
Overview
This product is for new AWS WAF. Cyber Security Cloud Managed Rules are compiled in a comprehensive package to mitigate and minimize vulnerabilities, including the most serious OWASP API Security/Serverless Top 10 Threats. With the API Gateway/Serverless ruleset, you can start protecting your Amazon API Gateway and Serverless environment right away with a low false-positive rate and a higher defense capability.
Included are a lot of managed rules targeting common vulnerabilities such as code injection techniques (SQLi, NoSQLi, OScommandi, etc), XML External Entity attacks, Server Side Request Forgery, XSS, directory traversal and Malicious Bots rulesets.
Highlights
- Can build a more secure API Gateway and Serverless environment immediately
- Designed to have the defense capability needed to protect your API Gateway and Serverless, with a low false-positive rate
- Minimizes OWASP API Security/Serverless Top 10 threats
Details
Introducing multi-product solutions
You can now purchase comprehensive solutions tailored to use cases and industries.
Features and programs
Buyer guide

Financing for AWS Marketplace purchases
Pricing
Dimension | Cost/unit |
|---|---|
Charge per month in each available region (pro-rated by the hour) | $30.00 |
Charge per million requests in each available region | $1.20 |
Vendor refund policy
Non-Refundable
How can we make this page better?
Legal
Vendor terms and conditions
Content disclaimer
Delivery details
Software as a Service (SaaS)
SaaS delivers cloud-based software applications directly to customers over the internet. You can access these applications through a subscription model. You will pay recurring monthly usage fees through your AWS bill, while AWS handles deployment and infrastructure management, ensuring scalability, reliability, and seamless integration with other AWS services.
Support
Vendor support
For issues related specifically to Cyber Security Cloud Managed Rules, you can contact support offered by Cyber Security Cloud by email.
AWS infrastructure support
AWS Support is a one-on-one, fast-response support channel that is staffed 24x7x365 with experienced and technical support engineers. The service helps customers of all sizes and technical abilities to successfully utilize the products and features provided by Amazon Web Services.


Standard contract
Customer reviews
Managed rules have protected our ecommerce site and have reduced botnet and sql injection attacks
What is our primary use case?
My main use case for Cyber Security Cloud Managed Rules is to protect against malicious attacks like SQL injection attacks and cyber attacks.
Recently, I discovered malicious IPs which I believed were operating as a botnet and attacking my e-commerce website. Because WAF is for web application security, I used WAF managed rules related to IP and IP injection attacks. There are additional rules available for IP rate limiting based attacks, which allow me to implement a maximum number of attempts from a particular IP within a specific time period. This rate-limiting rule helps prevent unknown IPs from accessing my website.
The general security vulnerabilities provided by AWS WAF through managed rules or custom rules that I can implement will protect my application and enhance the security of my application through these security rules. This is the main use case of implementing WAF rules.
What is most valuable?
The best features of Cyber Security Cloud Managed Rules are that there are managed rules available for free that I can implement. I can stop SQL injection attacks, which is one significant vulnerable attack that can be stopped by WAF. Bitcoin mining attacks can also be stopped by implementing WAF. Additionally, there are specific rules related to bot control, which are especially helpful when a bot attacks my website. I implemented a framework known as OWASP Top 10, so these ten security critical vulnerabilities can be mitigated by implementing them.
I implemented free managed rules by AWS , which include Cyber Security Cloud Managed Rules. These managed rules control SQL injection attacks and other attacks that are managed by WAF to prevent them from affecting my systems.
Cyber Security Cloud Managed Rules have impacted my organization very positively because my company is security-focused. We are focusing mainly on security-based setups and implementing everything that can enhance security. This is one of the key applications or services I can implement in my company to stop mitigation attacks, which is why I implemented WAF and attached it to CloudFront, API Gateway, and sometimes to a load balancer to stop and mitigate these attacks.
I noticed specific outcomes or metrics from Cyber Security Cloud Managed Rules in the form of reduced attacks. I discovered that there was no system through which I could conclusively determine what happened, but I noticed some IPs in the logs that were attacking my website and trying to exploit Bitcoin through our platform. This activity was reduced by implementing WAF, and this is what I verified from the logs, which were very helpful.
What needs improvement?
I believe that Cyber Security Cloud Managed Rules can be improved by reducing false positives with traffic-aware tuning. Out-of-the-box managed rules are generic, and sometimes they block legitimate traffic. Improvements can be achieved by running rules in count monitor mode first, reviewing blocked requests using logs, adding custom rules on top of managed rules, and enabling request inspection depth layer seven hardening. These are techniques I can use to improve these rules.
For how long have I used the solution?
