WAFY
HomeReferences › A UK General Insurer

A UK General Insurer

Part of the F5 Advanced WAF experience behind WAFY, described by business type rather than by name.

Reference

What the work involved.

F5 ASM experience building Advanced WAF policies for a SaaS-heavy insurance estate with no application-team input, and getting them accepted and enforcing.

WAFY's F5 ASM experience includes a UK general insurer with a very different challenge: almost no line to the application teams. Much of the estate was installed and configured SaaS rather than software built in-house, and the small internal team configured products rather than developing them, so there was often no one who could explain how a given application actually behaved. The Advanced WAF (ASM) policies therefore had to be built largely from the traffic itself. Product managers were resistant to putting OWASP-aligned ASM policies in front of their applications, but the directors backed the work, and each policy was built and tuned as tightly as the available information allowed. DDoS protection was a significant part of the engagement. After around nine months the insurer was satisfied the protection was working, and the engagement closed.

F5 scope
  • Advanced WAF (ASM) policies built for a SaaS-heavy estate with almost no in-house development
  • Policies modelled from live traffic, with no application-team knowledge available to draw on
  • OWASP-aligned enforcement delivered with director sponsorship despite product-side resistance
  • Each policy tuned as tightly as the available information allowed
  • A significant DDoS protection element
  • Protection accepted as working after around nine months