Services / Edge security: WAF, CDN & TLS
04
Stop bots and attacks without blocking your real customers.
Onboarding, tuning and hardening on Akamai and Cloudflare, plus AWS WAF and CloudFront. The approach comes from regulated financial services, where false positives cost money and missed attacks cost more.
Who it is for
- Companies hit by credential stuffing, scraping or DDoS
- Teams whose WAF has sat in monitor-only mode for months
- Businesses answering security questionnaires about edge protection
- Teams moving between CDN providers
Signs you need it
- Login endpoints are being hammered
- The WAF blocked real users, so it was switched off
- Your origin servers can be reached directly, bypassing the CDN
- Expired certificates have caused outages
What is included
WAF onboarding
Hostnames and properties onboarded, managed rule sets applied, and a staged rollout from monitor to block.
Tuning and false positives
Log analysis, exceptions scoped as narrowly as possible, and a regular review cycle.
Bot and abuse protection
Rate limiting, credential-stuffing defenses and API protection.
Origin lockdown
Traffic can only reach your servers through the edge, so the WAF cannot be bypassed.
TLS and certificates
Certificate lifecycle and automated renewal, modern protocol settings, and correct origin certificate chains.
What you get
- Configured and tuned edge security policy
- Rule documentation and change log
- Monitoring and alerting
- Tuning playbook for your team
Timeline
- Week 1
Traffic review and policy design
- Weeks 2–3
Onboarding in monitor mode, tuning on real traffic
- Week 4
Switch to blocking, then handover
Project for onboarding; monthly retainer for ongoing tuning.
Common questions
Akamai or Cloudflare?
Both are strong. Cloudflare is usually simpler and cheaper for smaller companies; Akamai is common in enterprises and regulated industries. We work with either.
Will turning on a WAF break our site?
Not when it is rolled out properly. It starts in monitor mode, we study real traffic, and rules only switch to blocking once false positives are handled.
OTHER SERVICES