Score every part of your Cloudflare estate.
Tap a category to see its top finding.
Gaps · 11 findings
API security
API Shield, schema validation, mTLS, rate limits per endpoint.
On this page
Nanosek provides Cloudflare Security Audit services for organizations that need to assess and improve security posture across Cloudflare WAF, DDoS protection, Bot Management, API Shield, Rate Limiting, DNS, TLS, certificates, origin protection, Zero Trust, Logpush, account governance, and incident readiness. The audit delivers evidence-based findings, severity ratings, affected zones or services, practical recommendations, quick wins, and a prioritized remediation roadmap.
Who this is for
Why audit Cloudflare security
Find exposed origins
Identify origin IPs, direct DNS records, bypass paths, firewall gaps, and origin access patterns that allow traffic to avoid Cloudflare controls.
Validate WAF enforcement
Review Managed Rules, Custom Rules, actions, exceptions, skip rules, rule ordering, and paths that are still only logging.
Reduce false-positive risk
Find broad rules, unscoped skips, sensitive flows, and enforcement patterns that could block legitimate users or integrations.
Protect APIs and login flows
Assess API Shield, mTLS, schema validation, WAF rules, rate limits, authentication-sensitive endpoints, and abuse-prone paths.
Review bot protection posture
Evaluate bot score usage, verified bot handling, challenge behavior, allowlists, false positives, and bot-event visibility.
Confirm DDoS readiness
Review HTTP DDoS posture, rate controls, origin resilience, cache behavior, escalation paths, and response workflows.
Improve DNS and TLS hygiene
Check proxy status, CAA, DNSSEC, risky records, SSL/TLS mode, minimum TLS version, certificate coverage, HSTS, and mTLS readiness.
Strengthen account governance
Review users, roles, API tokens, account structure, audit logs, naming standards, Terraform or API workflows, and change control.
Improve logging and investigation readiness
Assess Logpush, Security Events, WAF and bot events, audit logs, dashboards, SIEM integration, alerting, retention, and investigation workflows.
Build a prioritized remediation roadmap
Convert findings into critical fixes, quick wins, planned improvements, and longer-term maturity work with clear implementation notes.
Common security findings
Cloudflare security controls are powerful, but they only reduce risk when they are configured, tuned, monitored, and governed correctly. Many environments grow over time: new zones are added, WAF exceptions accumulate, origins remain reachable, APIs launch without rate limits, bot policies stay in monitor mode, TLS settings drift, and logs are not reviewed.
Our Cloudflare security audit methodology
Scope and access review
- Define accounts, zones, applications, APIs, Zero Trust components, products, and environments in scope.
- Confirm read-only access, stakeholders, documentation sources, and reporting expectations.
Security inventory
- Collect Cloudflare account settings, zone settings, DNS records, WAF rules, managed rules, custom rules, rate limits, bot settings, certificates, origin configuration, Logpush jobs, API tokens, and Zero Trust policies.
Risk analysis
- Review each area for security exposure, availability risk, false-positive risk, operational gaps, logging gaps, and governance issues.
Evidence-based findings
- Document each finding with affected zones or services, severity, evidence, business impact, recommended action, and implementation notes.
Remediation roadmap
- Prioritize recommendations into critical fixes, quick wins, planned improvements, and longer-term maturity work.
Review workshop
- Walk stakeholders through findings, validate assumptions, explain tradeoffs, and agree on remediation sequence.
Optional remediation and managed operations
- Nanosek can help implement fixes, tune WAF and bot controls, harden origins, configure logging, create runbooks, and provide ongoing Cloudflare security operations.
Severity model
Security audit coverage matrix
WAF
Managed Rules, Custom Rules, skips, exceptions, actions
WAF tuning and enforcement roadmap.
DDoS
HTTP DDoS posture, origin resilience, rate controls
DDoS readiness recommendations.
Bot
Bot score, verified bots, challenge behavior
Bot policy and false-positive tuning plan.
API security
API Shield, mTLS, schemas, rate limits
API protection roadmap.
Rate limiting
Login, forms, search, checkout, APIs
Scoped rate limiting recommendations.
Origin protection
Origin exposure, AOP, firewall allowlists
Origin hardening plan.
DNS security
Proxy status, CAA, DNSSEC, risky records
DNS security cleanup plan.
TLS/certificates
SSL mode, TLS minimums, cert coverage
TLS hardening recommendations.
Zero Trust
Access, Gateway, WARP, tunnels, posture
Zero Trust security findings.
Logging
Logpush, SIEM, alerts, retention
Security observability improvement plan.
Governance
Users, roles, API tokens, audit logs
Access and change-control recommendations.
| Security area | What we review | Example output |
|---|---|---|
| WAF | Managed Rules, Custom Rules, skips, exceptions, actions | WAF tuning and enforcement roadmap. |
| DDoS | HTTP DDoS posture, origin resilience, rate controls | DDoS readiness recommendations. |
| Bot | Bot score, verified bots, challenge behavior | Bot policy and false-positive tuning plan. |
| API security | API Shield, mTLS, schemas, rate limits | API protection roadmap. |
| Rate limiting | Login, forms, search, checkout, APIs | Scoped rate limiting recommendations. |
| Origin protection | Origin exposure, AOP, firewall allowlists | Origin hardening plan. |
| DNS security | Proxy status, CAA, DNSSEC, risky records | DNS security cleanup plan. |
| TLS/certificates | SSL mode, TLS minimums, cert coverage | TLS hardening recommendations. |
| Zero Trust | Access, Gateway, WARP, tunnels, posture | Zero Trust security findings. |
| Logging | Logpush, SIEM, alerts, retention | Security observability improvement plan. |
| Governance | Users, roles, API tokens, audit logs | Access and change-control recommendations. |
Deployment steps
- 01 Define scope, accounts, zones, applications, APIs, Zero Trust components, documentation sources, and read-only access.
