What the service covers

A WAF is no substitute for careful development, but it buys time: a hole found today is closed with a rule now and fixed in code in the next release.

Talk it through with us

Filtering

Blocking of well-known attack types: SQL injection, cross-site scripting, path traversal and probing of admin pages.

Login protection

Limits on login attempts for wp-admin and customer accounts, plus protection of the »forgotten password« flow.

Bots

Search engines are let through while scrapers, stock-checking bots and malicious automation are kept out.

Virtual patching

A vulnerability in a plugin is closed with a rule until the vendor releases a fix.

Forms

Spam in contact and quote forms is filtered without losing genuine enquiries.

Reports

What was blocked, where it came from and which rule caught it, in a monthly summary.

How we deliver it

Connecting the WAF takes a few days, but tuning the rules to your site takes longer than the setup itself.

01

Analysis

Platform, forms, customer login, payments through Nets, Quickpay or Stripe, and integrations.

02

Learning mode

The WAF runs without blocking and builds a picture of genuine traffic.

03

Tuning

False positives are removed. A live site always has some.

04

Enforcement

Blocking is enabled, and alerts plus a regular review are put in place.

A new site is scanned before it receives its first real visitor. There is no need to wait for a targeted attack: bots try admin panel addresses and known flaws in popular plugins day and night. That is why the WAF goes in at launch rather than after the first incident.

Common questions

A cloud WAF is simpler, usually cheaper and speeds up the site through a CDN at the same time. A self-hosted WAF makes sense when rules forbid routing traffic through an outside service, or when the site is not public at all.

They are reviewed during the first month and the rules adjusted. They never vanish completely, but they can be brought down to the odd case. That is why we never skip learning mode.

No. A WAF gives you breathing space, not immunity. It stops known attack patterns but cannot see logic flaws in your own business rules. Updates still have to be installed.

A cloud WAF absorbs most simple application-layer flooding. Large volumetric attacks need the provider's DDoS protection, which can often be added from the same vendor.

Protect your website

Describe the site and its platform. We will pick a suitable WAF and tune the rules to your traffic.

Coverage
All of Denmark, delivered remotely

This site uses only essential cookies: they keep pages working and store your chosen town. Read more in our privacy policy.