Service · IT security

Web application firewall (WAF)

An online shop is open around the clock, and not only to shoppers. A large share of traffic on a typical store comes from automated programs: bots scraping prices, scripts trying stolen credentials against the login page, scanners hunting for an outdated WordPress plugin or a known Magento flaw. Add the peaks just before Christmas or during a sale, which cannot always be told apart from an attack. A web application firewall sits in front of the application, inspects every request and lets through only what looks like a real visit. It is no substitute for updates, but it buys you time when a new vulnerability goes public and takes the bot load off your server. We set up the WAF, whether as a service from a provider such as Cloudflare, as a feature of your hosting, or as a module on the web server itself, and tune the rules so that checkout, eps bank transfers and the payment provider callback keep working.

In front of the server
attacks stop before reaching the application
Bot defence
for login, basket and search
Virtual patching
when a new flaw is published
No migration
the shop stays with your host

Everything this covers

A WAF is only as good as its tuning. The stock rules are a start; the real work is fitting them to your application.

Settle the details with an engineer

Choice and set-up

A cloud WAF in front of the domain, the WAF offered by your host, or ModSecurity with the OWASP rule set on your own server. We recommend what suits your architecture and budget and switch over the DNS records.

Core rules

Protection against common web attacks such as SQL injection, cross-site scripting and file inclusion, tailored to the platform in use, be it Shopware, WooCommerce, Magento or custom code.

Bot management

Request limits per address on login, password reset and the voucher field, detection of automated clients, and challenges for suspicious visitors instead of an outright ban.

Exceptions for partners

Payment providers, shipping software, marketplace feeds and the ERP all call in via APIs. These calls are explicitly allowed so orders and status updates do not get stuck in the filter.

Geographic rules

If you only ship within the DACH region, the admin area can be limited to access from Austria and selected countries, while the shop front stays open to all.

Reporting

A monthly look at blocked requests, false positives and trends, and a focused review of rules and capacity before any big promotion.

Our working method

The WAF first watches and only then protects, so you never lose an order to a false alarm.

01

Analysis

Platform, hosting, integrations and traffic patterns. We go through access logs to estimate how much of your traffic is bots.

02

Logging mode

The WAF runs in front of the shop but does not yet decide. For one or two weeks we record what it would have blocked.

03

Tuning and enforcement

Exceptions for legitimate traffic, then a switch to blocking. The checkout is tested with every payment method.

04

Operation

Monitoring, adjustments when plugins or integrations change, and quick extra rules when a new flaw in your platform becomes known.

A WAF that locks out paying customers costs more than any bot. Overly strict rules have a habit of blocking precisely the payment provider callback that marks an order as paid. That is why, after every rule change, we run through a full purchase with card, eps, PayPal and pay-by-invoice.

Frequently asked questions

Many hosts offer network-level protection against flooding, but no rules tuned to your application. Ask what exactly is included. Often a cloud WAF placed in front is the simplest addition and the shop does not have to move.

Cloud WAFs from large providers usually absorb flooding well because they spread the load across their own network. A WAF on your own server hardly helps, since the line is already saturated before any rule can act.

No. It bridges the gap between a flaw being published and the update being installed, and it catches automated attacks. Outdated software stays a risk that only updates remove.

That varies widely by provider and scope: prices currently tend to range from a few euros to a few hundred euros a month, and we check the latest terms with the provider. On top comes the effort for set-up and upkeep, billed at €110 per hour plus VAT or as part of a service plan.

Rein in the bots before your next sale

Tell us your platform, hosting and payment methods. We will suggest the right WAF approach and the best moment to put it in place.

Availability
Monday to Friday, 8:00-17:00 Austrian time (CET/CEST), reply within one working day
Meetings
By video on Microsoft Teams or Google Meet

We only use cookies that are technically required: to run the website and to remember the location you picked. There are no advertising or tracking cookies. Details are in the privacy notice.