WAFY's F5 ASM experience includes a UK general insurer with a very different challenge: almost no line to the application teams. Much of the estate was installed and configured SaaS rather than software built in-house, and the small internal team configured products rather than developing them, so there was often no one who could explain how a given application actually behaved. The Advanced WAF (ASM) policies therefore had to be built largely from the traffic itself. Product managers were resistant to putting OWASP-aligned ASM policies in front of their applications, but the directors backed the work, and each policy was built and tuned as tightly as the available information allowed. DDoS protection was a significant part of the engagement. After around nine months the insurer was satisfied the protection was working, and the engagement closed.