Cloudflare · Application Security · Öffentlicher Sektor DACH Cloudflare · Application Security · Public Sector DACH

Die Lücke, die Sie nicht patchen können. The gap you cannot patch.

Zwischen „CVE veröffentlicht" und „CVE ausgenutzt" liegen heute Stunden. Zwischen „CVE veröffentlicht" und „gepatcht" liegen in einer Behörde — Wochen. Between “CVE disclosed” and “CVE exploited” lies hours. Between “CVE disclosed” and “patched” lies, in a public agency — weeks.

⏳
Stunden — so schnell wird eine neue Schwachstelle nach Veröffentlichung ausgenutzt. Ihr Patch-Fenster für ein Fachverfahren misst sich in Wochen: Change-Advisory-Board, Wartungsfenster, Hersteller-Freigabe. Diese Lücke schließen Sie nicht mit schnellerem Patchen — sondern mit virtuellem Patchen an der Edge, vor der Anwendung. Hours — that is how fast a new vulnerability is exploited after disclosure. Your patch window for a legacy line-of-business system is measured in weeks: change-advisory board, maintenance window, vendor sign-off. You don't close that gap by patching faster — you close it with virtual patching at the edge, in front of the application.
Cloudflare Application Security· web-security.bacarda.de· Echte WAF — keine SimulationReal WAF — no simulation
Das Cloudflare-NetzThe Cloudflare network

Security an der EdgeSecurity at the edge

Klassische Sicherheit steht als eine Box vor einem Rechenzentrum. Cloudflare dreht das um: jeder einzelne Standort ist die volle Schutzschicht — WAF, Bot, DDoS, TLS, Rate Limiting in einem Durchlauf. Der Angriff trifft den nächstgelegenen Knoten und stirbt dort, nicht erst nach 4.000 km Umweg zu einer zentralen Appliance. Classic security is one box in front of one data centre. Cloudflare inverts that: every single location is the full protective layer — WAF, Bot, DDoS, TLS, rate limiting in a single pass. An attack hits the nearest node and dies there, not after a 4,000 km detour to a central appliance.

Regionalisierung:Regionalisation:
Cloudflare Points of Presence weltweit

330+ Städte als Schutzschild. Jeder Punkt fährt dieselbe Pipeline. Wählen Sie eine Region — bei Regional Services wird HTTPS nur noch dort entschlüsselt und inspiziert (mehr dazu in §4). Der Rest des Netzes nimmt Traffic weiter an und leitet ihn verschlüsselt in die Region. 330+ cities as a shield. Every dot runs the same pipeline. Pick a region — with Regional Services, HTTPS is decrypted and inspected only there (more in §4). The rest of the network still accepts traffic and forwards it encrypted into the region.

Sektion 2Section 2

Die 5-Sekunden-WahrheitThe 5-second truth

Eine einzige Zahl trägt den Rest der Geschichte. Sie beantwortet die Frage, die jede Sicherheitsverantwortliche in einer Behörde wirklich umtreibt: Wie schnell bin ich geschützt, wenn morgen die nächste kritische Schwachstelle bekannt wird — und ich die Anwendung selbst noch nicht patchen kann? A single number carries the rest of the story. It answers the question that actually keeps a public-sector security lead awake: how fast am I protected when the next critical vulnerability drops tomorrow — and I can't patch the application yet?

