What it is and what it does
A web application firewall, or WAF, is a screening point in front of a website or web service. Cloudflare checks incoming requests against rules and can block suspicious activity. For a manufacturer, the business being protected could be an order portal, a supplier login, or an online quotation system. Cloudflare: how a WAF works.
What that means for your business
If someone sends a malicious request to your ordering portal, the WAF may stop it before your application processes it. Your customer service team can keep taking orders while IT investigates. It cannot fix every software flaw or decide whether a legitimate user should approve a payment.
Is this a baseline system?
Baseline when you operate an important public web application. For a simple brochure site, choose protection proportionate to the exposure. If a software vendor hosts the portal, establish who provides and operates its web protection before buying another service.
Will insurance ask about it?
An underwriter may ask about public applications, vulnerability testing, patching, or a WAF when that exposure is material. There is no universal requirement to buy Cloudflare or a particular plan. Ask the broker which application question applies to your portal and whether the hosting provider already supplies the control.
See the insurance sources and how to interpret the levels.
Minimum operating position
Protect each relevant hostname; restrict direct access to the underlying server; enable suitable rules; name an owner for blocked orders and security events. Keep patching the application.
When the business needs stronger protection
For a revenue critical portal, add tested attack rules, monitoring outside business hours, recovery arrangements, and a safe process for tuning rules that interrupt customers. Consider bot and denial-of-service protection separately.
Evidence to request from IT
- List of public portals and their owners.
- Proof that traffic cannot bypass the screening point.
- Recent rule review, incident records, and application patch dates.
What belongs in the budget
Ask for the ongoing service fee, implementation work, log retention, and the staff time needed to investigate events. A low subscription fee can conceal an unowned operating task.
A documented incident
Equifax, 2017: a web vulnerability became a much larger breach
The FTC alleged that Equifax failed to patch a known web application flaw. Attackers exploited it and accessed sensitive information. FTC: Equifax security failures and settlement, 2019.
What this case shows: This is evidence for patching and layered web protection. It does not establish that Equifax lacked Cloudflare, or that a WAF alone would have prevented the breach.
Sources and scope
The baseline and stronger-protection positions are editorial planning guidance. Confirm your company’s required controls and insurance answers with the accountable IT owner and broker.