Start from a neutral baseline and add what matters to you. Criteria are labeled by source — the platform baseline is architecture-neutral; buyer-contributed criteria are shown separately.
Build your evaluation
no account needed
Match on your requirements
no account needed
This evaluation is stored in your browser only. We cannot see it, and it is not tied to any account. Save it to a link or create an account to keep it across devices — you can export it at any time either way.
1. Weight what matters
19 criteria
baselineDescribe DDoS mitigation capacity (stated Tbps/Gbps absorption) and time-to-mitigate for a volumetric attack, backed by a real customer incident, not just a marketing capacity number.
baselineDoes the platform provide a positive security model (allow-list known-good behavior) in addition to negative/signature-based rules, and how is the positive model trained/maintained without excessive false positives?
baselineHow does the platform handle Layer 7 application-layer DDoS (e.g., HTTP flood mimicking legitimate user behavior) distinct from volumetric Layer 3/4 attacks?
baselineWhat is the false-positive rate on legitimate traffic, and what mechanism exists for rapid emergency rule tuning during an active attack without taking the application offline?
baselineDetail bot management capability — can the platform distinguish malicious automated traffic (credential stuffing, scraping, inventory hoarding) from legitimate bots and from real users, and what accuracy figure does the vendor cite?
baselineDoes the platform provide API-specific protection (schema validation, API-specific rate limiting, detection of business-logic abuse) distinct from generic web-app WAF rules?
baselineExplain the deployment model (reverse proxy/CDN-edge, inline appliance, or cloud-native/sidecar) and the added latency it introduces to legitimate traffic under normal load, with a customer-measured figure.
baselineHow are WAF rules kept current against newly disclosed web application vulnerabilities (e.g., a new CVE in a popular CMS or framework), and what is the typical time from CVE disclosure to a protective rule being available?
baselineWhat is the pricing model — per request volume, per protected application, or a flat enterprise tier — and how does cost scale during a large legitimate traffic spike (e.g., a viral marketing event) versus during an actual DDoS attack, given both look similar in raw volume?
baselineDetail multi-CDN or multi-cloud deployment consistency — can protection policy be applied uniformly if the customer runs applications across multiple CDN providers or cloud regions, or does coverage/policy fragment across each deployment?
baselineDoes the platform satisfy PCI DSS's WAF requirement specifically (either the 'automated technical solution' or manual code-review alternative), and can the vendor provide documentation an assessor will actually accept as sufficient evidence?
baselineExplain the emergency-support SLA during an active attack — what is the guaranteed response time to reach a live human during a genuine incident, and is this support tier included in the base subscription or a paid add-on?
baselineHow does the platform integrate with the customer's SIEM/SOC for correlated visibility — is WAF/DDoS event data exported in real time for correlation with other security telemetry, or does it remain siloed in the vendor's own dashboard?
baselineDoes the platform provide mobile-app-specific protection (API abuse targeting mobile backends, mobile-app-specific bot/automation detection) distinct from generic web-application WAF rules built for browser traffic?
baselineDetail whether rule tuning is a self-service capability the customer's own team performs, or a managed service the vendor's team handles — and if managed, what is the typical turnaround time for a rule-tuning request during normal (non-emergency) operations?
baselineWhat historical attack-trend reporting is available for executive/board audiences — can the platform show attack volume and blocked-threat trends over quarters, suitable for demonstrating security posture and ROI to non-technical stakeholders?
baselineVendor should have a tool capable of monitoring, detecting and managing incidents for database security events (access to sensitive/PII data, database logins with client IP/server IP/source program info, admin command auditing) and IT infrastructure security events (buffer overflow, port/vulnerability scans, password cracking, worm/virus outbreak, unauthorized firewall rule changes, SQL injection, XSS, layer 7 web attacks) via integration with the WAF/Firewall solution deployed at the financial institution.
baselineConduct a comprehensive analysis of existing applications, application development and testing practices, and tools (e.g. HP Fortify, F5 Web Application Firewall) from a security standpoint and provide detailed findings and recommendations.
baselineDemonstrate configuration, support, and architectural design experience with AppDynamics, Azure Application Insight, HP Fortify, F5 Web Application Firewall, Checkpoint Next-Generation Firewalls, Microsoft SQL databases, and cloud/hybrid/on-premise application platforms in an enterprise environment.
Signing up adds sharing with your team, sending this as an RFP to vendors, and private document sharing. Nothing above is taken away, and nothing here is sent anywhere until you choose to.
Platform baseline
neutral · staff-reviewed
RFPDescribe DDoS mitigation capacity (stated Tbps/Gbps absorption) and time-to-mitigate for a volumetric attack, backed by a real customer incident, not just a marketing capacity number.Answer key — what a strong answer shows
Look for a real incident with a measured time-to-mitigate, since stated capacity numbers are often theoretical network-wide totals, not per-customer guarantees.
RFIDoes the platform provide a positive security model (allow-list known-good behavior) in addition to negative/signature-based rules, and how is the positive model trained/maintained without excessive false positives?Answer key — what a strong answer shows
A positive security model catches novel attacks signatures miss, but requires real tuning discipline — look for a described training/learning process, not just 'AI-powered.'
RFIHow does the platform handle Layer 7 application-layer DDoS (e.g., HTTP flood mimicking legitimate user behavior) distinct from volumetric Layer 3/4 attacks?Answer key — what a strong answer shows
L7 attacks are much harder to distinguish from real traffic — look for a specific behavioral/rate-based methodology, not just volumetric capacity.
RFIWhat is the false-positive rate on legitimate traffic, and what mechanism exists for rapid emergency rule tuning during an active attack without taking the application offline?Answer key — what a strong answer shows
Look for a stated false-positive figure and an emergency-tuning workflow that doesn't require a lengthy change-management process during a live incident.
