Cloudflare Kicks Off Security Week With a Full-Stack Agenda

Cyber threats are making headlines with increasing frequency. Global events have pushed governments to urge organizations to shore up their defenses, and high-profile vulnerabilities like Log4J demonstrated how quickly attackers will move once a vector becomes public. In response, Cloudflare is dedicating six days to security, aiming to make it a foundational consideration rather than an afterthought.

Welcome to Security Week 2022!

The company is framing its strategy around a simple reality: not everyone is a security expert. Cloudflare's approach has always been to apply sophisticated technical solutions to difficult problems while making them broadly accessible. Security Week 2022 will feature a mix of product enhancements, new offerings, and partnerships—including features that will be provided free to all users.

The Evolution From Website Protection to Network Security

Cloudflare's security journey began with website owners. Early offerings centered on DNS, DDoS mitigation, a Web Application Firewall (WAF), and SSL/TLS. Acting as a reverse HTTP proxy, Cloudflare could filter malicious traffic and upgrade the security protocols for large portions of the internet with a single deployment.

It quickly became apparent that a substantial share of internet traffic was automated—bots accounting for 30% or more. This drove development of dedicated Bot Management tools. The rise of APIs, which now represent roughly 54% of HTTP requests through Cloudflare's network, added another layer of challenge. That push toward securing applications and automated traffic remains a core focus in the first half of the week, with announcements expected around TLS, WAF, and Custom rules.

Expanding Beyond HTTP and Protecting People

HTTP, however, is just one protocol. Cloudflare extended its proxy to handle arbitrary TCP/UDP traffic through its Spectrum product and eventually began securing raw IP traffic at the edge. This opened the door for game servers, custom IoT protocols, and financial applications to receive the same DDoS mitigation and filtering as web traffic.

The next major shift was flipping the proxy model. By turning Cloudflare into a forward proxy, security could be applied to users rather than just servers. Configuring Cloudflare as a DNS resolver or forward proxy gives anyone an additional safety shield. This evolved into Cloudflare Zero Trust, which aims to replace clunky VPN infrastructure with a model where security is baked into every step of a connection.

That architectural rethink aligns with a broader industry shift. The castle-and-moat security paradigm no longer holds in a world of mobile workers, distributed applications, and cloud infrastructure. The logical alternative, Cloudflare argues, is to create a virtual secure environment by focusing on the one fundamental component: the network itself.

Dogfooding, Partnerships, and Closing a Crowded Week

Cloudflare also stresses that technology alone isn't enough. The company's internal security team uses its own products, and Cloudflare has been actively partnering with other cybersecurity firms to share insights and integrate products for improved user experiences.

The week's agenda runs the gamut: API security coverage lands mid-week, non-HTTP proxying updates follow on Thursday, Zero Trust improvements arrive Friday, and the week wraps with best practices, operational insights, and new partnership announcements. Over 75 announcements were considered for the week, though not all fit into the six-day schedule—Cloudflare is positioning Security Week as a stepping stone for a year of progress, not just a publicity sprint.