sports · CricClubs
CricClubs Strengthens Web Application Defense
CricClubs one of the leading cricket technology platform helps the league administrator, players, team managers, to manage, follow and experience Cricket Like Never Before. CricClubs is working closely with 35+ NGB along with 30,000+ leagues, 50,000+ tournaments, 5Mn+ players in 58+ countries and growing daily. CricClubs is known for ease of navigation, comprehensive league management and is absolutely loved by our users.
Results at a Glance
- 3.2M Requests Blocked/mo
- 99.98% Availability
- <1 day App Onboarding
- Edge WAF Protection
The Challenge
The customer's internet-facing applications were experiencing sustained cyber attacks, including distributed denial-of-service (DDoS), credential stuffing, and brute-force attempts targeting authentication endpoints. These attacks were degrading application performance, increasing the risk of unauthorized account access, and impacting the availability of customer-facing services.
The existing security controls were insufficient to mitigate the attacks. Web application protection was inconsistent across applications, rate-limiting was not implemented on critical endpoints, and security events were not centrally monitored. As a result, the security operations team had limited visibility into attack patterns, making it difficult to identify targeted applications, respond to emerging threats, or consistently enforce protection across the environment.
The customer engaged AxiomIO to implement a centralized application protection platform that mitigated DDoS and web application attacks at the edge, enforced consistent security policies across all internet-facing applications, and provided centralized visibility into security events for continuous monitoring and response.
Our Solution
AxiomIO implemented a centralized web application protection architecture using Cloudflare as the primary security edge for the customer's AWS-hosted applications. All inbound traffic was inspected before reaching AWS, allowing malicious requests to be identified and blocked while legitimate user traffic continued uninterrupted.
The solution combined Cloudflare Web Application Firewall (WAF), custom security policies, and rate-limiting controls with an AWS-native security analytics pipeline. Security events generated by Cloudflare were automatically collected, normalized, and integrated into the customer's AWS security monitoring environment, providing the Security Operations Centre (SOC) with centralized visibility across all protected applications.
The entire solution was deployed using Infrastructure as Code (IaC), enabling consistent security controls, repeatable application onboarding, and standardized operational processes across the customer's application portfolio.
Results
The solution established a standardized web application protection capability across the customer's internet-facing environment, significantly improving resilience against external attacks and providing consistent operational visibility.
Key outcomes included:
- Centralized protection for all internet-facing applications through a common Cloudflare security architecture.
- Automated mitigation of DDoS attacks, credential stuffing, brute-force attempts, and common web application attacks before traffic reached AWS resources.
- Consistent WAF policy enforcement and rate-limiting across all protected applications.
- Centralized monitoring of web application attacks through Amazon OpenSearch and AWS Security Hub.
- Automated alerting and security event correlation that improved SOC response and investigation capabilities.
- Repeatable onboarding of new applications using Infrastructure as Code, eliminating configuration drift and reducing operational overhead.
- Version-controlled WAF policy management, enabling governed security changes and continuous policy improvement based on observed attack patterns.