The New Network Reality
The corporate network that CIOs manage today bears little resemblance to the infrastructure of even half a decade ago. Applications have moved off-premises, users connect from anywhere, and the security perimeter has dissolved. These shifts have produced fragmented visibility, escalating costs, operational complexity, and a network fabric that is increasingly difficult to change without breaking something else.
The positive news is that the underlying technology has matured to a point where a different approach is feasible. The Internet is no longer an experimental overlay; it is the backbone of modern business. For CIOs, the pragmatic path forward is to build their corporate networks on top of the Internet rather than trying to maintain a parallel, private infrastructure alongside it. This is the premise behind Cloudflare One, a Zero Trust Network-as-a-Service designed to give organizations a faster, more secure, and more reliable foundation for connecting users to applications.
Generation 1: The Castle and Moat
The traditional enterprise network was built on a simple physical model. Companies housed their business-critical applications—email, ERP, CRM—on servers in data centers located near major offices. Employees connected to these applications over a LAN or through private WAN links from branch locations. Security was enforced by a stack of hardware appliances, typically firewalls, sitting at the data center edge. Once inside the network, users had implicit trust and could move laterally across systems, though physical badge access and basic authentication provided a crude barrier against outsiders.
This architecture centralized control at the network layer. Access decisions were made using IP addresses and ACLs—for example, allowing a specific range of IPs to reach another range that hosted an HR application. Managing this required detailed spreadsheets to track address allocations and policy mappings. The model was rigid but straightforward as long as the physical geography of the company matched its digital topology.
When Users and Apps Left the Building
The rise of the Internet broke that geographic alignment. Companies quickly realized they could rent computing power instead of buying servers, and they could run applications entirely in the cloud as SaaS offerings without managing any hardware. This transition was disruptive but not instantaneous. Most organizations now run hybrid environments, keeping some legacy infrastructure while adopting cloud-native services, often connected by aging MPLS circuits and backhauled traffic paths.
As more traffic headed to the Internet, CIOs faced a cost crunch. Sending branch traffic back through a central data center over MPLS for security inspection multiplied bandwidth expenses—particularly noticeable after adopting bandwidth-hungry cloud services like Office 365. The latency this introduced also hurt user experience, especially as employees worked from locations farther from those central chokepoints.
Simultaneously, the user base changed. Employees no longer had to be in the office to work. VPNs granted remote access, but they were slow, scaled poorly, and presented serious security risks. A user on a VPN had access to the entire network, enabling lateral movement to sensitive resources. The pandemic accelerated this shift, transforming VPN capacity and trust model flaws from a concern into a major operational disruption.
Generation 2: The Patchwork Era
A wave of vendors emerged to address specific problems created by these shifts. Some delivered virtualized appliances on cloud platforms; others offered cloud-native services for application access or web filtering. But stitching together these point solutions created new problems for CIOs.
Visibility and Security Gaps
With traffic fragmented across data centers, clouds, and remote users, IT lost the central vantage point that the castle-and-moat model provided. Systems like SIEM and SOAR tried to aggregate data from disparate tools, but piecing together the full traffic picture remained difficult. The result was a rise in "Shadow IT"—services employees adopted without IT approval—making it nearly impossible to enforce consistent security policy across all data flows.
Performance and Cost Pressures
The backhauling of traffic through central security appliances added latency that degraded application performance. IT teams struggled with unpredictable internet reliability and had limited control over factors like remote workers' home connections.
Financially, the model became untenable. CIOs continued to pay for MPLS links and the hardware to secure them, while adding new costs for point solutions to manage the expanding complexity. IT support costs grew as teams tried to triage issues with incomplete visibility. Making any change to the network—provisioning a new MPLS link, deploying a new appliance, or modifying one security tool—had cascading effects across other systems, with lead times stretching far beyond business needs. The result was a network that was expensive, fragile, and difficult to adapt at a time when business demands for flexibility were accelerating.
The Scorecard Changes
The contrast between the two generations is stark. Generation 1 offered centralized control but limited mobility and scale. Generation 2 addresses mobility and cloud adoption but creates fragmented control, higher costs, and a brittle architecture. The challenge for the modern CIO is not about choosing between these models but moving toward a third path—one that delivers the scale and flexibility of the Internet with the security and reliability that enterprises once expected from private networks.
Building corporate networks on the Internet
The third generation of corporate networking moves the network itself onto the Internet. CIOs have long resisted this shift because private connectivity feels more secure than the public Internet. A Zero Trust approach delivered at Internet scale flips that assumption: instead of trusting anything already inside the corporate perimeter and allowing lateral movement, every request into, out of, and between entities is authenticated and authorized. Users only reach applications they are explicitly permitted to access, and enforcing those policies from an edge location near the user avoids the performance penalty of backhauling traffic through central data centers or a long chain of security appliances.
