Zero Trust vendors bundle free security for US critical infrastructure
Cloudflare, CrowdStrike, and Ping Identity have launched the Critical Infrastructure Defense Project, a joint effort to provide free security services to US hospitals, energy utilities, and water utilities for at least the next four months. The initiative, announced today, responds to concerns raised by cybersecurity and government experts about potential retaliatory cyber attacks against US critical infrastructure following sanctions related to the Russian invasion of Ukraine.
The three companies identified these sectors as particularly vulnerable because they are often underprepared for sophisticated attacks and disruptions could have severe consequences. The project is detailed at CriticalInfrastructureDefense.org.
Three pillars of protection
The program is built around a Zero Trust security model with three core components: network security, endpoint security, and identity. Each company contributes its respective strength:
- Cloudflare provides Zero Trust network security services to protect connections regardless of where users access the network.
- CrowdStrike supplies endpoint security to keep laptops, phones, and servers from being compromised.
- Ping Identity offers identity solutions, including multi-factor authentication, as the foundation of an organization's security posture.

The integrated offering is designed to withstand sophisticated nation-state cyber attacks, which the companies characterize as a higher threat level than anything seen since their founding. Recognizing that they rely on the nation's infrastructure themselves, the three vendors are providing their technology at no cost during this period of heightened risk.
Fast deployment for understaffed IT teams
The companies have coordinated their products to work together and be easy to implement. This avoids the delays of long requisition processes or budget approvals, which could leave vulnerable organizations exposed. To further assist organizations with limited IT staff, the project provides a recommended security triage guide that outlines priorities for the next day, week, and month.
The guide, available for download at this link, acknowledges that not every organization can implement every recommendation. However, the companies note that completing each step incrementally improves preparedness.
Onboarding and future expansion
Organizations accepted into the program will receive onboarding support with the same service level as the companies' largest paying customers. The goal is to get protections in place immediately and keep critical infrastructure online through the current challenge.

The Critical Infrastructure Defense Project may expand to additional sectors and countries based on what the companies learn in the coming days. While the hope is that retaliatory cyberattacks do not materialize, the vendors state their solutions are ready for full deployment to protect the nation's most critical infrastructure. Matt contributed to the reporting of this story.



