Choice and set-up
A cloud WAF in front of the domain, the WAF offered by your host, or ModSecurity with the OWASP rule set on your own server. We recommend what suits your architecture and budget and switch over the DNS records.
A WAF is only as good as its tuning. The stock rules are a start; the real work is fitting them to your application.
A cloud WAF in front of the domain, the WAF offered by your host, or ModSecurity with the OWASP rule set on your own server. We recommend what suits your architecture and budget and switch over the DNS records.
Protection against common web attacks such as SQL injection, cross-site scripting and file inclusion, tailored to the platform in use, be it Shopware, WooCommerce, Magento or custom code.
Request limits per address on login, password reset and the voucher field, detection of automated clients, and challenges for suspicious visitors instead of an outright ban.
Payment providers, shipping software, marketplace feeds and the ERP all call in via APIs. These calls are explicitly allowed so orders and status updates do not get stuck in the filter.
If you only ship within the DACH region, the admin area can be limited to access from Austria and selected countries, while the shop front stays open to all.
A monthly look at blocked requests, false positives and trends, and a focused review of rules and capacity before any big promotion.
The WAF first watches and only then protects, so you never lose an order to a false alarm.
Platform, hosting, integrations and traffic patterns. We go through access logs to estimate how much of your traffic is bots.
The WAF runs in front of the shop but does not yet decide. For one or two weeks we record what it would have blocked.
Exceptions for legitimate traffic, then a switch to blocking. The checkout is tested with every payment method.
Monitoring, adjustments when plugins or integrations change, and quick extra rules when a new flaw in your platform becomes known.
A WAF that locks out paying customers costs more than any bot. Overly strict rules have a habit of blocking precisely the payment provider callback that marks an order as paid. That is why, after every rule change, we run through a full purchase with card, eps, PayPal and pay-by-invoice.
Many hosts offer network-level protection against flooding, but no rules tuned to your application. Ask what exactly is included. Often a cloud WAF placed in front is the simplest addition and the shop does not have to move.
Cloud WAFs from large providers usually absorb flooding well because they spread the load across their own network. A WAF on your own server hardly helps, since the line is already saturated before any rule can act.
No. It bridges the gap between a flaw being published and the update being installed, and it catches automated attacks. Outdated software stays a risk that only updates remove.
That varies widely by provider and scope: prices currently tend to range from a few euros to a few hundred euros a month, and we check the latest terms with the provider. On top comes the effort for set-up and upkeep, billed at €110 per hour plus VAT or as part of a service plan.
Tell us your platform, hosting and payment methods. We will suggest the right WAF approach and the best moment to put it in place.
Your enquiry has arrived
Our reply reaches you within one working day. Outages that leave your staff unable to work are dealt with first.
We could not find that town. Try another spelling, or choose whichever provincial capital lies closest; as everything is handled remotely, you get the same service in all nine Austrian states.