~5 Sekundenseconds
So lange dauert es (P99), bis eine neue WAF-Regel in allen 330+ Städten aktiv ist. Ein neuer Schutz greift global, bevor in Ihrer klassischen Appliance-Welt das erste Rechenzentrum die Config erhalten hätte — und lange bevor das Change-Advisory-Board getagt hat. Das ist virtuelles Patchen: die Schwachstelle bleibt offen, der Angriffsweg ist trotzdem zu. That is how long (P99) it takes for a new WAF rule to be live across all 330+ cities. Protection applies globally before your classic appliance estate would have pushed the config to its first data centre — and long before the change-advisory board has even met. That is virtual patching: the vulnerability stays open, the attack path is closed anyway.
Patch-Gap timeline CVE Stundenhours Exploit Patch Wochen — CAB, Wartungsfenster, Freigabeweeks — CAB, maintenance window, sign-off livelive ↑ Ihr Risiko-Fenster↑ your exposure window ~5 s Virtuelles Patchen an der Edge — Regel global aktivVirtual patching at the edge — rule live globally Angriffsweg zu, App bleibt ungepatchtattack path closed, app stays unpatched
Die Lücke, nicht das Patchen. Der Exploit ist in Stunden da, der Patch in Wochen. Virtuelles Patchen an der Edge überbrückt das Risiko-Fenster — in ~5 Sekunden global, ohne Wartungsfenster. The gap, not the patch. The exploit arrives in hours, the patch in weeks. Virtual patching at the edge bridges the exposure window — globally in ~5 seconds, with no maintenance window.
Stunden → Wochenhours → weeks
Exploit-Zeit gegen Patch-Zeit. Genau diese Lücke überbrückt die Edge — ohne Ihr Wartungsfenster.Exploit time vs. patch time. The edge bridges exactly this gap — without your maintenance window.
~5 s vs. 10–15 min
Regel-Propagation Cloudflare (P99) gegen Appliance-/Legacy-Config-Verteilung.Cloudflare rule propagation (P99) vs. appliance/legacy config rollout.
0 Inbound-Ports0 inbound ports
Der Schutz sitzt vor der App — kein DMZ-Umbau, keine Firewall-Änderung am Origin nötig.Protection sits in front of the app — no DMZ rework, no origin firewall change needed.

Merken Sie sich die ~5 Sekunden — das Thema trägt die ganze Section 4 zur Souveränität. Keep the ~5 seconds in mind — it carries straight into the sovereignty story in Section 4.

SE-Hinweis Warum diese Zahl statt „230 Mrd. Bedrohungen/Tag": Hyperscale-Zahlen triggern beim PS den „US-Marketing"-Reflex. Die Patch-Lücke ist ein Schmerz, den jede Behörde mit Legacy-Fachverfahren sofort wiedererkennt. Lead mit Risikoreduktion, nicht mit Größe. Why this number instead of “230bn threats/day”: hyperscale numbers trigger the “US marketing” reflex in PS. The patch gap is a pain every agency with legacy systems recognises instantly. Lead with risk reduction, not size.
Sektion 3 · LIVESection 3 · LIVE

Echt blocken — kein TheaterA real block — no theatre

Genug Theorie. Feuern Sie selbst einen Angriff ab. Wählen Sie ein Preset oder schreiben Sie Ihren eigenen Payload, und sehen Sie, wie das echte Cloudflare Managed Ruleset reagiert: 403 Forbidden, Error 1020, ausgelöste Regel, Cloudflare Ray ID, blockierende Phase. Enough theory. Fire an attack yourself. Pick a preset or write your own payload and watch the real Cloudflare Managed Ruleset respond: 403 Forbidden, Error 1020, the triggered rule, Cloudflare Ray ID, the blocking phase.

echt Diese Anfrage läuft durch eine reale, per Cloudflare WAF geschützte Zone. Der Block kommt aus der Phase http_request_firewall_managed am Edge — bevor der Request je das Origin erreicht. Nichts ist nachgebaut. Ihre Edge-Location: … This request runs through a real Cloudflare-WAF-protected zone. The block comes from the http_request_firewall_managed phase at the edge — before the request ever reaches an origin. Nothing is mocked. Your edge location: …

Presets:Presets:

Was beim Abfeuern passiert: Wir senden genau diesen Payload als echten HTTP-Request an /waf-probe. Die Cloudflare-WAF prüft ihn am Edge, bevor er ein Origin erreicht — blockiert (403), durchgelassen (200) oder gedrosselt (429). What firing does: we send exactly this payload as a real HTTP request to /waf-probe. The Cloudflare WAF inspects it at the edge before it reaches any origin — blocked (403), passed (200) or throttled (429).

