Customer Overview
| Customer | MADA |
| Industry | Retail / E-commerce |
| Location | Warsaw, Poland |
| Type | SMB |
Executive Summary
MADA, a leading Polish e-commerce retailer, operates a high-traffic online store processing over 500,000 requests daily with peaks exceeding 1.2 million during seasonal sales. The platform faced increasing automated attacks, bot-driven abuse, and compliance requirements for payment processing. Tehma Cloud implemented a comprehensive AWS WAF solution that achieved zero successful attacks, maintained 99.9% availability during peak periods, and satisfied PCI DSS compliance requirements – all managed through Infrastructure as Code for rapid, auditable security updates.
Challenge
MADA’s e-commerce platform faced a complex and growing threat landscape that directly impacted business operations:
- SQL injection and cross-site scripting attacks targeted the product database and customer sessions, threatening data integrity and customer trust.
- Automated bots scraped product prices every few minutes, leaking competitive intelligence to rivals. Inventory hoarding bots created artificial scarcity by filling shopping carts during peak periods, preventing legitimate customers from completing purchases.
- Credential stuffing attempts targeted customer accounts, creating support burden and account compromise risks.
- PCI DSS Requirement 6.6 mandated application-layer protections for payment processing – non-compliance could result in fines and loss of payment processing capabilities.
- The platform included legacy PHP endpoints required for inventory management integrations that could not be immediately migrated – any security solution needed to accommodate these business-critical flows.
Solution
We implemented AWS WAF (Web Application Firewall) integrated with MADA’s Application Load Balancer, providing multi-layer protection through eight security rules processing over 1,300 Web ACL Capacity Units.
The solution combines AWS Managed Rule Groups for automated threat protection – covering OWASP Top 10 vulnerabilities, SQL injection, IP reputation, anonymous proxies, and bot control – with carefully tuned custom rules that preserve business-critical functionality. A 14-day testing phase in „Count” mode identified and resolved false positives before any legitimate traffic was blocked.
Custom rules allow legacy integration endpoints to bypass security checks while maintaining protection for all other traffic. Rule overrides accommodate the mobile application’s non-standard user agents, large product image uploads, and legitimate hosting provider health checks.
DDoS protection operates in active mode, automatically engaging enhanced filtering during attack events. The entire WAF configuration is managed through Terraform, enabling changes to be deployed in under 15 minutes with full peer review and immediate rollback capabilities.
The owners says the WAF implementation protected their peak-season revenue without disrupting any of our business integrations. They went from constant bot abuse to zero successful attacks – and the cost is less than our monthly coffee budget.
Results
- Zero successful attacks – no application-layer breaches since implementation, protecting customer data and business operations.
- 99.9% availability – maintained during peak shopping periods with 1.2 million daily requests, ensuring no revenue loss from security-related downtime.
- PCI DSS compliance – Requirement 6.6 satisfied through comprehensive application-layer firewall protection.
- $15-25/month total cost – enterprise-grade security at a fraction of the cost of dedicated security appliances.
- 15-minute change deployment – Infrastructure as Code enables rapid security updates with full audit trails and rollback capability.
- Automated threat intelligence – AWS Managed Rules update automatically against emerging threats without manual intervention.
AWS Services Used
AWS WAF | Application Load Balancer | Amazon ECS (Fargate) | Amazon Aurora MySQL | Amazon EFS | Amazon CloudWatch | AWS Shield Standard