Closing the Attack Surface Blind Spot
Organizations struggle to maintain security visibility as their infrastructure expands faster than their ability to catalog and protect assets. Cloudflare announced a planned integration with Mastercard's RiskRecon attack surface intelligence to automatically discover and monitor internet-facing infrastructure, including shadow IT, forgotten subdomains, and unauthorized cloud servers that traditional credentialed scans often miss.
Key Capabilities and Security Benefits
The integration will deliver several critical security improvements:
- Automated Discovery: Continuously identify domains, hosts, and software stacks associated with your organization using passive, outside-in scanning that requires no credentials
- Criticality Scoring: Each discovered asset receives a criticality level (High/Medium/Low) based on data sensitivity, authentication requirements, and network proximity to critical systems
- Immediate Remediation: Route newly discovered assets through Cloudflare's proxy to instantly deploy WAF, DDoS protection, and encryption without changing underlying infrastructure
Mastercard's research on 388,000 organizations found that systems proxied through Cloudflare demonstrate significantly better security hygiene: 53% fewer software vulnerabilities, 58% fewer SSL/TLS issues, and 98% fewer malicious behavior indicators compared to unprotected systems.
Integration Timeline and Availability
Information Security practitioners with pay-as-you-go and Enterprise Cloudflare accounts will gain preview access to the RiskRecon integration in Q3 2026. The integration will extend Cloudflare's existing Security Insights product—which currently identifies DNS misconfigurations and weak encryption on proxied domains—to include discovery of unmanaged assets before they become attack vectors.
Development Actions
Organizations should begin cataloging their current internet footprint and preparing to integrate discovered assets into their Cloudflare protection strategy when the preview becomes available in Q3 2026.