I absolutely hate people who claim Cloudflare is their only solution for mitigation/protection, because it simply isn't true, and Cloudfare does some rather shady stuff.
With car insurance, the insurance company has incentive to mitigate their risk, (they don't want to shell out more than they need to,) charging more if you are higher risk. They don't want to take more risk than they have to. Key point, they evaluate risk on a case by case basis.
DDoS mitigators however, they already have invested in the risk by getting the hardware to handle the bandwidth. They don't care if you are attacked or not. Nothing then stops them from playing dirty. This kind of stuff frequently happened with Minecraft servers (what feels like) ages ago. Mitigating services would go out and attack servers, and competitors to get customers to switch to them.
But you still get attacked, but it's like a frame around you, so you don't hurt or damaged. (Here's an example of how Incapsula mitigates DDoS attacks - https://www.incapsula.com/ddos/ddos-mitigation-services.html)
Only if there's no overcharge when an attack happens. If there is, you are in the conflict of interest situation the GP was talking about.
I don't know what is CloudFare billion policy.