Skip to main content
← All work

SECURITY PRODUCT · NETWORK

From network risk to recurring revenue

A four-market carrier faced attacks far larger than anything it could absorb. Rather than build scrubbing capacity, I paired Cloudflare's global network with a Kentik control plane we owned, then turned the protection into a multi-tenant service customers could buy.

Role Product & Technology Lead
Period 2023 – 2024
Context ATN International (Brava Solutions), across four markets
Download as PDF ↓

4

markets protected by one automated platform

Seconds

from detection to mitigation, without waiting on a transit provider

Multi-tenant

designed for resale from day one

The situation

For an island carrier, availability is the product. An outage is felt by every subscriber at once, each market answers to its own regulator, and there is no second provider to blame. Attack sizes across the industry had grown past anything a group this size could absorb on its own, and mitigation depended on transit providers responding on their timescale, not ours.

Build, buy, or partner

Building our own scrubbing centres meant capital cost across four markets, years to reach useful capacity, and a specialist team we did not have. Buying per-market protection from each ISP meant fragmented policy and no single view of traffic.

The answer was to rent the scale and keep the control. Cloudflare's global network absorbs the attacks. Detection, policy and tenancy stayed ours, on a Kentik control plane fed by the network's own telemetry. Operating cost instead of capital, weeks per market instead of years, and a platform we could resell.

Two ways to survive, not one

I would not accept a design where a single control plane failing meant no protection. Mitigation runs in two independent phases: a fast, blunt network-level response that works even if the scrubbing provider is unreachable, and a precise scrubbing path that keeps customers online while the attack is absorbed elsewhere.

Two independent paths meant an availability commitment I was willing to sign. A single-path design would have rested the whole service promise on one vendor's API, which is not a promise I would put in front of a customer or a regulator.

What happened after

The service was validated end to end under a formal, signed acceptance test plan, including automated mitigation under simulated attack conditions and failover on both return paths.

Because the platform was built tenant-aware from the start, the same infrastructure that protects the group is sellable to enterprise customers across the region. The defensive spend became a product.

DDoS ProtectionCloudProduct DevelopmentVendor Governance

Working through something similar?

I read every message myself. Tell me what you are facing and I will tell you honestly whether I can help.

Get in Touch