Securing a Web Platform with AWS WAF

Discover how we strengthened the cybersecurity of a healthcare web platform, automating threat mitigation and securing patient data.

  • DevOps Services
  • HealthTech
  • UK

Our Customer

Healthera is a digital healthcare platform that enables patients in the UK to manage their prescriptions, medications, and health services in one place on the web.

For pharmacies and healthcare providers, Healthera helps future-proof their services in a world where patients expect digital-first solutions, reduces administrative burden, and drives business growth.

The Challenges

Addressing Cybersecurity Risks in a Data-Sensitive Web Platform

As a client’s platform handling a vast amount of sensitive medical data and patient transactions, it faced growing cybersecurity risks that threatened data security, application performance, and availability.
Key challenges which customer faced included:

  • Frequent Bot Attacks
    The platform experienced a surge in automated login attempts, raising concerns about credential stuffing and unauthorized account takeovers.
  • Web App Vulnerabilities
    The evolving cyber threat landscape increased the platform’s exposure to SQL injection (SQLi) and cross-site scripting (XSS) attacks. These emerging threats heightened the likelihood of data breaches and unauthorized access.
  • Access Control Issues
    The app also required strict whitelisting and blocking policies to prevent unauthorized users from accessing sensitive executive and transactional data.

THE SOLUTION

Comprehensive Security with Automated Threat Prevention and Access Control

To fortify the website and ensure its compliance, we implemented AWS Web Application Firewall with a combination of managed and custom security rules, specifically:

Multi-Layered Web Protection with AWS WAF

  • Bot Control
    Prevented malicious bot traffic while ensuring uninterrupted access for legitimate users.
  • AWS Core Rule Set (CRS)
    Protection against SQL injection, XSS, and PHP-specific vulnerabilities commonly exploited in healthcare platforms.
  • Managed Rules for WordPress
    Blocked request patterns targeting WP vulnerabilities, ensuring security for the site’s content management system.
  • IP Reputation Lists
    Automatically blocked traffic from known malicious IPs, reducing exposure to botnets and attack networks.
  • Rate-Based Rules
    Limited excessive requests per IP, protecting against credential stuffing, brute-force attacks, and DoS attempts.
  • IP Whitelisting
    Ensured that only trusted IP addresses could access sensitive administrative areas, strengthening access control.

AWS Integrations for Security and Performance

To enhance both security and system performance, AWS WAF was integrated with the following AWS services for edge-level filtering and real-time monitoring:

  • Amazon CloudFront
    Applied security rules at the CDN edge, blocking threats before they could reach the origin server, reducing latency and server load.
  • Amazon CloudWatch
    Provided real-time threat monitoring and traffic analysis, enabling data-driven security adjustments.

Automation and Continuous Refining

A combination of AWS Managed Rule Groups and rate-based rules delivers ongoing protection by automatically updating defenses against the OWASP Top 10 threats, malicious IPs, SQL injection attacks, PHP-specific vulnerabilities, and bot activity. These rules adapt to emerging security risks, significantly reducing the need for manual intervention.

By leveraging AWS WAF Managed Rule Groups, we ensure security policies remain consistently aligned with the latest threat intelligence, strengthening the overall resilience of your applications against web attacks.

Amazon Web Services Utilized

AWS WAF icon
WAF
Amazon CloudFront icon
CloudFront
Amazon CloudWatch icon
CloudWatch

The Results

Reduced Cyber Threats and Enhanced Platform Reliability

By implementing AWS Web Application Firewall, we helped the client’s web platform significantly enhance its security posture, streamline operations, improve application performance, and reduce operational overhead.

Key achievements in details:

  • Reduction in Malicious Traffic
    Strengthened protection against SQL injection, XSS, and automated attacks, ensuring data comprehensive security.
  • Lower Infrastructure Costs
    Rate-limiting and request filtering optimized server load, reducing unnecessary compute cloud resource consumption.
  • Increase in Application Uptime
    Eliminating bot traffic and malicious requests improved platform availability and response times for legitimate real users.
  • Faster Security Incident Response
    Automated threat mitigation minimized manual intervention, allowing IT engineering to focus on critical tasks, thus lowering administrative workload.
  • Compliance and Access Control
    IP whitelisting and request blocking policies ensured strict security compliance and controlled system access.

Why Romexsoft

Enhance Your Cybersecurity with Our Web Application Security Solutions

Romexsoft is an AWS-certified Consulting Partner, trusted Software Development Company and Managed Service Provider, founded in 2004. We help customer-centric companies build, run, and optimize their cloud systems on AWS with creative, stable, and cost-efficient solutions.

Our key values:

  • Delivery of quality solutions
  • Customer satisfaction
  • Long-term partnership

We have successfully delivered 100+ projects and have a proven track record in FinTech, HealthCare, AdTech, and Media industries.

Romexsoft possesses a 5-star rating on Clutch due to its strong expertise, responsiveness, and commitment. 60% of our clients have been working with us for over 4 years.

Related Success Stories

Web Application Security Services with AWS WAF
Explore our custom application security services, leveraging AWS WAF to protect web app against cyber threats and automate attack prevention.
Improving Website Performance and Security with AWS WAF and CloudFront
Uncover how we managed to improve website performance and security using AWS WAF and Amazon CloudFront.

Craft Your Vision – Make the First Step.
Book a Consultation With Our Experts.

    Contact Romexsoft
    Get in touch with AWS certified experts!