Cloudflare Makes Zero Trust Security Free for At-Risk Groups like Non-Profits, Public Interest Groups, and Election Sites

Cloudflare is democratizing access to Zero Trust security, a new security standard that is often out of reach for smaller organizations

San Francisco, CA, December 12, 2022Cloudflare, Inc. (NYSE: NET), the security, performance, and reliability company helping to build a better Internet, today announced that the Cloudflare One suite of Zero Trust security tools is available at no cost to at-risk public interest groups that are part of Cloudflare’s Project Galileo, as well as local and state election sites part of Cloudflare’s Athenian Project. These organizations will now have access to the comprehensive and deeply-integrated Zero Trust tools that have typically only been available to large enterprises and are used by over 10,000 customers today.

“Cloudflare is the only security provider ensuring that Zero Trust is accessible to those most in need – the vulnerable groups in our society, journalists, and nonprofits, as well as the sites that ensure we have trusted, free, and fair elections in the United States,” said Matthew Prince, co-founder and CEO, Cloudflare. “These organizations face constant threats and need to be safe online to achieve their missions – and now they'll have access to the same security architecture that Fortune 500 companies are using.”

Zero Trust is a modern security model that ensures all traffic in and out of a business is verified and authorized, and requires strict identity verification for every person and device. This replaces the old model where once a device or person was in a network, it was assumed to be trusted and had access to anything within that network. The problem with that approach is that once an attacker gains access to the network, they have free rein over everything inside.

Zero Trust has become standard for large enterprises, but so far has left out smaller organizations due to smaller IT teams, limited budgets, and lack of resources. “Since COVID, small and midsize businesses (SMBs) are more digitally exposed but have not been able to keep up with the right security posture and are increasingly being targeted for cybersecurity attacks”, according to Gartner®.

Equal Access to Zero Trust Cloudflare is extending the Zero Trust suite to two of its Impact Initiatives that support the security needs of public interest groups. Project Galileo participants are artists, journalists, humanitarian organizations, and the voices of political dissent that are consistently under attack because of their missions as vulnerable groups. Athenian Project participants are local and state election sites working to safeguard elections in the United States. These organizations lack the budget and security expertise needed to thwart sophisticated attacks. Advanced security architecture was previously out of reach, but necessary to protect their employees and members, and further their missions. Now with Cloudflare One, these at-risk groups can:

  • Automatically protect organizations from phishing attacks: Email is one of the largest cyber attack vectors on the Internet. Cloudflare Area 1 Security ensures malicious emails are blocked before making it to employees’ inboxes. If a malicious link arrives through other channels and is clicked, Cloudflare’s Browser Isolation and DNS filtering stops the query before the malicious destination can load.
  • Connect all employees, applications, partners, and volunteers: Employees can work in any location and still reach internal tools, while controlling exactly who can access which application or service. Administrators can control which partners and volunteers can reach specific applications and resources while logging every attempt.
  • Secure a path to the Internet: Whether connecting to a Wi-Fi network on the go or downloading a file from an unfamiliar source, Cloudflare One provides an encrypted, secured on-ramp to the entire Internet and keeps sensitive data from leaving the organization. Cloudflare One will block an attempt to connect to a malicious destination, scan downloads for malware, and block the download before the user can open it. Administrators can create policies that prevent the accidental or malicious loss of data while also restricting uploads to approved destinations.

At-Risk Groups Getting Started with Cloudflare One CyberPeace Institute is an independent and neutral nongovernmental organization, headquartered in Switzerland, whose mission is to ensure the rights of people to security, dignity and equity in cyberspace. The Institute works in close collaboration with relevant partners to reduce the harms from cyberattacks on people’s lives worldwide.

  • “The CyberPeace Institute works with humanitarian non-governmental organizations (NGOs) to protect their operations and build their cyber capabilities, data and resources in an increasingly complex digital environment. Both the Institute and Cloudflare share a core motivation to ensure the rights of people to security, dignity, and equity in cyberspace. This alignment gives us confidence that Cloudflare is the right strategic partner as we evolve with our mission. We are grateful for the support of Project Galileo,” said Stéphane Duguin, Chief Executive Officer, CyberPeace Institute.

The Information Technology Disaster Resource Center (ITDRC) is a nonprofit composed of thousands of service oriented technical professionals and private sector partners that assist in disaster response operations in the United States.

  • “Cloudflare Zero Trust is essential to securing our employees, volunteers, and disaster survivors on site and in the field. Cloudflare delivers secure, reliable, and fast connectivity to the Internet and critical applications that our teams need to respond to disasters effectively,” said Chris Hillis, Co-founder at ITDRC.
  • “Setting up policies has been simple for our administrators, and our team benefits from a safer, faster experience, whether accessing internally hosted applications, or the broader Internet. With Cloudflare Access, we are able to ensure that team members receive a consistent user experience accessing internal applications based on their role, all while utilizing our existing identity provider and securing our infrastructure. Utilizing Cloudflare Gateway adds an additional layer of security to our networks and devices, helping to protect our users from external threats, and themselves.”

