Skip to content
Back to insights

How African banks should buy Cloudflare

African banks often buy a Cloudflare licence and leave it half-configured. The real decision is who operates it after go-live.
|4 min

Most of the African banks we work with do not fail at buying Cloudflare. They fail at running it.

Procurement signs a licence. Someone does a go-live. Months later the WAF is still on default rules, bot management is half-on, and nobody can say who will change a rule at 2am when internet banking is under attack.

The buying decision is not Cloudflare or not. It is who runs managed Cloudflare after the licence is signed: WAF, bots, DNS, Zero Trust, and incidents.

The licence is not the operating model

Cloudflare is a platform. A bank still has to size it, deploy it against real workloads, and run it every week. That work does not disappear when the contract is signed. That is the work we take on.

We see two patterns often. The bank buys the licence, points DNS, turns on a managed ruleset, and treats the project as done. Internet banking and payment APIs stay exposed, just with a new dashboard nobody owns. Or someone is present for go-live and gone after cutover. When a payment API fails, or Zero Trust locks staff out of core banking, there is no named operator.

If you cannot name who will change a WAF rule, roll a DNS record, or lead a Cloudflare incident on a Sunday night, you have a licence, not an operating model.

Decide what you are actually putting on Cloudflare

Do not start with a SKU. Start with the surfaces that matter.

For most of the African banks we work with, that list is short. Internet banking and the mobile apps behind it. Payment and mobile-money APIs. Public sites and onboarding flows. Staff access to internal systems: Zero Trust, and who can reach the core.

Each has a different risk. Putting the marketing site and the payment API in the same project is how a licence looks complete and a perimeter is not. Scope first. Size the licence to that scope. Then decide who runs it. If you are still choosing the edge, start with Cloudflare vs Akamai or Cloudflare vs Imperva.

Who changes the rules, and who is on the hook at 2am

WAF rules change when you ship an internet-banking feature. Bot settings change when a campaign spikes traffic. DNS changes when you move an origin. Zero Trust changes when a vendor needs access. Incidents do not wait for the next change window.

A bank security lead is usually covering identity, endpoints, vendors, and the audit calendar. Cloudflare is a full-time operating job if you do it properly. If the plan is our IT team, when they have time, be honest about capacity.

We operate Cloudflare for the banks we work with. We size it, deploy it, and run it. We stay on the account after go-live. More on how we run Cloudflare.

Platform and operator are both part of the buy

We sell the Cloudflare licence and we run the account. The licence is the platform. The operating fee is the team that tunes WAF and bots, owns DNS and certificates, runs Zero Trust, and shows up for Cloudflare incidents. Buy both, or name who owns the second job.

We sell that as Core, Priority, or Critical. Pick the tier on Managed Cloudflare. Response clocks sit on the SLA. The quote should make both the licence and the fixed monthly operating fee clear.

Can you leave if the work is not being done

Ask how you get out. Prefer a term you can exit if the work is not being done, and keep the Cloudflare account when you leave.

If the operator is not running the account, you should be able to leave.

Before you sign

Walk these with IT, security, and procurement in the same room. What is in scope: internet banking, payment and mobile-money APIs, public sites, staff access? Who changes WAF, bots, DNS, and Zero Trust after go-live, and is that a named team or a mailbox? Who owns a Cloudflare incident on a Sunday night? How do changes fit change control, including emergency change? What will you show internal audit, a POPIA reviewer, a PCI assessor, and your regulator: configuration, change history, incident notes? Does the quote cover both the licence and who runs it? Can you leave if the operator disappears?

If the question is an operator versus a SIEM dashboard, Vigilbase vs Splunk is the cut. If you are already under attack and not on Cloudflare, start with emergency onboarding.

If you cannot answer those, wait.

If you want an operator who will size the account, deploy it against internet banking and payments, and run WAF, bots, DNS, and Zero Trust after go-live, talk to us.

Tags

CloudflareManaged CloudflareBankingAfricaWAFZero TrustFinancial Services
Ilyas Esmail

Ilyas Esmail

Founder

Founder @ Vigilbase

Related articles

NO IMAGE

What your team should see in the first 30 days after Cloudflare go-live

The first month should leave your team with tested customer journeys, clear change responsibilities, evidence for tuning decisions, and a usable response record.

Ilyas Esmail
NO IMAGE

When Cloudflare blocks checkout during your campaign

The campaign is live and support has a blocked-checkout screenshot. Start with the customer journey, connect it to security evidence, and verify the fix through payment.

Ilyas Esmail
NO IMAGE

A Cloudflare WAF change-control runbook for the first hours

A WAF adjustment needs a clear hypothesis, a narrow scope, and a recovery path. Here is what the first hours of a controlled change should contain.

Ilyas Esmail

Stay ahead of threats

Get the latest cybersecurity insights and best practices delivered to your inbox.

How African banks should buy Cloudflare | Vigilbase