As tension between performance and security in iGaming grows, the same real-time, mobile-first growth driving the sector is also creating new vulnerabilities. Noel Penzer, General Manager, SVP EMEA at Fastly, explores for iGaming Expert why operators need to rethink how they protect performance during the industry’s biggest betting moments.
Every growth chart across iGaming looks the same: up and to the right with the slope getting steeper. The global online gambling market is on a trajectory toward roughly $169 billion by 2031, up from around $100 billion this year – a compound annual growth rate of 10.72%! Sports betting alone accounts for more than half of that activity, and live, in-play wagering is closing in on the other half – consistently cited across industry research as the fastest-growing segment of the market – as regulation loosens and operators chase an increasingly mobile, increasingly impatient audience.
That’s the good news.
The uncomfortable implication is this: every one of those growth vectors – real-time wagering, mobile-first engagement, geographic expansion – is also a vector for strain. The same conditions that make iGaming one of the most exciting industries in digital right now also make it one of the most operationally exposed. Growth and vulnerability are the same force in this industry – or in any industry, for that matter – just viewed from two different desks.
The performance bar just got higher, and it’s not moving back down
Live, in-play betting has changed what “fast” means. It used to be enough to load a page quickly. Now, sub-150 millisecond responsiveness is fast becoming the baseline for placing a bet, receiving confirmation, and seeing odds move – because the product itself is the moment. A bettor wagering on the next three points, the next penalty, the next pitch isn’t browsing; they’re participating in something happening in real time, and the platform has to keep pace with the action. If they can’t, the moment is gone. When it lags, the cost isn’t a slow page load – it’s an abandoned bet, a canceled session, and a player who has no qualms trying a competitive platform next time.
Mobile platforms have made this harder, not easier. It’s now the majority revenue channel in iGaming and the fastest-growing one, which means the performance bar has to hold on inconsistent networks, at scale, globally, during the exact moments – kickoff, a buzzer-beater, a title fight – when everyone shows up at once. Traditional CDN architectures, built for relatively static content delivery, were never designed for workloads where every request is dynamic, time-sensitive, and tied to money changing hands.
Attackers read the same growth charts
Here’s the part that doesn’t get discussed enough in the performance conversation: the same peak moments that make platforms valuable also make them targets.
The 2026 FIFA World Cup made this explicit. According to threat research from bot-management vendor DataDome, one major European betting platform absorbed close to 19 million blocked malicious requests over just three weeks around the tournament, with daily blocked traffic climbing from roughly 200,000 requests in early June to a sustained flood by the tournament’s opening days. On the eve of the opening match, that same platform was hit with a flash DDoS attack that fired 786,000 requests in 87 seconds – a burst calibrated to hit at the exact moment attention and revenue exposure were both at their peak.
That wasn’t an isolated event. Cybersecurity firm Qrator Labs reported that the first quarter of 2026 saw a dramatic escalation in DDoS capability, with the largest tracked botnet growing tenfold in a year to roughly 13.5 million compromised devices. In mid-March, a betting company was hit with a 2.065 terabit-per-second attack that sustained peak intensity for 40 minutes, with the attackers shifting tactics eleven times to keep the assault alive. Betting platforms, alongside fintech and payments companies, were named among the sectors bearing the brunt of that surge.
Underneath the headline DDoS numbers sits a quieter, more persistent threat: bots that never announce themselves. Industry research on credential stuffing and account takeover shows the scale involved – enormous, continuously refreshed pools of stolen username + password combinations circulating on criminal marketplaces, tested automatically against login pages around the clock. Fastly’s reports on 2026 bot traffic suggest bots now account for more than half of measured web activity, with a substantial share classified as malicious, and account-takeover attempts having grown sharply year over year as automation has gotten cheaper and more convincing. For an iGaming operator, that traffic isn’t abstract – it’s aimed directly at wallets, deposit flows, and loyalty balances, and it runs whether or not a major event is underway.
