The problem
A live service that customers use started getting about a thousand requests a second from bots. Traffic like that slows a service down for real customers and can take it offline.
What we did
We led the response. We capped how many requests any one source could send, in three places: the firewall, the web server and the app itself.
What came after
We wrote down what worked as a step-by-step playbook for protecting a service. Other teams have used it since.
On your site
Every website gets bot traffic. Watching for it and blocking it is part of the monthly plan.