RFPDetail bot management capability — can the platform distinguish malicious automated traffic (credential stuffing, scraping, inventory hoarding) from legitimate bots and from real users, and what accuracy figure does the vendor cite?Answer key — what a strong answer shows
Strong answers give a real accuracy/detection figure and explain the fingerprinting/behavioral methodology, not just 'bot protection included.'
From other buyers
crowdsourced · anonymized
💬
No buyer-contributed criteria yet
Verified buyers can suggest criteria (anonymized before pooling).
RFIDoes the platform provide API-specific protection (schema validation, API-specific rate limiting, detection of business-logic abuse) distinct from generic web-app WAF rules?Answer key — what a strong answer shows
APIs have different attack surfaces than traditional web apps — look for API-specific capability, not a WAF ruleset repurposed without adaptation.
RFPExplain the deployment model (reverse proxy/CDN-edge, inline appliance, or cloud-native/sidecar) and the added latency it introduces to legitimate traffic under normal load, with a customer-measured figure.Answer key — what a strong answer shows
Look for a real measured latency figure from a customer, not a lab benchmark, since edge/CDN deployment models have very different latency profiles than inline appliances.
RFIHow are WAF rules kept current against newly disclosed web application vulnerabilities (e.g., a new CVE in a popular CMS or framework), and what is the typical time from CVE disclosure to a protective rule being available?Answer key — what a strong answer shows
Strong answers state a concrete time-to-rule figure; a WAF with stale rule coverage provides false confidence against current threats.
RFIWhat is the pricing model — per request volume, per protected application, or a flat enterprise tier — and how does cost scale during a large legitimate traffic spike (e.g., a viral marketing event) versus during an actual DDoS attack, given both look similar in raw volume?Answer key — what a strong answer shows
This is a genuine pricing tension specific to this category — ask explicitly how the vendor distinguishes and prices for legitimate traffic spikes versus attack traffic, since a naive volume-based pricing model could penalize a customer for their own successful marketing campaign.
RFPDetail multi-CDN or multi-cloud deployment consistency — can protection policy be applied uniformly if the customer runs applications across multiple CDN providers or cloud regions, or does coverage/policy fragment across each deployment?Answer key — what a strong answer shows
Look for a unified policy management layer across multi-CDN/multi-cloud deployments; fragmented, separately-managed policy per deployment is a real operational risk and consistency gap.
RFIDoes the platform satisfy PCI DSS's WAF requirement specifically (either the 'automated technical solution' or manual code-review alternative), and can the vendor provide documentation an assessor will actually accept as sufficient evidence?Answer key — what a strong answer shows
PCI compliance is a specific, checkable requirement — ask for real documentation/evidence that's been accepted by a QSA (Qualified Security Assessor) before, not just a generic 'PCI compliant' marketing claim.
RFPExplain the emergency-support SLA during an active attack — what is the guaranteed response time to reach a live human during a genuine incident, and is this support tier included in the base subscription or a paid add-on?Answer key — what a strong answer shows
Strong answers give a concrete, contractual response-time SLA and are explicit about whether emergency support requires a premium tier — during an active DDoS attack, minutes matter and self-service documentation isn't sufficient.
RFIHow does the platform integrate with the customer's SIEM/SOC for correlated visibility — is WAF/DDoS event data exported in real time for correlation with other security telemetry, or does it remain siloed in the vendor's own dashboard?Answer key — what a strong answer shows
Real-time export for SIEM correlation is materially more useful for a mature security team than data siloed in a separate vendor dashboard requiring manual cross-referencing.
RFIDoes the platform provide mobile-app-specific protection (API abuse targeting mobile backends, mobile-app-specific bot/automation detection) distinct from generic web-application WAF rules built for browser traffic?Answer key — what a strong answer shows
Mobile-app backend traffic patterns differ meaningfully from browser-based web traffic — a vendor should clarify whether mobile-specific protection is a real, distinct capability or an afterthought.
RFPDetail whether rule tuning is a self-service capability the customer's own team performs, or a managed service the vendor's team handles — and if managed, what is the typical turnaround time for a rule-tuning request during normal (non-emergency) operations?Answer key — what a strong answer shows
Look for clarity on the self-service-versus-managed model and a concrete non-emergency turnaround time; a customer without deep WAF expertise may specifically need (and should budget for) the managed-service option.
RFIWhat historical attack-trend reporting is available for executive/board audiences — can the platform show attack volume and blocked-threat trends over quarters, suitable for demonstrating security posture and ROI to non-technical stakeholders?Answer key — what a strong answer shows
Trend-over-time reporting suitable for board audiences is a distinct capability from a real-time technical dashboard built for security engineers — confirm this exists as a maintained, exportable report.
RFPVendor should have a tool capable of monitoring, detecting and managing incidents for database security events (access to sensitive/PII data, database logins with client IP/server IP/source program info, admin command auditing) and IT infrastructure security events (buffer overflow, port/vulnerability scans, password cracking, worm/virus outbreak, unauthorized firewall rule changes, SQL injection, XSS, layer 7 web attacks) via integration with the WAF/Firewall solution deployed at the financial institution.
RFPConduct a comprehensive analysis of existing applications, application development and testing practices, and tools (e.g. HP Fortify, F5 Web Application Firewall) from a security standpoint and provide detailed findings and recommendations.
RFPDemonstrate configuration, support, and architectural design experience with AppDynamics, Azure Application Insight, HP Fortify, F5 Web Application Firewall, Checkpoint Next-Generation Firewalls, Microsoft SQL databases, and cloud/hybrid/on-premise application platforms in an enterprise environment.