
<rss version="2.0" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:media="http://search.yahoo.com/mrss/">
    <channel>
        <title><![CDATA[ The Cloudflare Blog ]]></title>
        <description><![CDATA[ Get the latest news on how products at Cloudflare are built, technologies used, and join the teams helping to build a better Internet. ]]></description>
        <link>https://blog.cloudflare.com</link>
        <atom:link href="https://blog.cloudflare.com/" rel="self" type="application/rss+xml"/>
        <language>en-us</language>
        <image>
            <url>https://blog.cloudflare.com/favicon.png</url>
            <title>The Cloudflare Blog</title>
            <link>https://blog.cloudflare.com</link>
        </image>
        <lastBuildDate>Mon, 13 Apr 2026 18:50:04 GMT</lastBuildDate>
        <item>
            <title><![CDATA[Cloudflare named in 2025 Gartner® Magic Quadrant™ for Security Service Edge]]></title>
            <link>https://blog.cloudflare.com/cloudflare-sse-gartner-magic-quadrant-2025/</link>
            <pubDate>Fri, 23 May 2025 13:00:00 GMT</pubDate>
            <description><![CDATA[ For the third consecutive year, Gartner has named Cloudflare to the Gartner® Magic Quadrant™ for Security Service Edge (SSE) report. ]]></description>
            <content:encoded><![CDATA[ <p>For the third consecutive year, Gartner has named Cloudflare in the Gartner® Magic Quadrant™ for Security Service Edge (SSE) report. This analyst evaluation helps security and network leaders make informed choices about their long-term partners in digital transformation. We are excited to share that Cloudflare is one of only nine vendors recognized in this year’s report. </p><p>What’s more exciting is that we’re just getting started. <a href="https://blog.cloudflare.com/introducing-cloudflare-access/"><u>Since 2018</u></a>, starting with our Zero Trust Network Access (ZTNA) service <a href="https://www.cloudflare.com/zero-trust/products/access/"><u>Cloudflare Access</u></a>, we’ve continued to push the boundaries of how quickly we can build and deliver a mature SSE platform. In that time, we’ve released multiple products each year, delivering hundreds of features across our platform. That’s not possible without our customers. Today, tens of thousands of customers have chosen to connect and protect their people, devices, applications, networks, and data with Cloudflare. They tell us our platform is faster and easier to deploy and provides a more consistent and reliable user experience, all on a more agile architecture for longer term modernization. We’ve made a commitment to those customers to continue to deliver innovative solutions with the velocity and resilience they have come to expect from us. If you want to join them on this journey today, <a href="https://www.cloudflare.com/products/zero-trust/plans/enterprise/"><u>contact us</u></a> to discuss your own SSE journey. </p>
    <div>
      <h2>What is a Security Service Edge?</h2>
      <a href="#what-is-a-security-service-edge">
        
      </a>
    </div>
    <p>In general, a <a href="https://www.cloudflare.com/learning/access-management/security-service-edge-sse/"><u>Security Service Edge (SSE)</u></a> provides a helpful framing that gives teams guardrails as they adopt a Zero Trust architecture. The concept breaks down into a few typical buckets:</p><ul><li><p><b>Zero Trust access control</b>: Protect applications that hold sensitive data by creating <a href="https://www.cloudflare.com/learning/access-management/principle-of-least-privilege/">least privilege</a> rules that check for identity, device posture, and other signals on each and every request or connection.</p></li><li><p><b>Outbound filtering</b>: Keep people and devices safe as they connect to the rest of the Internet by filtering and logging network traffic, DNS queries, and HTTP requests.</p></li><li><p><b>Secure SaaS usage</b>: Analyze traffic to SaaS applications and scan the data sitting inside of SaaS applications for potential <a href="https://www.cloudflare.com/learning/access-management/what-is-shadow-it/">Shadow IT policy violations</a>, misconfigurations, or data mishandling.</p></li><li><p><b>Data protection</b>: Scan for data leaving your organization towards destinations that do not comply with your organization’s policies. Find data stored inside your organization, even in trusted tools, that should not be retained or that needs tighter <a href="https://www.cloudflare.com/learning/access-management/what-is-access-control/">access controls</a>.</p></li><li><p><b>Employee experience</b>: <a href="https://www.cloudflare.com/learning/performance/what-is-digital-experience-monitoring/">Monitor and improve the experience</a> that your team members have when using tools and applications on the Internet or hosted inside your own organization.</p></li></ul><p>The SSE space is a component of the larger <a href="https://www.cloudflare.com/learning/access-management/what-is-sase/"><u>Secure Access Service Edge (SASE)</u></a> market. You can think of the SSE capabilities as the security half of SASE, while the other half consists of the networking technologies that connect offices and data centers to each other along with everything that SSE connects. Some vendors only focus on the SSE side and rely on partners to connect customers to their security solutions. Other companies just provide the networking pieces. While today’s announcement highlights our SSE capabilities, Cloudflare offers both components as a unified SASE platform.</p>
    <div>
      <h2>How does Cloudflare fit into the SSE space?</h2>
      <a href="#how-does-cloudflare-fit-into-the-sse-space">
        
