CIOs are consolidating around Cloudflare One

Cloudflare's early reputation was built on Web Application Firewall and DDoS mitigation for Internet-facing properties. But in conversations with CIOs and CSOs over the past several years, a different need kept surfacing: managing connectivity and security across the entire enterprise. Whether they framed it as Zero Trust or Secure Access Service Edge (SASE), the message was consistent — legacy appliances and point solutions weren't scaling. Cloudflare One was built to answer that.

More than 10,000 organizations now use Cloudflare One to connect and secure users, devices, applications, and data. During CIO Week, we spoke with leaders at some of our largest customers to understand what drove their decision. Six themes emerged:

  1. Cloudflare One delivers more complete security.
  2. Cloudflare One makes your team faster.
  3. Cloudflare One is easier to manage.
  4. Cloudflare One products work better together.
  5. Cloudflare One is the most cost-efficient comprehensive SASE offering.
  6. Cloudflare can be your single security vendor.

A security architecture tested on ourselves

The first SASE conversations started when customers asked how Cloudflare keeps itself safe. Their public-facing properties relied on us for security and availability, so our own policies influenced their trust. We could not find a commercial product that offered strong security without adding latency, so we used our own network to connect employees to internal resources and secure their Internet access. When customers learned what we built to replace our private network, they wanted to adopt it themselves.

Why do CIOs choose Cloudflare One?

Cloudflare One has grown from that foundation. For internal access, we apply Zero Trust controls by default — policies that enforce hard keys on specific applications, restrict access to certain countries, or require administrative approval for sensitive tools. Every request can be evaluated against policies that match the sensitivity of the resource. On the outbound side, we built DNS filtering on the world's fastest resolver, layered a Secure Web Gateway and network firewall on top, and added an isolated browser for risky sites. More recent additions help control data sitting in SaaS applications and prevent sensitive data from leaving the enterprise.

One area that most SASE vendors overlook is email. After years of phishing attacks aimed at Cloudflare, we deployed Area 1 Email Security. The results were strong enough that we acquired the company and now offer the same protection as part of Cloudflare One.

The result is that when CIOs describe their security challenges, we can recommend a complete solution built on our own experience addressing those same concerns.

Access control at a major social media platform

One of the world's most prominent social media platforms embarked on a project to overhaul its access controls. After evaluating vendors on their ability to protect against phishing and lateral movement, the security team selected Cloudflare One for the granular access controls and layered security policies that can be applied to any request without slowing users down.

Performance without compromising security

Customers starting with Application Services typically chase every millisecond because performance directly impacts revenue. CIOs tackling SASE tend to rank performance lower — until user complaints generate help desk tickets. We believe they shouldn't have to accept that trade-off.

Cloudflare One accelerates users from the moment they connect. DNS lookups run through 1.1.1.1, the world's fastest DNS resolver. Device connections use BoringTun, our open source WireGuard implementation in Rust, which provides a high-performance on-ramp without draining battery. The same technology powers the WARP consumer offering, and we optimize continuously based on that feedback.

Out of the 3,000 top networks in the world measured by IPv4 addresses advertised, we rank fastest in 1,310. Once connected, traffic is routed through smart routing technology to find the quickest path to and from the destination. And because Cloudflare acts as reverse proxy for more than 20% of the HTTP Internet, we serve those sites from the same data centers where employees connect to our Secure Web Gateway — often delivering content from a server just centimeters away from where filtering occurs.

Protective DNS for the federal government

The Cybersecurity and Infrastructure Security Agency (CISA), which operates within the United States Department of Homeland Security, launched a program to find a protective DNS resolver for civilian government agencies. These agencies operate in both large cities and rural areas, requiring fast DNS resolution close to their users. After evaluation, CISA selected Cloudflare, in partnership with Accenture Federal Services, as the country's protective DNS resolver.

Replacing Zscaler at a Fortune 500 energy company

An American energy company attempted to deploy Zscaler but spent eight months struggling with integration and slow user performance. The organization already used Cloudflare's DDoS protection and ran a pilot of Cloudflare One. After the pilot showed significant performance improvements — particularly with the isolated browser — they removed Zscaler and consolidated on Cloudflare.

Management burden shapes SASE buying decisions

For many CIOs, how easy a SASE platform is to operate matters almost as much as the security outcomes it delivers. Hardware appliances and their virtual equivalents demand upfront deployment work plus ongoing maintenance and upgrades. Even migrating to another cloud-based SASE vendor can leave IT teams wrestling with a system that is merely less painful than what they replaced. When a solution is difficult to deploy, migrations stall and adoption of advanced features suffers. When it is hard to use, administrators waste time and users find ways to bypass it.

Cloudflare One was built so that advanced SASE technologies are accessible to teams of any size, including those without dedicated IT departments. The same design philosophy carries over to the enterprise IT and security teams managing large-scale deployments. Feedback from CIOs highlighted specific challenges at global scale: updating hundreds of policies or coordinating changes across dozens of administrators. To address that, every Cloudflare One feature is manageable via API support, and a Terraform provider enables peer-reviewed configuration-as-code workflows.