- 02 Inventory account settings, DNS, WAF, bot, DDoS, API Shield, rate limits, certificates, origins, Logpush, API tokens, and Zero Trust policies.
- 03 Assess security exposure, availability risk, false-positive risk, logging gaps, governance issues, and incident readiness.
- 04 Document evidence-based findings with severity, affected zones or services, business impact, recommendations, and implementation notes.
- 05 Prioritize remediation into critical fixes, quick wins, planned improvements, and maturity work.
- 06 Run a findings workshop with stakeholders to validate assumptions and agree on action order.
- 07 Optionally support remediation, runbook creation, tuning, hardening, logging, and managed Cloudflare security operations.
Risks and mitigations
Origin exposure.
Restrict origin access to Cloudflare, use Authenticated Origin Pulls, remove direct records, and review leaked origin paths.
Weak TLS posture.
Use Full Strict, valid origin certificates, modern TLS minimums, and careful HSTS planning.
Overbroad WAF skip rules.
Replace broad skips with scoped exceptions by hostname, path, method, IP, header, or integration.
WAF stuck in log mode.
Review events, tune exceptions, then promote controls gradually to challenge or block.
Missing rate limits.
Add scoped limits for login, forms, search, expensive APIs, and abuse-prone endpoints.
Bot false positives.
Use bot score review, verified bot handling, path-specific policies, and monitor-to-challenge rollout.
Unprotected APIs.
Add API-specific WAF rules, rate limits, API Shield, mTLS, and schema validation where appropriate.
Missing visibility.
Configure Logpush, dashboards, alerting, and security event review workflows.
Excessive API token permissions.
Replace broad tokens with scoped tokens and documented ownership.
Zero Trust policy drift.
Review Access, Gateway, WARP, tunnels, identity groups, and device posture policies.
| Risk | Mitigation |
|---|---|
| Origin exposure. | Restrict origin access to Cloudflare, use Authenticated Origin Pulls, remove direct records, and review leaked origin paths. |
| Weak TLS posture. | Use Full Strict, valid origin certificates, modern TLS minimums, and careful HSTS planning. |
| Overbroad WAF skip rules. | Replace broad skips with scoped exceptions by hostname, path, method, IP, header, or integration. |
| WAF stuck in log mode. | Review events, tune exceptions, then promote controls gradually to challenge or block. |
| Missing rate limits. | Add scoped limits for login, forms, search, expensive APIs, and abuse-prone endpoints. |
| Bot false positives. | Use bot score review, verified bot handling, path-specific policies, and monitor-to-challenge rollout. |
| Unprotected APIs. | Add API-specific WAF rules, rate limits, API Shield, mTLS, and schema validation where appropriate. |
| Missing visibility. | Configure Logpush, dashboards, alerting, and security event review workflows. |
| Excessive API token permissions. | Replace broad tokens with scoped tokens and documented ownership. |
| Zero Trust policy drift. | Review Access, Gateway, WARP, tunnels, identity groups, and device posture policies. |
Cloudflare security audit checklist
- Cloudflare accounts and zones inventoried
- Users and roles reviewed
- API tokens reviewed
- Audit logs reviewed
- DNS records and proxy status reviewed
- DNSSEC and CAA reviewed
- SSL/TLS mode reviewed
- Minimum TLS version reviewed
- Certificate coverage reviewed
- Origin exposure reviewed
- Authenticated Origin Pulls reviewed
- WAF Managed Rules reviewed
- WAF Custom Rules reviewed
- WAF skip rules reviewed
- WAF exceptions reviewed
- Rate limits reviewed
- Bot Management posture reviewed
- Verified bot handling reviewed
- API Shield posture reviewed
- Login, checkout, form, and API paths reviewed
- DDoS readiness reviewed
- Logpush and SIEM visibility reviewed
- Alerting and incident workflows reviewed
- Zero Trust Access policies reviewed
- Gateway and WARP policies reviewed
- Tunnels and private routes reviewed
- Change control and rollback reviewed
Deliverables
- Cloudflare security audit report
- Executive summary
- Technical findings with severity ratings
- Evidence and affected zones/services
- WAF posture review
- Bot and rate limiting review
- DDoS readiness assessment
- API security review
- Origin exposure assessment
- DNS and TLS security review
- Zero Trust security review, if in scope
- Logging and SIEM visibility review
- Account governance review
- Quick-win remediation list
- Prioritized security roadmap
- Review workshop
- Optional remediation backlog
Plan-aware recommendations
Cloudflare security capabilities vary by plan and add-on. Nanosek audits the environment against the controls available in your current Cloudflare plan, then separates recommendations into immediate configuration improvements, plan-dependent enhancements, and optional future-state controls.
When Nanosek should help
Frequently asked questions
What is a Cloudflare security audit?
Is this different from a Cloudflare environment audit?
What access does Nanosek need?
Will Nanosek make changes during the audit?
What are common Cloudflare security issues?
Can this audit include Cloudflare Zero Trust?
Do you account for Cloudflare plan limitations?
How are findings prioritized?
Can Nanosek help implement the recommendations?
Turn Cloudflare security findings into action
Nanosek helps you identify real risks, prioritize remediation, and improve Cloudflare security controls with evidence-based recommendations and practical implementation support.