Close Menu
  • Home
  • Articles
    • Attacks
      • BEC
      • Data Breach
      • DDoS
      • Evasion Attacks
      • Injection
      • Malware
      • MITM
      • Phishing
      • Ransomware
      • RCE
      • Social Engineering
      • Spoofing
      • Spyware
    • Business and Policy
      • BCP and DRP
      • GRC
      • Regulations
    • Data Protection
      • DLP
      • DRM
      • Encryption
      • IAM
    • Future, Trends and Insight
      • AI
      • Events & Community
      • Emerging Tech
      • Expert Panel
      • Interviews With Experts
      • Insights
      • Study & Research
    • Resources
      • Guides
      • Tools
      • Training & Education
    • Security
      • API
      • Apps
      • Cloud
      • Critical Infrastructure
      • Endpoint
      • Hardware
      • IoT
      • Mobile
      • Network
      • OT
      • Port Security
      • Security Architecture
      • Software Development
      • Supply Chain
      • Zero Trust
    • Threats and Vulnerabilities
      • Emerging Threats
      • Insider Threats
      • Risk Management
      • Threat Intelligence
      • Zero Day
  • News and Exclusives
    • Latest News
    • ISB Exclusive
    • Positive News
  • Who We Are
    • About Us
    • Information Security Buzz Expert Panel​
    • Write for Us
    • Media Pack
  • Contact Us
  • Newsletter
Facebook X (Twitter) LinkedIn
Facebook X (Twitter) LinkedIn
Information Security BuzzInformation Security Buzz
  • Home
  • Articles
    • Attacks
      • BEC
      • Data Breach
      • DDoS
      • Evasion Attacks
      • Injection
      • Malware
      • MITM
      • Phishing
      • Ransomware
      • RCE
      • Social Engineering
      • Spoofing
      • Spyware
    • Business and Policy
      • BCP and DRP
      • GRC
      • Regulations
    • Data Protection
      • DLP
      • DRM
      • Encryption
      • IAM
    • Future, Trends and Insight
      • AI
      • Events & Community
      • Emerging Tech
      • Expert Panel
      • Interviews With Experts
      • Insights
      • Study & Research
    • Resources
      • Guides
      • Tools
      • Training & Education
    • Security
      • API
      • Apps
      • Cloud
      • Critical Infrastructure
      • Endpoint
      • Hardware
      • IoT
      • Mobile
      • Network
      • OT
      • Port Security
      • Security Architecture
      • Software Development
      • Supply Chain
      • Zero Trust
    • Threats and Vulnerabilities
      • Emerging Threats
      • Insider Threats
      • Risk Management
      • Threat Intelligence
      • Zero Day
  • News and Exclusives
    • Latest News
    • ISB Exclusive
    • Positive News
  • Who We Are
    • About Us
    • Information Security Buzz Expert Panel​
    • Write for Us
    • Media Pack
  • Contact Us
  • Newsletter
Subscribe
Information Security BuzzInformation Security Buzz
Home - News & Analysis - Web Application Firewalls: The First Line of Defense Against Breaches
News & Analysis

Web Application Firewalls: The First Line of Defense Against Breaches

ISBuzz TeamBy ISBuzz TeamJuly 8, 2014Updated:July 8, 20243 Mins Read
Share LinkedIn Twitter Facebook Copy Link Email
waf
Share
Facebook Twitter LinkedIn Email Copy Link
Quick AI Summary
ChatGPTClaudeGeminiGrokPerplexityDeepSeekCopilot

Last week marked the inaugural release of Gartner’s Web Application Firewalls (WAF) Magic Quadrant. As the only Leader in this quadrant, a rarity in the world of Gartner Magic Quadrants, we at Imperva have recognized a larger trend that’s been emerging for some time from current and prospective customers. It’s great validation that now Gartner is recognizing the need for a WAF MQ to help customers identify corresponding trends and assist in making purchasing decisions.

One of the most frustrating things that happens to me is when an organization calls Imperva after they’ve been breached and when we go in to help out, we find out that they had been relying on a network security solution (either an Intrusion Prevention System or a Next Gen Firewall) to prevent web application attacks (almost always this is SQL Injection). We’ve even talked to organizations that have come to us only after their second breach to find out that their ‘solution’ the first time around was to buy more of the IPS solution that didn’t stop the first breach. Even worse, I think many security professionals disregarded our effort having been conditioned over time to be skeptical of vendor claims. The result has been that frustrating dynamic…getting called to come in after a breach that was easily preventable if the customer had just understood the difference between IPS or Next Gen Firewall and a Web Application Firewall.

