Web application firewall in front of every client project
Every web application we look after now sits behind a web application firewall based on the OWASP Core Rule Set. Suspicious requests are logged and evaluated; sources that appear repeatedly are blocked in escalating stages.
The rules are tuned per application, so editors are not held up by false positives.