Why Cloudflare Is Moving Past Edge-Only Defense

Cloudforce One's defensive mission has produced impressive volume — in Q2'25 alone, Cloudflare stopped an average of 190 billion cyber threats per day. But volume doesn't tell the whole story. Real-world incidents revealed a pattern: ransomware disrupting financial operations, data breaches paralyzing real estate firms, and misconfigurations causing major data loss. In each of these cases, the actual damage happened inside networks, not at the edge.

Those internal breaches exposed a second problem. When an incident required investigation and cleanup, customers had to hand off to separate internal teams. The handoffs introduced delays and fragmented the response, creating a gap that attackers could exploit. Context gathered at the edge often failed to reach the teams responsible for remediation, and critical time was lost in the process.

BLOG-3028 Hero Image

To close that gap, Cloudforce One is launching a suite of incident response and security services delivered by Cloudforce One REACT (Respond, Evaluate, Assess, Consult Team). The group is staffed by experienced responders and security veterans who investigate threats, hunt adversaries, and work with executive leadership to guide decision-making during a response.

New Services, Two Tracks

REACT services split into two components: advisory services for preparation and incident response for emergencies.

BLOG-3028 Image 1

Advisory services focus on assessing and improving an organization's security posture and readiness. These include proactive threat hunting backed by real-time global threat intelligence to find existing compromises, tabletop exercises that test response plans against simulated attacks, and incident readiness and maturity assessments designed to identify systemic weaknesses.

The incident response component activates during an active security crisis. The team handles complex threats spanning APT and nation-state activity, ransomware, insider threats, and business email compromise. Because the response draws on Cloudflare's threat intelligence and runs network-native, responders can deploy mitigation measures directly at the Cloudflare edge, accelerating containment.

Organizations requiring guaranteed availability can purchase incident response retainers, which provide priority response, tailored playbooks, and ongoing advisory support.

What Separates REACT From Traditional IR

Traditional incident response engagements often rely on out-of-band channels for data sharing and coordination. REACT is different because it is integrated directly into the Cloudflare platform. The primary differentiators:

  • Threat visibility at scale. With roughly 20% of the web behind Cloudflare's network, Cloudforce One observes emerging attacks as they unfold globally. REACT can correlate incident details with active attack vectors and known adversary tactics, accelerating investigations.
  • Network-native mitigation. With customer authorization, responders can push mitigations directly to the edge — for example, a WAF rule or Secure Web Gateway policy. This shortens the window between threat identification and containment, and every action is tracked in the dashboard.
  • Proven responders. The team includes researchers, consultants, and incident responders with documented experience managing complex incidents, including nation-state activity and sophisticated financial fraud.
  • Vendor-agnostic scope. While engagement is managed through the Cloudflare dashboard, the investigation and remediation are not limited to Cloudflare infrastructure. The team works across on-premise, public cloud, and hybrid environments, and the services are available to both existing customers and non-customers.

An analysis of REACT's engagements over the past six months surfaces three high-impact trends. The data suggests automated defenses alone aren't sufficient — these specific threats often require dedicated incident response capability.

Insider Threats With Trusted Access

A significant number of incidents involved insiders using legitimate, trusted access to bypass standard security controls. These are hard to detect because they blend technical actions with non-technical motivations. Observed scenarios include:

  • Disgruntled or current employees using specialized access to carry out targeted, destructive attacks.
  • Financially motivated insiders compensated by external actors to exfiltrate data or compromise internal systems.
  • State-sponsored operatives gaining privileged access through fraudulent remote work roles, enabling data exfiltration, espionage, and fund theft for illicit regime financing.

Ransomware's Persistent Threat

Ransomware continues to drive high-severity incidents across nearly every sector. Common patterns include hostage-taking of critical financial systems disrupting core operations, and paralysis of real estate business functions with client data compromise causing downtime and regulatory scrutiny. The impacts cross all industry verticals, and stopping these attacks requires not just strong defenses but rehearsed recovery plans that bring time-to-restoration down to hours, not weeks.

Application-Layer and Supply Chain Attacks

There has also been a marked increase in incidents originating at the application layer, manifesting in two primary forms:

  • Vibe coding vulnerabilities. The practice of using natural language prompts with AI models to generate code can produce critical flaws. Threat actors exploit these using techniques such as remote code execution (RCE), memory corruption, and SQL injection.
  • SaaS supply chain risk. A compromise at a critical third-party vendor can expose sensitive data — for example, attackers using a stolen Salesloft OAuth token to exfiltrate customer support cases from Salesforce instances.

Dashboard Integration and Engagement

For Cloudflare Enterprise customers, a new "Incident Response Services" tab now appears in the Threat intelligence navigation page. The integration keeps critical security information and the engagement pathway accessible during a crisis.

BLOG-3028 Image 2

Retainer customers get a dedicated Under Attack page, where a "Request Help" button immediately pages on-call incident responders.

BLOG-3028 Image 3
BLOG-3028 Image 4

Requests for proactive security advisory services are submitted through the same dashboard, with confirmation displayed after successful submission.

BLOG-3028 Image 5

Existing Enterprise customers can explore the incident response section in the Cloudflare dashboard for more details on REACT. New inquiries about proactive partnerships and retainers can go through Cloudflare sales. For active security emergencies requiring immediate response, the REACT team can be contacted directly through the under-attack hotline.