1. Client Pain Points

1-1. On-prem Infrastructure Inadequate Against Modern Threats

As cyberattacks evolve, legacy on-premises systems face multiple challenges. Aging equipment requires costly replacements, and limited bandwidth makes it difficult to withstand large-scale attacks, often resulting in website outages.

1-2. Data Routing Must Avoid China-Based Nodes

While not explicitly stated in regulations, the financial industry deals with highly sensitive data. Even after cloud adoption was permitted in Taiwan in 2023, clients remain cautious and prefer to avoid any chance of data passing through nodes in China.

1-3. Concerns Over Usage-Based Billing Models

Most cloud services charge based on traffic volume. As a major financial trading center, the client handles heavy daily traffic and is a likely target for DDoS attacks. This raises significant concerns about potential cost surges due to traffic-based billing.

1-4. Fear of Blocking Legitimate Transactions

Many cloud security services rely on strict blocking policies. However, during high-frequency trading, some legitimate user behaviors may resemble automated bot activity. The client is concerned that overly aggressive blocking could interfere with actual transactions and prefers a more flexible approach.

2. Twister5’s Support and Solutions

Integrated Cloud and On-Premise Defense: Achieving Cyber Resilience through Dual-Layer Protection

2-1. Cloud-On-Prem Joint Defense

By retaining the client’s existing on-prem infrastructure, Cloudflare is used as the first layer of protection—blocking threats at the edge, hiding the origin IP, and directing suspicious traffic through its Anycast network for mitigation.
Then, the on-prem system performs detailed adjustments by setting specific access rules. This approach not only simplifies the on-prem infrastructure over time but also establishes collaborative protection and failover between both environments

2-2. Excluding China, Hong Kong, and Macau—Using Nearby Nodes for Traffic Scrubbing

While Cloudflare by default does not route through China-based nodes, to further reduce any data leakage concerns, Twister5 helped the client configure the system to exclude Hong Kong and Macau as well.
Nearby traffic is instead routed through Japan, South Korea, or Taiwan’s own nodes for scrubbing, ensuring data security.

2-3. One Portal for Flexible Switching

Cloudflare only charges based on clean traffic, so clients don’t need to worry about cost spikes during large-scale attacks.
However, due to the client’s high daily trading volume, some traffic was evaluated as not needing Cloudflare filtering.
Twister5 assisted in setting up a one-click switching feature, allowing secure traffic to be routed directly to the on-prem system based on predefined conditions—striking a balance between cost control and protection.

2-4. Cloudflare AI-Based Automated Defense for Large-Scale and Zero-Day Attacks

Hacker techniques evolve daily. As mentioned earlier, Cloudflare provides first-layer, large-scale automated AI defense—achieving a “Fight AI with AI” strategy.
Cloudflare first verifies and blocks suspicious behavior (e.g., bot-like user actions) through its challenge mechanisms.

hen, the client can use its on-prem system to perform deeper analysis and filtering. This ensures that legitimate user transactions are not blocked while maintaining complete protection.

3. Architecture Diagram

Cloudflare cloud security and on-premise defense architecture diagram showing DNS CNAME routing to Anycast IP, load balancer, and firewall hiding the origin server IP across a six-step defense flow

4. Current Results

4-1. Successfully Defended Against Large-Scale Attacks

After restructuring its security architecture, the client successfully mitigated a large-scale traffic attack launched by hackers. On the day of the attack, traffic volume spiked to 350 times the normal level. However, after Cloudflare’s filtering, the traffic load returned to normal levels, and all trading activities remained unaffected.

4-2. Accurate Traffic Visibility

Previously, traffic estimates were rough and manually calculated by the client. In this case, actual traffic turned out to be nearly five times higher than originally estimated.
With the implementation of Cloudflare, the client can now clearly identify traffic sources and effectively filter out suspicious traffic.

About Twister5

Twister5 is a professional provider of application-layer cybersecurity services, with deep expertise in cloud-based security solutions. As one of Taiwan’s leading application security service providers, Twister5’s technical team brings exceptional knowledge in designing and implementing complex hybrid architectures that integrate both cloud and on-premise defenses.
We serve a wide range of critical sectors in Taiwan—including finance, government, and manufacturing—delivering fast, reliable, and comprehensive security infrastructures. Our goal is to meet the evolving needs of enterprises and become your most trusted cybersecurity partner.

👉 Contact our Twister5 team now!

Twister5 – Your full-service cybersecurity partner. Contact us today.

Subscribe to our newsletter to stay up to date on AI and cybersecurity news.