AI Briefing
KO

Cloudflare CASB Introduces Automated Remediation Policies

·2026.09.11 22:00

Key point

Cloudflare introduced automated remediation policies in CASB to block risks immediately upon detection and reduce processing time to under 5 minutes.

Details

Cloudflare has introduced automated remediation policies in CASB (Cloud Access Security Broker). The previous SSPM was a manual notification system that took hours to days from detection to action, posing a risk of sensitive file leaks, but this update enables full automation.

Automation Engine and Architecture

This feature operates based on the built-in automation engine in Cloudflare One. The engine automatically matches and executes response logic defined once by security teams, using Cloudflare Workflows to ensure durable and fault-tolerant execution. Jobs are preserved even during process restarts, and upon rate limit errors from third-party APIs, the system waits for an appropriate backoff window before retrying to prevent job loss.

Supported Actions and Visibility

When creating a policy, you can select two main Actions:

  • Run remediations: First-party actions performed directly by Cloudflare on SaaS integration APIs, currently supporting file/folder finding types for Microsoft and Google Workspace.
  • Send webhooks: Sends finding details to Slack, Microsoft Teams, Jira, ServiceNow, Tines, or custom HTTP endpoints.

All policy actions are recorded in Cloudflare One Insights as Admin Activity logs and Cloud & SaaS Security policies logs, serving as proof of fix for compliance. The goal is to complete the process from detection to remediation within 5 minutes, and support for Custom Findings is expected to be added in the coming weeks.

This summary was generated automatically by AI. Check the original for the author's claims and context. Copyright belongs to the original author.

Our guide explains how the AI works. Report summary errors, attribution issues, or removal requests via Contact.