Securing a distributed workforce and its applications — from one global network.
Press Space to advance · ← back · S for presenter notes · F full-screen · Esc overview
Why now
Your perimeter dissolved.
Users, applications, and data used to sit inside one building. Now they're everywhere at once.
16regions you operate in
Everywhereyour people work from
Employees work from home, branch offices, and the road
Apps live in SaaS, public cloud, and your own data centres
Contractors and BYOD need access without a laptop rebuild
Every one of those connections is a door to secure
The problem with the old way
Backhauling traffic doesn't scale.
◈ Castle-and-moat
VPN hairpins remote users back to HQ
Stacks of appliances at each site
Once inside the VPN, users see everything
Slow for users, expensive to run, hard to scale to 16 regions
→
◆ Secure at the edge
Users connect to the nearest edge location
Security runs in the cloud, not in boxes
Access is per-application, never "the whole network"
Fast for users, one policy everywhere
The definition
SASE = Networking + Security, delivered from the cloud.
Secure Access Service Edge. Instead of buying network and security products separately and wiring them together, you get them as one cloud service that sits between your users and everything they connect to.
Think of it as a smart, secure on-ramp to the internet and your apps — the same on every continent.
How it fits together — Cloudflare One
Every user and device, connected safely to every resource — through one network.
Traffic never goes straight to a resource. It flows through Cloudflare first — where identity, threats, and data are all checked. Press Space to walk through each service.
How it works — the journey of one request
Connect once. Verified every time.
01
Connect
The user's device or browser reaches the nearest Cloudflare location — one of 337+ cities.
02
Verify
Identity and device health are checked. Access decides — per app — whether to allow it.
03
Inspect
Gateway, DLP, and CASB filter threats and protect data in the same pass.
04
Deliver
Only clean, authorised traffic reaches the app, SaaS, or site — fast.
No hairpin, no appliance stack. The decision happens next to the user, then the request goes straight to its destination.
Start here — the VPN replacement
Zero Trust access to internal apps.
Per-app, not per-network — users reach only the apps they're entitled to
Identity + device posture checked on every request
Clientless option for contractors and BYOD — just a browser
Inspect once — the same policy for every user in every region
Gateway is the outbound counterpart to Access. Access controls who gets in; Gateway controls where users can go out.
Because email is how attacks start
Cloudflare Email Security (CES).
Phishing & business email compromise — catches what native filters miss
Layers on top of Microsoft 365 & Google — you don't rip anything out
Flexible deployment — inline (MX) or API/journaling with no mail-flow change
Feeds the same platform — links can open in Browser Isolation, findings enrich Zero Trust
#1Email is the top initial attack vector
A great, low-risk first project: it sits beside your existing mail, so you see value before changing anything.
Why Cloudflare
Every service. Every location. One dashboard.
337+cities worldwide
500 Tbpsnetwork capacity
~230Bthreats blocked / day
Because every Cloudflare location runs every service, there are no regional gaps and no appliances to deploy. Your team in any of 16 regions gets the same protection at local speed.
A sensible first step
Crawl, walk, run.
1 · Crawl
ZTNA / Access on a few internal apps. Immediate VPN relief, fast to prove. And CES beside your mail — value with no mail-flow change.
2 · Walk
Gateway for DNS/web filtering and WARP on managed devices. Now outbound traffic is covered too.
3 · Run
CASB, DLP, Browser Isolation for full data protection across SaaS and the web. The complete SASE picture.
You don't buy SASE in one go. Each step stands on its own and builds on the last — same platform, same dashboard.