WAFY's F5 ASM experience includes a large energy and utilities provider with a fast-moving, loosely-governed estate. Requirements arrived at a high level, typically 'we are deploying this application and need it to tick the OWASP compliance box', with little underlying knowledge to draw on and no one available to ask for detail. That left room to do the job properly, provided nothing broke. Over a roughly three-month engagement the policies were built to cover most of the OWASP Top 10: full attack signatures with automated signature updates, cookie protection, and entities enabled selectively rather than fully. The looser entity posture was a deliberate choice. With in-house teams continuing to build applications after the engagement ended, the policies had to keep delivering compliance and protection without generating false positives or blocking new functionality once no specialist was on hand. The result was a genuine balance between availability and security that survived ongoing development.