Cloudflare configuration hardening security checks
Vendor-recommended secure defaults, patch levels and housekeeping settings that drift as tenants grow and admins change.
On Cloudflare, Black Cat runs 5 checks in this area on every scan. Each one below lists its severity, how to fix it, and the compliance controls it satisfies where a control applies. See what access the Cloudflare connector needs.
Checks (5)
severity: medium Browser Integrity Check Disabled fix difficulty: easy #
Enable Cloudflare Browser Integrity Check to block requests from malicious clients
- Log in to the Cloudflare Dashboard and select the zone
- Navigate to Security > Settings
- Enable Browser Integrity Check
Satisfies: ISO 27001:2022 A.8.7 SOC 2 Type II CC6.8 CIS Controls v8 CIS-10.5 NIST CSF 2.0 DE.CM GDPR (SaaS Security) GDPR-25.1 HIPAA (SaaS Security) HIPAA-308.a1 NIS2 Directive NIS2-21.e.4 DORA (SaaS Security) DORA-9.10
severity: high WAF Disabled fix difficulty: medium #
Deploy a Cloudflare managed WAF ruleset for the zone
- Log in to the Cloudflare Dashboard and select the zone
- Navigate to Security > WAF > Managed rules
- Deploy the Cloudflare Managed Ruleset (and the OWASP Core Ruleset if appropriate)
- Confirm the deployed ruleset is enabled
Satisfies: ISO 27001:2022 A.8.7 SOC 2 Type II CC6.6 CIS Controls v8 CIS-10.5 NIST CSF 2.0 DE.CM GDPR (SaaS Security) GDPR-25.1 HIPAA (SaaS Security) HIPAA-308.a1 NIS2 Directive NIS2-21.e.4 DORA (SaaS Security) DORA-9.10
severity: high Security Level Essentially Off fix difficulty: easy #
Raise the Cloudflare zone security level from Essentially Off to Medium or higher
- Log in to the Cloudflare Dashboard and select the zone
- Navigate to Security > Settings
- Change Security Level from Essentially Off to Medium or High
- Save the changes
Satisfies: NIS2 Directive NIS2-21.e.4 DORA (SaaS Security) DORA-9.10
severity: medium Security Level Low fix difficulty: easy #
Raise the Cloudflare zone security level from Low to Medium or higher
- Log in to the Cloudflare Dashboard and select the zone
- Navigate to Security > Settings
- Change Security Level from Low to Medium or High
- Save the changes
Satisfies: NIS2 Directive NIS2-21.e.4 DORA (SaaS Security) DORA-9.10
severity: medium Zone Settings Unavailable fix difficulty: medium #
Investigate why Cloudflare zone settings cannot be retrieved and ensure API token has sufficient permissions
- Log in to the Cloudflare Dashboard and select the zone
- Verify the API token used by the connector has Zone Settings Read permission
- Check if the zone is on a plan that supports settings retrieval
- Re-run the scan after fixing API token permissions
Satisfies: NIS2 Directive NIS2-21.e.4 DORA (SaaS Security) DORA-9.10