Strategy & Industry

Cloudflare named a Leader in WAF by Forrester

Cloudflare named a Leader in WAF by Forrester

Forrester has recognised Cloudflare as a Leader in The Forrester Wave™: Web Application Firewalls, Q3 2022 report. The report evaluated 12 Web Application Firewall (WAF) providers on 24 criteria across current offering, strategy and market presence.

You can register for a complimentary copy of the report here. The report helps security and risk professionals select the correct offering for their needs.

We believe this achievement, along with recent WAF developments, reinforces our commitment and continued investment in the Cloudflare Web Application Firewall (WAF), one of our core product offerings.

The WAF, along with our DDoS Mitigation and CDN services, has in fact been an offering since Cloudflare’s founding, and we could not think of a better time to receive this recognition: Birthday Week.

We’d also like to take this opportunity to thank Forrester.

Leading WAF in strategy

Cloudflare received the highest score of all assessed vendors in the strategy category. We also received the highest possible scores in 10 criteria, including:

  • Innovation

  • Management UI

  • Rule creation and modification

  • Log4Shell response

  • Incident investigation

  • Security operations feedback loops

According to Forrester, “Cloudflare Web Application Firewall shines in configuration and rule creation”, “Cloudflare stands out for its active online user community and its associated response time metrics”, and “Cloudflare is a top choice for those prioritizing usability and looking for a unified application security platform.”

Protecting web applications

The core value of any WAF is to keep web applications safe from external attacks by stopping any compromise attempt. Compromises can in fact lead to complete application take over and data exfiltration resulting in financial and reputational damage to the targeted organization.

The Log4Shell criterion in the Forrester Wave report is an excellent example of a real world use case to demonstrate this value.

Log4Shell was a high severity vulnerability discovered in December 2021 that affected the popular Apache Log4J software commonly used by applications to implement logging functionality. The vulnerability, when exploited, allows an attacker to perform remote code execution and consequently take over the target application.

Due to the popularity of this software component, many organizations worldwide were potentially at risk after the immediate public announcement of the vulnerability on December 9, 2021.

We believe that we scored the highest possible score in the Log4Shell criterion due to our fast response to the announcement, by ensuring that all customers using the Cloudflare WAF were protected against the exploit in less than 17 hours globally.

We did this by deploying new managed rules (virtual patching) that were made available to all customers. The rules were deployed with a block action ensuring exploit attempts never reached customer applications.

Additionally, our continuous public updates on the subject, including regarding internal processes, helped create clarity and understanding around the severity of the issue and remediation steps.

In the following weeks from the initial announcement, we updated WAF rules several times following discovery of multiple variations of the attack payloads.

The Cloudflare WAF ultimately “bought” valuable time for our customers to patch their back end systems before attackers may have been able to find and attempt compromise of vulnerable applications.

You can read about our response and our actions following the Log4Shell announcement in great detail on our blog.

Use the Cloudflare WAF today

Cloudflare WAF keeps organizations safer while they focus on improving their applications and APIs. We integrate leading application security capabilities into a single console to protect applications with our WAF while also securing APIs, stopping DDoS attacks, blocking unwanted bots, and monitoring for 3rd party JavaScript attacks.

Related posts

More from the blog

All Strategy & Industry posts →
קלאודפלייר לסטארטאפים: נאנוסק מביאה את תוכנית Cloudflare for Startups לישראל

קלאודפלייר לסטארטאפים: נאנוסק מביאה את תוכנית Cloudflare for Startups לישראל

גלו איך ניתן לקבל גישה מלאה לתשתית ולפלטפורמת הפיתוח של Cloudflare, עם עד $250,000 בקרדיטים וליווי מקצועי של מומחי Cloudflare ונאנוסק בישראל. סטארטאפים פועלים בסביבה מהירה, מבוזרת ודינמית, שבה מוצרים נדרשים להיבנות במהירות, לשרת משתמשים מכל העולם ולהיות מוכנים לסקייל בכל רגע, לעיתים עם צוות קטן וללא

The NANO - SECOND: Exciting News from the Cloudflare 2023 EMEA Partner Kickoff

The NANO - SECOND: Exciting News from the Cloudflare 2023 EMEA Partner Kickoff

Cloudflare is a giant. 25% of all internet assets run through Cloudflare. After attending Cloudflare 2023 EMEA Partner Kickoff today, we...

Gartner Names Cloudflare a Leader in WAAP

Gartner Names Cloudflare a Leader in WAAP

Gartner Names Cloudflare a Leader in WAAPNanosekSep 7, 20226 min readThis article was originally published on Cloudflare's blog. As Cloudflare's exclusive MSP in Israel, we're excited to share in their excitement. For more information, and to schedule a demo, contact us here. Gartner has recognised

Polestar drives Chinese consumer confidence and scores a Super Bowl win with Cloudflare

Polestar drives Chinese consumer confidence and scores a Super Bowl win with Cloudflare

Polestar drives Chinese consumer confidence and scores a Super Bowl win with CloudflareNiki RazAug 4, 20225 min readThis article was originally published in Cloudflare's blog. We at Nanosek are thrilled to share Cloudflare's success. For more information, and to schedule a demo, please contact us. P

Cloudflare wins Microsoft Security Software Innovator of the Year

Cloudflare wins Microsoft Security Software Innovator of the Year

Cloudflare wins Microsoft Security Software Innovator of the YearNanosekJun 30, 20223 min readThis blog was originally posted by Nanosek's partner on their blog. As Cloudflare's exclusive MSP in Israel, we are extremely proud to share in Cloudflare's accomplishments and look forward to more successe

Cloudflare Servers Don't Own IPs Anymore – So How Do They Connect to the Internet?

Cloudflare Servers Don't Own IPs Anymore – So How Do They Connect to the Internet?NanosekDec 4, 202210 min readThis article comes from Cloudflare's official blog. We at Nanosek want to keep our clients informed on any news or updates from the Cloudflare team. For more information- and how you can up

Ready to talk?

Deliver Cloudflare without surprises.

Whether you're migrating, hardening, or operating Cloudflare — Nanosek brings authorized MSP & ASDP delivery, rollback-ready cutovers, and managed operations after launch.