      </a>
    </div>
    <p>Cloudflare’s global network was built for this. We’ve developed a unified, programmable <a href="https://www.cloudflare.com/network"><u>network</u></a> in which every service runs in every data center, spanning more than 330 cities across the globe. Cloudflare operates within approximately 50 milliseconds of 95% of the Internet-connected population globally. That means that regardless of where your people, apps, and data are located, your Security Service Edge is not far away.</p><p>Our SSE services operate on the same infrastructure and locations that support many of the world's most prominent Internet platforms. We've integrated proven strengths including the <a href="https://1.1.1.1/"><u>world’s fastest DNS resolver</u></a>, our robust <a href="https://workers.cloudflare.com/?_gl=1*1fqsg8y*_gcl_au*MTU0MzQ4NzIwMS4xNzQyMjE4OTk0*_ga*NjkzNTc3NzkzLjE3NDIyMTg5OTQ.*_ga_SQCRB0TXZW*MTc0NTU3ODIzOC4yNS4xLjE3NDU1NzkwMTEuMTkuMC4w"><u>serverless compute platform</u></a>, intelligence from our leading <a href="https://www.cloudflare.com/application-services/products/?_gl=1*1fqsg8y*_gcl_au*MTU0MzQ4NzIwMS4xNzQyMjE4OTk0*_ga*NjkzNTc3NzkzLjE3NDIyMTg5OTQ.*_ga_SQCRB0TXZW*MTc0NTU3ODIzOC4yNS4xLjE3NDU1NzkwMTEuMTkuMC4w"><u>Web Application and API Protection (WAAP) platform</u></a> and <a href="https://blog.cloudflare.com/network-performance-update-cio-edition/"><u>advanced global traffic routing</u></a> capabilities developed as a result of proxying and protecting <a href="https://w3techs.com/technologies/overview/proxy"><u>approximately 20% of websites</u></a>. Our architecture ensures single-pass inspection, regardless of how customers connect. We also consistently hear that this <a href="https://blog.cloudflare.com/spotlight-on-zero-trust"><u>performance is core</u></a> to why customers chose Cloudflare. When customers choose Cloudflare, they’re choosing a unified, resilient platform built for the future.</p><p>By building our SSE platform on top of our own network, it puts Cloudflare in the driver’s seat. Whether that’s implementing best practices like IPv6, incorporating new technologies like WireGuard or <a href="https://blog.cloudflare.com/masque-building-a-new-protocol-into-cloudflare-warp/"><u>MASQUE</u></a>, or safeguarding against the future with <a href="https://www.cloudflare.com/learning/ssl/quantum/what-is-post-quantum-cryptography/"><u>post-quantum encryption</u></a>, by building on our own network we’re able to react quickly as new Internet security standards mature.</p><p>Customers can rely on Cloudflare to solve a broad range of security problems represented by the SSE category. They can also just start with a single component. We know that an entire modernization journey can be an overwhelming prospect for any organization. While all the use cases below are built to work better together, we make it simple for teams to start by just solving one problem at a time.</p>
    <div>
      <h3>Zero Trust access control</h3>
      <a href="#zero-trust-access-control">
        
      </a>
    </div>
    <p>Traditional VPNs have been the backbone of enterprise remote access for decades. However, organizations are <a href="https://www.cloudflare.com/zero-trust/solutions/vpn-replacement/">rapidly moving away from VPNs</a> due to security vulnerabilities, performance bottlenecks, and poor user experience. As businesses adopt <a href="https://www.cloudflare.com/learning/security/glossary/what-is-zero-trust/">Zero Trust principles</a>, they expect modern solutions that:</p><ul><li><p>Improve security posture by enforcing least privilege access and per-resource authorization, eliminating dependence on perimeter-based defenses</p></li><li><p>Enhance user experience with seamless, high-performance connectivity.</p></li><li><p><a href="https://www.cloudflare.com/the-net/everywhere-security/">Reduce complexity and operational overhead</a> by consolidating tools and automating access policies.</p></li></ul><p>Cloudflare enables identity-driven, context-aware policies which replace the traditional <a href="https://www.cloudflare.com/learning/access-management/castle-and-moat-network-security/?_gl=1*q87nt7*_gcl_au*MTcyNTU4My4xNzQyMjIwMTA5*_ga*MTUyNTE2MzE3NC4xNzQyMjIwMTM2*_ga_SQCRB0TXZW*MTc0NTUwMzg1OS4yMS4xLjE3NDU1MDM5MjguNjAuMC4w"><u>castle-and-moat</u></a> model that come with VPN-based solutions. Applications can be made available to employees as well as third parties through a completely clientless deployment. Policies can also be applied to the applications that sit outside your infrastructure to ensure a consistent experience across SaaS applications as well. </p><p>By mid-2026, we plan to ship a number of new access control capabilities, including:</p><ul><li><p><b>Identity provider (IdP) agnostic </b><a href="https://www.cloudflare.com/learning/access-management/what-is-multi-factor-authentication/"><b><u>multi-factor authentication (MFA)</u></b></a><b>:</b> Admins can enforce step-up MFA without having to direct a user back to an identity provider.</p></li><li><p><b>Just-in-time access controls:</b> Review and approve timely access requests to sensitive resources. Users can request access via tools like Slack and Google Chat.</p></li><li><p><a href="https://developers.cloudflare.com/cloudflare-one/connections/connect-networks/use-cases/rdp/rdp-browser/"><b><u>Browser-based RDP</u></b></a><b>:</b> Traditionally, vendors provide a limited number of PoPs which can support clientless RDP. With Cloudflare, customers get highly performant clientless RDP from the browser by connecting to any of Cloudflare’s data centers. This feature enables access to RDP targets without any software installed on the user’s machine.</p></li></ul>
    <div>
      <h3>Secure Web Gateway and DNS filtering</h3>
      <a href="#secure-web-gateway-and-dns-filtering">
        
