Zero Trust for the Foundations of Everyday Life

Critical infrastructure is under relentless attack, and the consequences of failure are severe. Yet the organizations that form the backbone of local communities—the small hospitals, water treatment plants, and energy providers—often lack the resources to defend themselves. Cybercriminals increasingly target these smaller entities, exploiting their limited budgets and lean security teams.

To address this gap, Cloudflare has announced Project Safekeeping, an initiative that provides enterprise-grade Zero Trust cybersecurity solutions at no cost, with no time limit, to these vulnerable organizations. The program begins on December 13, 2022.

This effort builds on partnerships with government officials in Australia, Germany, Japan, Portugal, and the United Kingdom. While those governments focus on securing large-scale infrastructure—banks, major hospital networks, and airports—the smaller organizations that feed into these national systems often go overlooked.

The Scale of the Threat

Recent incidents highlight the real-world impact of attacks on these smaller entities. In Japan, a ransomware attack shut down a hospital's access to patient records for nearly two months, forcing it to turn away new patients, including emergencies. In Germany, a ransomware compromise of a local county's IT systems halted public services for weeks, with the region still recovering a year later.

These organizations typically run on tight budgets and cannot maintain dedicated security teams, threat intelligence, or modern security tools. They are essential to daily life but are the least equipped to handle sophisticated attacks.

A Practical Solution with Broad Coverage

Cloudflare's Zero Trust approach is designed to be both effective and easy to deploy—a critical requirement for organizations without dedicated security staff. This builds on the company's earlier work with the Critical Infrastructure Defense Project, which provided similar support to US organizations following Russia's invasion of Ukraine.

Cloudflare brings experience in protecting vulnerable groups through its Project Galileo and Athenian Project, plus the global infrastructure that blocked an average of 126 billion cyber threats each day in Q3 2022.

Eligible organizations receive a comprehensive suite of security services freely and indefinitely, with no obligations:

  • Connecting users to applications: Real-time verification of every user against every protected application to safeguard internal resources and prevent data breaches.
  • Filtering traffic: A Secure Web Gateway (SWG) that blocks unwanted content, stops unauthorized user behavior, and enforces corporate security policies.
  • Securing cloud applications: A Cloud Access Security Broker (CASB) for access control, data loss prevention, shadow IT detection, and compliance with data privacy regulations.
  • Protecting sensitive data: Data Loss Prevention (DLP) secures confidential information in transit.
  • Email security: Area 1 preemptively blocks phishing, Business Email Compromise, and malware-less fraud attempts.
  • Safer web browsing: Remote Browser Isolation (RBI) insulates users from untrusted web content and protects data during browser sessions.

Eligible organizations also receive access to Cloudflare's application security products, including DDoS protection and a Web Application Firewall (WAF).

Eligibility and How to Apply

To qualify for Project Safekeeping, organizations must meet three criteria:

  • Be located in Australia, Japan, Germany, Portugal, or the United Kingdom.
  • Be classified as critical infrastructure by their respective local governments.
  • Have a maximum of approximately 50 employees and/or less than USD $10 million in annual revenue or balance sheet total.

Organizations that believe they may be eligible can submit an application through the Project Safekeeping site. The goal is to let these vital entities focus on serving their communities rather than warding off cyber threats.