SSE Brief - Cloudflare One 2023 v2

Download as pdf or txt
Download as pdf or txt
You are on page 1of 2

SOLUTION BRIEF

Security Service Edge (SSE)


Planning for security service consolidation
while adopting at your own pace

Cloud-centric convergence
The complexity of maintaining multiple point solutions is driving most
organizations to consolidate their preferred vendors. Today, “Consolidate vendors, and cut
“best-of-breed” capabilities and broad platforms don’t have to be complexity and costs as
mutually exclusive. As the majority of IT buyers lean toward contracts renew for SWGs,
consolidation, security vendors are meeting the moment by amplifying CASBs and VPNs (replacing
the value of their security platforms beyond what each service could with a ZTNA approach).
accomplish individually. Leverage a converged market
The SSE approach — which straddles point products and full that emerges by combining
consolidation — focuses more deeply on security capabilities than most these services.” 1
Secure Access Service Edge (SASE) offerings, as it is not tied to
network infrastructure. In our opinion, our Zero Trust platform matches
Gartner’s SSE and converges formerly-distinct point products: ZTNA,
VPN, SWG, DNS Filtering, CASB, RBI, and Firewall as a Service (FWaaS).

Secure access
simplify and secure access
between any user and app,
Internet Apps on any device, in any location
Secure Internet
access gateway
Threat defense
keep your users and data
safe from web, email, and
SaaS app Browser multi-channel threats
security isolation

Self-Hosted Apps
Secure with Microsoft
Any User visibility and control of
Cloud email Data loss all SaaS suites across
security prevention Microsoft, Google, and more

Secure hybrid work


Digital experience
monitoring
improve team productivity,
reduce cyber risk, and
SaaS Apps increase tech efficiency

SSE as a bridge to SASE


Single-vendor SASE Multi-vendor SASE
While converging security and network edge For businesses aiming to fully For those with mature SD-WAN
services is the ultimate goal of SASE, some unify security and network edge deployments or disjointed security
companies may never look to fully services from a single vendor, and network teams, Cloudflare
consolidate to a single vendor, based on Cloudflare One, our SASE Zero Trust can help modernize
their history and current infrastructure. platform, provides Zero Trust security and achieve an SSE
Regardless of your long-term SASE strategy, network-as-a-service built on our implementation, leveraging
Cloudflare can help you modernize security, 300+ city global network. SD-WAN partnerships for
transform your corporate network, or both. multi-vendor SASE.

1 888 99 FLARE | [email protected] | www.cloudflare.com REV:PMM-JULY2023


Cloudflare | Security Service Edge (SSE)

Composable SSE adoption


The move to cloud-based SSE is not intended to be an
overnight switch; Cloudflare Zero Trust helps organizations “Inventory equipment and contracts to
phase out hardware at their desired pace. Many businesses will implement a multiyear phase out of
start their Zero Trust journey by augmenting their VPN with on-premises perimeter and branch
ZTNA, on a path to full replacement. Streamlining SaaS security security hardware in favor of
is a close second priority for most, with broader threat and cloud-based delivery of SSE. Target
data protection strategies following soon thereafter. consolidation of on-premises equipment
Our uniform, composable architecture facilitates modular ideally to a single appliance.” 1
adoption of security services. Businesses can deploy custom
combinations of services to fit their prioritized use cases—no
“all or nothing” mindset necessary.

Integration fuels innovation


All Cloudflare services run on every server in every data center across our massive global network, so there are no gaps in
coverage or inconsistencies. This helps us deliver single-pass inspection and ensure the highest level of security, performance,
and reliability.
Natively integrated services also surface more creative opportunities to combine functionality across multiple services and
deliver on our customers’ desired use cases. As these product lines blur, cross-service interaction helps us solve more
advanced scenarios and truly modernize security.

Strengthen third-party access security Visualize and audit SSH sessions


■ ZTNA and RBI integrate to provide safe access for ■ ZTNA and SWG integrate to provide visibility across
third parties like contractors and partners entire SSH sessions to monitor privileged access
■ Verify contextual information for authorization, and ■ Simplify SSH access with clientless, browser-based
serve apps in isolated browsers to protect data SSH sessions through ZTNA
■ Clientless operation for both services simplifies ■ Provide SSH session visibility at a network layer; log
rollout with no downloads required every command using SWG as a proxy

Simplify SaaS remediation workflows Better protect against phishing


■ SWG and CASB integrate to enable a “find and fix” ■ Email security and RBI integrate to combat
workflow; block some or all suspicious SaaS activity sophisticated phishing attacks and business email
straight from CASB security findings compromise (BEC)
■ Expand SaaS visibility to help detect and remediate ■ No predictive threat intelligence is perfect; opening
issues that could lead to data leaks or compliance email links in an isolated browser provides an extra
violations layer of protection

Not ready to try it


out? Keep learning
Start your journey to a faster, more reliable, more secure network
more about
Cloudflare One
Request a workshop

1
Gartner Hype Cycle™ for Network Security, 2021

GARTNER and HYPE CYCLE are registered trademarks and service marks of Gartner, Inc. and/or its affiliates in the U.S. and internationally and are used herein with permission. All rights reserved.

1 888 99 FLARE | [email protected] | www.cloudflare.com REV:PMM-JULY2023

You might also like