      </a>
    </div>
    <p>For decades, organizations relied on on-prem hardware firewalls to secure Internet access. Like applications, users have moved beyond the perimeter and <a href="https://www.cloudflare.com/learning/cloud/cloud-native-security/">cloud-based security services</a> have become essential. Modern businesses expect solutions that:</p><ul><li><p>Protect users across locations from malware, ransomware, and other Internet threats</p></li><li><p>Enforce those protections with real-time, comprehensive threat intelligence that adapts with emerging attack vectors</p></li><li><p>Reduce management complexity while maintaining granular policy control across the entire network</p></li></ul><p><a href="https://www.cloudflare.com/zero-trust/products/gateway/"><u>Cloudflare Gateway</u></a>, our <a href="https://www.cloudflare.com/learning/access-management/what-is-a-secure-web-gateway/">secure web gateway (SWG)</a>, inspects and filters DNS, network, HTTP, and egress traffic with consistent protections across the Internet and internal resources. Customers adopt our SWG to block threats across remote and office workers, enforce acceptable use policies, encrypt traffic, and block unauthorized SaaS and cloud destinations. In a single-pass architecture, all traffic is verified, filtered, and inspected without the performance penalties seen with hardware-based firewalls and proxies. Threat intelligence is derived from unique real-time visibility across our global network, including 4.3 trillion DNS queries per day, which powers AI-backed threat hunting models to identify, for example, new / newly seen domains before other vendors. </p><p><a href="https://www.cloudflare.com/learning/access-management/what-is-browser-isolation/"><u>Browser isolation</u></a> capabilities are also natively built-in, enabling organizations to insulate users from threats online and protect data in applications with a seamless user experience. For example, isolating web browsing safeguards users from unknown threats, including zero-days, while isolating apps like AI tools can restrict oversharing of proprietary information.</p><p>Customers can get started with a variety of deployment methods including device agents, network locations, PAC files, or DNS over HTTPS (DoH) endpoints. Regardless of implementation, consistent policy enforcement and comprehensive logging is easily accessible through our dashboard, our SQL-based Log Explorer experience, or third-party tools via LogPush.</p><p>By mid-2026, we plan to ship a number of new filtering and traffic handling capabilities, including:</p><ul><li><p>Deep packet inspection to apply filtering to non-standard ports for protocols like HTTP, SSH, and many others.</p></li><li><p>Filtering using Fully Qualified Domain Names (FQDNs): Admins will no longer need to filter packets or egress connections based on destination IP addresses. They will be able to use the FQDN, application name, or destination category with the egress and network policy builders.</p></li><li><p>Identity + PAC files, providing identity-based filtering without having to install the device client.</p></li></ul>
    <div>
      <h3>Cloud firewall</h3>
      <a href="#cloud-firewall">
        
      </a>
    </div>
    <p>Our comprehensive cloud firewall delivers <a href="https://www.cloudflare.com/learning/cloud/what-is-a-cloud-firewall/">“firewall as a service” protection</a> that helps organizations manage traffic flows globally. All traffic passing through Cloudflare has firewall policies evaluated first, thus providing the first layer of defense, eliminating unnecessary/unwanted traffic before being further evaluated against security policies. The Cloudflare firewall applies configuration changes globally in seconds, thus providing immediate response to emerging needs. With Cloudflare’s network and data center capacity, you get virtually limitless firewall capacity, without the constraints of traditional hardware firewalls, making it a vital component of your Zero Trust and <a href="https://www.cloudflare.com/learning/security/glossary/what-is-defense-in-depth/">defense-in-depth architecture</a>.</p>
    <div>
      <h3>Inline and API-based CASB</h3>
      <a href="#inline-and-api-based-casb">
        
      </a>
    </div>
    <p>SaaS applications relieve IT teams of the burden to host, maintain, and monitor the tools behind their business. However, they also create entirely new headaches for corresponding security teams. Modern organizations need solutions that:</p><ul><li><p>Provide visibility into unauthorized application usage that creates compliance and security risks</p></li><li><p>Enable granular control over data flows within both sanctioned and unsanctioned applications</p></li><li><p>Automate discovery and remediation of security misconfigurations in approved SaaS tools</p></li></ul><p>Any user in an enterprise now needs to connect to an application on the public Internet to do their work, and some users prefer to use their favorite application rather than the ones vetted and approved by the IT department. This kind of Shadow IT infrastructure can lead to <a href="https://www.cloudflare.com/the-net/shadow-it/">surprise fees, compliance violations, and data loss</a>.</p><p>Cloudflare offers comprehensive scanning and filtering to detect when team members are using unapproved tools. With a single click, administrators can block those tools outright or control how those applications can be used. If your marketing team needs to use Google Drive to collaborate with a vendor, you can quickly apply a rule that makes sure they can only download files and never upload. Alternatively, you can allow users to visit an application and read from it while blocking all text input. Cloudflare's Shadow IT policies offer easy-to-deploy controls to help manage how your organization uses the Internet.</p><p>Beyond unsanctioned applications, even approved resources can cause trouble. Your organization might rely on Microsoft OneDrive for day-to-day work, but your compliance policies prohibit your HR department from storing files with employee Social Security numbers in the tool. Cloudflare's <a href="https://www.cloudflare.com/learning/access-management/what-is-a-casb/">Cloud Access Security Broker (CASB) </a>can routinely scan the SaaS applications your team relies on to detect improper usage, missing controls, or potential misconfiguration.</p><p>By mid-2026, we look forward to bringing our customers a slew of new capabilities designed to give teams even better visibility and control over their SaaS and cloud applications, including:</p><ul><li><p><b>Robust remediation capabilities:</b> Resolve detected issues right from the dashboard, both automatically and on-demand with a single click.</p></li><li><p><b>Advanced workflows:</b> Configure automated behavior when new issues are detected, like custom alerting outputs and business justification prompts.</p></li><li><p><b>User and Entity Behavior Analytics (UEBA) &amp; suspicious activity monitoring:</b> Monitor live events across your SaaS apps and detect anomalous/suspicious activity that could indicate compromise.</p></li></ul>
    <div>
      <h3>Data security</h3>
      <a href="#data-security">
        
