Skip to content

Cloudflare configuration hardening security checks

Vendor-recommended secure defaults, patch levels and housekeeping settings that drift as tenants grow and admins change.

On Cloudflare, Black Cat runs 5 checks in this area on every scan. Each one below lists its severity, how to fix it, and the compliance controls it satisfies where a control applies. See what access the Cloudflare connector needs.

Checks (5)

severity: medium Browser Integrity Check Disabled fix difficulty: easy #

Enable Cloudflare Browser Integrity Check to block requests from malicious clients

  1. Log in to the Cloudflare Dashboard and select the zone
  2. Navigate to Security > Settings
  3. Enable Browser Integrity Check

Vendor docs ↗

Satisfies: ISO 27001:2022 A.8.7 SOC 2 Type II CC6.8 CIS Controls v8 CIS-10.5 NIST CSF 2.0 DE.CM GDPR (SaaS Security) GDPR-25.1 HIPAA (SaaS Security) HIPAA-308.a1 NIS2 Directive NIS2-21.e.4 DORA (SaaS Security) DORA-9.10

severity: high WAF Disabled fix difficulty: medium #

Deploy a Cloudflare managed WAF ruleset for the zone

  1. Log in to the Cloudflare Dashboard and select the zone
  2. Navigate to Security > WAF > Managed rules
  3. Deploy the Cloudflare Managed Ruleset (and the OWASP Core Ruleset if appropriate)
  4. Confirm the deployed ruleset is enabled

Vendor docs ↗

Satisfies: ISO 27001:2022 A.8.7 SOC 2 Type II CC6.6 CIS Controls v8 CIS-10.5 NIST CSF 2.0 DE.CM GDPR (SaaS Security) GDPR-25.1 HIPAA (SaaS Security) HIPAA-308.a1 NIS2 Directive NIS2-21.e.4 DORA (SaaS Security) DORA-9.10

severity: high Security Level Essentially Off fix difficulty: easy #

Raise the Cloudflare zone security level from Essentially Off to Medium or higher

  1. Log in to the Cloudflare Dashboard and select the zone
  2. Navigate to Security > Settings
  3. Change Security Level from Essentially Off to Medium or High
  4. Save the changes

Vendor docs ↗

Satisfies: NIS2 Directive NIS2-21.e.4 DORA (SaaS Security) DORA-9.10

severity: medium Security Level Low fix difficulty: easy #

Raise the Cloudflare zone security level from Low to Medium or higher

  1. Log in to the Cloudflare Dashboard and select the zone
  2. Navigate to Security > Settings
  3. Change Security Level from Low to Medium or High
  4. Save the changes

Vendor docs ↗

Satisfies: NIS2 Directive NIS2-21.e.4 DORA (SaaS Security) DORA-9.10

severity: medium Zone Settings Unavailable fix difficulty: medium #

Investigate why Cloudflare zone settings cannot be retrieved and ensure API token has sufficient permissions

  1. Log in to the Cloudflare Dashboard and select the zone
  2. Verify the API token used by the connector has Zone Settings Read permission
  3. Check if the zone is on a plan that supports settings retrieval
  4. Re-run the scan after fixing API token permissions

Vendor docs ↗

Satisfies: NIS2 Directive NIS2-21.e.4 DORA (SaaS Security) DORA-9.10

More Cloudflare checks

The information on this page is provided for general informational purposes and is believed to be accurate as of its most recent update. Product names, logos, and trademarks are the property of their respective owners and are used for identification purposes only; their use does not imply any affiliation with or endorsement by those owners. Descriptions of third-party applications and of compliance frameworks are based on publicly available documentation and may change over time.

See these checks run on your stack

Start a free 14-day trial — no credit card required.

Start Free Trial