Protecting Global Ticketing While Maximizing Conversion & User Experience


Your WAF is quietly blocking some of your real users, and the evidence never reaches your application logs - only the WAF’s. Three true stories: a share button that dies at 21 KB, a tracking cookie unlucky enough to contain --, and users in Portugal spending a summer unable to tell a server what time it is. Plus numbers on which rules teams end up switching off fleet-wide, and a live demo where you trip a real firewall yourself.
Overview
Merlin Entertainments, Europe’s largest theme park operator and the second biggest globally after Disney ,operates some of the world’s most iconic entertainment brands - including Legoland, Madame Tussauds, Sea Life, Minecraft parks, and many more - serving millions of guests each year across theme parks, attractions, and global digital ticketing platforms. As Merlin expanded its digital presence and customer acquisition efforts, its websites began processing massive volumes of traffic from an increasingly diverse mix of sources, including paid campaigns, partnerships, affiliates, and emerging channels such as AI-driven discovery and LLM-based search.
During peak seasons and major campaigns, availability, performance, and user experience directly impact revenue. Security must ensure that only malicious traffic is blocked-while legitimate ticket buyers are allowed through without friction.
While Merlin relied on industry-leading WAF and edge technologies to protect its digital estate, operating these tools at global scale introduced new challenges. Traditional edge security solutions lack context, making it so difficult to tune-especially in environments where legitimate customer traffic, scraping, and malicious activity can look increasingly similar and hard to differentiate.
Merlin partnered with Huskeys to elevate its edge security posture-ensuring protection of revenue, brand trust, and guest experience, while enabling continued digital growth.
The Challenge
As Merlin’s digital footprint and online ticket sales continued to grow, several challenges became clear
- Brand-level risks beyond pure edge security like subdomain takeover and brand abuse
- Legitimate ticket buyers were being blocked by generic managed WAF rules
- False positives impacted critical booking and checkout journeys
- Limited visibility across a complex environment spanning multiple providers, third parties, iframes, and integrations
- Complexity, that make it difficult to understand how security decisions impacted conversion, revenue, and performance
- Manual WAF tuning that could not keep pace with new traffic sources and campaigns
Merlin needed a way toprotect its entire brand and digital ecosystem, while empowering marketing and digital teams to scale traffic confidently. At the same time, the security team wanted to transform operations and become a driver of business growth.
“Huskeys stands out as one of the strongest innovations I’ve seen in web application security. Its AI Adaptive Control Plane delivers exceptional protection by intelligently tuning and augmenting any existing WAF in real time turning good defenses into truly resilient ones. What impresses me most is the ease of deployment: it integrates seamlessly without requiring architecture overhauls, agents, or lengthy configurations often up and running in hours, not weeks. Since implementing Huskeys, we’ve significantly hardened our current WAF, reducing false positives, catching sophisticated threats that previously slipped through, and elevating overall security posture without adding operational complexity.”
Why Huskeys
Huskeys provides a plug-and-play, AI-powered Control Plane that sits on top of existing WAF and edge infrastructure. Rather than replacing Merlin’s security stack, Huskeys added context, intelligence, and orchestration-aligning edge controls with business goals.
With Huskeys, Merlin Gained
- Comprehensive edge & WAF assessment A deep evaluation of Merlin’s existing setup to identify misconfigurations, coverage gaps, shadow rules, cost-saving opportunities, and performance bottlenecks-improving both security posture and business outcomes.
- False-positive reduction with business context Rule tuning informed by real user journeys, endpoints, and revenue impact-not just static managed rules-providing clear insight into how WAF controls affected ticket selection, checkout, and payment flows.
- Brand and external surface protection Continuous discovery and monitoring of external assets to identify risks such as subdomain takeover, exposed services, and brand abuse-before exploitation.
- Unified visibility across teams A shared view of traffic, endpoints, and risk that enabled security, marketing, and e-commerce teams to operate from a single source of truth.
- Smart orchestration and automation Rapid conversion of findings-false positives, posture gaps, brand exposure risks, and incident signals-into validated, production-ready WAF and edge controls, deployed safely and quickly.
Why It Matters
As digital teams drive more traffic from an expanding set of channels - ads, partnerships, and AI-driven discovery - security must evolve from a blocking function into a business enabler.
Huskeys helps organizations like Merlin Entertainments ensure that security enables growth instead of slowing it down, protects users, revenue, and brand trust that turning edge protection into a competitive advantage and the biggest revenue generator.