I see this quadrant as a possible antidote as to why our WAF (and probably our competitor’s products, by the way) could have been able to stop the attacks with a default policy. Gartner is a third party and doesn’t have a vested interest in a WAF vs IPS and NGFW purchasing outcome, so their opinion is more easily accepted by security professionals. And Gartner has been consistent and clear on this point.

In a recent paper, Web Application Firewalls are Worth the Investment for Enterprises, (Jeremy D’Hoinne, Adam Hils. Gartner, Inc., 28 February 2014) Gartner wrote:

“Firewalls and intrusion prevention systems don’t provide sufficient protections for most public-facing websites or internal business-critical and custom Web applications. Here, we explain how Web application firewalls help security leaders to better protect Web applications in their organizations.”

And even in the 2014 Magic Quadrant for Enterprise Network Firewalls, (Greg Young, Adam Hils, and Jeremy D’Hoinne. Gartner, Inc., April 2014) the team shared:

“…Gartner does not see NGFW and WAF technologies converging because they are for different tasks at different placements.”

I’m hopeful that because of reports like these and the recently released WAF Magic Quadrant, security professionals will begin to realize that their existing network security products don’t protect them from web application attacks, and instead of getting called in after the breach, Imperva and other WAF providers will be given the chance to protect organizations before an attack.

By Mark Kraynak, SVP Worldwide Marketing at Imperva

About Imperva

Imperva LogoImperva is focused on closing the dangerous gap in today’s enterprise security that leaves organizations vulnerable to attack, theft, and fraud. It specializes in data center security and delivers a new layer of protection that keeps high-value applications and data assets in physical and virtual data centers safe, yet accessible. Imperva is pioneering is a third pillar of enterprise security designed specifically for the modern, hyperconnected world.

ISBuzz Team
  • ISBuzz Team
    Air Canada Data Breach: BianLian Extortion Group Claims A Massive Heist Contrary To Airline’s Earlier Statement
  • ISBuzz Team
    Unprecedented DDoS Attack Rocks The Web: Tech Giants Reveal A Digital Tsunami
  • ISBuzz Team
    CISA Flags High-Severity Adobe Acrobat Reader Flaw Amid Active Exploits
  • ISBuzz Team
    Curl Security Alert: Patching A Critical Bug Averting Potential Cyber Catastrophe

The opinions expressed in this post belong to the individual contributors and do not necessarily reflect the views of Information Security Buzz.

Share. Facebook Twitter LinkedIn Email Copy Link

Related Posts

Understanding Cloud Access Security Brokers (CASB)

March 28, 202410 Mins Read

Decoding Cloud Security Posture Management (CSPM)

March 28, 202411 Mins Read

Master Cloud Compliance Tools: Achieve Regulatory Success

March 28, 202411 Mins Read
ISB-Bora-Side-Bar

No se ha podido establecer conexión. Error 429

 
ISB-Bora-Side-Bar
Black ISB Logo

Information Security Buzz is an independent resource that provides the experts’ comments, analysis, and opinion on the latest Cybersecurity news and topics

X (Twitter) LinkedIn Facebook RSS

Working With Us

  • About Us
  • Advertise With Us
  • Contact Us

Write For Us

  • How To Contribute

The Pages

  • Privacy Policy
  • Cookie Policy
  • AI Policy
  • Terms & Conditions
  • Copyright Notice

Information Security Buzz and all its contents are copyright © 2014-2025. All rights reserved. All third-party trademarks are recognized.

Type above and press Enter to search. Press Esc to cancel.

Manage Consent
To provide the best experiences, we use technologies like cookies to store and/or access device information. Consenting to these technologies will allow us to process data such as browsing behavior or unique IDs on this site. Not consenting or withdrawing consent, may adversely affect certain features and functions.
Functional Always active
The technical storage or access is strictly necessary for the legitimate purpose of enabling the use of a specific service explicitly requested by the subscriber or user, or for the sole purpose of carrying out the transmission of a communication over an electronic communications network.
Preferences
The technical storage or access is necessary for the legitimate purpose of storing preferences that are not requested by the subscriber or user.
Statistics
The technical storage or access that is used exclusively for statistical purposes. The technical storage or access that is used exclusively for anonymous statistical purposes. Without a subpoena, voluntary compliance on the part of your Internet Service Provider, or additional records from a third party, information stored or retrieved for this purpose alone cannot usually be used to identify you.
Marketing
The technical storage or access is required to create user profiles to send advertising, or to track the user on a website or across several websites for similar marketing purposes.
  • Manage options
  • Manage services
  • Manage {vendor_count} vendors
  • Read more about these purposes
View preferences
  • {title}
  • {title}
  • {title}