The free and pay-as-you-go plans are intentionally available to anyone with a credit card. A European Fortune 500 telecommunications company started that way when their Developer Operations team lost patience with the existing VPN. Developers complained that the legacy private network slowed access to the tools they needed. DevOps administrators set up Cloudflare One in minutes without talking to a Cloudflare sales representative. The company now relies on the platform to secure internal resources and internet paths for over 100,000 employees.

Integration beats a stack of point solutions

CIOs evaluating SASE often start with the goal of replacing multiple point solutions. The effort required to glue those products together consumes IT time, and the gaps between them create security blind spots. Many SASE vendors, however, offer platforms that simply bundle point solutions under one brand. There may be a single invoice, but interoperability challenges and security gaps remain.

Cloudflare One is designed as a single, comprehensive SASE solution where every feature adds value to what already exists without adding maintenance overhead. When an organization secures applications behind Zero Trust access control, enabling Cloudflare’s Web Application Firewall (WAF) to run in-line is a single button click. Users who click unknown links open the site in an isolated browser automatically. Data Loss Prevention (DLP) rules built for data-in-transit filters will soon also apply to data at rest through the API-driven Cloud Access Security Broker (CASB).

A US-based national provider of residential services, including plumbing and climate control repair, recently chose Cloudflare One to consolidate its disparate stack of cloud-based security vendors. After evaluating competitors that stitch together point solutions, they found more value in deploying Cloudflare’s Zero Trust network access together with outbound filtering for thousands of employees.

The cost model behind Cloudflare One

CIOs migrating from hardware appliances that attempt Zero Trust functions can realize immediate savings by eliminating license and maintenance costs or avoiding new capital expenditure. Over the past decade, Cloudflare has helped more than 100,000 organizations replace hardware with a faster, safer, and more cost-efficient alternative. But a newer form of the problem has emerged: renewal sticker shock. CIOs who adopted a cloud-based SSE solution two or three years ago now describe significant price increases from their existing vendors.

Many of those vendors rely on dedicated appliances that struggle to scale with traffic, forcing them to purchase more hardware and pass those costs on to customers. Others run on public cloud providers and pass along rising infrastructure costs with usage-based pricing. Cloudflare’s network follows a different model. Rather than dedicated appliances, Cloudflare deploys commodity hardware on which any Cloudflare service, from Bot Management to Workers to SASE products, can run. Server hardware is purchased from multiple vendors in the exact same configuration, providing supply chain flexibility and reducing the risk that any single component drives up costs.

Because over 20% of the world’s HTTP internet relies on that hardware today, Cloudflare has a strong incentive to obsess over computing efficiency. Since every service can run on every server, that investment also benefits Cloudflare One, and no additional hardware is needed for SASE capacity. The network is built to absorb traffic spikes from the largest internet properties, so enterprise SASE deployments do not strain it. Transit costs are similarly managed. In many cases, the reverse proxy motivates exchanges and ISPs to waive transit fees because providing fast, reliable access to Cloudflare-hosted websites benefits them. When the network is turned around for SASE customers, the same savings apply.

An infrastructure company in South Africa faced this exact renewal problem earlier this year. Their existing cloud-based Secure Web Gateway vendor, Zscaler, demanded a significant price increase and threatened to shut off service. Already trusting Cloudflare’s network for their internet properties, the company replaced their SASE vendor with Cloudflare One’s more cost-efficient model without losing any functionality.

Consolidating to a single connectivity and security vendor

A growing number of CIOs want to reduce the number of vendors they manage and invoices they pay. Hundreds of enterprises that adopted Cloudflare One began as customers of Cloudflare’s Application Services and Application Security products. The consolidation journey takes two forms. In the first, CIOs are stitching together multiple security point solutions into a SASE deployment and choose Cloudflare’s network for its integrated features and reduced maintenance burden. In the second, a broader migration to cloud-based services has led to vendor bloat, with customers struggling to inventory which services they have purchased and actually use.

Vendor proliferation adds cost in dollars and time. Each vendor’s contract may introduce redundant fixed platform fees, and every vendor adds another account manager to contact and another system to involve when debugging issues that span multiple components. Bundling Cloudflare One with Application Services and Application Security lets organizations rely on a single vendor for every connection that needs securing and accelerating, with a single control plane spanning cache rules and Zero Trust gap review. CIOs get one point of contact — a Cloudflare Customer Success Manager — to escalate requests that previously might involve dozens of vendors.

A large American data analytics company chose Cloudflare One on that journey. They first came to Cloudflare for load balancing and DDoS protection for their applications. After seeing how performance features for public-facing applications could extend to internal resources, they selected Cloudflare One over Zscaler and Cisco.

Starting points vary

CIO motivations differ depending on business, industry, and stage in a Zero Trust adoption journey. Cloudflare has a team dedicated to helping organizations evaluate SASE options and experiment with Cloudflare One; they can be reached here. For those who prefer to explore independently, nearly every Cloudflare One feature is free for up to 50 users, and many of the largest enterprise customers started on the free plan by signing up here.