A Year of Remote Work Stress-Tests ANZ Security

It has been a year since Cloudflare opened its Australia and New Zealand operations under my leadership. Reviewing that period means acknowledging the backdrop against which it unfolded: Melbourne’s lockdown, where I write this, and a global pandemic that redrew the security perimeter for virtually every organisation.

The shift to remote work did more than change commutes. Security teams lost visibility into office network traffic. Employees moved to home WiFi and video conferencing tools that IT had not provisioned. VPN platforms built for peak office loads buckled under sustained remote traffic. The migration to cloud applications that many companies had already started became an urgent requirement rather than a strategic option.

Growth Against a Rising Threat Picture

The operational side of the year was defined by resilience. Our local team grew more than 60 percent, with many new hires never meeting colleagues in person, yet the culture held and customer support remained responsive. Much of that support was emergency work: organisations needing to optimise and secure systems for a workforce that 2020 forced online overnight.

The threat data justifies the urgency. Australian scammers stole AU$1.2 million in the first half of the year, and Cloudflare's Q2 2020 network-layer DDoS report ranked Australia fifth globally by attack volume. The Internet has become essential infrastructure, and it is under proportionally greater attack.

Australia’s Cyber Security Strategy, unveiled by Prime Minister Scott Morrison, was a welcome step. I consulted on it, and it provides direction. But a strategy document is not a security posture. Organisations need concrete tools and support to raise their defences, not just a plan describing how they might.

Two Illustrative Engagements

The range of problems our team addressed over the past year is best shown by two very different organisations.

Canva, the online graphic design platform used by over 35 million people monthly, needed to scale without sacrificing performance or security. It now runs several Cloudflare products: Access for securing remote entry to internal applications, Workers for customising traffic handling at the network edge, and Bot Management to cut down attacks from image-scraping bots. As Canva's Head of Infrastructure, Jim Tyrrell, put it, the company can focus on product growth knowing its platform remains fast, reliable and secure.

At the other end of the spectrum is Citizens of the Great Barrier Reef, a conservation organisation participating in Project Galileo. Launched in 2014, Project Galileo provides enterprise-grade cybersecurity at no cost to qualify public interest groups — advocates, humanitarian organisations, artists and political dissent voices. For Citizens of the Great Barrier Reef, the protection focuses on securing an origin server against traffic bursts and malicious access attempts. Technologist Som Meaden described the benefit as enterprise-level network confidence on a startup's resources.

Partnerships and Continued Expansion

Security is not something we can deliver alone, which is why the year also involved deepening regional partnerships. In June we expanded our relationship with Rackspace to offer combined managed services. We also added partnerships with Baidam and AC3. The ANZ network footprint, already significant, continues to gain points of presence.

Looking ahead, the mission remains incomplete. The plan is to grow the ANZ team substantially through 2020 and 2021 to match the challenge. In the meantime, the conversation about security risk needs to reach every board member and employee. Hundreds of organisations have engaged with us on security this year, including dozens of CIO, CSO and CISO meetings on my end alone, and the response has been consistent: the need for better security is urgent and shared. That sense of community, all working toward a safer Internet, is the most encouraging sign yet.