Amazon debuts AWS Shield, its Cloudflare competitor, to protect against DDoS attacks, and offers two tiers; basic version will be on by default
Todd Bishop / GeekWire :
Context & Ripple Effects
With AWS Shield, Amazon is extending a pattern it started earlier: applying to become a root Certificate Authority in 2015, then adding default encryption to S3 a year later — each time pulling a security layer customers previously bought separately inside the AWS bill. The twist this time is the named incumbent: Cloudflare built its business on standing between websites and DDoS traffic, and the basic Shield tier being on by default means every AWS customer gets that layer without asking for it.
First-order effects
- Every AWS customer gains baseline DDoS protection by default, with a second paid tier for those who want more — no procurement step required.
- Cloudflare's core product now competes directly with a bundled offering from the largest cloud provider, which can absorb the cost of basic protection.
Second-order effects
- Cloudflare's answer comes within a year: free Unmetered Mitigation, matching Amazon's move to give away what was once the paid product.
- Google follows the same playbook on its own platform with ML-powered Cloud Armor Adaptive Protection, turning DDoS defense into a table-stakes feature across all three major clouds.
Third-order effects
- Standalone DDoS protection drifts from product to default capability, pressuring specialists to differentiate on scale and intelligence rather than availability — an escalation that shows up later as AWS Shield absorbing a 2.3 Tbps attack, then the largest on record.
The trend: Security functions that specialists once sold as products are being absorbed by hyperscalers as always-on defaults, forcing incumbents like Cloudflare to compete on mitigation capacity instead.