Given how little they do now to stop malicious content hosted behind/by Cloudflare, the bare minimum if anything.
Any process that doesn't take down phishing sites within a few hours at most is inadequate for protecting potential victims. Especially when I compare it to all the other providers I report abuses to, Cloudflare doesn't strike me as a company that takes abuse reports particularly seriously.
CF does have small anti-abuse teams, but it’s just not a business priority for the company to do better. We’ve tried many times to engage at a corporate level and the bottom line is they don’t care - they don’t want to police content as often stated by the executives.