Requests / 60 sRequests / 60 s0/5
BegriffsschärfeTerminology OWASP Core Rule Set ≠ OWASP Top 10. Das Cloudflare Managed Ruleset ist signaturbasiert (was Sie gerade getriggert haben). Das OWASP Core Rule Set arbeitet mit Anomaly-Scoring. Beide laufen in derselben Phase — http_request_firewall_managed — und lassen sich kombinieren. OWASP Core Rule Set ≠ OWASP Top 10. The Cloudflare Managed Ruleset is signature-based (what you just triggered). The OWASP Core Rule Set uses anomaly scoring. Both run in the same phase — http_request_firewall_managed — and can be combined.

Mehr als Managed Rules — Ihre eigenen SchutzebenenBeyond managed rules — your own layers

Das Managed Ruleset ist die Basis. Darüber und davor liegen weitere Phasen, die Sie selbst steuern — alle im selben Durchlauf am Edge. The Managed Ruleset is the baseline. Above and before it sit further phases you control yourself — all in the same pass at the edge.

http_request_firewall_custom
Custom RulesCustom Rules
Eigene Ausdrücke in der Cloudflare-Rules-Sprache — z. B. „blockiere Zugriff auf /admin außerhalb des Behörden-IP-Bereichs" oder „nur Land = DE".
(ip.src ne 1.2.3.0/24 and http.request.uri.path contains "/admin")
Your own expressions in the Cloudflare rules language — e.g. “block /admin outside the agency IP range” or “country = DE only”.
(ip.src ne 1.2.3.0/24 and http.request.uri.path contains "/admin")
ip access / lists
IP- & BedrohungslistenIP & threat lists
Eigene IP-Listen (Allow/Block) plus von Cloudflare gepflegte Managed IP Lists: bekannte offene Proxies, Anonymizer, Botnet-/C2-Netzwerke. Ganze ASNs oder Länder lassen sich in einer Regel sperren. Your own IP lists (allow/block) plus Cloudflare-managed IP lists: known open proxies, anonymizers, botnet/C2 networks. Whole ASNs or countries can be blocked in one rule.
http_ratelimit
Rate LimitingRate Limiting
Drosselt Brute-Force, Credential-Stuffing und Scraping pro IP/Token. Genau diese Phase haben Sie oben mit schnellem Klicken ausgelöst — echter HTTP 429. Throttles brute-force, credential stuffing and scraping per IP/token. You triggered exactly this phase above by clicking fast — a real HTTP 429.
Kapitel · Bot ManagementChapter · Bot Management

Mensch oder Maschine?Human or machine?

Ein erheblicher Teil des Web-Traffics ist automatisiert — nicht alles davon böse (Suchmaschinen, Monitoring). Aber Credential-Stuffing auf Login-Portale, Scraping öffentlicher Register, Formular- und Kommentar-Spam und das Abgreifen knapper Ressourcen treffen gerade Behörden. Bot Management bewertet jeden Request mit einem Score von 1–99 — per ML-Modell, trainiert auf der Traffic-Menge des gesamten Cloudflare-Netzes. A substantial share of web traffic is automated — not all of it malicious (search engines, monitoring). But credential stuffing against login portals, scraping of public registries, form and comment spam, and the grabbing of scarce resources hit public agencies in particular. Bot Management scores every request 1–99 — via an ML model trained on the traffic of the entire Cloudflare network.

—
Lädt die Rohsignale…Loading raw signals…
1–29 = automatisiert · 30–99 = menschlich. Der 1–99-Score ist die ML-Verdichtung dieser Rohsignale (Bot-Management-Add-on). 1–29 = automated · 30–99 = human. The 1–99 score is the ML distillation of these raw signals (Bot Management add-on).
Selbst gegenprüfen — als Maschine Verify it yourself — as a machine
curl -s https://web-security.bacarda.de/api/botscore

Ihr Browser oben bekommt einen hohen Score (menschlich). Führen Sie denselben Aufruf im Terminal aus — curl bekommt einen niedrigen Score (z. B. 1) und automated: true: anderer User-Agent (curl/…), anderer TLS-Fingerprint. Genau diese Rohsignale verdichtet Bot Management zum echten 1–99-ML-Score, in Echtzeit am Edge. Your browser above gets a high score (human). Run the same call in your terminal — curl gets a low score (e.g. 1) and automated: true: different user-agent (curl/…), different TLS fingerprint. These raw signals are what Bot Management distils into the real 1–99 ML score, in real time at the edge.