Two problems, one root cause
It’s tempting to treat “make it faster” and “make it safer” as separate initiatives, run by separate teams, with separate tools. That’s exactly the model most operators have inherited – a CDN for delivery, a WAF bolted on for security, a separate bot-management layer, separate logging, and a lot of manual coordination between all of them when something goes wrong. It’s a workable model when nothing is happening. However, it buckles under the two conditions iGaming lives in permanently: dynamic, transaction-heavy traffic, and adversaries who specifically target the moments when that traffic peaks.
The reason performance and protection keep colliding in this industry is that they were never actually separate problems. Both come down to the same question: what happens at the edge, in the first few milliseconds after a request arrives, before it ever reaches your origin? If bet validation, odds updates, bot detection, and DDoS mitigation are all handled at that same layer – rather than daisy-chained across disconnected tools – you don’t have to trade speed for security. You get both, because they’re being decided in the same place, at the same time, by the same system.
That’s the architectural shift now underway across the sector: moving from a patchwork of point solutions toward a single programmable edge that can absorb a 2 Tbps attack and shave milliseconds off a bet confirmation without those two jobs ever getting in each other’s way. It’s not a nice-to-have anymore. As live betting keeps growing and attackers keep timing their campaigns to the industry’s biggest moments, the operators who treat performance and security as one problem – solved in one layer – will be the ones still standing when the next World Cup, Super Bowl, or title fight sends traffic through the roof.
In the next installment, we’ll look at the other half of this equation: what happens when that same real-time pressure meets a regulatory map that changes by the state, and sometimes by the week.
On September 8th, SBC Webinars will host Fastly’s Sales Engineer Joseph Younis for How to Stop Bots Turning Online Casinos into Cybercrime Profit Machines.
Join us to explore how operators can detect and stop credential stuffing, account takeovers, bonus abuse and payment fraud at scale.
Register for the webinar here and learn how to protect your platform, players and revenue.
The contested edge: Why iGaming’s growth is also its biggest vulnerability
You’ve shared it!
As tension between performance and security in iGaming grows, the same real-time, mobile-first growth driving the sector is also creating new vulnerabilities. Noel Penzer, General Manager, SVP EMEA at Fastly, explores for iGaming Expert why operators need to rethink how they protect performance during the industry’s biggest betting moments.
Every growth chart across iGaming looks the same: up and to the right with the slope getting steeper. The global online gambling market is on a trajectory toward roughly $169 billion by 2031, up from around $100 billion this year – a compound annual growth rate of 10.72%! Sports betting alone accounts for more than half of that activity, and live, in-play wagering is closing in on the other half – consistently cited across industry research as the fastest-growing segment of the market – as regulation loosens and operators chase an increasingly mobile, increasingly impatient audience.
That’s the good news.
The uncomfortable implication is this: every one of those growth vectors – real-time wagering, mobile-first engagement, geographic expansion – is also a vector for strain. The same conditions that make iGaming one of the most exciting industries in digital right now also make it one of the most operationally exposed. Growth and vulnerability are the same force in this industry – or in any industry, for that matter – just viewed from two different desks.
The performance bar just got higher, and it’s not moving back down
Live, in-play betting has changed what “fast” means. It used to be enough to load a page quickly. Now, sub-150 millisecond responsiveness is fast becoming the baseline for placing a bet, receiving confirmation, and seeing odds move – because the product itself is the moment. A bettor wagering on the next three points, the next penalty, the next pitch isn’t browsing; they’re participating in something happening in real time, and the platform has to keep pace with the action. If they can’t, the moment is gone. When it lags, the cost isn’t a slow page load – it’s an abandoned bet, a canceled session, and a player who has no qualms trying a competitive platform next time.
Mobile platforms have made this harder, not easier. It’s now the majority revenue channel in iGaming and the fastest-growing one, which means the performance bar has to hold on inconsistent networks, at scale, globally, during the exact moments – kickoff, a buzzer-beater, a title fight – when everyone shows up at once. Traditional CDN architectures, built for relatively static content delivery, were never designed for workloads where every request is dynamic, time-sensitive, and tied to money changing hands.
