Cloudflare Email Security Now Feeds KnowBe4’s Real-Time Coaching

Cloudflare’s Area 1 email security product now integrates with KnowBe4’s Security Awareness Training platform (KSMAT) and its SecurityCoach real-time coaching tool. The integration lets mutual customers automatically deliver targeted security training to employees the moment Cloudflare detects a phishing attempt in their inbox.

Phishing remains one of the most effective attack vectors because it exploits human behavior rather than technical flaws. Attackers rely on urgency, impersonation, and distraction to get users to click malicious links or enter credentials on fake pages. The 2021 Verizon Data Breach Investigations Report found that phishing accounted for 36% of all breaches and that a human element was involved in 85% of them. Technical defenses alone cannot close that gap, so training users to recognize threats is a necessary complement to email filtering.

The integration triggers coaching when Area 1 flags one of four event types: malicious attachments, malicious links, spoofed emails, or suspicious emails. IT and security teams configure the response from the KnowBe4 console, choosing which training messages users receive based on the type of threat detected.

“KnowBe4 is proud to partner with Cloudflare to provide a seamless integration with our new SecurityCoach product, which aims to deliver real-time security coaching and advice to help end users enhance their cybersecurity knowledge and strengthen their role in contributing to a strong security culture. KnowBe4 is actively working with Cloudflare to provide an API-based integration to connect our platform with systems that IT/security professionals already utilize, making rolling out new products to their teams an easy and unified process.”
— Stu Sjouwerman, CEO, KnowBe4

The combination means users are not just protected by a filter that blocks malicious email; when a threat gets through, they receive immediate, contextual guidance. This addresses a frequently requested feature from Cloudflare customers.

Setting Up the Integration

Configuration requires creating API credentials in the Cloudflare Area 1 dashboard, then registering those credentials in the KnowBe4 KSMAT console.

Generate Keys in the Area 1 Dashboard

  • Log in to the Cloudflare Area 1 email security console as an admin.
  • Click the gear icon in the top-right corner, then navigate to the Service Accounts tab.

BLOG-1727 Embedded Image - jMoHka

  • Click + Add Service Account.

BLOG-1727 Embedded Image - C0iimy

  • Enter a name in the NAME field.

BLOG-1727 Embedded Image - tQP8dE

  • Click + Create Service Account.
  • In the pop-up window, copy and save the private key in a secure location. You will need it for the next step.

BLOG-1727 Embedded Image - Qor3a4

Register the Integration in KnowBe4

  • Log in to the KMSAT console and go to SecurityCoach > Setup > Security Vendor Integrations.
  • Locate Cloudflare Area 1 Email Security and click Configure.

BLOG-1727 Embedded Image - FfBTbt

  • Enter the public key and private key you saved earlier.

BLOG-1727 Embedded Image - BmO8RR

  • Click Authorize. After authorization succeeds, detection rules for Cloudflare Area 1 can be managed on the Detection rules subtab of SecurityCoach.

What Users See

Once configured, users receive a notification when Area 1 identifies a malicious email sent to them. The message alerts them that they are being actively targeted and provides follow-up steps to secure their account.

BLOG-1727 Embedded Image - ALrGXK

BLOG-1727 Embedded Image - PpizBR

The content and appearance of that notification are configurable from the KnowBe4 console, giving organizations full control over what they communicate to employees when a threat is detected.

Roadmap

Cloudflare plans to extend the same integration pattern with KnowBe4 to its other Zero Trust products in the coming months. Customers with questions or feedback should contact their Cloudflare account team.