Your WAF and your CDN: actually protecting you, or just turned on?
A deep audit of your edge (Akamai, Cloudflare, F5, AWS CloudFront, Azure Front Door) by someone who spent years configuring these platforms for the world’s most demanding companies.
The problem
You pay thousands a year for a WAF/CDN that a partner configured three years ago and nobody has touched since. Rules in "alert only" mode, exposed origins that allow a full bypass, half-done coverage, and the false comfort of "we have a WAF".
What's included
- WAF configuration review: rules, operating mode, per-application coverage, dangerous exceptions, false negatives
- Edge architecture: origin exposure (can the WAF be bypassed?), end-to-end TLS, caching and its security impact
- Bot and DDoS posture: what you have on, what you’re missing, what you’re paying for without using
- API security review at the edge
How we work
- Read-only console access, or a guided session with your team
- Exhaustive review against each platform’s good practices
- Prioritized gap report
- Technical remediation session with your team or your partner
What you get
- Configuration gap report with severity and evidence
- Prioritized recommended configuration: what to change first and why
- Hands-on technical session
- Executive risk summary
Pricing
from USD 1,000
by platform and number of applications
What this service is NOT
- Not ongoing WAF administration. That’s what monthly advisory is for
- Not a platform migration. We can advise on one separately
- We don’t sell or resell any vendor: our only incentive is that your configuration is right
Frequently asked questions
Do you work with our current partner?
Yes. The report doubles as a work plan for your partner; we usually run the technical session with them in the room.
Do you need admin access?
No. Read-only, or a guided screen-share session with your team.
Want to talk about your case?
A free, no-strings 20-minute intro call. Tell us your context and we’ll tell you honestly whether this service makes sense for you.