Attackers read the same growth charts
Here’s the part that doesn’t get discussed enough in the performance conversation: the same peak moments that make platforms valuable also make them targets.
The 2026 FIFA World Cup made this explicit. According to threat research from bot-management vendor DataDome, one major European betting platform absorbed close to 19 million blocked malicious requests over just three weeks around the tournament, with daily blocked traffic climbing from roughly 200,000 requests in early June to a sustained flood by the tournament’s opening days. On the eve of the opening match, that same platform was hit with a flash DDoS attack that fired 786,000 requests in 87 seconds – a burst calibrated to hit at the exact moment attention and revenue exposure were both at their peak.
That wasn’t an isolated event. Cybersecurity firm Qrator Labs reported that the first quarter of 2026 saw a dramatic escalation in DDoS capability, with the largest tracked botnet growing tenfold in a year to roughly 13.5 million compromised devices. In mid-March, a betting company was hit with a 2.065 terabit-per-second attack that sustained peak intensity for 40 minutes, with the attackers shifting tactics eleven times to keep the assault alive. Betting platforms, alongside fintech and payments companies, were named among the sectors bearing the brunt of that surge.
Underneath the headline DDoS numbers sits a quieter, more persistent threat: bots that never announce themselves. Industry research on credential stuffing and account takeover shows the scale involved – enormous, continuously refreshed pools of stolen username + password combinations circulating on criminal marketplaces, tested automatically against login pages around the clock. Fastly’s reports on 2026 bot traffic suggest bots now account for more than half of measured web activity, with a substantial share classified as malicious, and account-takeover attempts having grown sharply year over year as automation has gotten cheaper and more convincing. For an iGaming operator, that traffic isn’t abstract – it’s aimed directly at wallets, deposit flows, and loyalty balances, and it runs whether or not a major event is underway.
Two problems, one root cause
It’s tempting to treat “make it faster” and “make it safer” as separate initiatives, run by separate teams, with separate tools. That’s exactly the model most operators have inherited – a CDN for delivery, a WAF bolted on for security, a separate bot-management layer, separate logging, and a lot of manual coordination between all of them when something goes wrong. It’s a workable model when nothing is happening. However, it buckles under the two conditions iGaming lives in permanently: dynamic, transaction-heavy traffic, and adversaries who specifically target the moments when that traffic peaks.
The reason performance and protection keep colliding in this industry is that they were never actually separate problems. Both come down to the same question: what happens at the edge, in the first few milliseconds after a request arrives, before it ever reaches your origin? If bet validation, odds updates, bot detection, and DDoS mitigation are all handled at that same layer – rather than daisy-chained across disconnected tools – you don’t have to trade speed for security. You get both, because they’re being decided in the same place, at the same time, by the same system.
That’s the architectural shift now underway across the sector: moving from a patchwork of point solutions toward a single programmable edge that can absorb a 2 Tbps attack and shave milliseconds off a bet confirmation without those two jobs ever getting in each other’s way. It’s not a nice-to-have anymore. As live betting keeps growing and attackers keep timing their campaigns to the industry’s biggest moments, the operators who treat performance and security as one problem – solved in one layer – will be the ones still standing when the next World Cup, Super Bowl, or title fight sends traffic through the roof.
In the next installment, we’ll look at the other half of this equation: what happens when that same real-time pressure meets a regulatory map that changes by the state, and sometimes by the week.
On September 8th, SBC Webinars will host Fastly’s Sales Engineer Joseph Younis for How to Stop Bots Turning Online Casinos into Cybercrime Profit Machines.
Join us to explore how operators can detect and stop credential stuffing, account takeovers, bonus abuse and payment fraud at scale.
Register for the webinar here and learn how to protect your platform, players and revenue.