Woran das Modell erkennt, was Sie sindHow the model knows what you are

Verifizierte BotsVerified bots
Allow-List
Gute Bots (Google, Bing, Monitoring) werden verifiziert und durchgelassen — kein Kollateralschaden bei der Sichtbarkeit Ihrer Dienste.Good bots (Google, Bing, monitoring) are verified and allowed — no collateral damage to your services' visibility.
FingerprintingFingerprinting
JA3 / JA4
TLS-/HTTP-Fingerabdrücke erkennen automatisierte Clients, auch wenn sie einen Browser vortäuschen — z. B. curl, Skripte, Headless-Tools.TLS/HTTP fingerprints expose automated clients even when they fake a browser — e.g. curl, scripts, headless tools.
Verhaltens-MLBehavioural ML
Netzwerk-SignalNetwork signal
Das Modell lernt aus dem Verhalten über das gesamte Netz — Anomalien, Request-Muster, Velocity. Mehr Traffic → besseres Modell für alle.The model learns from behaviour across the whole network — anomalies, request patterns, velocity. More traffic → a better model for everyone.

Im selben Modell: Turnstile als datensparsamer CAPTCHA-Ersatz — ohne Klick-Puzzles, DSGVO-freundlich. Der Bot-Score fließt als Stufe in die Request-Journey (§ Inside one request) ein. In the same model: Turnstile as a privacy-friendly CAPTCHA replacement — no click puzzles, GDPR-friendly. The bot score feeds the request journey as a stage (§ Inside one request).

Kapitel · DDoS-SchutzChapter · DDoS protection

Volumen, das kein Mensch mehr stopptVolume no human can stop

Bürgerportale, Antragsstrecken und Wahlabend-Seiten sind beliebte DDoS-Ziele — oft politisch motiviert. Die Angriffsvolumina übersteigen längst, was eine lokale Appliance oder ein Uplink verkraftet. Schutz muss autonom, always-on und am Edge passieren, nicht über Umleitung in ein zentrales Scrubbing-Center. Citizen portals, application flows and election-night sites are popular DDoS targets — often politically motivated. Attack volumes long exceed what a local appliance or uplink can absorb. Protection must be autonomous, always-on and at the edge — not via redirect to a central scrubbing centre.

330+
Standorte sind Ihr Schutzschild. Es gibt kein zentrales Scrubbing-Center, auf das umgeleitet wird — jeder einzelne der 330+ PoPs absorbiert Angriffsverkehr dort, wo er ankommt. Die Kapazität des gesamten Cloudflare-Netzes ist Ihre Abwehrkapazität. cities are your shield. There is no central scrubbing centre to redirect to — every single one of the 330+ PoPs absorbs attack traffic where it lands. The capacity of the entire Cloudflare network is your defence capacity.
DDoS im Kleinen — feuern Sie einen Burst von 40 Anfragen ab und sehen Sie, wie die Rate-Limiting-Phase greift: DDoS in miniature — fire a burst of 40 requests and watch the rate-limiting phase kick in:

echt Die abgewehrten Anfragen bekommen einen echten HTTP 429 aus der http_ratelimit-Phase am Edge. Ein realer Volumenangriff (Millionen Pakete/s) wird darüber hinaus autonom über L3/L4 + L7 an allen 330+ PoPs absorbiert — ohne dass Ihr Origin je Last sieht. The blocked requests get a real HTTP 429 from the http_ratelimit phase at the edge. A real volumetric attack (millions of packets/s) is additionally absorbed autonomously via L3/L4 + L7 across all 330+ PoPs — without your origin ever seeing the load.