I have been using Cyber Security Cloud Managed Rules for the past one year.
What do I think about the stability of the solution?
Cyber Security Cloud Managed Rules are stable in the sense that I do not experience issues with availability or performance.
What do I think about the scalability of the solution?
Regarding scalability, I can easily implement them.
Which solution did I use previously and why did I switch?
I have not previously used a different solution because we are AWS native and implemented this solution only.
How was the initial setup?
Regarding pricing, setup cost, and licensing, I find it a bit more expensive.
What about the implementation team?
Regarding scalability, I can easily implement them.
What was our ROI?
I have seen a return on investment.
What's my experience with pricing, setup cost, and licensing?
Regarding pricing, setup cost, and licensing, I find it a bit more expensive.
Which other solutions did I evaluate?
Before deciding on Cyber Security Cloud Managed Rules, we went straight to using these rules. Everything is deployed on AWS, and we want to use AWS. This is the only sole provider for our company, so we are bound to use it.
What other advice do I have?
I would advise others looking into Cyber Security Cloud Managed Rules to use WAF if they want to eliminate security attacks, especially if they are using AWS. I would rate this product 8 out of 10.
Which deployment model are you using for this solution?
If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?
Automated rules have reduced manual security work and now protect our APIs from modern attacks
What is our primary use case?
My main use case for Cyber Security Cloud Managed Rules is the protection of any cyber attack on my API servers and cloud managed rules on my WAF .
A specific example of how I use Cyber Security Cloud Managed Rules to protect my API servers is that we have an AWS WAF at the parameter level where we have implemented the OWASP top 10 attack rule as a cybersecurity managed rule in the parameter. Any traffic coming to our API server passes through the WAF , and the WAF OWASP top 10 rule filters that traffic for any attack.
What is most valuable?
The best features Cyber Security Cloud Managed Rules offers are mainly that there is less human intervention, which reduces the chances of error, and it is also less time-consuming and more intelligent compared to manual rules.
When I mention more intelligent, Cyber Security Cloud Managed Rules stands out in that these rules are generally updated according to the latest cyber attacks and the latest signatures in the system, so we don't need to manually change the rule, as they get updated mostly in real time, making detection easier.
Cyber Security Cloud Managed Rules has positively impacted my organization because earlier, a complete SOC team was required 24/7 for manually checking the alerts, acting upon those alerts, and doing forensics. With cloud managed rules being automated and intelligent and updating in real time, the manual intervention by the SOC team has been significantly reduced, resulting in a comparatively higher detection rate than before.
What needs improvement?
I sometimes need to tweak Cyber Security Cloud Managed Rules because it is a predefined rule where I adjust it based on our request sizes. Sometimes a rule states that only a 5 MB request is allowed, but we have requests greater than 5 MB, which causes it to block that traffic. I have to adjust the rule and increase the size of the request or payload above 5 MB to resolve this issue.
Cyber Security Cloud Managed Rules can be improved in that they are mostly general rules and not specific to organizational needs. Being predefined rules, if we have to make any changes, we need to create a rule above or before that cybersecurity rule or a bypass rule. There should be an option to tweak those cloud managed rules to adjust them based on organizational needs, as this has been one challenge we faced.
Cyber Security Cloud Managed Rules is limited to specific scenarios. For example, AWS WAF can only be used in an AWS scenario, which makes it complex to integrate with on-prem systems.
For how long have I used the solution?
I have been using Cyber Security Cloud Managed Rules for more than five years.
What do I think about the stability of the solution?
Cyber Security Cloud Managed Rules is stable, and the support is excellent with the cloud service. The after-sales support and technical support team are very reliable, so I have no issues with that.
What do I think about the scalability of the solution?
Scalability with Cyber Security Cloud Managed Rules is not a problem, as we have opted for a BYOL (bring your own license) model where systems automatically adjust during high demand, which is advantageous for scalability.
How are customer service and support?
Customer support for Cyber Security Cloud Managed Rules is great, as it is easy to reach out compared to on-prem vendors, and overall, I am satisfied with the customer support provided.
Which solution did I use previously and why did I switch?
I previously used an on-prem solution where everything was done manually, which was expensive regarding employee count and time, with higher chances of error. This prompted us to switch to a hybrid environment that includes both on-prem and cloud solutions.
What was our ROI?
The return on investment is great. Earlier, we had to manage the whole infrastructure on-prem with a different team at every step, which incurs high costs. With cloud infrastructure, we avoid a significant upfront investment, so it operates on a pay-as-we-grow model, which is beneficial.
What's my experience with pricing, setup cost, and licensing?
My experience with pricing, setup cost, and licensing is that it is very transparent and easy to manage the infrastructure in the cloud. The pricing is very clear, allowing us to track costs using the price calculator and the pricing dashboard, making it very straightforward.
