- INDUSTRY :
- KEY PRODUCT:

COST SAVINGS
ROI
PROFESSIONAL
SERVICES COST
SECURITY SERVICE
Company Overview

JTB is one of Japan’s leading travel companies, operating a wide range of travel services, websites, and digital platforms.
The Challenge
- Needed to migrate from a private cloud in their data center to a public cloud environment
- Wanted to leverage a native public cloud WAF, but had concerns about ongoing operations
- Required maintaining the same level of security as their previous third-party WAF
- Concerned that managed rules could increase operational workload due to false positives and overblocking
The Solution
The Results
- Eliminated operational concerns with automated rule management and IP blocklisting via WafCharm
- Achieved stable WAF operations with no major incidents since deployment
- Maintained equivalent security levels by combining WafCharm with CloudFastener
- Reduced operational overhead and vendor dependency
Conclusion
Rebuilding Security During the Shift to Public Cloud
—Can you tell us about your business and your roles?
We operate primarily in the travel industry and manage a large number of travel-related websites and online services.
The Web Systems Solutions Department is responsible for planning, operating, and maintaining the websites used by our Web Sales Division. This includes improving user experience, enhancing content, and managing security.
The IT Planning Team oversees company-wide infrastructure and leads cross-functional IT initiatives and system-related projects.
—What led to your migration to the public cloud?
We had been running a private cloud environment in our own data center for many years. However, we began facing challenges in scalability, operational efficiency, and cost.
As a result, we decided to shut down the data center and move to the public cloud.
Some of our business units had already been building systems in the public cloud, so we had internal expertise in place. That made the decision to migrate much easier.

—Why did you choose a public cloud WAF?
Security has always been a priority for us. In our previous environment, we used a third-party cloud-based WAF with strong vendor support, including dedicated teams and regular meetings.
However, as part of our cloud migration, we wanted to reduce points of failure and simplify our architecture. That made a cloud-native WAF the more attractive option.
Cost was also a factor. Compared to our previous third-party WAF, the public cloud WAF’s pay-as-you-go pricing model offered better cost efficiency.
Why Automation Made the Difference
—What challenges did you face when implementing the public cloud WAF?
Once we decided to move forward, managing WAF rules became a major challenge.
Our previous WAF was somewhat of a black box, and understanding its rule sets was difficult. We struggled to determine how to migrate those rules effectively.
We also looked at managed rules, but there were too many options, making it hard to decide which ones to use. We weren’t confident that managed rules alone would provide the same level of protection.
Additionally, we were concerned about false positives and overblocking. Since we didn’t have enough in-house expertise for tuning, we worried that operational workload could actually increase.
That’s when we started looking for a solution that could address these operational challenges more holistically.

Why We Chose WafCharm
—How did you discover WafCharm, and what stood out?
We were already familiar with WafCharm and had previously used CSC’s managed rules for API Gateway.
For this project, however, our priority was not just applying rules—we needed to reduce operational workload while maintaining strong security.
WafCharm stood out because it automates WAF operations end-to-end, rather than focusing on individual rule sets.
The automated IP blocklist feature was especially valuable. Manually identifying malicious IPs from logs and updating blocklists is time-consuming. With WafCharm, this process is fully automated.
We also appreciated that WafCharm is available through the public cloud marketplace, which added an extra level of trust.
Another important factor was support. Many marketplace solutions are overseas products, which can create communication challenges due to language barriers and time zones. With WafCharm, we had access to reliable, local-language support.
We wanted a solution that would allow us to proactively maintain strong security operations without increasing costs—and WafCharm aligned perfectly with that goal.
Addressing Concerns with a Broader Security Approach
—Did you have any concerns before adopting WafCharm?
Our biggest concern was whether we could maintain the same level of security as our previous third-party WAF.
There were internal concerns about operational stability, and I personally shared some of those concerns.
During the evaluation process, Cyber Security Cloud also introduced us to CloudFastener, a fully managed security service for public cloud environments.
CloudFastener provides a dedicated Technical Account Manager (TAM) who offers tailored guidance and ongoing support.
By combining WafCharm for WAF automation and CloudFastener for broader cloud security monitoring, we felt confident that we could maintain—and even improve—our overall security posture.
This combined approach also helped address internal concerns and made it easier to gain stakeholder buy-in.
Stable Operations with Less Effort
—What results have you seen since implementation?
In short, the system has been extremely stable.
It’s been several months since deployment, and we haven’t experienced any major incidents. We also haven’t received any complaints from the team managing the system, which speaks to how smoothly things are running.
We regularly monitor blocking activity, and it remains consistent with our previous WAF. We’re confident that malicious traffic is being properly handled.
Another major benefit is that we no longer need to coordinate with a third-party WAF vendor. Previously, we had regular meetings, but those are no longer necessary thanks to automation.
From a cost-performance standpoint, even with both WafCharm and CloudFastener, we’ve reduced costs while maintaining—or even improving—our security level.

Looking Ahead: Security as a Continuous Priority
—What are your future plans for security?
We see security as a critical component of business continuity.
Recent incidents affecting large enterprises have shown that no organization is immune. There’s no such thing as “complete” security—it’s something that must continuously evolve.
As we continue expanding globally, building a security framework that supports global operations will be a key priority.
Advice for Other Organizations
—What advice would you give to companies facing similar challenges?
Implementing security solutions is essential, but more isn’t always better.
Instead of simply replicating what you’ve done in the past, it’s important to clearly define your requirements and choose solutions that align with them.
Security also doesn’t end with implementation—you need to plan how it will be operated over time.
Fully outsourcing everything isn’t ideal, but handling everything in-house can also be challenging due to limited resources. The key is finding the right balance between internal ownership and external support.
—Thank you.