Founded in 2018, mod.io provides a white-label service that enables game developers to enhance user engagement by incorporating user-generated content and mods into their PC, console, or VR games. In just a few years, the company has grown tremendously. Today, mod.io supports 160 games on their platform, which generate around one billion API requests per month.
As the customer base has grown, the mod.io team has ramped up security for their own platform and all the games they support. โThe quality and quantity of games coming onboard is accelerating,โ says Greg Macsok, head of cloud and IT at mod.io. โWe need to make sure that not only are those games always playable and online, but also that theyโre protected with good, solid cybersecurity.โ
The mod.io team relies on Cloudflare for critical cybersecurity services. โWe turned on Cloudflare capabilities very early on,โ says Macsok. โThatโs evolved over the years now to almost 20 Cloudflare products and services, from load balancing and Zero Trust capabilities to Cloudflare Workers. Weโve brought on each product to help us improve performance or security in a specific area.โ
Though mod.io began in Australia, the companyโs workforce has expanded to Europe and the United States. To help ensure all employees can access resources quickly and securely with their laptops, mod.io uses Cloudflare Access โ Cloudflareโs Zero Trust Network Access service.
โCloudflare Access allows us to provide secure access to our testing and development environments from anywhere,โ says Macsok. โIt also enables us to use third-party endpoint protection tools to ensure those laptops are secure. Once we know the devices are secure, users can reach out to the Internet and to our network.โ
Mod.io began using the rate limiting functionality of the Cloudflare Web Application Firewall (WAF) to protect the network from malicious requests. โWe know weโre sending only legitimate traffic and requests to our origin servers,โ says Macsok.
Rate limiting also reduces the load on backend servers. โWhen youโre talking about a billion API requests per month, tracking individual users and API keys can require serious resources,โ says Macsok. โNow we can do that work at the edge, which takes a significant amount of load and compute off our backend systems.โ
The Cloudflare platform makes it easy for the mod.io team to manage numerous security capabilities without in-depth technical expertise. โThe Cloudflare dashboard abstracts the technical knowledge away from the end user,โ says Macsok. โWhen I want to configure a new firewall rule, I donโt need to know a programming language.โ
The team can employ rich capabilities without excessive time, effort, or cost. โIt takes away the complexity of us building complicated rate limiting systems in our infrastructure,โ says Macsok. โThat helps us avoid cost and allows us to build our product faster.โ
The ease of using Cloudflare for security enables mod.io team members to concentrate on building new products. โBy using Cloudflare services, weโre saving between 60 and 70% of the effort we would normally spend on cybersecurity,โ says Macsok. โThat allows us to focus on product development. Weโre delivering new features to customers faster โ and then moving onto the next customer request.โ
Mod.io has been capitalizing on the robust performance of Cloudflareโs content delivery network (CDN) for some time. More recently, the company started using Cloudflare Workers to support content delivery. Workers enables the team to localize assets and website text for global users. โWe can make sure a German user receives German assets,โ says Macsok.
The company also moved their object storage to Cloudflare R2 to improve the economics of storing assets in the cloud. โWeโve been able to cut out the egress costs associated with pulling assets from a third-party cloud provider,โ says Macsok. โWe now have much more predictable spending.โ
As the mod.io team plans for the future, they are exploring ways to protect external cloud environments while further simplifying their security stack. They have no doubt that continuing their work with Cloudflare will be the best way forward.
โWeโve had a very successful relationship with Cloudflare. In almost 20 years, weโve never had a security breach,โ says Macsok. โWe have a security-first philosophy internally. So, we plan to work extremely hard with Cloudflare to make sure our excellent track record continues.โ
Eliminated up to 70% of staff time spent on cybersecurity, refocusing on new feature development
Provided remote employees with secure access to testing and development environments
Blocked malicious traffic at the edge, reducing the load on backend servers
Avoided cloud egress costs with new object storage
โBy using Cloudflare services, weโre saving between 60 and 70% of the effort we would normally spend on cybersecurity. That allows us to focus on product development. Weโre delivering new features to customers faster.โ
Greg Macsok
Head of Cloud and IT
โThe Cloudflare dashboard abstracts the technical knowledge away from the end user. When I want to configure a new firewall rule, I donโt need to know a programming language.โ
Greg Macsok
Head of Cloud and IT