shiichan

Cloudflare joins the UK government's Cyber Resilience Pledge — and its defenses block 234 billion threats a day!

Hi everyone, it's me! Today's news is about a security "promise." It might look a little formal at first, but it's actually packed with the Cloudflare spirit, so let's take a look together!

Cloudflare Blog blog.cloudflare.com

What was announced?

On the Cloudflare blog, Cloudflare announced that it has joined the UK government's Cyber Resilience Pledge! This is an announcement-style post, so it's less about a new product and more about "Cloudflare has signed this kind of commitment."

The pledge is a voluntary framework launched by the UK government, asking organizations to commit to cybersecurity governance and accountability. And Cloudflare is one of the founding cohort of signatories!

Why it matters

Cyberattacks aren't just a problem for a handful of IT staff anymore. That's exactly why leadership at the very top — the board level — needs to take responsibility, and that's the core idea of this pledge.

According to Cloudflare, in the first quarter of 2026 it blocked an average of 234 billion cyber threats every day. It also mitigated a DDoS attack that peaked at 31.4 Tbps. The UK was the "sixth-most targeted" location for DDoS attacks by the end of 2025, so it makes sense that this pledge carries real weight there!

What changes

The pledge itself isn't a new tool you can pick up. But there's real value in industry leaders publicly declaring that "security is a leadership responsibility." For partners and users, it makes a vendor's security posture easier to see.

For Cloudflare, it's a way to put what it has already been doing — free protection and transparent disclosure — into writing as a commitment. For organizations operating in the UK, and the users behind them, it's a step toward raising the baseline of defense!

Dive Deep

The pledge asks organizations to commit to three main things:

  • Board-level accountability and governance — treating cyber risk as a leadership matter
  • Supply chain security — setting meaningful baselines
  • Technical compliance — aligning with the UK's Cyber Essentials certification scheme

And Cloudflare makes the case that "we've lived this spirit for over a decade!" The post highlights three pillars:

  • Democratizing security — so everyone can be protected
  • Leadership accountability — making security a business priority
  • Radical transparency — being honest when something happens

As concrete examples, the post points to things like:

  • Being the first company to offer SSL certificates to all users for free (encrypting traffic)
  • Unmetered DDoS protection even on the free plan, regardless of the size, duration, or volume of attacks
  • Free access to a global CDN and DNSSEC
  • Impact programs like Project Galileo (protecting vulnerable voices) and the Athenian Project (supporting elections and civic engagement)
  • Deploying post-quantum cryptography across the network
  • Peering with more than 13,000 networks globally

On governance, the Chief Security Officer briefs the board quarterly, and the Audit Committee receives quarterly enterprise risk briefings with a cyber focus. Cloudflare also requires critical suppliers to maintain ISO 27001 and SOC 2 Type II certifications.

On transparency, the post mentions the "Code Orange" effort launched after a fall outage, which redesigned systems to "fail small."

Wrap-up

  • Cloudflare has joined the UK government's Cyber Resilience Pledge as a founding signatory!
  • The pledge is a voluntary framework committing to board-level accountability, supply chain security, and Cyber Essentials compliance
  • Cloudflare argues it has practiced "democratizing security, leadership accountability, and radical transparency" for over a decade
  • It backs this up with concrete work: free SSL, free DDoS protection, Project Galileo, post-quantum cryptography, and more

Rather than a new feature, this one gives you a clear look at Cloudflare's security philosophy! It'll resonate with anyone interested in security governance or how a company carries itself on security!