Managed WAF for government websites
City, county, and agency web teams do not lose sleep over one polished homepage. They lose sleep over public forms that must stay up: permits, benefits, FOIA, licensing, notices — plus a trail of Drupal and WordPress microsites nobody fully owns. ProtectMyWebsite is a managed WAF for government websites: one DNS change (or we handle DNS), rules at the edge, hosting and CMS unchanged. Short product page: /waf-for/government. This guide goes deeper — why a city website firewall has to be count-first, how public sector WAF false positives show up on citizen POSTs, and why hiding the origin IP is as important as the rule pack.
Why public-sector sites need a managed edge WAF
Citizen forms define the brand. A blocked permit upload or benefits application is not an internal ticket — it is a closed counter the public notices.
Inventory is incomplete. The CISO’s list and the web team’s list diverge. Forgotten event, FOIA, and licensing portals still accept POSTs.
Drupal and WordPress dominate. Many agency properties sit on mixed hosts and mixed contrib/plugin stacks with uneven patch windows. Edge coverage without a module or plugin matters. See /waf-for/drupal and /waf-for/wordpress.
Thin teams, freeze windows, shared VIPs. One web team covers city hall, parks, utilities, and a stack of departmental microsites. Deny-on-day-one packs punish editors and citizens alike.
That is why /waf-for/government and /waf-for/higher-education share one operator problem: many sites, one thin team, zero appetite for false positives on the forms that define the institution.
Public sector WAF false positives — forms that cannot go down
Public sector WAF false positives rarely announce themselves as security events. The ticket says the permit PDF timed out, the benefits form never submitted, or payment never came back.
Abuse and legitimate traffic share the same shape: long POSTs, multipart uploads, case numbers that look like SQL, narratives with pasted markup, and partner callbacks with atypical User-Agents. Path-only rules miss the fight — the body. Block-first makes citizen services the first casualties.
Count-first: (1) rules start in count (2) ~24 hours real traffic (3) dashboard shows what’s safe — one click (4) Promote Copilot recommends Promote/Hold/Needs allowlist — does not auto-block. You still click.
Links: /guides/waf-false-positives-forms, /guides/waf-count-mode, /guides/whats-safe-to-block.
City website firewall — what managed actually means
Edge-managed WAF: (1) probes/floods/bots hit shield first (2) less junk CPU (3) no CMS module/plugin (4) promote from evidence.
Pricing: $150/site/month, 14-day trial. Larger estates: Talk to sales — no Estate dollar amounts.
| Step | What happens |
|---|---|
| Onboard | One DNS change, or concierge DNS (~one business day). Hosting and CMS stay put — no module, no plugin. |
| Observe | Managed rules for injection, XSS-class noise, known CMS exploit patterns, bad bots, malicious IPs, plus rate limits useful on shared logins — all start in count. |
| Promote | After about 24 hours, the dashboard surfaces candidates. Copilot explains Promote / Hold / Needs allowlist; the human promotes. You still click once. |
| Operate | We run the shield. You keep the site. Multi-site and Campus Estate: Talk to sales. |
Origin IP still matters
Hide origin; allowlist edge IPs only. Promote Copilot does not auto-block.
Link /guides/origin-ip-bypass and /blog/request-flood-origin-bypass.
Drupal and WordPress on the government estate
Virtual-patch; keep forms in count; one operator story.
See /waf-for/drupal, /waf-for/wordpress, and /solutions.
FAQ
What is a managed WAF for government websites? An edge web application firewall in front of city, county, and agency sites that you do not install as a CMS module or plugin. ProtectMyWebsite sits on DNS; hosting and the CMS stay as they are. Rules start in count; you promote what’s safe to block.
How avoid false positives on permit/benefits forms? Count first. Rules start in count so citizen POSTs are not denied on day one. After about 24 hours, Promote Copilot explains Promote, Hold, or Needs allowlist. Allowlist the form route when hits look like residents. You still click once. See WAF false positives on forms.
What is a city website firewall in practice? A managed edge shield in front of the properties residents actually use — permits, benefits, FOIA, licensing — plus the Drupal and WordPress microsites that share the estate. One DNS change (or we handle DNS). Observe, then promote. We run the shield; your team keeps the site.
Why origin IP bypass matters? A quiet edge means nothing if attackers still punch the origin. Leftover A records, vendor portals, and forgotten subdomains publish the origin IP. Hide the origin and allowlist edge IPs only. See hide your origin IP behind a WAF.
Does Promote Copilot auto-block? No — The human still clicks.
Start here
ProtectMyWebsite is the managed WAF for government websites — a city website firewall that stays count-first so citizen forms stay up.
Pricing: $150/site/month, 14-day trial. Larger estates: Talk to sales — no Estate dollar amounts.
Related
- All guides
- Managed WAF for government and public-sector websites
- WAF false positives on forms: stop blocking legitimate POSTs
- Hide your origin IP behind a WAF (and allowlist edge IPs only)
- What is WAF count mode? (and why you start there)
- What's safe to block on a WAF?
- Managed WAF for Drupal without a module
- Managed WAF for WordPress without a plugin
- A managed WAF for your Drupal site
- A managed WAF for your WordPress site
- Managed WAF for university and college websites
- Managed WAF for multi-site teams
- Solutions & guides
- Free security scan
- Start a 14-day trial
- Pricing
- A client was taking 90 million requests an hour. The WAF was only half the fight.