~35 Sekunden~35 seconds
autonome Mitigation des größten je abgewehrten Angriffs — ohne menschliches Eingreifen.autonomous mitigation of the largest attack ever blocked — no human in the loop.
L3/L4 + L7
Netz-/Transport- und HTTP-Layer-Abwehr in einem Netz, an jedem Standort.network/transport and HTTP-layer defence in one network, at every location.
unmeteredunmetered
DDoS-Schutz ohne Volumen-Abrechnung — kein Überraschungs-Invoice nach einem Angriff. Planbar für ein Behördenbudget.DDoS protection with no volumetric billing — no surprise invoice after an attack. Predictable for a public budget.
L3 / L4
Netz- & Transport-LayerNetwork & transport layer
Volumetrische Floods (SYN, UDP, Reflection) werden am Edge absorbiert — ohne TLS zu entschlüsseln, an jedem der 330+ Standorte. Genau die Stufe ddos_l4 aus der Request-Journey.Volumetric floods (SYN, UDP, reflection) are absorbed at the edge — without decrypting TLS, at each of the 330+ locations. Exactly the ddos_l4 stage from the request journey.
L7
HTTP-LayerHTTP layer
Anwendungs-DDoS (HTTP-Floods) wird über adaptive, ML-gestützte Fingerprints autonom mitigiert — ddos_l7. Reagiert in Sekunden, nicht in SOC-Schichten.Application DDoS (HTTP floods) is mitigated autonomously via adaptive, ML-based fingerprints — ddos_l7. Reacts in seconds, not SOC shifts.
ArchitekturArchitecture
330+ PoPs · Always-on
Kein Umleiten im Angriffsfall, kein Hairpinning. Jeder PoP absorbiert — der Schutzschild aus „Security an der Edge". Die Kapazität des Netzes ist die Kapazität Ihrer Abwehr.No redirect under attack, no hairpinning. Every PoP absorbs — the shield from “Security at the edge”. The network's capacity is your defence's capacity.
Sektion 4Section 4

Wo Ihre Daten bleibenWhere your data stays

Der Block eben passierte am Edge — am nächstgelegenen Cloudflare-Standort. Für den öffentlichen Sektor ist damit sofort die entscheidende Frage im Raum: Wo wird mein Traffic inspiziert, und wo bleiben meine Metadaten und Logs? Die Antwort ist nicht „irgendwo im Netz" — sie ist steuerbar. The block just now happened at the edge — at the nearest Cloudflare location. For the public sector that immediately raises the decisive question: where is my traffic inspected, and where do my metadata and logs reside? The answer is not “somewhere in the network” — it is configurable.

Datensouveränität: konfigurierbar, nicht versprochenData sovereignty: configured, not promised

Wo inspiziert wirdWhere inspection happens
Regional Services
TLS-Terminierung und L7-Inspektion (inkl. WAF) lassen sich auf eine geografische Region festnageln — z. B. nur EU. Der Request verlässt die Region für die Sicherheitsprüfung nicht.TLS termination and L7 inspection (incl. WAF) can be pinned to a geographic region — e.g. EU only. The request never leaves the region for security processing.
Wo Metadaten bleibenWhere metadata stays
Customer Metadata Boundary = EU
Logs und Metadaten werden in der EU-Region gespeichert und abgefragt — inklusive DNS-Analytics. Erfüllt Datenlokalisierungs-Anforderungen ohne Funktionsverlust.Logs and metadata are stored and queried in the EU region — including DNS analytics. Meets data-localisation requirements with no loss of functionality.
👤Nutzer · USUser · US
📍PoP · US
🛡️PoP · EU
🗄️Origin · EU
🔒 TCP / TLS
L3/L4-DDoS · kein TLS-UnwrapL3/L4 DDoS · no TLS unwrap
🔒 verschlüsselt weiterforwarded encrypted
TLS-Terminierung (Entschlüsselung)TLS termination (decryption)
WAF · Bot · Cache · Workers
Inspektion nur hierinspection only here
🔒 fordert Inhaltrequests content
Antwort-Inhaltresponse content
Cache · verschlüsselte Diskscache · encrypted disks
🔒 verschlüsselte Antwort zurückencrypted response back
Souveränität als Schalter. Jeder PoP nimmt Traffic an und wehrt L3/L4-DDoS ab — aber TLS-Entschlüsselung und L7-Inspektion (WAF/Bot/Cache) passieren nur in der gewählten Region (EU). Metadaten/Logs hält die Customer Metadata Boundary in der EU. Nachbau des offiziellen Regional-Services-Flows. Sovereignty as a switch. Every PoP accepts traffic and mitigates L3/L4 DDoS — but TLS decryption and L7 inspection (WAF/bot/cache) happen only in the chosen region (EU). The Customer Metadata Boundary keeps metadata/logs in the EU. Rebuilt from the official Regional Services flow.

