SWR7
Home/Services/Service · DDoS protection
Service · DDoS protection

DDoS protection for online casinos: proactive hardening and runbook

Whether a ransom email is a threat or a nuisance is decided weeks earlier, in your edge configuration and in whether your team knows what to switch.

What the add-on does

The DDoS protection add-on makes the protection you already pay for — typically Cloudflare — configured, armed and rehearsed. It is built for the sector where DDoS-for-ransom concentrates: online casinos, crypto-casinos and sportsbooks, whose revenue is time-sensitive and whose players leave in seconds. The background is in DDoS extortion against online casinos.

Four deliverables

  1. Origin exposure check. Your server must not be reachable around the edge: old DNS records, mail headers, forgotten subdomains that point straight to the origin. Detect looks for exactly this.
  2. Edge configuration tuned to your traffic. Security level, bot handling, rate limits on the endpoints that matter (login, deposit, bet placement), caching for what can be cached — proposed with the reason, applied by your team.
  3. A learned baseline. Requests per minute and latency measured over weeks, with thresholds that sit far above your legitimate peaks — a derby, a newsletter, a shared article — so an alarm means something.
  4. An under-attack runbook. Who is notified, what gets switched (up to Cloudflare's Under Attack Mode), which sources get blocked, how you roll back. Written down, rehearsed once with your team.

During an attack

Monitor sees the request rate and the latency cross the learned thresholds, confirms on a second reading, and alerts your operators within minutes with the numbers and the runbook step that applies. On your edge SWR7 proposes, it does not switch: the hand on the lever is yours, and the runbook is what makes that hand fast.

What it is not

Not a scrubbing center, not a CDN, not a replacement for your edge provider. It is the layer that makes sure the edge is doing its job — and the pair of eyes that notices when it stops, including when the reason is your own deploy.

PositionSWR7 does not pay or negotiate ransoms. The ransom funds the next attack; the service exists so the threat is not credible in the first place.

Frequently asked questions

We are already on Cloudflare — is this redundant?

You have the tool. The add-on checks that the origin is hidden, that rate limits sit on the right endpoints, that thresholds match your real traffic, and that your team has rehearsed the runbook. Most operators have the tool and none of the four.

Do you need access to our Cloudflare account?

Read-only analytics access is enough for the baseline and monitoring. Configuration changes are proposed to your team, who applies them — SWR7 does not hold write access to your edge.

Is it only for casinos?

It is designed for casinos and crypto-casinos because that is where extortion concentrates, but it fits any platform whose revenue is time-sensitive: sportsbooks, exchanges, ticketing, live commerce.

Want to know what your surface looks like from outside?

An intro call, no commitment. If it makes sense, you receive the Rules of Engagement — nothing is tested before you sign.

Book an intro call