Approach
Deployed and operated a reverse-proxy WAF (Imperva) to protect the public-facing citizen-services websites of a German federal state — an added security layer that couldn't disrupt live public services, and had to align with BSI Grundschutz requirements for public-sector IT security.
Implementation
- Deployed Imperva WAF as a reverse proxy in a datacenter environment, in front of 47 citizen-services websites
- Tuned detection rules and wrote custom rules to fit the specific traffic patterns of government web applications, minimizing false positives without weakening protection
- Implemented bot and DDoS protection to shield public-facing citizen services from automated abuse and volumetric attacks
- Integrated the WAF into existing datacenter infrastructure — networking, monitoring, and existing security tooling
- Aligned the deployment with BSI Grundschutz compliance requirements
- Managed cutover of all 47 sites onto the new WAF layer with zero impact to public availability
Outcome
All 47 government websites went live behind the new WAF with a zero-impact cutover, and there have been no major incidents since launch — citizen-facing digital services secured without disrupting public access to them.