How Cloudflare uses Cloudflare Area 1 Email Security

Area 1 works through Cloudflare’s Zero Trust network to block phishing attacks for exceptionally secure email delivery

Cloudflare is building the world’s most powerful cloud network. The goal: help make the Internet safer, faster, more reliable, and more private. This includes helping customers around the world adopt Zero Trust, a security framework that requires all users to be authenticated, authorized, and continuously validated to ensure only legitimate traffic reaches an organization’s applications and data.

Amidst this broad focus on Zero Trust comes an interest in phishing prevention specifically. It’s estimated that phishing accounts for around 90% of data breaches. Despite ongoing training and constant warnings from security teams, it is inevitable that a certain number of employees might take the bait, which can lead to massive financial damage and data loss.

Cloudflare wanted to shield its employees from phishing attacks by augmenting its Zero Trust approach with strong phishing protection.

Challenge: Implementing a proactive approach to phishing

In recent years, the number of Cloudflare employees working remotely has grown substantially. That growth has driven an increase in email usage — and an uptick in employee-reported phishing attempts. Although the company’s email provider offered strong spam filtering, it didn’t adequately block malicious threats and other advanced attacks.

Due to the increasing number of incidents, the security team was spending an excessive amount of time investigating and managing suspicious messages. “We were constantly trying to find new ways to detect fraudulent messages and quarantine them,” explains Daniel Stinson-Diess, Security Engineer, Detection and Response at Cloudflare. “It was a manual effort that might take 15 to 30 minutes for a simple attack. But more sophisticated attacks triggered an involved process that took far longer.”

The team began searching for a solution that would protect incoming email at the application and content level. After an in-depth evaluation, the team selected Area 1 Security because of its ability to preemptively discover and eliminate phishing attacks before they inflict damage in a corporate environment.

"We didn't want our team spending time or being exposed to suspicious emails. But we also had to avoid blocking messages that employees need to do their jobs. We bought Area 1 because it lets us do both. Good messages get through and people don’t have to sift through as much junk or risk clicking a dangerous link,” said John Graham-Cumming, CTO at Cloudflare.

Area 1 Security delivers results

By deploying Area 1 Security with Google Workspace, Cloudflare was able to achieve comprehensive cloud email security to better protect the company’s hybrid workforce. Within 30 days, 90,000 total detections were blocked. In addition, the low false-positive rate, feedback loops, and detection accuracy ensure that legitimate messages still make their way to employees.

Of particular benefit is visibility into the email surface risk. The security team now has rich insights into the most-attacked employees, look alike and cousin domains, and more.

Delivering the most complete Zero Trust security platform available

In 2021, Cloudflare launched its Advanced Email Security Suite along with tools to tackle email spoofing and phishing and improve the deliverability of millions of emails. Cloudflare recognized that more robust email protection was an important element of ensuring a secure and efficient overall work environment through Zero Trust.

Cloudflare Area 1’s scalable, preemptive, cloud-native email security technology fits perfectly into Cloudflare’s strategy. Area 1 technologies use globally distributed sensors, massive scale web-crawling, and comprehensive pre-attack analytics to identify phishing campaigns, attacker infrastructure, and attack delivery mechanisms during the earliest stages of a phishing attack cycle.

Area 1 augments Cloudflare’s Advanced Email Security Suite to provide the full email protection Cloudflare required. The combination worked so well that Cloudflare acquired Area 1 in early 2022, permitting even closer collaboration between the two strategically aligned organizations.

“Cloudflare’s Zero Trust vision is an integrated, one-click approach to securing all of an organization’s applications. Exceptional email security is critical to getting from vision to reality,” said Matthew Prince, Cloudflare Co-Founder and CEO. “The Cloudflare and Area 1 combination allows us to deliver the fastest, most effective, and most reliable email security on the market.”

How Cloudflare uses Cloudflare Area 1 Email Security
Related Case Studies
Related Products
Key Results
  • Cloudflare Area 1 Email Security deployed with Google Workspace provides comprehensive cloud email security

  • More than 160,000 malicious emails blocked within 90 days

  • Higher productivity through reduction in fraudulent messages in employee inboxes

Cloudflare’s Zero Trust vision is an integrated, one-click approach to securing all of an organization’s applications. Exceptional email security is critical to getting from vision to reality. The Cloudflare and Area 1 combination allows us to deliver the fastest, most effective, and most reliable email security on the market.

Matthew Prince
Co-founder and CEO

We didn't want our team spending time or being exposed to suspicious emails. But we also had to avoid blocking messages that employees need to do their jobs. We bought Area 1 because it lets us do both.

John Graham-Cumming
CTO