      </a>
    </div>
    <p>Over the past year, <a href="https://www.cloudflare.com/cio/">CIOs</a> and <a href="https://www.cloudflare.com/ciso/">CISOs</a> have consistently identified data protection as a top concern, particularly regarding artificial intelligence and large language models. As organizations increasingly rely on cloud services and AI tools, they require modern solutions that:</p><ul><li><p>Protect sensitive information across all environments without hampering productivity</p></li><li><p>Provide visibility into how data flows through both internal and external systems</p></li><li><p>Enforce consistent security policies that adapt to evolving regulatory requirements</p></li></ul><p>Cloudflare provides comprehensive visibility and control over data movement and data at rest. This helps organizations avoid the <a href="https://www.cloudflare.com/the-net/pursuing-privacy-first-security/privacy-led-security/">financial impact and reputational consequences of data loss and theft</a>.</p><p>Our data security is an integral component of our SASE platform, providing granular control over how users interact with applications. This approach allows organizations to establish nuanced policies that <a href="https://www.cloudflare.com/learning/cloud/what-is-dspm/">safeguard sensitive information</a> without completely blocking access to productivity-enhancing technologies.</p><p>We are introducing a number of exciting data protection capabilities by mid-2026, including <a href="https://blog.cloudflare.com/improving-data-loss-prevention-accuracy-with-ai-context-analysis/"><u>AI-based DLP detections</u></a>, <a href="https://developers.cloudflare.com/cloudflare-one/policies/data-loss-prevention/dlp-policies/logging-options/#send-http-requests-to-logpush-destination"><u>delivering simple, innovative forensics</u></a>, <a href="https://blog.cloudflare.com/scan-cloud-dlp-with-casb/"><u>classifying sensitive data in the public cloud</u></a>, and <a href="https://blog.cloudflare.com/cloudflare-acquires-kivera/"><u>innovative, preventative cloud security controls</u></a>. These features provide administrators with robust controls while maintaining the seamless performance and user experience that organizations expect from Cloudflare. </p>
    <div>
      <h3>Digital experience monitoring</h3>
      <a href="#digital-experience-monitoring">
        
      </a>
    </div>
    <p>Organizations today struggle with limited visibility into their users' digital experiences. When performance or availability issues arise, internal support teams often lack the tools to determine whether problems originate in the first, middle, or last mile, resulting in multiple support tickets and delayed resolutions.</p><p>Cloudflare addresses this challenge with a comprehensive monitoring toolkit built on the same systems we use to manage our massive global network in-house. This solution empowers IT teams to:</p><ul><li><p>Collect on-demand forensic and diagnostic information</p></li><li><p>Systematically gather telemetry data</p></li><li><p>Analyze patterns to anticipate issues before they impact productivity</p></li></ul><p>Cloudflare provides unmatched insight into Internet outages and performance trends that affect your users. This intelligence allows administrators to refine their deployments and quickly identify whether issues are localized to their environment or part of broader global disruptions.</p><p>By mid-2026, we plan to ship a number of new <a href="https://www.cloudflare.com/learning/performance/what-is-digital-experience-monitoring/">digital experience monitoring capabilities</a>, including:</p><ul><li><p>Real user monitoring (RUM) that measures the performance of every user’s request.</p></li><li><p>Advanced monitoring for communication applications like Zoom and Microsoft Teams.</p></li><li><p>Contextualizing user performance in terms of global Internet performance data.</p></li></ul>
    <div>
      <h3>Built for what’s next</h3>
      <a href="#built-for-whats-next">
        
      </a>
    </div>
    <p>Security Service Edge forms a critical component of modern enterprise protection, but organizations have modernization requirements across their network infrastructure. Cloudflare designed our capabilities with these needs in mind, because we deliver true convergence of both networking and security from our connectivity cloud.</p><p>Across the industry, we’ve seen many instances where vendors start with either networking or security as their primary focus, and acquire a vendor with an entirely different architecture to enter the SASE market. In such scenarios, there is no convergence with security and networking, because internal traffic is handled through different security controls than the cloud traffic. </p><p>Cloudflare delivers networking services using the same global data centers and backbone as our security components. Our composable architecture ensures all of our services are designed to work together, in any order. This means that your security and networking stays consistent and provides a common destination for your SASE journey, no matter where you start. </p><p>We’re proud of the work that we’ve done to solve customer problems. Cloudflare continues to receive industry-wide recognition, earning additional positions in 2024 for our comprehensive suite of security solutions beyond SSE, built for the enterprise.</p><ul><li><p>Cloudflare named in <a href="https://www.cloudflare.com/lp/gartner-magic-quadrant-cloud-application-platforms-2024/"><u>Gartner® Magic Quadrant™ for Cloud Application Platforms</u></a><sup>2</sup></p></li><li><p>Cloudflare named in <a href="https://www.gartner.com/en/documents/6019335">Gartner® Magic Quadrant™ for Email Security Platforms</a><sup>3</sup></p></li><li><p>Cloudflare named in <a href="https://www.cloudflare.com/lp/gartner-magic-quadrant-single-vendor-sase-2024/"><u>Gartner® Magic Quadrant™ for Single-Vendor SASE</u></a><sup>4</sup></p></li></ul><p>We believe this recognition underscores our position as a pioneering security and networking platform built for tomorrow's challenges. When organizations choose Cloudflare, they gain more than just another SSE vendor; they’re establishing a partnership with a holistic platform capable of addressing their broader spectrum of requirements for both public and private resources, both today and in the future.</p>
    <div>
      <h2>How does that impact customers?</h2>
      <a href="#how-does-that-impact-customers">
        
      </a>
    </div>
    <p>Tens of thousands of organizations trust Cloudflare to secure their teams every day.  We talk to customers directly about that feedback, and they have helped us understand <a href="https://blog.cloudflare.com/why-cios-select-cloudflare-one"><u>why CIOs and CISOs choose Cloudflare One</u></a>. For some teams we offer a cost-efficient opportunity to consolidate point solutions. Others appreciate that the ease-of-use means that many practitioners have set up our solution before they even talk to our team. <a href="https://blog.cloudflare.com/spotlight-on-zero-trust"><u>We know that speed matters</u></a> when we are 46% faster than Zscaler, 56% faster than Netskope, and 10% faster than Palo Alto Networks.</p>
    <div>
      <h2>What’s next?</h2>
      <a href="#whats-next">
        
