· via dev.to (home feed)
Radware opens Thailand cloud security service center, pitching behavior-based defenses
Radware opened a cloud security service center in Thailand, using a Bangkok launch event to pitch behavior-based defenses against authenticated attacks, business logic abuse and AI agents.

Radware has opened a cloud security service center in Thailand, marking the launch with a customer and partner event at the Ritz-Carlton in Bangkok on 8 October 2026. According to a dev.to write-up by an engineer who attended the plenary, which carried the theme "Investing in Thailand's AI and Security Transformation: Technology. Talent. Trust.", the day combined the site announcement with a broader argument: many damaging attacks now arrive with valid credentials, so defenses need to watch behavior rather than rely on signatures alone.
What the new center offers
Slides shown at the event, as summarized on dev.to, describe Radware as having roughly 1,200 employees, 40 Tbps of global DDoS mitigation capacity and a network of more than 60 cloud security centers, with Thailand the newest addition. The service lineup presented includes WAF, bot management, API security, account takeover protection, client-side protection, DDoS protection and threat intelligence.
The reviewer flags two gaps. The slides do not state the Thai site's own capacity, and the company-level figures are Radware's own. A local center may improve latency and help answer questions about traffic paths, the write-up notes, but a presence in Thailand does not by itself mean that TLS termination or log storage happen in-country; both should be confirmed with the vendor in writing.
Attacks that log in correctly
Radware's central pitch, per the dev.to review, is the attacker who authenticates successfully: replayed credentials used at scale, bots that have learned an application's flow, or scripts that follow each step exactly. Because every request looks legitimate, signature matching has little to work with, and malicious intent instead shows up in behavior. The reviewer adds context the slides skipped: behavioral detection is a common approach to account takeover, but it can generate false positives and usually needs tuning to an organization's own traffic.
A related segment covered business logic abuse, with three examples: altering a value the application trusts, such as a transfer amount; skipping or repeating steps in a workflow, like bypassing an approval; and scraping rates, offers and customer data at machine speed. No vulnerability is exploited and every request is a valid API call, so generic rules may not catch it. Workflow analysis and server-side validation remain baseline controls, the review argues, with runtime API behavior analysis acting as an additional layer rather than a substitute.
The event also posed three self-assessment questions for security teams: whether every exposed API and AI agent is known before go-live, including undocumented ones; who protects those endpoints while customers, apps and agents use them in production; and how behavior and risk scoring are tracked as they change. Any answer that starts with uncertainty signals a gap, the slides suggested.
Agentic AI controls
The final portion presented Radware's agentic AI solution. As described on dev.to, a policy enforcer discovers, classifies, enforces policy on and monitors AI agents, separating approved tools from unmanaged "shadow AI" such as desktop apps and browser extensions. The slides reference the EU AI Act, GDPR, NIST AI RMF and ISO/IEC 42001.
Runtime security runs at two levels: agent-level detection of misuse, prompt injection and tool abuse, and an LLM-level configurable policy covering prompts and inputs, data and privacy, content safety, file attachments and resource usage. A diagrammed traffic path runs from the internet through DDoS protection, firewall, WAF, bot management and LLM guardrails before reaching agents with a behavioral layer.
What the slides did not provide, the reviewer notes, are detection rates, false-positive rates or results from tests with real agents. Behavioral monitoring of agents is still a developing area in both technology and industry practice, so the recommendation is to define success criteria and test in your own environment.
Why it matters
The Thailand center extends Radware's global security network and may reduce latency for local customers, but the write-up shows how much of a launch rests on vendor-reported figures that no third party has tested. The direction, however, is clear: the highlighted threats — account takeover, bots, business-logic abuse and AI agents acting with user permissions — all occur after authentication, which pushes the industry toward behavioral and runtime defenses layered on top of signature checks. For buyers, the practical follow-ups are the verification questions raised in the review: where TLS termination and log storage occur, what capacity the Thai site has, how detection and false-positive rates were measured, whether API testing covers abuse of business flows and not just vulnerability scanning, and how an inventory of unapproved APIs and AI agents gets built. As the review concludes, real effectiveness has to be measured against an organization's own traffic.
- #cloud-security
- #ddos-protection
- #api-security
- #agentic-ai
- #radware
- #thailand