we have had to implement CloudFlare
No, you didn't have to.
There are plenty of alternatives to CloudFlare that are actually good at what they do.
Barring that, there are hosts that provide excellent, creative, and sometimes passive protection against DOS and bots while also giving you the tools to further build your own protection to that end. I've run a 10k+ user site with guest (non-login) features for 8+ years now with zero DOS attacks and bot behavior below the level of noise. I host with Nearly Free Speech, but there may be others like it.
https://ancillary-proxy.atarimworker.io?url=https%3A%2F%2Fwww.nearlyfreespeech.n...
Our current situation remains unchanged: CloudFlare is still blocking our access to websites through the challenges, and the captcha/turnstile continues to hang the browser until our watchdog terminates the hung script after which it reloads and hangs again after a short pause (but allowing users to close the tab in that pause, at least). To say that this upsets me is an understatement. Other than deliberate intent or absolute incompetence, I see no reason for this to endure. Neither of those options are very flattering for CloudFlare.
I wish I had better news.
A conclusion is simply the place where someone got tired of thinking.