Most of the African banks we work with do not fail at buying Cloudflare. They fail at running it.
Procurement signs a licence. Someone does a go-live. Months later the WAF is still on default rules, bot management is half-on, and nobody can say who will change a rule at 2am when internet banking is under attack.
The buying decision is not Cloudflare or not. It is who runs managed Cloudflare after the licence is signed: WAF, bots, DNS, Zero Trust, and incidents.
The licence is not the operating model
Cloudflare is a platform. A bank still has to size it, deploy it against real workloads, and run it every week. That work does not disappear when the contract is signed. That is the work we take on.
We see two patterns often. The bank buys the licence, points DNS, turns on a managed ruleset, and treats the project as done. Internet banking and payment APIs stay exposed, just with a new dashboard nobody owns. Or someone is present for go-live and gone after cutover. When a payment API fails, or Zero Trust locks staff out of core banking, there is no named operator.
If you cannot name who will change a WAF rule, roll a DNS record, or lead a Cloudflare incident on a Sunday night, you have a licence, not an operating model.
Decide what you are actually putting on Cloudflare
Do not start with a SKU. Start with the surfaces that matter.
For most of the African banks we work with, that list is short. Internet banking and the mobile apps behind it. Payment and mobile-money APIs. Public sites and onboarding flows. Staff access to internal systems: Zero Trust, and who can reach the core.
Each has a different risk. Putting the marketing site and the payment API in the same project is how a licence looks complete and a perimeter is not. Scope first. Size the licence to that scope. Then decide who runs it. If you are still choosing the edge, start with Cloudflare vs Akamai or Cloudflare vs Imperva.
Who changes the rules, and who is on the hook at 2am
WAF rules change when you ship an internet-banking feature. Bot settings change when a campaign spikes traffic. DNS changes when you move an origin. Zero Trust changes when a vendor needs access. Incidents do not wait for the next change window.
A bank security lead is usually covering identity, endpoints, vendors, and the audit calendar. Cloudflare is a full-time operating job if you do it properly. If the plan is our IT team, when they have time, be honest about capacity.
We operate Cloudflare for the banks we work with. We size it, deploy it, and run it. We stay on the account after go-live. More on how we run Cloudflare.
Platform and operator are both part of the buy
We sell the Cloudflare licence and we run the account. The licence is the platform. The operating fee is the team that tunes WAF and bots, owns DNS and certificates, runs Zero Trust, and shows up for Cloudflare incidents. Buy both, or name who owns the second job.
We sell that as Core, Priority, or Critical. Pick the tier on Managed Cloudflare. Response clocks sit on the SLA. The quote should make both the licence and the fixed monthly operating fee clear.
Can you leave if the work is not being done
Ask how you get out. Prefer a term you can exit if the work is not being done, and keep the Cloudflare account when you leave.
If the operator is not running the account, you should be able to leave.
Before you sign
Walk these with IT, security, and procurement in the same room. What is in scope: internet banking, payment and mobile-money APIs, public sites, staff access? Who changes WAF, bots, DNS, and Zero Trust after go-live, and is that a named team or a mailbox? Who owns a Cloudflare incident on a Sunday night? How do changes fit change control, including emergency change? What will you show internal audit, a POPIA reviewer, a PCI assessor, and your regulator: configuration, change history, incident notes? Does the quote cover both the licence and who runs it? Can you leave if the operator disappears?
If the question is an operator versus a SIEM dashboard, Vigilbase vs Splunk is the cut. If you are already under attack and not on Cloudflare, start with emergency onboarding.
If you cannot answer those, wait.
If you want an operator who will size the account, deploy it against internet banking and payments, and run WAF, bots, DNS, and Zero Trust after go-live, talk to us.
