Knowledge Hub · Security

Is Cloudflare a SOC or managed detection and response (MDR) service?

Web Application & DDoS Protection · Answered by FirstNet Technology Services

Short answer

No. Cloudflare is a security platform, not a 24/7 security operations centre. For managed detection and response, FirstNet offers Sophos MDR with FirstNet Incident Response.

In detail

How the two fit together:

  • Cloudflare protects public apps, APIs, networks and remote users at the edge with WAF, DDoS, bot management and Zero Trust controls
  • FirstNet tunes Cloudflare policies, triages false positives and reviews attack events as part of its managed wrap
  • Cloudflare logs can be forwarded into your SIEM or into FirstNet's monitoring
  • Sophos MDR analysts monitor, hunt and alert around the clock across endpoints, firewalls, identity, cloud and email
  • When Sophos raises an alert, FirstNet's Incident Response team works with you to contain, remediate and recover

Cloudflare does not include a full SIEM or an MDR-style 24/7 SOC, so if you need analyst-led detection around the clock, plan Sophos MDR or your own SOC alongside it.

Support for both runs through FirstNet's Rapid Response desk as a single entry point, with escalation into Cloudflare or Sophos as needed.

Source: FirstNet Web Application & DDoS Protection service page →

Didn’t answer your question?

Call