Nachweise, die ein Vergabeverfahren überstehtEvidence that survives a tender

C5
BSI C5-TestatBSI C5 attestation
der De-facto-Standard für Cloud im deutschen PSthe de-facto cloud standard in German PS
BSIG
BSI-KRITIS-Audit (TÜViT)BSI KRITIS audit (TÜViT)
alle 2 Jahre · NIS-Directive-konform in DEevery 2 years · NIS-Directive aligned in DE
ISO
27001 · 27701 · SOC 2 · PCI DSS L1
ISMS, Datenschutz (GDPR-aligned), Karten-ComplianceISMS, privacy (GDPR-aligned), card compliance
Der Souveränitäts-Satz: Cloudflare liefert nicht nur ein global verteiltes Netz, sondern die Kontrolle darüber, wo Inspektion und Daten liegen — plus die Testate (C5, BSIG/KRITIS, ISO), die Beschaffung und Datenschutzbeauftragte sehen wollen. Souveränität ist hier ein konfigurierbarer Schalter und ein auditierter Nachweis, kein Marketing-Bullet. The sovereignty sentence: Cloudflare delivers not just a globally distributed network but control over where inspection and data live — plus the attestations (C5, BSIG/KRITIS, ISO) that procurement and DPOs ask for. Here, sovereignty is a configurable switch and an audited proof, not a marketing bullet.
SE-Hinweis Vor externem Einsatz prüfen: exakten C5-Status (Testat vs. Scope) und aktuellen Regional-Services-Scope im Trust Hub gegenchecken. „C5-testiert" vs. „C5-aligned" ist im Tender load-bearing — nie aus dem Gedächtnis behaupten. Verify before external use: confirm exact C5 status (attestation vs. scope) and current Regional Services scope in the Trust Hub. “C5-attested” vs. “C5-aligned” is load-bearing in a tender — never claim from memory.
Sektion 5Section 5

Inside One Request

Ihr Payload aus §3 wurde nicht von „der Firewall" gestoppt. Er lief durch eine geordnete Pipeline von Phasen — und fiel in genau einer davon. Das ist der wichtigste mentale Shift: Cloudflare Application Security ist kein Produkt und keine Box, sondern eine Sequenz, die jeder Server in einem Durchlauf (one pass) abarbeitet. Your payload from §3 wasn't stopped by “the firewall”. It ran through an ordered pipeline of phases — and fell in exactly one of them. That's the key mental shift: Cloudflare Application Security is not a product and not a box, but a sequence every server executes in a single pass.

DNS Start: DNS löst Ihren Hostnamen per Anycast zum nächstgelegenen Cloudflare-Edge auf. Erst dann beginnt die Journey — der gesamte Transport ist durchgängig TLS-verschlüsselt 🔒. Start: DNS resolves your hostname via Anycast to the nearest Cloudflare edge. Only then does the journey begin — the whole transport is TLS-encrypted end to end 🔒.

