Security Week 2023: Shifting Focus from Applications to People

At a recent dinner with 56 CISOs and CSOs from banking, gaming, ecommerce, and retail companies, the conversation consistently circled back to one theme: convincing internal business and product teams to follow security guidance. Notably absent were technical concerns like sophisticated skimmers, GraphQL API protection, multi-cloud security, or the growing scale of DDoS attacks. The recurring challenge was human behavior — getting people to make secure choices.

This mirrors a phishing attack Cloudflare thwarted last August. Despite sophisticated text messages impersonating our Okta login page, some employees fell for the lure — because they are human. However, the attack failed because every employee is required to use physical security keys for all application access. The attacker obtained valid credentials but could not bypass the hard key requirement. Phishing attacks are only becoming more prevalent in 2023.

The core issue is deploying the right tools to prevent people from making mistakes. Last year, the shift was from protecting websites to protecting applications. This year, the shift is from protecting applications to protecting employees wherever they are. This direction aligns with the White House's recent national cybersecurity strategy, which mandates multi-factor authentication, complete attack surface visibility, and cloud security tool adoption across agencies.

Complexity Is the Enemy of Security

As one gaming platform CISO put it: “The more tools you use the less secure you are.” Adding vendors can seem like adding security layers, but it also introduces new risks:

  • Each third party adds another potential vulnerability. The LastPass breach, for example, started with access to a cloud storage service that enabled a secondary phishing attack.
  • More tools mean more complexity — more logins and dashboards. Critical changes are easier to miss when information is fragmented.
  • No one can master every tool. Coordination across specialized security teams slows response and loses context.
  • New tools can create a false sense of security if they aren't configured properly or actively used.

This week's announcements will focus on reducing this complexity. Expect integrations that allow Zero Trust deployment and management across multiple platforms from within the Cloudflare dashboard, along with extended detection capabilities to replace additional point vendors. A new migration tool will also simplify moving from competing solutions to Cloudflare.

Using Machine Learning for Pattern Detection

Machine learning is often overused as a buzzword, but the practical value is clear: computers excel at pattern recognition. Training models to identify good and bad patterns frees humans to focus on what they do best — critical thinking and decision-making on exceptions. This optimizes the time of your most valuable people.

Cloudflare's approach differs because of its architecture: code runs at every data center, on every machine. This globally distributed network allows inference to run close to end users. This unique speed advantage means machine learning inference runs more than 40 million times every second — a capability competitors with centralized infrastructure can't match. This week will include a full day on new models for detecting patterns like fraud and API endpoints.

Turning Intelligence into Action

Cloudforce One, launched in June, was the first step in leveraging threat intelligence gathered from handling nearly 20% of Internet traffic. Customers have since asked for actionable insights and easy ways to respond. This week's announcements will include new views and products to act on Cloudflare's threat intelligence, such as account-level reporting for a command view of security trends across your entire organization.

Designing Security Around Human Behavior

Development and business teams want speed and familiar tools. Security that adds friction will struggle to gain adoption — the recent T-Mobile breach, where an unintentionally public API was exploited, underscores the cost. The solution is to make existing tools more secure, not demand teams change their processes.

New features will target the most common human errors: automatically blocking domains hosting phishing links, preventing data from leaving specific regions, delivering security alerts within the tools users already work in, and detecting shadow APIs without altering development workflows.

Whether you're a CISO, SecOps lead, or developer responsible for organizational security, the coming announcements aim to simplify your role: protect more infrastructure from a wider range of threats while reducing vendor sprawl — and, crucially, minimize the mistakes the humans on your team can make.