blog.cloudflare.com 11 Sept 2026, 13:00 UTC

Cloudflare CASB Adds Automated Remediation for Risky File Shares

Cloudflare CASB Adds Automated Remediation for Risky File Shares
CyberSIXT Evidence Panel Source marked as original reporting

CLOUDFLARE’S CASB has been enhanced with automatic remediation policies, allowing security teams to design event-driven logic that revokes risky file shares and dispatches custom webhooks without human intervention. The update shifts Cloudflare One’s CASB from a primarily passive monitoring role to an active automation layer, so that when a finding is detected, a pre-configured action is executed immediately. This addresses the typical delay between detection and remediation that could allow sensitive data to be downloaded or shared further.

CASB policies are built into the Cloudflare platform and operate as automated workflows. When a finding is detected, the system checks policy configurations and can trigger remediation actions against the SaaS API, send webhooks, or both. In practice, organisations can enforce controls such as prohibiting public sharing, while exempting necessary groups, and have the public share revoked within minutes.

The backend architecture uses a findings engine, a Cloudflare Queue, a Worker consumer, and Cloudflare Workflows to deliver durable, fault-tolerant execution with graceful handling of third‑party rate limits, aiming for five minutes or less from detection to completed remediation.

To get started, admins can create CASB policies from the Cloudflare dashboard, selecting the vendor, the relevant integrations, the finding type, and the action (remediation, webhook, or both). The article notes that current remediation supports Microsoft and Google Workspace file/folder findings, and that logs capture policy changes (admin activity) and runtime outcomes (policy invocations) for compliance. Cloudflare also signals upcoming support for Custom Findings.

View full article

Article by CyberSIXT