Free tools to harden your online presence

Cloudflare’s founding mission has been to "help build a better Internet," and a core part of that involves making enterprise-grade security accessible beyond large organizations with dedicated security teams. Unmetered DDoS protection and SSL at scale are now available for free, as is a free zero-trust plan for internal infrastructure.

These tools matter more than usual right now. Concurrent with the Russian invasion of Ukraine, cyberattacks have escalated, and government agencies including the U.S. Cybersecurity & Infrastructure Security Agency, the UK’s National Cyber Security Center, and Japan’s Ministry of Economy, Trade, and Industry have all urged organizations to raise their shields. Below are free Cloudflare services available to anyone today, plus a reminder of the basic security habits that make the biggest difference.

For public-facing infrastructure

If you run a website, app, or API, the Cloudflare free plan provides unmetered DDoS mitigation, free SSL, and protection against vulnerabilities like the Log4J exploit, plus a global CDN and DNS built in. These protections are not rate-limited or subscription-gated; they scale with the largest deployments and are designed to absorb serious attack traffic.

For internal tools and remote teams

Cloudflare Zero Trust is free for up to 50 users and provides secure access controls for self-hosted apps, SaaS applications, and general Internet access. It’s aimed at organizations that need to lock down internal-facing infrastructure without the licensing costs typical of enterprise security products.

For personal devices and home networks

Individual users can protect phones, computers, and routers with Cloudflare’s 1.1.1.2 DNS resolver, also known as Cloudflare for Families. Unlike the standard 1.1.1.1 resolver, 1.1.1.2 blocks resolution of known malware domains, so clicking a malicious link will not load the site. Setup is straightforward: follow the instructions to enable malware protection, or manually change DNS settings to:

  • 1.1.1.2
  • 1.0.0.2
  • 2606:4700:4700::1112
  • 2606:4700:4700::1002

Although branded as a consumer product, it functions equally well for business environments.

Free enterprise-grade help for at-risk organizations

Beyond its general free plans, Cloudflare offers additional no-cost services to two categories of organizations facing targeted attacks.

Project Galileo, launched in 2014, protects vulnerable public interest groups—artistic collectives, humanitarian organizations, and voices of political dissent. Qualification is determined through partnerships with groups such as the Freedom of the Press Foundation, the Electronic Frontier Foundation, and the Center for Democracy and Technology, rather than by Cloudflare alone. Applications have increased recently from civil society and community groups in Ukraine and the region, many organizing to provide support and essential information. Qualified organizations receive services normally reserved for large enterprise customers. More information and the application are available on the Project Galileo page.

The Athenian Project similarly provides free enhanced services to qualifying election entities. Attackers have repeatedly targeted election sites to disrupt democratic processes, and constrained government budgets often make it difficult to obtain sufficient protection. The tools offered keep these sites fast, reliable, and secure, with details and application instructions available on the Athenian Project page.

Basic security hygiene worth revisiting

Beyond Cloudflare’s services, a handful of straightforward habits substantially reduce risk. Most readers will recognize these—but they merit a refresh and an immediate implementation:

  • Do not reuse passwords. Data breaches happen daily, and stolen username/password pairs are routinely traded in illegal markets. Attackers will quickly test those combinations on banking, email, and other high-value sites. Check whether credentials you use have been exposed via services like Have I Been Pwned, and use unique passwords anywhere you would be harmed by a compromise.
  • Turn on multi-factor authentication. A second factor—a text or email code, an authentication app’s generated code, or ideally a hardware key—confirms the person logging in is you. Cloudflare mandates hardware keys internally because of their superior security.
  • Use a password manager. A password manager generates and stores a distinct, random password for every account and can also handle multi-factor codes. Apple’s iOS and macOS include one, and options like 1Password and LastPass are popular alternatives. Cloudflare requires password managers internally and recommends them to everyone.
  • Keep software updated. Vulnerabilities surface in operating systems and applications constantly. Patches may arrive within minutes over the Internet, but they only help if the update is installed—set automatic updates to remove hesitation from the equation.
  • Think before clicking email links. CISA attributes more than 90% of successful cyberattacks to phishing emails. Messages may appear legitimate but are designed to steal passwords or sensitive data. Check the URL carefully, or skip clicking altogether and navigate to the site by typing the address or searching for it. The 1.1.1.2 resolver described above is also a safety net in case a malicious link gets clicked.
  • Do not give credentials to unexpected callers. Phishing can occur by phone, too—scammers pose as bank representatives or IT admins, create a sense of urgency, and ask for passwords or text confirmation codes. If uncertain, take the caller’s name, department, and organization, then end the call and reach back through a publicly advertised number.
  • Maintain backups of critical data. Even with every protection in place, incidents happen. An offline backup—or at minimum one in the cloud—serves as the last line of defense, also protecting against lost devices, natural disasters, and other non-security outages.

These steps are simple to implement but easy to postpone. Given the current threat landscape, making them now is a cost-effective investment in resilience.