TL;DR: WAF protection is often inconsistent, with 52.3% of cloud-hosted assets and 66.4% of off-cloud assets uncovered, and even PII-collecting pages frequently left exposed, according to CYCOGNITO’s analysis of 500,000 internet-exposed assets. The operational issue is not the absence of WAFs but fragmented ownership, unknown assets, and inconsistent policy enforcement across teams.
NHIMG editorial — based on content published by CYCOGNITO: WAF coverage gaps across enterprise internet-facing assets
By the numbers:
- 52.3 percent, hosted assets, slightly more than half of those in the dataset, 52.3 percent, had no WAF protection.
- 66.4 percent, d assets, two out of three, 66.4 percent, were uncovered by WAF protection.
- 39.3 percent of PII-collecting assets lacked WAF protection., lacked WAF protection.
Questions worth separating out
Q: How should security teams verify that WAF coverage is actually complete?
A: Start with external discovery, not policy documents.
Q: Why do uncovered login and PII pages create outsized risk?
A: Because they sit directly in front of identity and transaction flows.
Q: What do security teams get wrong about owning multiple WAF products?
A: They often assume more products equal more protection.
Practitioner guidance
- Verify external asset coverage against WAF enforcement Run black-box discovery across all internet-facing properties, then reconcile each asset to an active WAF policy and named owner.
- Prioritise identity-adjacent web flows Place login, registration, password reset, and account recovery pages at the top of the remediation queue because they are the most likely entry points for credential stuffing and related abuse.
What's in the full report
CYCOGNITO's full analysis covers the operational detail this post intentionally leaves for the source:
- Asset-level coverage methodology for identifying internet-exposed systems across large enterprise estates
- The manual validation approach used to separate business-critical assets from noise and parked domains
- The full vendor breakdown of WAF technology diversity and deployment fragmentation across teams
- The asset triage approach for deciding whether uncovered systems should be protected or retired
👉 Read CYCOGNITO's analysis of WAF coverage gaps across enterprise internet-facing assets →
WAF coverage gaps: what security teams are missing in exposed assets?
Explore further
Coverage drift is the real control failure here. The problem is not whether an organisation owns a WAF product, but whether every exposed asset is actually covered by a policy that matches its risk. Fragmented deployment across teams and regions creates a false sense of perimeter control. In a modern external attack surface, coverage assurance is the control, not the product count.
A question worth separating out:
Q: Who is accountable when exposed assets are left without WAF protection?
A: Accountability should sit with the team that owns the asset and the security function that governs external exposure standards. If the asset is absent from inventory, accountability has already failed at the governance layer. The fix is ownership assignment, exception tracking, and regular exposure reconciliation.
👉 Read our full editorial: WAF coverage gaps leave internet-exposed assets inconsistently protected