Strengthening Account Defenses Under CISA’s Secure by Design Pledge
Since signing the Cybersecurity and Infrastructure Security Agency (CISA) Secure by Design pledge in May 2024, Cloudflare has rolled out a series of account security enhancements. A primary focus has been the pledge’s first goal: boosting adoption of multi-factor authentication (MFA).
Credential-based attacks remain the leading cause of application breaches, according to the 2024 Verizon Data Breach Investigations Report. Attackers increasingly rely on credential stuffing and password spraying—techniques that exploit credentials leaked from prior breaches—rather than slower brute-force methods. MFA remains the most effective countermeasure, with research indicating it can block 99.9% of automated attacks.
All Cloudflare users are already protected by a built-in challenge system that triggers an email-based MFA code when a login originates from an unfamiliar IP address. Beyond this default layer, Cloudflare makes additional MFA methods available to every customer and encourages enabling at least one extra factor.
New Authentication Options and Protections
Several improvements shipped throughout 2024 to expand MFA coverage and harden accounts.
Social Login via Google and Apple
Cloudflare now supports social login using Google or Apple credentials. Since most accounts on these platforms mandate MFA, this option provides a strong security baseline while eliminating the need to manage separate Cloudflare credentials. Social login has quickly gained traction, now accounting for roughly 25% of all weekly logins.
Leaked Password Alerts
Cloudflare automatically identifies accounts using passwords that have appeared in known data breaches. When such a user logs in, they are prompted to change their password, helping to close a common security gap before it is exploited.
Practical Steps to Tighten Account Security
Users who have not yet adopted MFA have several paths forward, and existing security configurations are worth revisiting.
Strong Passwords Come First
MFA is only as strong as the underlying password. Cloudflare does not issue default or preconfigured passwords, aligning with CISA’s second pledge goal on default credentials. Instead, users are expected to generate unique, strong passwords that meet CISA recommendations. A password manager can simplify this process and reduce the temptation to reuse credentials.
Available MFA Methods
Cloudflare supports multiple MFA options. For maximum protection, phishing-resistant hardware security keys—such as a YubiKey or platform-built keys like Windows Hello and Apple Touch ID—are recommended. Users can also opt for Time-Based One-Time Passwords (TOTP) via authenticator apps like Google Authenticator or Microsoft Authenticator, many of which offer cloud backup so access is not lost with a device. Regardless of method, users should store backup codes in a secure location, such as a password manager, in case their primary MFA device is unavailable.
Enforcing MFA Across an Organization
Account administrators can require MFA for all members via the Manage Members policy settings. This control is unavailable for accounts not using MFA or those relying solely on social login; in the latter case, users are urged to enable MFA on their associated Google or Apple accounts.
Enterprise Single Sign-On
Enterprise customers can leverage single sign-on (SSO) for streamlined, secure authentication at scale. Cloudflare provides SSO at no cost to all enterprise accounts and encourages its adoption as a core security measure.