To make this model work, the underlying platform must deliver on three fronts:
- Connect everything. Users, applications, offices, data centers, and cloud properties all need to be linked flexibly, easily, and reliably. That means supporting the hardware and connectivity options enterprises have today—mobile clients across OS versions, standard tunneling protocols, and peering with global telecom providers.
- Enforce comprehensive security. The platform must integrate with existing identity and endpoint security providers and apply Zero Trust protections across all OSI layers, whether traffic stays internal (East/West) or reaches the Internet (North/South). That includes end-to-end encryption, microsegmentation, precise filtering and inspection, and defenses against DDoS and bot attacks.
- Provide visibility and insight. Beyond basic questions about who accesses what and how performance looks (latency, jitter, packet loss), next-generation tools should surface trends and flag potential problems before they become incidents—then offer one-click controls to act on those findings from a single dashboard.
Performance, reliability, and compliance everywhere
The old critiques of the public Internet—slow, unreliable, legally messy—are being answered by platforms that optimize the real user experience rather than raw speed-test numbers. Application-specific factors and live Internet health data inform routing decisions end to end.
Reliability is no longer about scheduled maintenance windows. Networks must operate 24x7 with near-100% uptime and global reachability. The provider itself must be resilient, have capacity to absorb massive attacks, and route around issues with intermediary providers without requiring manual intervention from the customer’s network team. Onboarding a new location should not depend on a vendor provisioning new nearby capacity.
Data sovereignty rules keep shifting. CIOs need one interface to manage data globally, not fractured regional solutions, so they can adapt as new regulations appear.
Making the leap without ripping out the old network
This shift sounds disruptive, but it does not require a big-bang migration. A Generation 3 platform should let an organization start with a single traffic flow—for instance, clientless Zero Trust access for one application—and prove value in minutes, regardless of company size.
From there, migration proceeds in stages:
- Move from IP-level to application-level architecture incrementally. Start with a GRE or IPsec tunnel, then use automatic service discovery to identify high-priority applications for finer-grained connection.
- Tighten policies gradually. Begin with rules that mirror the legacy setup, then use analytics and logs to enforce more restrictive policies once traffic patterns are visible.
- Keep changes quick and easy. Design the new network through a modern SaaS interface.

Cloudflare One: a single platform for next-generation networks
Cloudflare positions Cloudflare One as the first platform to combine Zero Trust and network services on a global network, built from scratch in software on commodity hardware. It began as an internal project for Cloudflare’s own IT and security teams before being extended to customers.
Every Cloudflare service runs on every server across more than 250 cities with over 100 Tbps of capacity. DNS filtering runs on the world’s fastest public DNS resolver, and identity checks run on Cloudflare Workers. Insights from over 28 million requests per second and 10,000+ interconnects inform security and performance decisions for all customers. Network connectivity and security services are delivered in a single platform with single-pass inspection and single-pane management, closing visibility gaps that point solutions leave open.
Characteristic | Score | Description |
|---|---|---|
Security | ⭐⭐⭐ | Granular security controls are exercised on every traffic flow; attacks are blocked close to their source; technologies like Browser Isolation keep malicious code entirely off of user devices. |
Performance | ⭐⭐⭐ | Security controls are enforced at location closest to each user; intelligent routing decisions ensure optimal performance for all types of traffic. |
Reliability | ⭐⭐⭐ | The platform leverages redundant infrastructure to ensure 100% availability; no one device is responsible for holding policy and no one link is responsible for carrying all critical traffic. |
Cost | ⭐⭐ | Total cost of ownership is reduced by consolidating functions. |
Visibility | ⭐⭐⭐ | Data from across the edge is aggregated, processed and presented along with insights and controls to act on it. |
Agility | ⭐⭐⭐ | Making changes to network configuration or policy is as simple as pushing buttons in a dashboard; changes propagate globally within seconds. |
Precision | ⭐⭐⭐ | Controls are exercised at the user and application layer. Accomplishing “allow only HR to access employee payment data” looks like: Users in HR on trusted devices allowed to access employee payment data |
This week’s coverage recaps and expands on Cloudflare One with real customer examples building next-generation networks on the platform. It digs into capabilities available today, how they address the problems of earlier network generations, and new product areas aimed at removing legacy hardware costs and complexity, hardening security from multiple angles, and making all routed traffic even faster. As one of our customers recently said: "The Internet is our network, and Cloudflare is how we make it work."