      </a>
    </div>
    <p>We kicked off 2025 with a <a href="https://www.cloudflare.com/security-week/"><u>week focused on new security features</u></a> that teams can begin deploying now. In the year ahead, look forward to announcements for our Secure Web Gateway, data protection capabilities, digital experience monitoring, and our inline and API CASB tools. And stay tuned for exciting innovations with AI-driven analytics and monitoring tools, too.</p><p>Our commitment in 2025 is the same as it was in 2024. We are going to continue to help your teams solve more security problems so that you can focus on your own mission.</p><p>Ready to hold us to that commitment? Cloudflare offers something unique among the players in this space — you can start using nearly every feature in our SSE platform right now at no cost. Teams of up to 50 users can adopt the solution <a href="https://www.cloudflare.com/zero-trust/products/#overview"><u>for free</u></a> to jumpstart a proof of concept. We believe that organizations of any size should be able to quickly and easily start their journey to modernize security.</p><p>Footnotes:</p><p><sup>1 </sup>Gartner, Magic Quadrant for Security Service Edge, Analyst(s): Charlie Winckless, Thomas Lintemuth, Dale Koeppen, Charanpal Bhogal, May 20, 2025</p><p><sup>2 </sup>Gartner, Magic Quadrant for Cloud Application Platforms, Analyst(s): Tigran Egiazarov, Mukul Saha, Anne Thomas, Steve Schwent, November 1, 2024</p><p><sup>3 </sup>Gartner, Magic Quadrant for Email Security Platforms, Analyst(s): Max Taggett, Nikul Patel, Franz Hinner, Deepak Mishra, December 16, 2024</p><p><sup>4 </sup>Gartner, Magic Quadrant for Single-Vendor SASE, Analyst(s): Andrew Lerner, Neil MacDonald, Jonathan Forest, Charlie Winckless, July 3, 2024</p><p>GARTNER is a registered trademark and service mark of Gartner, Inc. and/or its affiliates in the U.S. and internationally, and MAGIC QUADRANT is a registered trademark of Gartner, Inc. and/or its affiliates and are used herein with permission. All rights reserved.</p><p>Gartner does not endorse any vendor, product or service depicted in its research publications, and does not advise technology users to select only those vendors with the highest ratings or other designation. Gartner research publications consist of the opinions of Gartner’s research organization and should not be construed as statements of fact. Gartner disclaims all warranties, expressed or implied, with respect to this research, including any warranties of merchantability or fitness for a particular purpose.</p> ]]></content:encoded>
            <category><![CDATA[Cloudflare One]]></category>
            <category><![CDATA[Zero Trust]]></category>
            <category><![CDATA[SSE]]></category>
            <category><![CDATA[Gartner]]></category>
            <guid isPermaLink="false">3hrGWvhYC2P5tMUc42xvuX</guid>
            <dc:creator>Abe Carryl</dc:creator>
            <dc:creator>Corey Mahan</dc:creator>
        </item>
        <item>
            <title><![CDATA[Cloudflare named in 2024 Gartner® Magic Quadrant™ for Security Service Edge]]></title>
            <link>https://blog.cloudflare.com/cloudflare-sse-gartner-magic-quadrant-2024/</link>
            <pubDate>Thu, 18 Apr 2024 14:58:23 GMT</pubDate>
            <description><![CDATA[ Gartner has once again named Cloudflare to the Gartner® Magic Quadrant™ for Security Service Edge (SSE) report ]]></description>
            <content:encoded><![CDATA[ <p></p>
            <figure>
            
            <img src="https://cf-assets.www.cloudflare.com/zkvhlag99gkb/662cBI3NCcvlyl0OjiQzEv/96500a36f1f589e28d4de5b528feed72/image1-18.png" />
            
            </figure><p>Gartner has once again named Cloudflare to the Gartner® Magic Quadrant™ for Security Service Edge (SSE) report<sup>1</sup>. We are excited to share that Cloudflare is one of only ten vendors recognized in this report. For the second year in a row, we are recognized for our ability to execute and the completeness of our vision. You can read more about our position in the report <a href="https://www.cloudflare.com/lp/gartner-magic-quadrant-sse-2024/">here</a>.</p><p><a href="/cloudflare-sse-gartner-magic-quadrant">Last year</a>, we became the only new vendor named in the 2023 Gartner® Magic Quadrant™ for SSE. We did so in the shortest amount of time as measured by the date since our first product launched. We also <a href="/cloudflare-sse-gartner-magic-quadrant#:~:text=bot%20management.-,What%E2%80%99s%20next%3F,-When%20customers%20choose">made a commitment</a> to our customers at that time that we would only build faster. We are happy to report back on the impact that has had on customers and the Gartner recognition of their feedback.</p><p>Cloudflare can bring capabilities to market quicker, and with greater cost efficiency, than competitors thanks to the investments we have made in our global network over the last 14 years. We believe we were able to become the only new vendor in 2023 by combining existing advantages like our robust, multi-use global proxy, our lightning-fast DNS resolver, our serverless compute platform, and our ability to reliably route and accelerate traffic around the world.</p><p>We believe we advanced further in the SSE market over the last year by building on the strength of that network as larger customers adopted <a href="https://www.cloudflare.com/zero-trust/">Cloudflare One</a>. We took the ability of our Web Application Firewall (WAF) to scan for attacks without compromising speed and applied that to our now comprehensive Data Loss Prevention (DLP) approach. We repurposed the tools that we use to measure our own network and delivered an increasingly mature Digital Experience Monitoring (DEX) suite for administrators. And we extended our Cloud Access Security Broker (CASB) toolset to scan more applications for new types of data.</p><p>We are grateful to the customers who have trusted us on this journey so far, and we are especially proud of our customer reviews in the Gartner® Peer Insights™ panel as those customers report back on their experience with Cloudflare One. The feedback has been so consistently positive that Gartner named Cloudflare a <a href="https://www.gartner.com/reviews/market/zero-trust-network-access/vendor/cloudflare/product/cloudflare-access">Customers’ Choice</a><sup>2</sup> for 2024. We are going to make the same commitment to you today that we made in 2023: Cloudflare will only build faster as we continue to build out the industry’s best SSE platform.</p>
    <div>
      <h2>What is a Security Service Edge?</h2>
      <a href="#what-is-a-security-service-edge">
        
