Radware adds cloud DDoS intelligence to DefensePro X on-premises kit
Radware (NASDAQ: RDWR) has launched a cloud-augmented protection architecture for its DefensePro X on-premises appliance, starting with a new Cloud Web DDoS Protection service. The approach is designed to give enterprise security teams access to AI-powered, cloud-based attack intelligence while keeping traffic inspection, mitigation, and TLS private keys entirely on customer premises.
The hybrid model is a direct response to a widely acknowledged tension in DDoS defence: cloud-based scrubbing services improve detection of application-layer attacks, but they typically require either traffic redirection through the cloud or access to a customer's private encryption keys. Both conditions create friction for organisations operating under strict data-sovereignty, privacy, or compliance mandates.
How the architecture works
Radware's cloud-augmented model decouples intelligence gathering from traffic handling. The DefensePro X appliance continues to perform inline traffic inspection and enforcement locally, while cloud algorithms running across the company's network of more than 65 cloud centres analyse attack patterns and push updated detection models back to the on-premises device in real time.
The first service built on this architecture, Cloud Web DDoS Protection, targets Layer 7 attacks: the increasingly common category where attackers use AI-generated traffic, encrypted HTTPS channels, and distributed botnets to mimic legitimate user behaviour. These techniques are designed to evade signature-based detection, which depends on local traffic visibility alone.
Gabi Malka, chief operating officer at Radware, said the company intends the approach to avoid forcing customers to choose between security posture and operational control. "By extending DefensePro X with cloud-augmented protection, Radware gives customers access to cloud-powered intelligence while helping to preserve the speed, privacy, and control of inline enforcement," he said.
Radware did not disclose specific detection-rate benchmarks, latency figures for the cloud feedback loop, or pricing in its announcement.
Market context and competitive positioning
The application-layer DDoS market has grown more complex as attack tooling has become commoditised and AI-assisted. Vendors including Akamai, Cloudflare, Imperva and F5 all offer Layer 7 DDoS mitigation, predominantly through cloud-based or hybrid scrubbing architectures. Most of those approaches require some degree of traffic diversion, making them a harder sell for financial services firms, healthcare organisations and public-sector bodies with data-residency obligations.
Radware's on-premises enforcement model is already present in regulated enterprise environments, and the cloud-augmented approach is positioned as an upgrade path that avoids architectural disruption. The company notes the service is particularly suited to organisations protecting applications behind CDNs and reverse-proxy setups, where traffic flows are already complex and rerouting through an additional scrubbing cloud adds latency risk.
Regulatory read-across
Data sovereignty concerns have become more acute since the EU AI Act and NIS2 Directive took effect, with the latter requiring essential-service operators to demonstrate proportionate and documented DDoS mitigation controls. The ability to meet those controls without transmitting traffic or keys outside a jurisdiction is a compliance differentiator that Radware is clearly leaning into.
The UK's equivalent NIS Regulations, currently under review by the Department for Science, Innovation and Technology, place similar obligations on critical national infrastructure operators. For customers in both jurisdictions, an on-premises enforcement model with cloud-augmented intelligence may simplify the evidence trail for auditors.
Radware said Cloud Web DDoS Protection is available now for existing DefensePro X deployments. The company described the cloud-augmented architecture as a framework for future services beyond DDoS defence, though no additional capabilities or timelines were announced.