Results
- Endpoints achieved 99.99% uptime by reducing bot traffic spikes.
- Blocked massive "invisible" bot traffic: Kasada stopped 16M scraping attempts (previously labeled "legitimate") in one month, revealing ~80% of total site traffic was bot-driven scrapers.
- Rapidly generated millions in bottom-line savings by delivering time-to-value under 30 minutes, eliminating costly, friction-generating solutions.
- Offered versatile multi-page, multi-site protection, closing defense gaps while reducing friction and latency for authentic users.
- Dramatically reduced the need for manual bot mitigation (saving hundreds of hours) and stabilized performance, mitigating downtime risk valued at ~$100K per hour.
A global hospitality enterprise with 20 premier brands and more than 900 hotel and resort properties in 65 countries across six continents, Hyatt’s purpose — “to care for people so they can be their best” — informs every business decision it makes, including its technology investments.
Hyatt is known for its commitment to operational excellence and distinct guest experiences, and its IT and digital product teams aspire to the same high caliber, working in tandem with the cybersecurity team that prides itself on “leaving no stone unturned.”
At Hyatt, we do our very best every day to protect our guests’ and our colleagues’ information, and we continuously evaluate strategic opportunities to strengthen our cyber defense systems. As one of our most important digital assets, it’s critical that we have myriad controls and layers of protection for hyatt.com. We have a robust combination of human expertise, policies, systems, and solutions in place to protect our digital platforms—and we find Kasada to be one of our most valuable controls within our ecosystem.
— Benjamin Vaughn, Vice President and Chief Information Security Officer, Hyatt
Addressing Tech, Platform Ops, and Information Security Needs
Before implementing Kasada, Hyatt used two primary lines of bot defense, among several layers of platform, to contain standard, albeit potentially damaging, issues, such as fake login attempts, account takeover, and credential stuffing.
Room rate data is extremely valuable information for other parties in the industry.
— Benjamin Vaughn, Vice President and Chief Information Security Officer, Hyatt
Jason Ayson, Director of IT, E-Commerce Technology at Hyatt concurred: “We needed solutions that could help us get ahead of the evolving threat landscape and approaches of the malicious threat actor, as well as protect us from potential attacks in the future. To get a firsthand look at Kasada’s solution, we ran a POC to test its ability to produce the evolving protection it promised without requiring the level of manual intervention that our teams were used to.”
Vaughn added, “We ran the POC through our search pages for specific browser user agents and were able to see the full picture of all traffic processed by Kasada, including bots. With this insight, we could see the value in Kasada right away.”
When we place Kasada in front of an endpoint, we are very confident that there won’t be any bots hitting that endpoint anymore, which enables our digital team to know that the traffic stream is real guests and customers. The false positive rate is incredibly low and we now have more robust and actionable data.
— Benjamin Vaughn, Vice President and Chief Information Security Officer, Hyatt
Capacity Growth and ROI
Hyatt benefits from Kasada’s solution in terms of its capacity growth strategy. “Every time we added capacity, it was consumed by unprofitable traffic,” said Lawson Kelly, Vice President and Global Chief Technology Officer. “Kasada allowed us to slow our rate of capacity growth so that we could extend the useful life of that capacity. Instead of being consumed in three years, it is extended to five years, which defers future cost rather than lowering current cost. This enables us to model a more accurate capacity growth strategy rather than having to over-invest.”
Across departments, the ROI from Kasada was evident and nearly immediate at both the human and machine levels. Vaughn explained, “Here’s an easy way to look at ROI: an attacker gaining access to a single guest account would be unacceptable to us. The first time Kasada prevented an account takeover event, we saw value.”
He added, “We see very regular updates and new features added to the product—indicating Kasada’s commitment to continuous improvement—and full transparency on pricing. From a service standpoint, Kasada offers us an embedded, finely integrated support model that ensures the right actions are taken at the right time. Having their support team available to answer questions 24/7 is something very special. It’s immersive and demonstrates something we highly value at Hyatt—commitment to genuine care.”
Following deployment, Hyatt saw a 90%+ reduction in automated attacks and infrastructure load from non-human traffic decreased by ~30%, improving reliability and performance with no added guest friction.
Running on AWS
Kasada’s platform protecting Hyatt runs on AWS, leveraging Amazon EKS for real-time inspection, Amazon MSK and Apache Flink for telemetry processing, Amazon DynamoDB and ElastiCache for policy and session state, and Amazon S3 and Athena for secure analytics, while integrating with Amazon CloudFront, AWS WAF, and AWS Shield to protect Hyatt’s edge and application layer.

