The 41 Cloudflare security checks Black Cat runs
Black Cat SSPM evaluates 41 security policies against your Cloudflare configuration on every scan, classifies each finding by risk, and provides remediation steps. Browse them by topic below.
How to connect Cloudflare — what access Black Cat needs, and why.
Access control & privilege
9 checks · highest severity: critical
Encryption, keys & secrets
9 checks · highest severity: critical
Network security
3 checks · highest severity: medium
Configuration hardening
5 checks · highest severity: high
AI governance
12 checks · highest severity: high
Access control & privilege (9)
- External Account Member severity: medium
- SSO Not Configured severity: medium
- Super Admin Count Excessive severity: medium
- Super Admin Redundancy Missing severity: high
- Super Admin Without MFA severity: critical
- Pending Account Member severity: medium
- Role-less Account Member severity: low
- API Token Without Expiry severity: medium
- API Token Stale severity: medium
Encryption, keys & secrets (9)
- SSL Encryption Disabled severity: critical
- SSL Mode Flexible severity: high
- Always Use HTTPS Disabled severity: high
- Automatic HTTPS Rewrites Disabled severity: medium
- HSTS Disabled severity: high
- Minimum TLS Version Weak severity: high
- Opportunistic Encryption Disabled severity: low
- TLS 1.3 Disabled severity: medium
- TLS Mode Not Strict severity: medium
Network security (3)
- DNS Wildcard Record severity: medium
- DNS Record Points to Private IP severity: medium
- DNS Record Not Proxied severity: low
Configuration hardening (5)
- Browser Integrity Check Disabled severity: medium
- WAF Disabled severity: high
- Security Level Essentially Off severity: high
- Security Level Low severity: medium
AI governance (12)
- AI Gateway Logging Disabled severity: high
- AI Gateway No Authentication severity: high
- AI Gateway No Rate Limiting severity: high
- AI Gateway ZDR Disabled severity: medium
- AI Gateway No Guardrails severity: medium
- AI Gateway No Log Export severity: medium
- AI Gateway Log Overflow Silent severity: medium
- AI Gateway Aggressive Retry Without Rate Limit severity: medium
- Worker AI Binding Ungoverned severity: low
- AI Gateway Account-Wide No Authentication severity: low
- Fine-Tuned Model Present severity: low
- Cloudflare AI Gateway Agent High Risk Unblocked severity: high
Other checks (3)
severity: high MFA Not Enabled fix difficulty: easy #
Require Cloudflare account members to enable two-factor authentication
- Instruct the account member to log in to their Cloudflare profile
- Navigate to My Profile > Authentication
- Enable two-factor authentication using TOTP or security key
- Verify MFA is active for the account
Satisfies: ISO 27001:2022 A.5.15 SOC 2 Type II CC6.1 CIS Controls v8 CIS-06.3 NIST CSF 2.0 PR.AA-03 GDPR (SaaS Security) GDPR-32.1b.i HIPAA (SaaS Security) HIPAA-312.d NIS2 Directive NIS2-21.j DORA (SaaS Security) DORA-9.4
severity: critical Two-Factor Enforcement Disabled fix difficulty: easy #
Enable two-factor authentication enforcement for all Cloudflare account members
- Log in to the Cloudflare Dashboard
- Navigate to the Members page
- Enable 2FA enforcement for the account
- Notify members so they can enroll an authenticator app or security key before the policy takes effect
Satisfies: ISO 27001:2022 A.8.5 SOC 2 Type II CC6.1 CIS Controls v8 CIS-06.5 NIST CSF 2.0 PR.AA-03 GDPR (SaaS Security) GDPR-32.1b.i HIPAA (SaaS Security) HIPAA-312.d NIS2 Directive NIS2-21.j DORA (SaaS Security) DORA-9.4
severity: high Cloudflare AI Gateway Agent Orphaned Owner fix difficulty: easy #
Reassign the AI Gateway agent to an active owner
- Identify the agent owner in the Cloudflare dashboard
- Transfer ownership to an active team member
Satisfies: NIS2 Directive NIS2-21.i.2 DORA (SaaS Security) DORA-9.6