Cloudflare to Acquire Area 1 Security, Bolstering Email Protection

Cloudflare has announced an agreement to acquire Area 1 Security, a company specializing in cloud-native protection against email-based threats. The plan is to integrate Area 1's technology into Cloudflare's global network and its Zero Trust security platform. The acquisition is expected to close early in the second quarter of 2022.

Why Email Remains a Critical Attack Vector

Email has been a battleground for security since the days of early spam filters. While machine learning helped push spam into a mostly ignored junk folder, email itself remains a primary communication channel for businesses. That importance makes it a prime target for more dangerous threats, including phishing and malware campaigns.

Many organizations still run on-premise email servers, and even those using cloud providers often rely on security that goes beyond what is built into the platform. Cloudflare has historically focused on protecting networks and HTTP-based applications, defending mail servers from DDoS and other attacks. However, the more insidious threats are content-based: emails sent directly into an organization with the intent to deceive or compromise.

Area 1 estimates that phishing alone accounts for more than 90% of cyber security damages. News reports regularly cite breaches triggered by a single employee falling for a well-crafted phishing email. Despite the danger, the traditional response has been to layer legacy, box-based security products. This results in a fragmented approach, with one in seven Fortune 1000 companies running two or more separate email security solutions. As email shifts to the cloud, driven by platforms like Google's G Suite and Microsoft's Office 365, the need for a more integrated defense becomes clear. These built-in protections often fall short against sophisticated attacks and provide limited control over access from mobile devices or third-party clients.

Field Testing the Solution

Cloudflare's interest in email security was formalized last year with the launch of its Email Security DNS Wizard, a tool focused on spoofing and phishing prevention. The Area 1 acquisition is a significant expansion of this effort.

Prior to the acquisition decision, Cloudflare used Area 1 internally. In early 2020, after an increase in employee-reported phishing attempts, the company's security team found its cloud email provider's native filtering inadequate. Controls were also insufficient for protecting its iOS app and other email access methods. The team assessed vendors based on four criteria: attachment scanning, malicious link analysis, business email compromise (BEC) protection, and robust APIs for cloud email providers. Area 1 was selected and deployed.

The results were immediate. Phishing attempts dropped significantly, and the service operated without a high rate of false positives. In fact, the lack of employee-reported phishing attempts became so notable that Cloudflare's CEO asked if the email security had stopped working. In reality, Area 1 was intercepting the threats before they reached any inbox.

Area 1's effectiveness stems from two key assets. First, a substantial data platform collects and analyzes metadata, such as sender patterns and originating IP addresses. Second, this nine years' worth of threat intelligence is used to train machine learning models that can act preemptively against emerging campaigns.

The Case for Integration

The vision for the acquisition goes beyond simply adding a separate email security product. Cloudflare intends to make email security a component of its existing Zero Trust platform. The current practice of layering disparate security products is difficult to manage, as they often lack unified configuration or reporting mechanisms. The SMTP protocol, originating in 1982, has accumulated numerous add-on standards for security, making interoperability a challenge.

Microsoft and Google offer basic protection, but many companies do not consider it sufficient1. A more effective model would involve seamlessly integrated layers. This would allow a scenario where phishing defense is primary, but if a malicious link does reach an inbox, it could be opened in a remote browser without text input or scanned for malware automatically.

Bringing email and Zero Trust together also enables a shared intelligence model. Combining Area 1's email-derived threat data with threat signals from Cloudflare's global network can strengthen security capabilities across all products and locations.

Alignment and Outlook

Cloudflare notes that despite email being a critical issue, it is not the only attack vector. The goal is to build a comprehensive set of defense layers that work together in the same stack. Until the deal closes, Cloudflare and Area 1 will remain separate and independent companies.

1Piper Sandler, 1Q2021 Email Security Survey; Gartner, Market Guide for Email Security, 2020.