WAF and Logging Posture Review
A review of what your web application firewall blocks and what your logs would show after an incident.
- Cadence
- Monthly or quarterly
- Pricing
- Scoped to your environment after the assessment.
- Family
- Cloud and application
The problem
Web application firewalls run in log-only mode for years, and key systems never send logs anywhere. Teams find the gaps during an incident, when the evidence is already missing.
What you get
- WAF coverage: which apps are protected, and in what mode
- Rule findings, ranked by risk
- A logging coverage map: which systems log, where, and for how long
- A fix plan for the gaps that matter most
How it works
Step 1: You create read-only roles
Read-only access to your WAF and logging platforms.
Step 2: Agents map coverage
Protected apps, rule modes, log sources, and retention compared.
Step 3: An expert reviews the gaps
Gaps ranked by what an attacker could do unseen.
Step 4: You approve any change
Rule and logging changes happen only with your approval. Every approval is logged.
Access we need
- AWS WAF and CloudWatch settings: the
SecurityAuditmanaged policy - Cloudflare: the
Administrator Read Onlyrole - Read-only access to your log platform or SIEM
What we never do
- We never change WAF rules or logging settings ourselves.
- We never copy your logs out of your environment.
The full access model is on the security and trust page.
Related services
- Cloud Configuration Posture
Misconfigurations and waste, checked monthly.
- Incident Response Readiness
Plans, runbooks, and tabletops built on your systems.
Questions about WAF and Logging Posture Review?
Tell us what you run and what you need, and we will reply with next steps.