Security Center: A unified view of your attack surface
Cloudflare has launched the public beta of Security Center, a new offering that consolidates the company's security products, expertise, and internet intelligence into a single security intelligence solution. The goal is to help organizations map their attack surface, identify potential risks, and address them directly from the Cloudflare dashboard.
The product is available to all Cloudflare users now, accessible from the Account Home page. It represents a step toward the broader Cloudflare One vision of a unified platform for solving enterprise security challenges, rather than relying on a collection of point solutions.
Why attack surfaces have grown harder to manage
Several shifts in how organizations build and run IT have made attack surface management more difficult. The traditional corporate network model, built around a central perimeter, has been replaced by a mix of public cloud resources, SaaS applications, mobile devices, and remote work. This distribution means security teams must track assets spread across many environments, not just those behind a corporate firewall.
Application development practices have also evolved. Web applications increasingly depend on open source code and third-party scripts, which introduces supply-chain risk. Organizations must monitor these dependencies for vulnerabilities and potentially malicious behavior. Cloudflare's Page Shield product, now generally available, was designed to help with tracking JavaScript dependencies.
In addition, organizational changes such as growth, attrition, and merger and acquisition activity continually alter the IT landscape. IT teams report that they frequently lack a complete picture of their own infrastructure, especially when development teams spin up new resources without fully aligning them with corporate security standards.
The problem with existing attack surface tools
Customers who have attempted to solve this problem with in-house tools or dedicated security products consistently report the same shortcomings. These solutions generate too many alerts, making it difficult for security teams to triage and prioritize what matters. They also contribute to vendor sprawl, adding yet another tool to integrate with existing security stacks rather than reducing complexity. Given constrained staff and budget resources, security teams want a solution that decreases their workload rather than increasing it along with risk from unmanaged or forgotten assets.
How Security Center works
Security Center includes two primary features: Security Insights and Infrastructure. Security Insights provides a log of potential security risks, vulnerabilities, and insecure configurations associated with IT infrastructure on Cloudflare. The detections are curated by Cloudflare security experts to help users quickly address the most critical issues.
Infrastructure offers an inventory of assets on Cloudflare, including a breakdown of DNS records by proxy usage and a list of all domains with key details.
First-time users must click Start scan to consent to Cloudflare scanning their infrastructure. After opting in, scans run on a regular schedule. For zones on Pro or higher plans, or for customers using Teams Standard or higher, scans occur daily. For all other Cloudflare plans, scans run every three days.
After each scan, the Security Insights page shows a summary of the attack surface, and users can resolve any identified insights by making recommended changes to Cloudflare configurations with a few clicks.
Security Center is available as a beta release at no additional cost beyond existing Cloudflare plans. Cloudflare intends to expand the product's capabilities—first to cover a customer's entire IT footprint beyond assets on Cloudflare, and then to broaden risk detection to include network security, enterprise security, and brand security concerns. Feedback can be submitted via email or the Cloudflare Community forum.