Which other solutions did I evaluate?
Before choosing Cyber Security Cloud Managed Rules, I evaluated other options including on-prem systems and building our servers for automation with tools such as Ansible . I found that the cloud managed rules were easier to set up and better suited for our environment.
What other advice do I have?
My advice to others looking into using Cyber Security Cloud Managed Rules is to maintain a blend of on-prem and cloud solutions, while also performing regular checks and balances on the cloud managed rules to observe their behavior with applications.
My additional thoughts on Cyber Security Cloud Managed Rules are that the effectiveness largely depends on the specific business use case, as it will not fit every business logic. Sometimes, there is over-blocking within the cloud managed rules where valid requests or IPs could be blocked, which should be fine-tuned to reduce over-blocking. I would rate this product an 8 overall.
Which deployment model are you using for this solution?
If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?
Security guardrails have protected web and AI workflows but rules need more flexibility and accuracy
What is our primary use case?
A specific example of how we have used Cyber Security Cloud Managed Rules to protect our web applications or CDN is that we have a proper dashboard of all attacks that were attempted on those exposed URLs at the application level and we have clear visibility. Whenever there is some type of IP which is trying to DDoS our domain, then it gets automatically blocked and we have configured alerts as well. We do get a consolidated report weekly and monthly that shows a lot of hits, what the IP was, and that it was automatically blocked.
We also have AI workload, so it is important to consider that in our main use case for Cyber Security Cloud Managed Rules. We are catering to that in our workflow and trying to manage it so that even our AI workflows do not have prompt injections or, if we are having agents, we do not get man-in-the-middle attacks with the prompts.
What is most valuable?
Cyber Security Cloud Managed Rules has positively impacted our organization because we are a tech company, so we always prefer to get security first. This is a big thing when it comes to exposing any domain. We would want to ensure that we have secure guardrails around it, and whenever we roll it out, we properly ensure that there was a design doc, there was a review, and make sure that it was behind those security gates to avoid any issues after go-live. It is a proper process that we follow to ensure that no new application sneaks through and before go-live, all these checks are done.
What needs improvement?
Cyber Security Cloud Managed Rules does the job, and if you have it configured in the correct way as per your requirements, such as IP sets or SQL injection, you are able to get a basic cover, but the workloads are evolving, and I would like to see more flexibility around those rules so that I can make better use of them. Because use cases are increasing, I would to play around with the rules a bit more so that I can say with certainty that my workloads are secure and ingress traffic is secure. That would help me, so I would give a better rating if that can happen.
Cyber Security Cloud Managed Rules are generally stable in my experience, but if a new attack vector rises or if something new comes up, they are not very adaptable, which is my feeling and experience. I would say they are stable, but not very versatile.
For how long have I used the solution?
What do I think about the stability of the solution?
What do I think about the scalability of the solution?
How are customer service and support?
Which solution did I use previously and why did I switch?
Before choosing Cyber Security Cloud Managed Rules, I have always used WAF as a web application firewall and at the network level, we have a network firewall. That is how it has been. At the API Gateway level also we have WAF and even if we expose it via a load balancer, we use WAF. No matter how we expose to the internet, it has always been WAF in the forefront. WAF rules are the thing we have always used.
What was our ROI?
What other advice do I have?
I think the AI space is something really big right now, so I would to see some improvements around those lines.
I am not one hundred percent sure if we purchased Cyber Security Cloud Managed Rules through the AWS Marketplace . We may have, but I have not looked into that.
I have not been involved in the pricing, setup cost, and licensing phase for Cyber Security Cloud Managed Rules. It usually comes via procurement, so I am not involved in the licensing side of things because I am mostly technical and I am someone who implements things. I have not come across looking at the pricing, licensing, or setup cost.
I would give Cyber Security Cloud Managed Rules an overall rating of seven.
Managed web rules have protected our apps and have reduced common cyber attacks and downtime
What is our primary use case?
My main use case for Cyber Security Cloud Managed Rules is to prevent basic cyber attacks that happen most commonly using a Web Application Firewall .
Regarding my main use case and experience, the Web Application Firewall handles basic attacks. There is also a dashboard where I can check how these rules are blocking requests. I can check from which countries are sending more vulnerable requests towards us, which is very useful.
I can give a specific example of a situation where I used the managed rules to block or prevent an attack. In my recent project, the Web Application Firewall prevented attacks such as SQL injection, cross-site scripting, and brute force attempts. I was getting many requests from different servers, which may have been a DDoS attack. I had already written a managed rule for this situation. I created a custom rule in which if many requests come from a specific source, they will be blocked.
