Use cases
Security problems, solved end to end.
Operational playbooks for the work regulated teams actually run on Cloudflare: architecture, rollout and 24/7 managed operation. Some come with interactive tools to size the problem before you talk to anyone.
All use cases
Pick your problem.
The AI tools nobody told you about
Your people already pasted customer data into a chatbot. See which tools, which data, and bring the useful ones inside your perimeter instead of banning everything.
Estimate how many of your people are pasting sensitive data into gen-AI tools.
Read the playbookBy the time you react to a DDoS, the site is already down
The switch you flip mid-attack is always too late. Always-on scrubbing, sized to your real traffic, triggered without human intervention.
Size a single outage against your own revenue in seconds.
Read the playbookRetire the VPN without a Monday-morning outage
Phased ZTNA migration: which applications move first, what breaks if you rush it, and who runs access once you're live.
Sketch a phased VPN-to-ZTNA rollout for your headcount.
Read the playbookIt looked like an invoice. It was phishing.
BEC and phishing carry no malware, just a plausible request from a name you trust. What catches them, and what your gateway lets through.
Size your annual business-email-compromise exposure by headcount and sector.
Read the playbookFour consoles on your edge, one blind spot: your APIs
WAF, API protection, bot management and L7 DDoS are one category now. What each actually covers, where they overlap, and where your APIs fall between them.
Score your API exposure in five questions.
Read the playbookSomeone awake when the alert fires at 3am
What a managed SOC actually does between alerts, what it costs against hiring, and how 24/7 follow-the-sun coverage gets switched on without disrupting your team.
Benchmark your detection and response times against where a 24/7 SOC should put them.
Read the playbookCatch data leaving without blocking the business
Email, cloud, USB, internal network, AI prompts. Observation mode first, enforcement only once the signal is trustworthy, so the first rule you turn on doesn't stop an invoice going out.
Score where your DLP program stands in five honest questions.
Read the playbookYour AI agent has credentials and no manager
It authenticates on its own and writes without review. Govern the identity it holds, the rights that identity opens, and what your MCP servers expose.
Score what one compromised agent could reach with the identity model you run today.
Read the playbookHalf your traffic is already post-quantum. Which half?
Cloudflare negotiates hybrid ML-KEM on TLS 1.3 by default. Find the segments still falling back to a classical key exchange, and close the gap before the deadline does it for you.
Score your post-quantum coverage across routing, versions, clients and tunnels.
Read the playbookHow many AI models are in production right now?
Not the tools your teams use — the ones you deployed. Models, inference endpoints and training data on one register, ranked by who can reach them from outside.
Read the playbookNobody can tell you what your AI actually costs
Each provider shows only its own calls. One gateway gives you the total, the spend per application, and the team to bill it back to.
Read the playbookFind your server’s IP, bypass your WAF entirely.
WAF, DDoS protection, and bot management operate at the edge. Direct traffic to your origin IP completely bypasses them. Discover how to close this gap, and where a separate product is still required.
Read the playbook