Magnolia cuts operational costs while securing digital experiences at the edge
Key results
Reduced platform operational costs by 55-60%
Blocked 3.2 million attack requests monthly across hundreds of events, proactively protecting high-profile financial and government environments.
Achieved a flawless 99.9% uptime for customers by automatically stopping Distributed Denial-of-Service (DDoS) attacks at the edge.
Propagated Next-Gen WAF security rules across hundreds of PaaS customers instantly to ensure immediate collective protection against new threats.
Decreased total cost of ownership by unifying edge compute, bot management, and WAF capabilities into a single, cohesive defensive layer.
The challenge
Magnolia is a leading digital experience platform (DXP) and content management provider that serves 450 customers and 200 partners globally. The company hosts more than 250 clusters and supports highly security-conscious verticals, such as the financial sector and government agencies. Because of their high-profile nature, Magnolia's clients frequently become targets for malicious actors and hacktivists.
As Magnolia scaled its Platform-as-a-Service (PaaS) model, the company assumed responsibility for runtime reliability and defending customer websites against increasingly complex abuse.
“These attacks tend to come in very quick bursts, so the speed of the response is very important for us,” explained Jan Haderka, CISO and CTO at Magnolia. Manual mitigation proved too slow to handle modern DDoS strikes. Furthermore, aggressive content scraping became a major concern as AI evolved. Magnolia required a nuanced solution to block malicious bots while controlling how legitimate AI agents index content.
The solution
Magnolia initially adopted Fastly for its API-driven CDN, a move that resolved complex legacy setups and cut initial platform costs by 40%. To proactively protect bespoke customer environments, Magnolia expanded their Fastly stack to include the Next-Gen WAF, AI Bot Management, and DDoS Protection. Fastly's zero-attack-fee pricing model—billing only for legitimate traffic—allowed Magnolia to scale its security posture efficiently, driving cumulative platform operational cost savings to 55-60%.
Activate automatic DDoS mitigation with intelligent threat validation: With a flip of a switch, Fastly's DDoS Protection serves as Magnolia's critical first layer of defense, dynamically mitigating short bursts of malicious volumetric traffic before it reaches origin servers. Fastly's Adaptive Threat Engine continuously validates traffic legitimacy in near real-time, isolating malicious characteristics as they emerge. When a large banking customer faced multi-day attacks, Magnolia immediately activated Fastly's blocking mode, neutralizing the offending IP ranges and helping the platform consistently hit its 99.9% uptime SLA.
Ensure collective immunity with Next-Gen WAF: With hundreds of customers on the same platform, Magnolia uses Fastly's Next-Gen WAF to build unified rule sets once and propagate them across all customer environments. When paired with the Next-Gen WAF’s highly accurate SmartParse detection engine, this allows Magnolia’s team to quickly apply high efficacy policies to ensure the protection of their entire customer base.
Control AI with Bot Management: Magnolia uses Fastly to go beyond basic bot detection and indiscriminate blocking. With multiple bot detection methods driving deep visibility, they accurately identify AI agents, malicious automation, headless bots, and much more. This visibility allows Magnolia to automatically block aggressive scrapers while allowing the legitimate bots that clients need on their sites to drive business outcomes.
Leverage a unified AWS and Fastly foundation: For Magnolia, the AWS-Fastly partnership is a core architectural foundation dating back to the inception of their cloud journey, pairing AWS's cloud infrastructure with Fastly's edge platform for an optimized, production-ready stack without operational friction. Unified billing via AWS Marketplace eliminated procurement bottlenecks and streamlined lifecycle management. Architecturally, AWS delivers backend compute power while Fastly secures and accelerates the front end through its CDN and Next-Gen WAF. While isolated performance metrics can be hard to pin down, the operational synergy between the two platforms delivers a reliable, frictionless experience for Magnolia's teams.
Key takeaway
By expanding from Fastly's API-driven CDN into a full edge platform usage with Compute, DDoS Protection, Next-Gen WAF, and AI Bot Management, Magnolia turned a growing security burden into a competitive advantage — cutting costs while delivering enterprise-grade protection across hundreds of customer environments.
"The relationship and collaboration with the people at Fastly is the cornerstone of the success that we have," said Lukas Reck, Head of Cloud Services. "It goes from account management to technical account management to support at all levels. We are very happy with what we get from Fastly."