WAFY's F5 ASM experience includes a global payments gateway, a fast-growing startup for whom demonstrable security was a launch-critical selling point. As with several of these engagements there was little internal knowledge to draw on, so the policies were built from the ground up: full attack signatures and fully OWASP-compliant enforcement, delivered through change management. Because it was a payment gateway, a large part of the work was API security to the OWASP API Top 10, alongside the OWASP web Top 10, with heavy emphasis on session-theft protection through cookie protection and JWT handling. The estate spanned multiple sites across the globe, load-balanced with F5 GTM, and the ASM policies had to stay identical everywhere, kept in step across all sites through a custom sync group. Protection also covered brute-force and anonymity and web-scraping detection, and a significant DDoS element.