👤 · 🤖
AnfrageRequest
Nutzer / Botuser / bot
🔒→
☁ Cloudflare Edge — ein Durchlauf, wenige Millisekunden Cloudflare Edge — one pass, a few milliseconds
DDoS-AbwehrDDoS defence
L3 / L4
→
DDoS-AbwehrDDoS defence
L7 · ~35 s
→
Eigene RegelnCustom rules
Ihre Policyyour policy
→
Rate Limiting
429
→
hier geblocktblocked here
WAF
Managed + OWASP
→
Bot-AbwehrBot defence
Bot Score
🔒→
Origin
Ihr Serveryour server
Eine Anfrage, ein Durchlauf. Die orange umrandeten Stufen laufen alle im Cloudflare-Edge, in einem Durchgang in wenigen Millisekunden — keine Box, kein Service-Hop. Außen: Ihr Client und Ihr Origin. Maus über jede Stufe = technische Phase. One request, one pass. The orange-bordered stages all run inside the Cloudflare edge, in a single pass within a few milliseconds — no box, no service hop. Outside: your client and your origin. Hover each stage = technical phase.
Warum das für eine unterbesetzte Behörde zählt: Die ~35 Sekunden sind autonom — kein SOC, das um 3 Uhr nachts reagieren muss. Genau das adressiert den Fachkräftemangel: die Abwehr läuft im Modell, nicht im Schichtplan. Why this matters for an understaffed agency: the ~35 seconds are autonomous — no SOC that has to react at 3 a.m. That directly addresses the skills shortage: defence runs in the model, not in a shift roster.
2026-Frische (Talk-Track): Über cf.intel-Felder fließt Cloudforce One Threat Intelligence direkt in WAF-Regeln. Enterprise-Capability erwähnen, nicht live demoen. 2026 freshness (talk track): via cf.intel fields, Cloudforce One Threat Intelligence feeds directly into WAF rules. Mention as Enterprise capability, don't demo live.
Sektion 6Section 6

Die anderen TürenThe other doors

Die WAF schützt die offensichtliche Tür: eingehende HTTP-Requests. Aber moderne Verwaltungs-Anwendungen haben mehr Türen. Zwei gehören in jedes PS-Gespräch — besonders dort, wo Bürger-Bezahlfunktionen oder offene Schnittstellen im Spiel sind. The WAF protects the obvious door: inbound HTTP requests. But modern government applications have more doors. Two belong in every PS conversation — especially where citizen payment functions or open interfaces are involved.

PrimärPrimary
API Shield
APIs sind der größte wachsende Angriffsvektor — und eine Negativliste reicht nicht. API Shield dreht das Modell um: positives Sicherheitsmodell.
  • Schema Validation — OpenAPI-Schema hochladen; alles, was nicht exakt passt, wird abgelehnt.
  • Erlaubt explizit das Erwartete, statt das Bekannte zu verbieten.
  • mTLS, JWT-Validierung, Sequence Analytics.
APIs are the fastest-growing attack vector — and a deny-list isn't enough. API Shield inverts the model: positive security model.
  • Schema Validation — upload your OpenAPI schema; anything that doesn't match exactly is rejected.
  • Explicitly allows the expected instead of denying the known-bad.
  • mTLS, JWT validation, Sequence Analytics.
SekundärSecondary
Page Shield
Der Angriff, den die WAF nicht sieht, weil er im Browser des Bürgers passiert — Client-Side / Magecart.
  • Überwacht Third-Party-Skripte und JS-Dependencies.
  • Alarmiert bei unerwarteten Skript-Änderungen (Supply-Chain / Skimming).
  • Adressiert PCI-DSS-4.0 — relevant für jede Behörde mit Online-Bezahlung.
The attack the WAF can't see, because it happens in the citizen's browser — client-side / Magecart.
  • Monitors third-party scripts and JS dependencies.
  • Alerts on unexpected script changes (supply chain / skimming).
  • Addresses PCI-DSS 4.0 — relevant for any agency with online payments.

Verwandt, aber mit eigenem Kapitel oben: Bot Management und Turnstile (CAPTCHA-Ersatz). Alles dieselbe Pipeline, dieselbe Edge, dieselben Souveränitäts-Schalter aus dem Kapitel „Wo Ihre Daten bleiben". Related, with their own chapter above: Bot Management and Turnstile (CAPTCHA replacement). All the same pipeline, same edge, same sovereignty switches from the “Where your data stays” chapter.

