With a population of over 273 million, Indonesia is one of the world's fastest-growing consumer markets, with ecommerce revenues growing nearly 20 percent annually. Amidst significant regional and international competition, locally-owned Blibli is one of the countryโs top five online retailers.
Founded in 2011, Blibli maintains a strong following with Indonesiaโs most affluent consumers, a demographic expected to double from 9 percent to 21% of the population by 2030. Offering unmatched quality is Blibliโs key strategy โ in a market where counterfeit goods are common, Blibli guarantees their inventory and brand name products are genuine. They offer a no-question, money-back return policy on everything they sell. As a result, Blibli customers are more likely to make their higher-value transactions on the Blibli platform than through competing channels.
Blibli faced several challenges โ some common to online enterprises and some exclusive to Indonesia. The companyโs primary pain points were competitor-driven DDoS and bot attacks and a fragile payment gateway.
โTo conduct payment in Indonesia, Blibli payment gateway service needs a direct connection with the bank,โ explains Rendra. โIt canโt reside in the cloud. We need to maintain an on-premise payments infrastructure and keeping that infrastructure secure is one of our top priorities.โ
Blibli needs threat protection above current Indonesia IXP can provide. Blibli site and payment gateway were particularly vulnerable to deliberate volumetric DDoS attacks. The attacks occurred during major promotions and advertised online events, leaving Blibli customers unable to complete payments even though they were able to put things in their carts. Blibli was losing revenue and brand reputation.
In addition to DDoS attacks, malicious bots strained Blibliโs hosting infrastructure, increased bandwidth costs due to traffic spikes, made products unavailable by hoarding inventory, and skewed expenses with unusually high off-peak traffic volumes. Blibli needed to ensure they could process customer transactions without any interruptions.
Finally, Blibli sought to improve security and governance over their internal infrastructure and gain more granular control over employee access. โAchieving a Zero Trust infrastructure was always part of the plan,โ explains Rendra. โBut the pandemic pushed us to quickly find a solution that allowed our employees to work securely from home.โ
In 2019, Blibli moved to Cloudflare. โOur previous solution was difficult to use, time-consuming to configure, and slow to propagate changes. It also wasnโt very effective,โ relates Rendra. โCloudflare is a much more agile solution โ we make changes often and see them reflected immediately. The Cloudflare dashboard is also much more user-friendly because it is designed to be used by anyone, not just security experts and CDN specialists.โ
With several major events planned and DDoS attacks surging, Rendra and the Blibli team implemented Cloudflare Magic Transit โ the secure managed networking solution that operates on layers 3 and 4. The goal was to ensure their payment infrastructure and network assets were safeguarded using private network interconnects. Before implementing Magic Transit, Rendra and his team spent a significant amount of time and resources reactively, rather than proactively, combatting attacks.
โMagic Transit was our savior. During the emergency onboarding, Cloudflare engineers secured our infrastructure very rapidly,โ explains Rendra. โWe worked together to determine what kind of traffic we would let through and what we wouldnโt. Now it just works seamlessly โ when attacks happen, we monitor them from the dashboard and carry on with our work day.โ
Blibli configured Magic Transit and Cloudflare Network Firewall in under 48 hours, effectively mitigating the ongoing DDoS attacks and helping them gain critical network visibility. โSince then, it hasnโt required much additional attention at all. It is easy to create firewall rules and immediately deploy them when we see something happening or when we get intelligence that an attack will occur soon.โ
Cloudflare has created a better experience for Blibli users and the security team. โWith Magic Transit in place, we can honor our SLAs (Service Level Agreements) for event tickets and ensure our customers a failure-free shopping experience,โ he says, โWhen management announces an event and asks me about our security landscape, I can say with complete peace of mind, โWe got this. We are good to go.โ
With their DDoS issues resolved, Blibli focused on implementing Cloudflare Bot Management to monitor automated activity on their domains and block attempts to hoard inventory.
โWe were concerned about blocking beneficial traffic like Google and price comparison sites that provide us with positive exposure,โ says Rendra. โUsing Cloudflare Bot Management, we can identify and allow good bot traffic while using Rate Limiting on login post requests to stop application-layer attacks on our pages.โ
Blibli also relies on Cloudflare threat intelligence and JA3 fingerprint identification to combat unwanted traffic. Overall, Cloudflare has reduced bot activity on Blibli domains by over 35%, resulting in corresponding savings on infrastructure costs without impeding organic search rankings or useful third-party links.
The Covid-19 pandemic not only forced Blibli to transition to remote work but also to keep up with increased demand for goods online. Blibliโs distributed employees and partners needed more secure, efficient ways to connect to their corporate applications and the Internet to remain productive and serve their growing customer base.
Blibli turned to Cloudflare Zero Trust to proactively address their remote work security needs. Blibli rolled out Cloudflareโs Zero Trust Network Access (ZTNA) solution to apply granular, identity-based access controls for priority users who interact with sensitive data in internal applications. Over time, Blibli plans to extend these Zero Trust controls to several hundred more users and a broader range of resources, including SaaS apps and legacy apps hosted in private IP spaces.
Blibli appreciates how easy Cloudflare made it to secure applications, deploy a device client, and set up policies.
โWe wanted to accelerate our Zero Trust plan, but we did not want to substantially increase overhead by adding extra appliances or setting up dedicated services,โ Rendra said. โCloudflare Zero Trust fit the bill perfectly. It was easy to integrate into our infrastructure and connect to our portfolio of applications.โ
From now on, the Blibli security and IT teams are thinking proactively about better protecting their devices and data while users browse the Internet. One early step will be layering Secure Web Gateway (SWG) capabilities such as DNS & HTTP filtering and inspection to protect users from online threats like phishing and ransomware. In the long term, Blibli is exploring ways to leverage Cloudflareโs Browser Isolation to insulate users from untrusted web content further and protect data that users interact with in their browsers.
Cloudflare solutions and support are central to Blibliโs continued growth in Indonesia. โThe Cloudflare engineering team is always there to help us ensure our rules are set up right,โ says Rendra. โCloudflare support is so effective that any organization can provide onboard the solution without much technical knowledge.โ
โIn the past, when zero-day threats arose, we were only aware of them following the vulnerability. Now, the Cloudflare team responds immediately, providing advice and mitigating attacks before going offline. It is the speed of that response that we appreciate.โ

Mitigated unwanted bot traffic and reduced bandwidth and computing costs by 35%
Automatically mitigate DDoS attacks, keeping Blibliโs ecommerce and payment gateway services online for major promotions and events
Prevented inventory hoarding and product blocking to keep customers satisfied with available products and frictionless transactions
Connecting Blibli employees and partners securely through the Cloudflare Gateway, preventing breaches and sensitive data leaving the organization
โOur previous solution was unintuitive to use, time-consuming to configure, and slow to propagate changes. Cloudflare is a much more agile solution โ now we make changes often and see them reflected immediately.โ
Rendra Perdana
Cybersecurity Architect
โWe wanted to accelerate our Zero Trust plan, but didnโt want to substantially increase overheads by adding extra appliances or setting up dedicated services. At this point, Cloudflare Access fit the bill perfectly.โ
Rendra Perdana
Cybersecurity Architect