      </a>
    </div>
    <p>A <a href="https://www.cloudflare.com/learning/access-management/security-service-edge-sse/">Security Service Edge (SSE)</a> “secures access to the web, cloud services and private applications. Capabilities include access control, threat protection, data security, security monitoring, and acceptable-use control enforced by network-based and API-based integration. SSE is primarily delivered as a cloud-based service, and may include on-premises or agent-based components.”<sup>3</sup></p><p>The SSE solutions in the market began to take shape as companies dealt with users, devices, and data leaving their security perimeters at scale. In previous generations, teams could keep their organization safe by hiding from the rest of the world behind a figurative castle-and-moat. The firewalls that protected their devices and data sat inside the physical walls of their space. The applications their users needed to reach sat on the same intranet. When users occasionally left the office they dealt with the hassle of backhauling their traffic through a legacy <a href="https://www.cloudflare.com/learning/access-management/what-is-a-vpn/">virtual private network (VPN)</a> client.</p><p>This concept started to fall apart when applications left the building. SaaS applications offered a cheaper, easier alternative to self-hosting your resources. The cost and time savings drove IT departments to migrate and security teams had to play catch up as all of their most sensitive data also migrated.</p><p>At the same time, users began working away from the office more often. The rarely used VPN infrastructure inside an office suddenly struggled to stay afloat with the new demands from more users connecting to more of the Internet.</p><p>As a result, the band-aid boxes in an organization failed — in some cases slowly and in other situations all at once. SSE vendors offer a cloud-based answer. SSE providers operate their own security services from their own data centers or on a public cloud platform. Like the SaaS applications that drove the first wave of migration, these SSE services are maintained by the vendor and scale in a way that offers budget savings. The end user experience improves by avoiding the backhaul and security administrators can more easily build smarter, safer policies to defend their team.</p><p>The SSE space covers a broad category. If you ask five security teams what an SSE or <a href="https://www.cloudflare.com/learning/security/glossary/what-is-zero-trust/">Zero Trust</a> solution is, you’ll probably get six answers. In general, SSE provides a helpful framing that gives teams guard rails as they try to adopt a Zero Trust architecture. The concept breaks down into a few typical buckets:</p><ul><li><p><b>Zero Trust Access Control</b>: protect applications that hold sensitive data by creating least-privilege rules that check for identity and other contextual signals on each and every request or connection.</p></li><li><p><b>Outbound Filtering</b>: keep users and devices safe as they connect to the rest of the Internet by filtering and logging DNS queries, HTTP requests, or even network-level traffic.</p></li><li><p><b>Secure SaaS Usage</b>: analyze traffic to SaaS applications and scan the data sitting inside of SaaS applications for potential Shadow IT policy violations, misconfigurations, or data mishandling.</p></li><li><p><b>Data Protection</b>: scan for data leaving your organization or for destinations that do not comply with your organization’s policies. Find data stored inside your organization, even in trusted tools, that should not be retained or needs tighter access controls.</p></li><li><p><b>Employee Experience</b>: monitor and improve the experience that your team members have when using tools and applications on the Internet or hosted inside your own organization.</p></li></ul><p>The SSE space is a component of the larger <a href="https://www.cloudflare.com/learning/access-management/what-is-sase/">Secure Access Service Edge (SASE)</a> market. You can think of the SSE capabilities as the security half of SASE while the other half consists of the networking technologies that connect users, offices, applications, and data centers. Some vendors only focus on the SSE side and rely on partners to connect customers to their security solutions. Other companies just provide the networking pieces. While today’s announcement highlights our SSE capabilities, Cloudflare offers both components as a comprehensive, <a href="/single-vendor-sase-announcement-2024">single-vendor SASE</a> provider.</p>
    <div>
      <h2>How does Cloudflare One fit into the SSE space?</h2>
      <a href="#how-does-cloudflare-one-fit-into-the-sse-space">
        
      </a>
    </div>
    <p>Customers can rely on Cloudflare to solve the entire range of security problems represented by the SSE category. They also can just start with a single component. We know that an entire “digital transformation” can be an overwhelming prospect for any organization. While all the use cases below work better together, we make it simple for teams to start by just solving one problem at a time.</p>
    <div>
      <h3>Zero Trust access control</h3>
      <a href="#zero-trust-access-control">
        
      </a>
    </div>
    <p>Most organizations begin that problem-solving journey by attacking their virtual private network (VPN). In many cases, a legacy VPN operates in a model where anyone on that private network is trusted by default to access anything else. The applications and data sitting on that network become vulnerable to any user who can connect. Augmenting or replacing legacy VPNs is one of the leading Zero Trust use cases we see customers adopting, in part to eliminate pains related to the ongoing series of high-impact VPN <a href="https://www.cisa.gov/news-events/alerts/2024/04/12/palo-alto-networks-releases-guidance-vulnerability-pan-os-cve-2024-3400">vulnerabilities</a> in on-premises firewalls and gateways.</p><p>Cloudflare provides teams with the ability to build Zero Trust rules that replace the security model of a traditional VPN with one that evaluates every request and connection for trust signals like identity, device posture, location, and multifactor authentication method. Through <a href="https://www.cloudflare.com/learning/access-management/what-is-ztna/">Zero Trust Network Access (ZTNA)</a>, administrators can make applications available to employees and third-party contractors through a fully clientless option that makes traditional tools feel just like SaaS applications. Teams that need more of a private network can still build one on Cloudflare that supports arbitrary TCP, UDP, and ICMP traffic, including <a href="/introducing-warp-connector-paving-the-path-to-any-to-any-connectivity-2">bidirectional traffic</a>, while still enforcing Zero Trust rules.</p><p>Cloudflare One can also apply these rules to the applications that sit outside your infrastructure. You can deploy Cloudflare’s identity proxy to enforce consistent and granular policies that determine how team members log into their SaaS applications, as well.</p>
    <div>
      <h3>DNS filtering and Secure Web Gateway capabilities</h3>
      <a href="#dns-filtering-and-secure-web-gateway-capabilities">
        