Kapitel · OnboardingChapter · Onboarding

So geht der Schutz liveHow protection goes live

Im Kern ist alles in diesem Kapitel eine Schutzkonfiguration vor Ihrer bestehenden Anwendung — aktiviert über DNS, nicht über einen Agenten auf dem Server und ohne Re-Architektur. Der Traffic fließt künftig durch Cloudflare, bevor er Ihr Origin erreicht. Drei Fragen klärt jede Behörde dabei. At its core, everything in this chapter is a protection configuration in front of your existing application — activated via DNS, not an agent on the server and with no re-architecture. Traffic now flows through Cloudflare before reaching your origin. Every agency clarifies three questions in the process.

1 · Aktivierung1 · Activation
Über DNSVia DNS
Full Setup: die Nameserver der Domain zeigen auf Cloudflare. Partial / CNAME-Setup: Sie behalten Registrar und DNS, leiten nur die betroffenen Hostnamen per CNAME ein — der pragmatische Weg, wenn der NS-Wechsel im PS schwer ist.Full setup: the domain's nameservers point to Cloudflare. Partial / CNAME setup: you keep registrar and DNS and onboard only the affected hostnames via CNAME — the pragmatic path when an NS change is hard in PS.
2 · Origin-Anbindung2 · Origin connection
Origin abriegelnLock the origin down
Das Origin bleibt, wo es ist — wird aber unsichtbar: IP-Allowlist (nur Cloudflare-IPs erreichen den Server), Authenticated Origin Pull (mTLS zwischen Cloudflare und Origin) oder Cloudflare Tunnel — keine offenen Inbound-Ports (Brücke zu Zero Trust).The origin stays where it is — but becomes invisible: IP allowlist (only Cloudflare IPs reach the server), Authenticated Origin Pull (mTLS between Cloudflare and origin) or Cloudflare Tunnel — no open inbound ports (bridge to Zero Trust).
3 · Scharfschalten3 · Enforcement
Erst beobachten, dann blockenObserve first, then block
Regeln laufen zuerst im Log-/Simulate-Modus: Sie sehen, was geblockt würde, ohne echten Traffic zu beeinträchtigen. Dann schrittweise auf Block — kein Big-Bang, jederzeit per DNS reversibel. Genau das, was Risiko-Aversion verlangt.Rules first run in log/simulate mode: you see what would be blocked without affecting real traffic. Then step up to block — no big bang, reversible via DNS at any time. Exactly what risk aversion demands.
Warum das im PS zählt: kein Agent, keine Origin-Migration, kein Wartungsfenster für die Inbetriebnahme — und ein reversibler, beobachtbarer Rollout. Die Hürde, „Schutz einzuschalten", ist ein DNS-Eintrag, kein Projekt. Why this matters in PS: no agent, no origin migration, no maintenance window to go live — and a reversible, observable rollout. The hurdle to “turn on protection” is a DNS record, not a project.
Sektion 7Section 7

Wie Sie es bekommenHow you procure it

Die beste Technik nützt nichts, wenn der Beschaffungsweg unklar ist. Für den öffentlichen Sektor zählen drei Dinge: ein gangbarer Vergabeweg, Referenzen aus der eigenen Welt und nachprüfbare Nachweise. The best technology is useless if the procurement path is unclear. For the public sector, three things matter: a viable procurement route, references from your own world, and verifiable evidence.

SE-Hinweis · BeschaffungProcurement Konkreten Reseller/Rahmenvertrag für die jeweilige Behörde vorab klären (Land/Kommune/Bund unterscheiden sich). Referenzen nur nennen, wenn öffentlich referenzierbar — sonst generisch bei „kritische Infrastruktur DE" bleiben. Clarify the specific reseller/framework for the agency in advance (state/municipal/federal differ). Only name references that are publicly referenceable — otherwise stay generic with “critical infrastructure DE”.
Sie haben gerade angegriffen — und nichts ist durchgekommen. Der Block war echt, kam am Edge, ~5 Sekunden nach jeder Regeländerung weltweit aktiv, DSGVO-konform inspizierbar und C5-testiert. Ihr Origin hat nie davon erfahren — und Ihr Change-Advisory-Board musste nicht tagen. You just attacked — and nothing got through. The block was real, happened at the edge, live worldwide ~5 seconds after any rule change, inspectable in a GDPR-compliant way and C5-attested. Your origin never knew — and your change-advisory board never had to convene.