WAFY
HomeReferences › An Energy and Utilities Major

An Energy and Utilities Major

Part of the F5 Advanced WAF experience behind WAFY, described by business type rather than by name.

Reference

What the work involved.

F5 ASM experience delivering OWASP Top 10 coverage for a large energy provider, deliberately balanced for availability so it kept working as teams continued to ship.

WAFY's F5 ASM experience includes a large energy and utilities provider with a fast-moving, loosely-governed estate. Requirements arrived at a high level, typically 'we are deploying this application and need it to tick the OWASP compliance box', with little underlying knowledge to draw on and no one available to ask for detail. That left room to do the job properly, provided nothing broke. Over a roughly three-month engagement the policies were built to cover most of the OWASP Top 10: full attack signatures with automated signature updates, cookie protection, and entities enabled selectively rather than fully. The looser entity posture was a deliberate choice. With in-house teams continuing to build applications after the engagement ended, the policies had to keep delivering compliance and protection without generating false positives or blocking new functionality once no specialist was on hand. The result was a genuine balance between availability and security that survived ongoing development.

F5 scope
  • Coverage of most of the OWASP Top 10 across a fast-moving energy estate
  • Full attack signatures with automated signature updates
  • Cookie protection and selectively-enabled entities
  • Entity posture deliberately kept looser to balance availability against security
  • Policies designed to keep working, and stay compliant, as in-house teams continued to build