      </a>
    </div>
    <p>Cloudflare operates the world’s fastest DNS resolver, helping users connect safely to the Internet whether they are working from a coffee shop or operating inside some of the <a href="/helping-keep-governments-safe-and-secure/">world’s largest networks</a>.</p><p>Beyond just <a href="https://www.cloudflare.com/learning/access-management/what-is-dns-filtering/">DNS filtering</a>, Cloudflare also provides organizations with a comprehensive <a href="https://www.cloudflare.com/learning/access-management/what-is-a-secure-web-gateway/">Secure Web Gateway (SWG)</a> that inspects the HTTP traffic leaving a device or entire network. Cloudflare filters each request for dangerous destinations or potentially malicious downloads. Besides SSE use cases, Cloudflare operates one of the largest forward proxies in the world for Internet privacy used by Apple iCloud Private Relay, Microsoft Edge Secure Network, and beyond.</p><p>You can also mix-and-match how you want to send traffic to Cloudflare. Your team can decide to send all traffic from every mobile device or just plug in your office or data center network to Cloudflare’s network. Each request or DNS query is logged and made available for review in our dashboard or can be exported to a 3rd party logging solution.</p>
    <div>
      <h3>In-line and at-rest CASB</h3>
      <a href="#in-line-and-at-rest-casb">
        
      </a>
    </div>
    <p>SaaS applications relieve IT teams of the burden to host, maintain, and monitor the tools behind their business. They also create entirely new headaches for corresponding security teams.</p><p>Any user in an enterprise now needs to connect to an application on the public Internet to do their work, and some users prefer to use their favorite application rather than the ones vetted and approved by the IT department. This kind of <a href="https://www.cloudflare.com/learning/access-management/what-is-shadow-it/">Shadow IT</a> infrastructure can lead to surprise fees, compliance violations, and data loss.</p><p>Cloudflare offers comprehensive scanning and filtering to detect when team members are using unapproved tools. With a single click, administrators can block those tools outright or control how those applications can be used. If your marketing team needs to use Google Drive to collaborate with a vendor, you can apply a quick rule that makes sure they can only download files and never upload. Alternatively, allow users to visit an application and read from it while blocking all text input. Cloudflare’s Shadow IT policies offer easy-to-deploy controls over how your organization uses the Internet.</p><p>Beyond unsanctioned applications, even approved resources can cause trouble. Your organization might rely on Microsoft OneDrive for day-to-day work, but your compliance policies prohibit your HR department from storing files with employee Social Security numbers in the tool. Cloudflare’s <a href="https://www.cloudflare.com/learning/access-management/what-is-a-casb/">Cloud Access Security Broker (CASB)</a> can routinely scan the SaaS applications your team relies on to detect improper usage, missing controls, or potential misconfiguration.</p>
    <div>
      <h3>Digital Experience Monitoring</h3>
      <a href="#digital-experience-monitoring">
        
      </a>
    </div>
    <p>Enterprise users have consumer expectations about how they connect to the Internet. When they encounter delays or latency, they turn to IT help desks to complain. Those complaints only get louder when help desks lack the proper tools to granularly understand or solve the issues.</p><p>Cloudflare One provides teams with a <a href="https://www.cloudflare.com/learning/performance/what-is-digital-experience-monitoring/">Digital Experience Monitoring</a> toolkit that we built based on the tools we have used for years inside of Cloudflare to monitor our own global network. Administrators can measure global, regional, or individual latency to applications on the Internet. IT teams can open our dashboard to troubleshoot connectivity issues with single users. The same capabilities we use to <a href="https://w3techs.com/technologies/overview/proxy">proxy approximately 20% of the web</a> are now available to teams of any size, so they can help their users.</p>
    <div>
      <h3>Data security</h3>
      <a href="#data-security">
        
      </a>
    </div>
    <p>The most pressing concern we have heard from CIOs and CISOs over the last year is the fear around data protection. Whether data loss is malicious or accidental, the consequences can erode customer trust and create penalties for the business.</p><p>We also hear that deploying any sort of effective data security is just plain hard. Customers tell us anecdotes about expensive point solutions they purchased with the intention to implement them quickly and keep data safe, that ultimately just didn’t work or slowed down their teams to the point that they became shelfware.</p><p>We have spent the last year aggressively improving our solution to that problem as the single largest focus area of investment in the Cloudflare One team. Our data security portfolio, including <a href="https://www.cloudflare.com/learning/access-management/what-is-dlp/">data loss prevention (DLP)</a>, can now scan for data leaving your organization, as well as data stored inside your SaaS applications, and prevent loss based on exact data matches that you provide or through fuzzier patterns. Teams can apply optical character recognition (OCR) to find potential loss in images, scan for public cloud keys in a single click, and software companies can rely on predefined ML-based source code detections.</p><p><a href="https://www.cloudflare.com/learning/cloud/what-is-dspm/">Data security</a> will continue to be our largest area of focus in Cloudflare One over the next year. We are excited to continue to deliver an SSE platform that gives administrators comprehensive control without interrupting or slowing down their users.</p>
    <div>
      <h3>Beyond the SSE</h3>
      <a href="#beyond-the-sse">
        
