
Protecting Global Ticketing Platforms While Maximizing Conversion, Performance, and User Experience - Transforming Security Teams into Revenue Enablers

Ready to start?
Overview

Merlin Entertainments, Europe’s largest theme park operator and the second biggest globally after Disney ,operates some of the world’s most iconic entertainment brands - including Legoland, Madame Tussauds, Sea Life, Minecraft parks, and many more - serving millions of guests each year across theme parks, attractions, and global digital ticketing platforms. As Merlin expanded its digital presence and customer acquisition efforts, its websites began processing massive volumes of traffic from an increasingly diverse mix of sources, including paid campaigns, partnerships, affiliates, and emerging channels such as AI-driven discovery and LLM-based search.
During peak seasons and major campaigns, availability, performance, and user experience directly impact revenue. Security must ensure that only malicious traffic is blocked-while legitimate ticket buyers are allowed through without friction.
While Merlin relied on industry-leading WAF and edge technologies to protect its digital estate, operating these tools at global scale introduced new challenges. Traditional edge security solutions lack context, making it so difficult to tune-especially in environments where legitimate customer traffic, scraping, and malicious activity can look increasingly similar and hard to differentiate.
Merlin partnered with Huskeys to elevate its edge security posture-ensuring protection of revenue, brand trust, and guest experience, while enabling continued digital growth.
The Challenge
As Merlin’s digital footprint and online ticket sales continued to grow, several challenges became clear:
- Brand-level risks beyond pure edge security like subdomain takeover and brand abuse
- Legitimate ticket buyers were being blocked by generic managed WAF rules
- False positives impacted critical booking and checkout journeys
- Limited visibility across a complex environment spanning multiple providers, third parties, iframes, and integrations
- Complexity, that make it difficult to understand how security decisions impacted conversion, revenue, and performance
- Manual WAF tuning that could not keep pace with new traffic sources and campaigns
Merlin needed a way to protect its entire brand and digital ecosystem, while empowering marketing and digital teams to scale traffic confidently. At the same time, the security team wanted to transform operations and become a driver of business growth.
“Huskeys stands out as one of the strongest innovations I’ve seen in web application security. Its AI Adaptive Control Plane delivers exceptional protection by intelligently tuning and augmenting any existing WAF in real time turning good defenses into truly resilient ones. What impresses me most is the ease of deployment: it integrates seamlessly without requiring architecture overhauls, agents, or lengthy configurations often up and running in hours, not weeks. Since implementing Huskeys, we’ve significantly hardened our current WAF, reducing false positives, catching sophisticated threats that previously slipped through, and elevating overall security posture without adding operational complexity.”
Matthew Wilmot, Merlin Entertainments
Why Huskeys
Huskeys provides a plug-and-play, AI-powered Control Plane that sits on top of existing WAF and edge infrastructure. Rather than replacing Merlin’s security stack, Huskeys added context, intelligence, and orchestration-aligning edge controls with business goals.
With Huskeys, Merlin Gained:
- Comprehensive edge & WAF assessment
A deep evaluation of Merlin’s existing setup to identify misconfigurations, coverage gaps, shadow rules, cost-saving opportunities, and performance bottlenecks-improving both security posture and business outcomes. - False-positive reduction with business context
Rule tuning informed by real user journeys, endpoints, and revenue impact-not just static managed rules-providing clear insight into how WAF controls affected ticket selection, checkout, and payment flows. - Brand and external surface protection
Continuous discovery and monitoring of external assets to identify risks such as subdomain takeover, exposed services, and brand abuse-before exploitation. - Unified visibility across teams
A shared view of traffic, endpoints, and risk that enabled security, marketing, and e-commerce teams to operate from a single source of truth. - Smart orchestration and automation
Rapid conversion of findings-false positives, posture gaps, brand exposure risks, and incident signals-into validated, production-ready WAF and edge controls, deployed safely and quickly.
The Scale
Huskeys operated across Merlin’s global digital estate, including multiple flagship brands and high-traffic booking platforms:
- Thousands of internet-facing assets and endpoints analyzed
- Multiple global ticketing and booking websites protected
- Hundreds of security rules reviewed and optimized
- High-volume, globally distributed traffic continuously analyzed
All improvements were delivered without agents, without downtime, and without disrupting live sales, using simple API-based integrations.
Security and Growth Working Together
A key outcome of the engagement was breaking down silos between Merlin’s security teams and its digital, marketing, and e-commerce stakeholders.
As marketing teams launched new campaigns and acquisition channels, we ensured that:
- Legitimate traffic was recognized, validated, and allowed
- New traffic patterns could be assessed and adapted to quickly
- Security controls evolved alongside marketing activity, not after incidents occurred
This transformed the role of the security team into a business driver and growth enabler, protecting the organization while actively supporting revenue generation.
Measurable Outcomes
Posture, Performance, and Edge Optimization
By removing unnecessary friction at the edge, Huskeys helped Merlin protect revenue-generating journeys while maintaining strong, consistent security.
Results:
- Overall edge and WAF posture improved by 70%+
- Thousands of dollars per month in cost savings through configuration and rule optimizations
- 40%+ improvement in website performance and availability
- Enhanced detection, investigation, and prevention of DDoS attempts, strengthening overall infrastructure resilience
- Better protection across booking flows, third-party integrations, and external-facing assets
Continuous monitoring and defense against brand-level risks, including subdomain takeover and abuse.
Faster, Safer Security Operations
Manual WAF tuning was replaced with intelligent automation and guided decision-making.
Results
- Security changes and validations deployed in minutes instead of weeks
- 90%+ reduction in manual WAF tuning effort
- Faster support for new campaigns, traffic sources, and acquisition channels
Real-World Example: Dramatic Reduction in False Positives
During the engagement, Huskeys identified and resolved false-positive patterns caused by existing managed WAF rules that were directly blocking legitimate users on ticketing and booking endpoints.
In one scenario, legitimate users arriving from marketing campaigns were blocked by a default managed rule from the existing WAF vendor. An overly broad SQL injection detection—triggered by third-party tracking cookies - prevented users from accessing ticketing pages and directly impacted sales.
Results
- 80%+ reduction in false positives across booking and checkout journeys
- Tens of thousands of unique legitimate ticket requests restored monthly
- Critical purchase flows no longer disrupted by generic managed rules
- Improved conversion and confidence during peak traffic periods
- Millions of dollars in revenue preserved by preventing unnecessary traffic loss
The Business Impact
With Huskeys, Merlin Entertainments achieved:
- Strong protection without sacrificing ticket sales
- Fewer false positives across booking and checkout flows
- Improved website performance and guest experience
- Clear alignment between security decisions and business outcomes
- Greater return on existing WAF and CDN investments
- A security team recognized as a key enabler of growth
Huskeys enabled Merlin to move from static managed rules into a dynamic, brand-aware, and growth-enabling edge security model.
Why It Matters
As digital teams drive more traffic from an expanding set of channels - ads, partnerships, and AI-driven discovery - security must evolve from a blocking function into a business enabler.
Huskeys helps organizations like Merlin Entertainments ensure that security enables growth instead of slowing it down, protects users, revenue, and brand trust that turning edge protection into a competitive advantage and the biggest revenue generator.

