Skip to content
Second Key Security

WAF and Logging Posture Review

A review of what your web application firewall blocks and what your logs would show after an incident.

Cadence
Monthly or quarterly
Pricing
Scoped to your environment after the assessment.
Family
Cloud and application

The problem

Web application firewalls run in log-only mode for years, and key systems never send logs anywhere. Teams find the gaps during an incident, when the evidence is already missing.

What you get

How it works

  1. Step 1: You create read-only roles

    Read-only access to your WAF and logging platforms.

  2. Step 2: Agents map coverage

    Protected apps, rule modes, log sources, and retention compared.

  3. Step 3: An expert reviews the gaps

    Gaps ranked by what an attacker could do unseen.

  4. Step 4: You approve any change

    Rule and logging changes happen only with your approval. Every approval is logged.

Access we need

  • AWS WAF and CloudWatch settings: the SecurityAudit managed policy
  • Cloudflare: the Administrator Read Only role
  • Read-only access to your log platform or SIEM

What we never do

  • We never change WAF rules or logging settings ourselves.
  • We never copy your logs out of your environment.

The full access model is on the security and trust page.

Questions about WAF and Logging Posture Review?

Tell us what you run and what you need, and we will reply with next steps.