Sadly I work with web developers that all assume they don’t need to bother too much with security “because we have a WAF”.