WAFY's F5 ASM experience includes a government and public-sector body implementing new internal services to support its work. These were not public-facing services, and the engagement was handled with a high degree of discretion. Advanced WAF (ASM) policies were required as part of the organisation's own internal security procedures, and were built to be fully OWASP-compliant. As is typical in government, progress ran through many meetings and deliberate, slow decision-making over an extended period, so a large part of the work was delivering carefully governed, well-documented policy work at the pace the organisation's processes allowed.