Meedan is a global technology not-for-profit that builds software and programmatic initiatives to strengthen journalism, digital literacy, and accessibility of information online and off.

  • “Meedan and Cloudflare both share a vision of a more equitable, safer Internet. We were proud to be a founding member of Project Galileo in 2014 and support the work that program has done to protect Human Rights Defenders around the world. Closer to home Cloudflare helps our employees be more secure and productive when creating and distributing our open source software,” said Aaron Huslage, Director of Systems and Security at Meedan.

The Organization of American States (OAS) is the world’s oldest regional organization and a home for multilateral dialogue on topics such as the rights of indigenous peoples, territorial disputes, and regional goals for education.

  • "The partnership with Cloudflare will help the Organization of American States (OAS) democratize best-in-class security to modernize and strengthen our internal cybersecurity posture with a Zero Trust approach, delivered in the cloud, without sacrificing our workforce performance," said Andrew Vanjani, OAS Chief Information Officer.

Rowan County, North Carolina protects election websites with Cloudflare.

  • “Prior to Area 1 Security, we were using Office 365 email protection with limited insight for the specifics for messages that were quarantined. While cloud services from Microsoft are continually evolving, we were looking to reduce complexity to support security functions within our environment, allowing us to continue implementing new layers of defense,” said Randy Cress, Chief Information Officer at Rowan County.
  • “Leading up to the elections, reports within our Area 1 dashboard indicated 2x as many inbound malicious emails from the same time period in October 2022. We saw credential harvesting as the top threat and we are easily able to see which users are targeted for email compromise.”
  • “With Area 1 Security under the Athenian Project, we were able to add additional layers of security to our organization, as it allowed us to preemptively defend against malicious messages before an employee can click on a malicious link. This gives us comfort knowing that Cloudflare is our first line of defense so we can focus on providing a secure voting process for the constituents of Rowan County.”

To learn more, please check out the resources below:

Source: Gartner, Inc., Emerging Tech: The Impact of Emerging Trends on Security Solution Demand, Rustam Malik, 7 Oct 2022. GARTNER is a registered trademark and service mark of Gartner, Inc. and/or its affiliates in the U.S. and internationally and is used herein with permission. All rights reserved.

About Cloudflare Cloudflare, Inc. (www.cloudflare.com / @cloudflare) is on a mission to help build a better Internet. Cloudflare’s suite of products protect and accelerate any Internet application online without adding hardware, installing software, or changing a line of code. Internet properties powered by Cloudflare have all web traffic routed through its intelligent global network, which gets smarter with every request. As a result, they see significant improvement in performance and a decrease in spam and other attacks. Cloudflare was named to Entrepreneur Magazine’s Top Company Cultures 2018 list and ranked among the World’s Most Innovative Companies by Fast Company in 2019.

Forward-Looking Statements This press release contains forward-looking statements within the meaning of Section 27A of the Securities Act of 1933, as amended, and Section 21E of the Securities Exchange Act of 1934, as amended, which statements involve substantial risks and uncertainties. In some cases, you can identify forward-looking statements because they contain words such as “may,” “will,” “should,” “expect,” “explore,” “plan,” “anticipate,” “could,” “intend,” “target,” “project,” “contemplate,” “believe,” “estimate,” “predict,” “potential,” or “continue,” or the negative of these words, or other similar terms or expressions that concern Cloudflare’s expectations, strategy, plans, or intentions. However, not all forward-looking statements contain these identifying words. Forward-looking statements expressed or implied in this press release include, but are not limited to, statements regarding the potential benefits to Project Galileo and Athenian Project participants from Cloudflare’s Zero Trust, application security, and other products and technology, the capabilities and effectiveness of Cloudflare’s Zero Trust, application security, and other products and technology, the expected functionality and performance of Cloudflare’s Zero Trust, application security, and other products and technology, the timing of when any new features for Cloudflare’s Zero Trust, application security, and other products and technology will be generally available to all current and potential Cloudflare customers, Cloudflare’s technological development, future operations, growth, initiatives, or strategies, and comments made by Cloudflare’s CEO and others. Cloudflare’s actual results could differ materially from those stated or implied in forward-looking statements due to a number of factors, including but not limited to, risks detailed in its filings with the Securities and Exchange Commission (SEC), including Cloudflare’s Quarterly Report on Form 10-Q filed on November 3, 2022, as well as other filings that we may make from time to time with the SEC.

The forward-looking statements made in this press release relate only to events as of the date on which the statements are made. We undertake no obligation to update any forward-looking statements made in this press release to reflect events or circumstances after the date of this press release or to reflect new information or the occurrence of unanticipated events, except as required by law. We may not actually achieve the plans, intentions, or expectations disclosed in Cloudflare’s forward-looking statements, and you should not place undue reliance on Cloudflare’s forward-looking statements.

© 2022 Cloudflare, Inc. All rights reserved. Cloudflare, the Cloudflare logo, and other Cloudflare marks are trademarks and/or registered trademarks of Cloudflare, Inc. in the U.S. and other jurisdictions. All other marks and names referenced herein may be trademarks of their respective owners.

Press Contact Information
Daniella Vallurupalli
+1 650-741-3104