Cloudflare Email Security Now Feeds KnowBe4’s Real-Time Coaching
Cloudflare’s Area 1 email security product now integrates with KnowBe4’s Security Awareness Training platform (KSMAT) and its SecurityCoach real-time coaching tool. The integration lets mutual customers automatically deliver targeted security training to employees the moment Cloudflare detects a phishing attempt in their inbox.
Phishing remains one of the most effective attack vectors because it exploits human behavior rather than technical flaws. Attackers rely on urgency, impersonation, and distraction to get users to click malicious links or enter credentials on fake pages. The 2021 Verizon Data Breach Investigations Report found that phishing accounted for 36% of all breaches and that a human element was involved in 85% of them. Technical defenses alone cannot close that gap, so training users to recognize threats is a necessary complement to email filtering.
The integration triggers coaching when Area 1 flags one of four event types: malicious attachments, malicious links, spoofed emails, or suspicious emails. IT and security teams configure the response from the KnowBe4 console, choosing which training messages users receive based on the type of threat detected.
“KnowBe4 is proud to partner with Cloudflare to provide a seamless integration with our new SecurityCoach product, which aims to deliver real-time security coaching and advice to help end users enhance their cybersecurity knowledge and strengthen their role in contributing to a strong security culture. KnowBe4 is actively working with Cloudflare to provide an API-based integration to connect our platform with systems that IT/security professionals already utilize, making rolling out new products to their teams an easy and unified process.”
— Stu Sjouwerman, CEO, KnowBe4
The combination means users are not just protected by a filter that blocks malicious email; when a threat gets through, they receive immediate, contextual guidance. This addresses a frequently requested feature from Cloudflare customers.
Setting Up the Integration
Configuration requires creating API credentials in the Cloudflare Area 1 dashboard, then registering those credentials in the KnowBe4 KSMAT console.
Generate Keys in the Area 1 Dashboard
- Log in to the Cloudflare Area 1 email security console as an admin.
- Click the gear icon in the top-right corner, then navigate to the Service Accounts tab.

- Click + Add Service Account.

- Enter a name in the NAME field.

- Click + Create Service Account.
- In the pop-up window, copy and save the private key in a secure location. You will need it for the next step.

Register the Integration in KnowBe4
- Log in to the KMSAT console and go to SecurityCoach > Setup > Security Vendor Integrations.
- Locate Cloudflare Area 1 Email Security and click Configure.

- Enter the public key and private key you saved earlier.

- Click Authorize. After authorization succeeds, detection rules for Cloudflare Area 1 can be managed on the Detection rules subtab of SecurityCoach.
What Users See
Once configured, users receive a notification when Area 1 identifies a malicious email sent to them. The message alerts them that they are being actively targeted and provides follow-up steps to secure their account.


The content and appearance of that notification are configurable from the KnowBe4 console, giving organizations full control over what they communicate to employees when a threat is detected.
Roadmap
Cloudflare plans to extend the same integration pattern with KnowBe4 to its other Zero Trust products in the coming months. Customers with questions or feedback should contact their Cloudflare account team.



