The blind-spot problem in modern security
Every new domain, application, website, or API endpoint expands an organization’s attack surface. For many teams, the pace of innovation outstrips their ability to catalog and protect these assets, creating a "target-rich, resource-poor" environment where unmanaged infrastructure becomes a prime entry point for attackers.
Cloudflare has announced a planned integration to address this by bringing Mastercard’s RiskRecon attack surface intelligence directly into the Cloudflare dashboard. The feature will enable continuous discovery, monitoring, and remediation of Internet-facing blind spots, and is slated for preview by Information Security practitioners in pay-as-you-go and Enterprise accounts in the third quarter of 2026.
What attack surface intelligence reveals
Mastercard’s RiskRecon solution maps an organization’s entire Internet footprint using only publicly accessible data, functioning as an outside-in scanner. This approach can be deployed instantly to uncover shadow IT, forgotten subdomains, and unauthorized cloud servers that internal, credentialed scans typically miss. By observing what an attacker sees in real time, security teams can close vulnerabilities before they are exploited.
Mastercard’s 2025 study of 15,896 breached organizations identified recurring hallmarks, including unpatched software, exposed services such as databases and remote administration, weak application security like missing authentication, and outdated web encryption.

The same research found that organizations with significant posture gaps in these areas were 5.3x more likely to suffer a ransomware attack and 3.6x more likely to experience a data breach compared to those maintaining good cybersecurity hygiene.
Why the partnership matters
The collaboration combines Mastercard’s ability to detect security gaps with Cloudflare’s capability to remediate them. When organizations discover shadow assets—forgotten domains or unprotected cloud instances—they can route traffic through Cloudflare’s proxy to deploy security controls immediately without altering the underlying website or application.
Analysis of roughly 388,000 organizations spanning over 18 million systems indicates that systems proxied by Cloudflare exhibit notably better security hygiene than those that are not:
- Software Patching: 53% fewer software vulnerabilities
- Web Encryption: 58% fewer SSL/TLS issues
- System Reputation: 98% fewer instances of malicious behavior, including communication with botnet command and control servers or hosting phishing sites

| Category | Security Check | Description |
|---|---|---|
| Software Patching | Application Servers | Unpatched application server software. |
| OpenSSL | Unpatched OpenSSL. | |
| CMS Patching | Unpatched content management system software. | |
| Web Servers | Unpatched webserver software. | |
| Application Security | CMS Authentication | Enumeration of content management system administration interfaces publicly exposed to the internet. |
| High Value System Encryption | Enumeration of systems that collect sensitive data that do not have encryption implemented. | |
| Malicious Code | Enumeration of systems containing malicious code (Magecart). | |
| Web Encryption | Certificate Expiration Date | SSL certificate expired. |
| Certificate Valid Date | SSL certificate valid date not yet valid. | |
| Encryption Hash Algorithm | Weak SSL encryption hash algorithm. | |
| Encryption Key Length | Weak SSL encryption key length. | |
| Certificate Subject | Invalid SSL certificate subject. | |
| Exposed Services / Network Filtering | Unsafe Network Services | Enumeration of unsafe network services running on the system such as databases (e.g. SQL Server, PostgreSQL) and remote access services (e.g. RDP, VNC). |
| IoT Devices | Enumeration of IoT devices such as printers, embedded system interfaces, etc. |
Closing the discovery gap
Cloudflare Security Insights within Cloudflare’s Application Security suite currently identifies risks for domains already proxied by Cloudflare, such as DNS misconfigurations, weak web encryption, or inactive WAF rules. The limitation is fundamental: you cannot protect domains you don’t know exist.
Mastercard’s continuous profiling of over 12 million organizations addresses this by identifying domains, hosts, and software stacks associated with a company, even those not yet behind a Cloudflare proxy. This enables Security Insights to surface shadow IT and unprotected hosts so they can be secured using Cloudflare’s WAF and DDoS protection.
Each discovered host receives a criticality rating to help teams prioritize:
- High Criticality: Hosts that collect sensitive data, require authentication, or run sensitive network services like database listeners or remote access
- Medium Criticality: Brochure websites adjacent to high-criticality systems, such as those on the same class-C network
- Low Criticality: Brochure websites with no adjacency to critical systems
| Domain | Protected by Cloudflare | Host (IP) | Criticality | Location | Hosting Provider |
|---|---|---|---|---|---|
| search-engine.net | Yes | portal.search-engine.net (10.XXX.XX.5) | HIGH | Springfield, United States | Cloudflare |
| zenith-industries.com | No | vpn.zenith-industries.com (10.XXX.XXX.106) | HIGH | Helsinki, Finland | CloudNode-Services |
| stratus-global.com | No | store.stratus-global.com (10.XXX.XXX.124) | HIGH | Munich, Germany | SwiftStream-Tech |
| core-logic.cl | No | extranet.core-logic.cl (10.XXX.XXX.178) | HIGH | Santiago, Chile | SecureCanopy Ltd. |
| vanguard-labs.com | No | extranet.vanguard-labs.com (10.XXX.XX.197) | HIGH | Metropolis, United States | GlobalSoft Systems |
| fusion-id.com | No | fusion-id.com (10.XXX.XXX.146) | HIGH | Prague, Czechia | EuroData-Hub |
| norden-biotech.no | No | store.norden-biotech.no (10.XXX.XX.124) | MEDIUM | Chicago, United States | SwiftStream-Tech |
| norden-biotech.se | No | store.norden-biotech.se (10.XXX.XX.124) | MEDIUM | Chicago, United States | SwiftStream-Tech |
Example of shadow domains and unprotected hosts associated with an organization
Mastercard also provides continuous visibility into security posture across software patching, exposed network services, and application security issues like unauthenticated CMSes, complementing the existing Cloudflare Security Insights view.

Security Insights dashboard with shadow domains, unproxied hosts, and posture findings
The insights are designed to drive action. Rather than merely flagging risk, Cloudflare Security Insights will suggest concrete remediation steps, such as enabling a Cloudflare proxy (which brings DDoS and bot protection to shadow zones and hosts), activating the Web Application Firewall (WAF), or enforcing stricter TLS encryption to address the specific vulnerabilities identified.
Roadmap and next steps
Work is underway to integrate Mastercard’s RiskRecon attack surface intelligence into the Cloudflare Security Insights dashboard, providing immediate visibility into shadow domains, unprotected hosts, and related posture gaps. As the volume of insights grows, Cloudflare’s roadmap includes risk scoring and AI-assisted diagnosis paths—offering not just an insight but relevant correlations, such as traffic to an unpatched host, and recommending the specific WAF rule or API Shield configuration required to neutralize the threat.



