Note sull'episodio
This week we are joined by Michael Collins, Principal Consulting Solutions Architect at Barracuda, to explain what a web application firewall (WAF) is and how it differs from a network firewall. Along with Nate, CIT's Director of Cybersecurity, we explore how WAFs help defend websites, web apps, and APIs against threats like injection, bot attacks, brute force attempts, and DDoS, especially as AI “vibe coding” leads to insecure public-facing applications. The episode covers choosing basic vs enterprise-grade WAF protection based on business criticality and sensitive data, tuning to reduce false positives using detect vs block modes and staged deployment, visibility into daily attacks, geofencing and IP blocking, and how WAFs support compliance efforts like PCI and HIPAA as part of a broader security strategy.
00:27 What Is a WAF
...