S3 + CloudFront Website / CDN
Static hosting where the bucket is private, the certificate is right, and deploys invalidate the cache.
From $249 1–3 days
Rules tuned against your real traffic, in count mode first, so nothing legitimate gets blocked.
From $349
Typically $349–$749, fixed in writing before anything starts.
What moves it up
Some of this you can check yourself, right now, for free: Website Health Check →
WAF gets deployed the way a smoke alarm gets installed by someone who then takes the battery out. The managed rule groups go on in block mode straight away, something legitimate trips a rule within a fortnight — an admin pasting SQL into a form, a webhook with an unusual user agent — and rather than tune it, the rule group goes to count mode "temporarily" and stays there. What is left is a WAF that costs money every month and blocks nothing. The other half is scope: the rules sit on CloudFront while the load balancer behind it is still reachable directly.
aws wafv2 list-web-acls, then get-web-acl — how many rules are actually in block modeaws wafv2 get-sampled-requests — real requests a rule matched, before deciding to enforce itThe ALB's DNS name requested directly, to see whether the edge can be bypassed entirelyaws wafv2 get-web-acl-for-resource for every public resource, not just the one you rememberIt will if you deploy it in block mode on day one, which is why nothing here is enforced until it has spent time counting against your real traffic. False positives get found in the log, not in a support ticket.
Shield Standard is already protecting you at layer three and four, at no cost. WAF handles the application layer — request floods, bad bots, credential stuffing. A genuinely large volumetric attack is Shield Advanced territory, which is a serious monthly commitment and I will tell you if you are nowhere near needing it.
A few dollars a month for the web ACL and rules, plus a charge per million requests. For most sites this size it is a small line — the cost that surprises people is the logging, which is why retention gets set with everything else.
Yes, and that is part of the point. Logging goes somewhere queryable so any block can be traced to a rule and a request, which is what makes tuning possible rather than guesswork.
Static hosting where the bucket is private, the certificate is right, and deploys invalidate the cache.
From $249 1–3 days
A record of who did what, kept long enough to be useful and somewhere it cannot be edited.
From $299 2–4 days
Tell me what you are running and I will come back with a fixed price and a date. If it turns out you do not need this, I will say that instead.
Prefer to talk? Book a free call ↗ · Or hire me on Upwork ↗ · Typical reply within one business day.
Sunday to Thursday, 09:00–18:00 EET. Outside that I will still look, but I will not promise a time.
One person, one time zone. If round-the-clock cover is what you need, you need a team, and I will say so rather than sell you a plan that cannot deliver it.
You pay Amazon directly and you keep control of the account. Nothing here resells your infrastructure or sits between you and your own billing.
Every service page lists exactly what pushes a quote above it, before you ask. You get a fixed number in writing before any work begins.