Web Application Firewalls Are Not a Substitute for Testing
Web application firewalls have a place in any serious security stack. They block common attacks at scale, absorb opportunistic scanning, and provide useful telemetry about what attackers are trying. They do not replace application security testing, despite occasional sales pitches that suggest otherwise. Treating a WAF as the primary line of defence creates a false […]