How has it helped my organization?
The number of incidents and downtime have decreased significantly since implementing Cyber Security Cloud Managed Rules . My team saves considerable time as a result of using this solution.
What is most valuable?
The best features Cyber Security Cloud Managed Rules offers include tracking the IPs or bots sending requests that try to attack our servers. I can also block them using these WAF rules, Web Application Firewall rules, which is a good feature.
It is very easy for me to track those IPs and bots using the managed rules, and it integrates well with my dashboards and logs.
Regarding valuable features, the ability to see the IP and the country where the request comes from is very useful when I want to find which countries are getting the most malicious requests and which bots are sending malicious requests. This allows me to block them or add them into my blocked IP list.
Cyber Security Cloud Managed Rules has positively impacted my organization; the impact was great. Since I can track all these malicious requests, I was able to block those, and we do not get attacked much lately since I have been using a Web Application Firewall. I also use their bot rules, where it automatically blocks specific bots which are flagged or blacklisted, which really helps.
I did notice changes in the number of incidents, downtime, and time saved for my team since I started using Cyber Security Cloud Managed Rules. We do not get downtimes now since we have been using this, and the impact is quite positive. Everyone should at least use the basic common rule set of these WAF rules.
What needs improvement?
Cyber Security Cloud Managed Rules can be improved through more research on malicious attack patterns and threats.
For how long have I used the solution?
I have been using Cyber Security Cloud Managed Rules for approximately 1.5 years.
What do I think about the stability of the solution?
Cyber Security Cloud Managed Rules is stable.
What do I think about the scalability of the solution?
The scalability of Cyber Security Cloud Managed Rules depends on the rules and what type of rules are being used.
How are customer service and support?
I would describe the customer support for Cyber Security Cloud Managed Rules as pretty average. They provide a link and then disappear, so I have to do my own research. My experience with support was not good.
Which solution did I use previously and why did I switch?
I have not previously used a different solution; AWS Web Application Firewall was my first.
How was the initial setup?
I can purchase Cyber Security Cloud Managed Rules from the AWS console. I do not have to go to the AWS Marketplace .
What about the implementation team?
My advice for others looking into using Cyber Security Cloud Managed Rules is to definitely consider it.
What was our ROI?
I have seen a return on investment with Cyber Security Cloud Managed Rules. It really saved my time debugging attacks by showing me where the attack came from, whether it was detected, and how to prevent it. Since I have been using WAF, these incidents are very less frequent than before. It is really helpful for the person in charge of security for the cloud infrastructure.
What's my experience with pricing, setup cost, and licensing?
Amazon provides around five to six rules which are literally free of cost, saving me from many basic attacks such as SQL injection, SSH scripts, or any vulnerable common attacks. I can use these rules free of cost. Some of the rules AWS provides cost some money, around $10. For example, there is a rule which blocks suspicious bots automatically.
Which other solutions did I evaluate?
I have not evaluated other options before choosing Cyber Security Cloud Managed Rules because I first tried AWS Web Application Firewall since my whole project infrastructure was on AWS, which is why I chose AWS Web Application Firewall.
What other advice do I have?
Everyone should use these rules for better security for their applications and implement them. Additionally, they should learn from the mistakes they make when implementing rules for the future. I give Cyber Security Cloud Managed Rules an overall rating of eight out of ten.
Managed rules have protected our APIs and AI chatbot and now need better automation and insights
What is our primary use case?
I am integrating these WAF rules with the API Gateway and CloudFront to ensure security from cybersecurity issues, minimizing vulnerabilities and mitigating threats from hackers, including the OWASP top 10 web application threat lists. I have configured it for our front end and for the API Gateway.
I am using Cyber Security Cloud Managed Rules for our GenAI applications, specifically for the chatbot I have recently created, which helps tremendously and prevents hackers' exploits in our application.
What is most valuable?
In my day-to-day work, I find the malicious bot detection feature of Cyber Security Cloud Managed Rules to be the most valuable.
Cyber Security Cloud Managed Rules has positively impacted my organization by reducing the manual WAF management by fifty percent and accelerating the automated updates and improvement in threat intelligence.
What needs improvement?
For how long have I used the solution?
What do I think about the stability of the solution?
What do I think about the scalability of the solution?
How are customer service and support?
Which solution did I use previously and why did I switch?
How was the initial setup?
What was our ROI?
What's my experience with pricing, setup cost, and licensing?
What other advice do I have?
I do not have any additional thoughts about Cyber Security Cloud Managed Rules at the moment, but if I encounter something while developing more agentic AI applications in the future, I hope to find something helpful for improving the cybersecurity managed rules. I have provided this review with a rating of seven.
