WAFY
HomeFixed Price Services › ASM policy review

ASM policy review

An audit of an existing Advanced WAF policy: enforcement state, signatures, entities, false positives and OWASP coverage, delivered as a prioritised findings report. The fastest way to find out what a policy is really doing.

What's included

A complete package.

Plenty of ASM policies are switched on but never trusted, stuck in transparent, riddled with false positives, or enforcing far less than the owner thinks. WAFY reviews an existing policy end to end: enforcement mode, signature sets and staging, entity coverage, learning backlog, false-positive hotspots and OWASP alignment, then hands you a plain-English, prioritised report. It is the natural first step before we take a policy under management.

From £750 · Per policy
Scope: Read-only review. Findings and recommendations only; remediation and tuning are quoted separately or covered under a subscription.
  • Delivered remotely
  • Enforcement, signatures, entities and staging reviewed
  • False-positive and OWASP-coverage assessment
  • Prioritised findings and recommendations report
In practice

When ASM policy review gets booked.

Illustrative examples, not a fixed list. If your job is the same shape, it fits.

Inherited policy

You have taken on a policy you did not build and need to know what it enforces and what it misses.

Stuck in transparent

A policy that has never made it to blocking, reviewed to find out what is holding it back.

Pre-management baseline

An independent baseline before WAFY takes the policy under a managed subscription.

One job, done properly

Book ASM policy review

Enquire and WAFY will scope it, confirm a fixed price in writing, and schedule it into the next window.