Managed WAF for government websites

City, county, and agency web teams do not lose sleep over one polished homepage. They lose sleep over public forms that must stay up: permits, benefits, FOIA, licensing, notices — plus a trail of Drupal and WordPress microsites nobody fully owns. ProtectMyWebsite is a managed WAF for government websites: one DNS change (or we handle DNS), rules at the edge, hosting and CMS unchanged. Short product page: /waf-for/government. This guide goes deeper — why a city website firewall has to be count-first, how public sector WAF false positives show up on citizen POSTs, and why hiding the origin IP is as important as the rule pack.

Why public-sector sites need a managed edge WAF

Citizen forms define the brand. A blocked permit upload or benefits application is not an internal ticket — it is a closed counter the public notices.

Inventory is incomplete. The CISO’s list and the web team’s list diverge. Forgotten event, FOIA, and licensing portals still accept POSTs.

Drupal and WordPress dominate. Many agency properties sit on mixed hosts and mixed contrib/plugin stacks with uneven patch windows. Edge coverage without a module or plugin matters. See /waf-for/drupal and /waf-for/wordpress.

Thin teams, freeze windows, shared VIPs. One web team covers city hall, parks, utilities, and a stack of departmental microsites. Deny-on-day-one packs punish editors and citizens alike.

That is why /waf-for/government and /waf-for/higher-education share one operator problem: many sites, one thin team, zero appetite for false positives on the forms that define the institution.

Public sector WAF false positives — forms that cannot go down

Public sector WAF false positives rarely announce themselves as security events. The ticket says the permit PDF timed out, the benefits form never submitted, or payment never came back.

Abuse and legitimate traffic share the same shape: long POSTs, multipart uploads, case numbers that look like SQL, narratives with pasted markup, and partner callbacks with atypical User-Agents. Path-only rules miss the fight — the body. Block-first makes citizen services the first casualties.

Count-first: (1) rules start in count (2) ~24 hours real traffic (3) dashboard shows what’s safe — one click (4) Promote Copilot recommends Promote/Hold/Needs allowlist — does not auto-block. You still click.

Links: /guides/waf-false-positives-forms, /guides/waf-count-mode, /guides/whats-safe-to-block.

City website firewall — what managed actually means

Edge-managed WAF: (1) probes/floods/bots hit shield first (2) less junk CPU (3) no CMS module/plugin (4) promote from evidence.

Pricing: $150/site/month, 14-day trial. Larger estates: Talk to sales — no Estate dollar amounts.

How ProtectMyWebsite runs government protection
StepWhat happens
OnboardOne DNS change, or concierge DNS (~one business day). Hosting and CMS stay put — no module, no plugin.
ObserveManaged rules for injection, XSS-class noise, known CMS exploit patterns, bad bots, malicious IPs, plus rate limits useful on shared logins — all start in count.
PromoteAfter about 24 hours, the dashboard surfaces candidates. Copilot explains Promote / Hold / Needs allowlist; the human promotes. You still click once.
OperateWe run the shield. You keep the site. Multi-site and Campus Estate: Talk to sales.

Origin IP still matters

Hide origin; allowlist edge IPs only. Promote Copilot does not auto-block.

Link /guides/origin-ip-bypass and /blog/request-flood-origin-bypass.

Drupal and WordPress on the government estate

Virtual-patch; keep forms in count; one operator story.

See /waf-for/drupal, /waf-for/wordpress, and /solutions.

FAQ

What is a managed WAF for government websites? An edge web application firewall in front of city, county, and agency sites that you do not install as a CMS module or plugin. ProtectMyWebsite sits on DNS; hosting and the CMS stay as they are. Rules start in count; you promote what’s safe to block.

How avoid false positives on permit/benefits forms? Count first. Rules start in count so citizen POSTs are not denied on day one. After about 24 hours, Promote Copilot explains Promote, Hold, or Needs allowlist. Allowlist the form route when hits look like residents. You still click once. See WAF false positives on forms.

What is a city website firewall in practice? A managed edge shield in front of the properties residents actually use — permits, benefits, FOIA, licensing — plus the Drupal and WordPress microsites that share the estate. One DNS change (or we handle DNS). Observe, then promote. We run the shield; your team keeps the site.

Why origin IP bypass matters? A quiet edge means nothing if attackers still punch the origin. Leftover A records, vendor portals, and forgotten subdomains publish the origin IP. Hide the origin and allowlist edge IPs only. See hide your origin IP behind a WAF.

Does Promote Copilot auto-block? No — The human still clicks.

Start here

ProtectMyWebsite is the managed WAF for government websites — a city website firewall that stays count-first so citizen forms stay up.

Pricing: $150/site/month, 14-day trial. Larger estates: Talk to sales — no Estate dollar amounts.

Related

Scan a public site — then start in count