Security Basics6 min read29 September 2026

What Is a Web Application Firewall (WAF)? UK Business Guide

A web application firewall (WAF) blocks attacks before they reach your website. This plain-English guide explains what a WAF is, what it protects against, and whether your UK business needs one.

By Yrzo AI — UK cybersecurity specialists

What Is a Web Application Firewall?

A web application firewall — commonly called a WAF — is a security layer that sits between your website and the internet. Every request that hits your site passes through the WAF first. The WAF inspects that request, compares it against a set of rules, and decides whether to let it through or block it.

Think of it as a bouncer at the door of your website. Legitimate visitors walk straight in. Requests that look like SQL injection attempts, cross-site scripting payloads, or known attack patterns get stopped before they ever reach your application.

For UK businesses that handle customer data, process payments online, or simply cannot afford downtime, understanding what a WAF does — and whether you already have one — is basic due diligence.

What Does a WAF Protect Against?

A well-configured WAF provides protection against the most common web application attacks, including:

**SQL injection** — Attackers submit crafted input to your forms, search boxes, or URL parameters attempting to manipulate your database. A WAF identifies the signatures of SQL injection payloads and blocks them before they reach your application.

**Cross-site scripting (XSS)** — Malicious scripts injected into your web pages that execute in visitors' browsers, potentially stealing session cookies or redirecting users to phishing sites. WAF rules catch the most common XSS patterns at the perimeter.

**Cross-site request forgery (CSRF)** — Attacks that trick authenticated users into performing actions they didn't intend. Modern WAFs enforce origin validation to reduce this risk.

**Directory traversal** — Attempts to access files outside your web root using path manipulation sequences like `../../etc/passwd`. A WAF blocks these traversal patterns at the request level.

**Bot attacks and credential stuffing** — Automated tools testing thousands of username and password combinations against your login page. Rate limiting and bot detection rules in a WAF significantly reduce the success rate of these attacks.

**DDoS mitigation** — Many cloud WAF providers include volumetric attack mitigation, absorbing traffic floods before they reach your origin server.

A WAF is not a complete security solution. It does not protect against vulnerabilities in your server configuration, compromised credentials, or logic flaws in your application that don't involve malicious payloads. But it removes a large category of opportunistic attacks that are otherwise trivially easy to launch.

WAF vs Traditional Firewall: What's the Difference?

A traditional network firewall operates at the network layer. It controls which IP addresses and ports can communicate — blocking unauthorised access to services. It is essential, but it has no understanding of HTTP traffic.

A web application firewall operates at the application layer. It understands HTTP, HTML, JavaScript, and the structure of web requests. It can inspect query strings, POST bodies, cookies, and headers — and make intelligent decisions based on what that content looks like.

The two work together, not instead of each other. Most UK businesses need both.

Do You Already Have a WAF?

Many UK businesses have a WAF in place without realising it. If your website sits behind Cloudflare, AWS CloudFront, or similar CDN providers, you likely have access to a WAF — though it may not be enabled or correctly configured.

Some hosting platforms include a WAF as part of their stack. Managed WordPress hosts like WP Engine and Kinsta include WAF rules by default. Shopify's infrastructure includes WAF protection for all stores.

If you're running on basic shared hosting, a VPS, or a self-managed server without a CDN, you probably don't have a WAF. This is where the risk is highest.

How to Know If Your WAF Is Actually Working

Having a WAF enabled and having a WAF that works are not the same thing. WAF rules require ongoing maintenance — new attack techniques emerge regularly, and rules that block them need to be kept current.

Signs your WAF may not be providing the protection you expect:

- It's in detection-only mode (logging attacks but not blocking them) - Rules haven't been updated in months - Custom application logic isn't covered by the default ruleset - Your origin server IP is publicly exposed, allowing attackers to bypass the WAF entirely

A penetration test will verify whether your WAF rules hold up under real attack conditions. Automated tools like Yrzo AI include specific checks for common WAF bypass techniques as part of a full 44-point security assessment.

WAF Options for UK Businesses

**Cloudflare WAF** — Available from the free tier upward, with more sophisticated rules on paid plans. Easy to set up if you're already using Cloudflare for DNS. Widely used by UK SMEs.

**AWS WAF** — Tightly integrated with AWS infrastructure. Managed rule groups available from AWS and third-party vendors. Suits businesses already running on AWS.

**Sucuri** — A popular option for WordPress and other CMS-based sites. Includes WAF, CDN, and malware scanning in one service.

**ModSecurity** — Open-source WAF that runs on Apache and Nginx servers. Powerful but requires technical knowledge to configure correctly. The OWASP Core Rule Set (CRS) is the standard ruleset used with ModSecurity.

For most UK small businesses, a cloud-based WAF like Cloudflare is the right starting point — low cost, managed rules, and no server configuration required.

WAF and GDPR Compliance

Under UK GDPR, organisations processing personal data must implement "appropriate technical and organisational measures" to protect that data. A WAF is one of the technical controls that the ICO would expect to see in a serious security posture.

The ICO has taken enforcement action against organisations whose websites were compromised through web application vulnerabilities that appropriate technical controls — including WAF deployment — could have prevented. A WAF alone does not guarantee GDPR compliance, but its absence is a meaningful gap in your security posture.

Getting Started

If you don't have a WAF in place, the first step is to run a security scan to understand your current exposure. Yrzo AI performs 44 automated security checks on your web-facing attack surface, identifying the vulnerabilities that a WAF would need to protect against — and whether your existing defences are holding. Scans start at £99, with results in under 20 minutes.

Find out if your website has these vulnerabilities

Yrzo AI runs 44 automated security checks and delivers a full report in under 20 minutes. Starting from £399.

Scan your website →