      </a>
    </div>
    <p>The scope of an SSE solution captures a wide range of the security problems that plague enterprises. We also know that issues beyond that definition can compromise a team. In addition to offering an industry-leading SSE platform, Cloudflare gives your team a <a href="https://www.cloudflare.com/cybersecurity/">full range of cybersecurity tools</a> to protect your organization, to connect your team, and to secure all of your applications.</p><p>IT compromise tends to start with email. The majority of attacks begin with some kind of multi-channel <a href="https://www.cloudflare.com/learning/access-management/phishing-attack/">phishing</a> campaign or social engineering attack sent to the largest hole in any organization’s perimeter: their employees’ email inboxes. We believe that you should be protected from that too, even before the layers of our SSE platform kick in to catch malicious links or files from those emails, so Cloudflare One also features best-in-class cloud <a href="https://www.cloudflare.com/learning/email-security/what-is-email-security/">email security</a>. The capabilities just work with the rest of Cloudflare One to help stop all phishing channels — inbox (cloud email security), social media (SWG), SMS (ZTNA <a href="/2022-07-sms-phishing-attacks/">together with hard keys</a>), and cloud collaboration (CASB). For example, you can allow team members to still click on potentially malicious links in an email while forcing those destinations to load in an isolated browser that is transparent to the user.</p><p>Most SSE solutions stop there, though, and only solve the security challenge. Team members, devices, offices, and data centers still need to connect in a way that is performant and highly available. Other SSE vendors partner with networking providers to solve that challenge while adding extra hops and latency. Cloudflare customers don’t have to compromise. Cloudflare One offers a complete <a href="/magic-wan-connector-general-availability">WAN connectivity solution</a> delivered in the same data centers as our security components. Organizations can rely on a single vendor to solve how they connect and how they do so securely. No extra hops or invoices needed.</p><p>We also know that security problems do not distinguish between what happens inside your enterprise and the applications you make available to the rest of the world. You can secure and accelerate the applications that you build to serve your own customers through Cloudflare, as well. Analysts have also <a href="https://www.cloudflare.com/analysts/">recognized</a> Cloudflare’s <a href="https://www.cloudflare.com/application-services/products/">Web Application and API Protection (WAAP) platform</a>, which protects some of the world’s largest Internet destinations.</p>
    <div>
      <h2>How does that impact customers?</h2>
      <a href="#how-does-that-impact-customers">
        
      </a>
    </div>
    <p>Tens of thousands of organizations trust Cloudflare One to secure their teams every day. And they love it. Over 200 enterprises have reviewed Cloudflare’s Zero Trust platform as part of Gartner® Peer Insights™. As mentioned previously, the feedback has been so consistently positive that Gartner named Cloudflare a <a href="https://www.gartner.com/reviews/market/zero-trust-network-access/vendor/cloudflare/product/cloudflare-access">Customers’ Choice</a> for 2024.</p><p>We talk to customers directly about that feedback, and they have helped us understand <a href="/why-cios-select-cloudflare-one">why CIOs and CISOs choose Cloudflare One</a>. For some teams, we offer a cost-efficient opportunity to consolidate point solutions. Others appreciate that our ease-of-use means that many practitioners have set up our platform before they even talk to our team. <a href="/spotlight-on-zero-trust">We also hear that speed matters</a> to ensure a slick end user experience when we are 46% faster than Zscaler, 56% faster than Netskope, and 10% faster than Palo Alto Networks.</p>
    <div>
      <h2>What’s next?</h2>
      <a href="#whats-next">
        
      </a>
    </div>
    <p>We kicked off 2024 with a <a href="https://www.cloudflare.com/security-week/">week focused on new security features</a> that teams can begin deploying now. Looking ahead to the rest of the year, you can expect additional investment as we add depth to our Secure Web Gateway product. We also have work underway to make our industry-leading access control features even easier to use. Our largest focus areas will include our data protection platform, digital experience monitoring, and our in-line and at-rest CASB tools. And stay tuned for an overhaul to how we surface analytics and help teams meet compliance needs, too.</p><p>Our commitment to our customers in 2024 is the same as it was in 2023. We are going to continue to help your teams solve more security problems so that you can focus on your own mission.</p><p>Ready to hold us to that commitment? Cloudflare offers something unique among the leaders in this space — you can start using nearly every feature in Cloudflare One right now at no cost. Teams of up to 50 users can <a href="https://www.cloudflare.com/zero-trust/products/">adopt our Zero Trustplatform for free</a>, whether for their small team or as part of a larger enterprise proof of concept. We believe that organizations of any size should be able to start their journey to deploy industry-leading security.</p><p>***</p><p><sup>1</sup>Gartner, Magic Quadrant for Security Service Edge, By Charlie Winckless, Thomas Lintemuth, Dale Koeppen, April 15, 2024</p><p><sup>2</sup>Gartner, Voice of the Customer for Zero Trust Network Access, By Peer Contributors, 30 January 2024</p><p><sup>3</sup><a href="https://www.gartner.com/en/information-technology/glossary/security-service-edge-sse">https://www.gartner.com/en/information-technology/glossary/security-service-edge-sse</a></p><p>GARTNER is a registered trademark and service mark of Gartner, Inc. and/or its affiliates in the U.S. and internationally, MAGIC QUADRANT and PEER INSIGHTS are registered trademarks and The GARTNER PEER INSIGHTS CUSTOMERS’ CHOICE badge is a trademark and service mark of Gartner, Inc. and/or its affiliates and is used herein with permission. All rights reserved.</p><p>Gartner® Peer Insights content consists of the opinions of individual end users based on their own experiences, and should not be construed as statements of fact, nor do they represent the views of Gartner or its a iliates. Gartner does not endorse any vendor, product or service depicted in this content nor makes any warranties, expressed or implied, with respect to this content, about its accuracy or completeness, including any warranties of merchantability or fitness for a particular purpose.</p><p>Gartner does not endorse any vendor, product or service depicted in its research publications and does not advise technology users to select only those vendors with the highest ratings or other designation. Gartner research publications consist of the opinions of Gartner’s research organization and should not be construed as statements of fact. Gartner disclaims all warranties, expressed or implied, with respect to this research, including any warranties of merchantability or fitness for a particular purpose.</p> ]]></content:encoded>
            <category><![CDATA[Cloudflare One]]></category>
            <category><![CDATA[Zero Trust]]></category>
            <category><![CDATA[Security Service Edge]]></category>
            <category><![CDATA[SSE]]></category>
            <category><![CDATA[Gartner]]></category>
            <category><![CDATA[Connectivity Cloud]]></category>
            <guid isPermaLink="false">74GVTMXQHRWPaBWcm9NRgX</guid>
            <dc:creator>Sam Rhea</dc:creator>
        </item>
    </channel>
</rss>