A device-wide F5 attack signature update across the whole ASM module. A signature update lands on every policy on the box, not just the ones under management, so this is priced per module, not per policy. We review the current signature state first and confirm the price.
A signature update is a device-level job, not a policy-level one. When the update is imported it lands on every policy on the F5 ASM module, so before anything enforces we check that every policy stages new signatures, otherwise new signatures jump straight to blocking and break production. That is why this is priced per module (a base of £1,250 plus £50 per policy on the box), and why we review the current signature state before we quote. If the module has not been updated for six months, a year, or as we have seen, three years, there is a large backlog of signatures to import and a correspondingly large amount of learning-suggestion review and false-positive tuning, so the price can move up or down against the base. Once staged and tuned, we promote to blocking and hand over a before/after note.
Illustrative examples, not a fixed list. If your job is the same shape, it fits.
A module reviewed on a regular cadence, so each update brings a small, manageable set of new signatures to stage and tune.
A sizeable backlog of signatures imported in one controlled pass, with the extra learning suggestions and false positives worked through carefully.
A large backlog: every policy on the module checked for safe staging first, then signatures staged and tuned in stages before promotion.
Enquire and WAFY will scope it, confirm a fixed price in writing, and schedule it into the next window.