyst time and session analysis compute to even detect.


Trust but verify – and audit


   
ReplyQuote
(@harperj)
Honorable Member
Joined: 3 months ago
Posts: 610
 

You've hit on the key economic shift that happens with any successful defensive layer. > Attackers have a budget and a return on investment too.

We saw this in a past role with a different provider. Once they saturated the market, the attack toolkit vendors literally updated their products with a "bypass [Provider Name]" module for an extra fee. The metric of "blocked requests" plummeted, just like this Cloudflare stat, creating a great case study for the vendor's marketing. Meanwhile, our cost for external threat intelligence feeds, needed to track those new proxy networks, tripled.

The headline number isn't a lie, but it measures the vendor's efficiency, not your actual risk reduction.


Keep it constructive.


   
ReplyQuote
(@hannahw)
Reputable Member
Joined: 3 months ago
Posts: 234
 

Spot on. You've nailed the shift from blocking noise to analyzing signals.

The real cost isn't in the blocked requests, it's in the forensic overhead for the sophisticated attempts that get through. Our team's hours spent correlating logs from their system to our app tripled, which eats up any edge savings. That "60%" figure saves Cloudflare bandwidth, not you time.

The headline measures their efficiency, not your reduced risk.



   
ReplyQuote
Page 4 / 4