Support: 0870 8030 100

The quiet pain in application security: it’s not the tools, it’s the time

Over the last few years, I’ve noticed a pattern that comes up repeatedly in conversations with security teams.

Most security teams I speak to don’t have a problem with their security products. They have a time problem.

On paper, the application layer is covered. In reality, it rarely is.

The technology is rarely the problem. The challenge is operating it effectively.

If you run security in a mid-sized organisation, the chances are you already have a Web Application Firewall (WAF), along with supporting services such as CDN, DDoS protection and possibly bot management.

The platforms are there. The licences are paid for.

In practice, it is rarely that tidy

 

The honest version of what is actually happening

The version you hear after a couple of coffees is usually the same.

The WAF is in monitor mode.

Or it’s blocking, but no one has touched the rules in months. False positives stack up. Real signals get buried. Bot traffic increases quietly in the background.

And nobody has the time to properly get hold of it.

None of this is because security teams lack capability. It is the natural consequence of running a security function with finite people and an evolving attack surface.

 

The application layer has become one of the primary battlegrounds in cybersecurity

This is exactly where we see the gap widen.

The capability is there. The coverage is there.

The operational layer is where things fall down.

The application layer is where much of the business logic lives, customer interaction happens, and attackers are increasingly focused.

APIs have become the front door for many organisations, and in some environments they receive less mature protection and monitoring than the web tier sitting in front of them.

Credential stuffing, scraping, account takeover attempts and API abuse remain some of the most persistent challenges facing application security teams.

A WAF deployment that is stood up quickly and then left without ongoing tuning and operational attention is unlikely to provide the level of protection organisations expect.

 

The audit ask has changed

The expectations from auditors, insurers and enterprise customers have also changed.

A yes or no answer to “do you have a WAF?” is no longer enough.

They want to see:

  • The policy itself
  • The tuning history
  • Evidence of incident response
  • Patching cadence against new CVEs
  • Ongoing operational governance

Security teams are being asked to produce more evidence than ever before.

The team size has not.

 

The gap between what good looks like and what gets done

What I am seeing across the organisations we work with is that the gap between what good looks like and what actually gets done has widened.

Not because security leaders do not know what good looks like.

They do.

The gap is operational.

It is the difference between owning a high-end security platform and having the time to use it properly.

Most security teams own the equipment.

Few have the time to use it properly.

 

There are a few ways to close that gap

Organisations generally either build specialist capability internally, partner with specialists who already operate these platforms every day, or use a combination of both approaches.

The right answer depends on the organisation, its risk profile and available resources.

But leaving critical application security platforms largely unmanaged is becoming increasingly difficult to justify.

 

Why operational expertise matters

This is the work we do at Vnetrix.

We’ve been delivering managed web application security services using Imperva’s platform since 2015, protecting both our customers’ environments and our own infrastructure.

That experience matters because we’re not approaching this purely as a reseller.

We operate the technology, understand the operational challenges, and help organisations get the value they expect from their security investments.

Sometimes that means optimising existing platforms; sometimes it means introducing new capabilities where gaps exist.

The important part is ensuring security technology is properly implemented, managed and aligned with the organisation’s risk profile.

If this sounds familiar, it’s because it’s a pattern we see repeatedly across UK organisations.

 

Written by: Robert Norman

Related Articles

Top 5 Reasons to Outsource your IT to an MSP

IT managed services is an expanding sector, currently worth $23.21 billion worldwide and projected to grow at 2.86% per year (1). And it’s no surprise that more and more companies are partnering with a Managed Service Provider (or MSP). In a world where technology is the driving force behind your

Read More »