Secure Your Future: Internet-native Zero Trust Architecture Helps you Transform your Business Faster
Download resourcesAbout this session
John Engates, field CTO at Cloudflare, argues that the Internet has become the corporate network even though it was never designed for security, reliability, privacy or performance, and that the castle-and-moat model of a perimeter firewall with everything trusted inside no longer holds when attackers log in rather than break in, exploit VPN and firewall appliances, and open the door with email, the starting point of 91 percent of attacks. The first wave of cloud migration merely virtualised firewalls and VPNs and produced convoluted routing. He defines zero trust (verify every request, default deny, least privilege, log everything, assume breach) and SASE, where control is centralised but security functions run at the edge close to the user, and presents Cloudflare's network of about 275 cities as that edge. A typical journey starts with VPN replacement, then secure web gateway, remote browser isolation, consolidating security across clouds, retiring MPLS circuits and email protection, with a vendor-neutral roadmap at zerotrustroadmap.org. The Q&A covers encryption in zero-trust tunnels, DLP, device posture on home networks, ticket-driven policies, ZTNA versus ZTA and WireGuard.
We’re all facing more apps moving to the cloud and teams working remotely, amid a growing and evolving security threat landscape. When it comes to security, there’s never a single destination. The largest risk is committing to a network or security approach that locks you out of your own future. Today, organizations of all sizes need highly effective security delivered via an Internet-native architecture that consistently flexes to tackle the challenges of our current landscape, and that innovates at a pace to help you foresee what’s ahead. Join this session for an in-depth look at an Internet-native approach to security based on zero trust principles and learn how you can ‘secure the future’ of your organization.
Key takeaways
- Start a zero-trust journey where the pain is: replace the legacy VPN for remote workers and contractors with per-application access policies tied to identity, device posture, location and hours.
- Apply the zero-trust tenets at every request: default deny, least privilege, continuous verification and logging, and assume the internal network is already breached.
- Push security functions (firewall, secure web gateway, ZTNA) to an edge close to the user in a single pass rather than backhauling traffic through a data centre, which is what makes users turn off the VPN for video calls.
- Use remote browser isolation for risky or all external sites so malware never executes on the endpoint, and treat email as a zero-trust vector since most attacks start there.
- Make access policies dynamic and automated, for example granting administrative access only while a ticket is open, and require a hardware key or fingerprint so someone must be physically at the machine.
Speakers

John Engates joined Cloudflare in September of 2021 as Field Chief Technology Officer and is responsible for leading the Field CTO organization globally. Prior to Cloudflare, John was Client CTO at NTT Global Networks and Global CTO at Rackspace… Read moreRead less
John Engates joined Cloudflare in September of 2021 as Field Chief Technology Officer and is responsible for leading the Field CTO organization globally. Prior to Cloudflare, John was Client CTO at NTT Global Networks and Global CTO at Rackspace Technology, Inc. Earlier in his career, John helped launch one of the first Internet service providers in his hometown of San Antonio, Texas. John is a graduate of the University of Texas at San Antonio and lives in Texas with his wife and two daughters. He is passionate about technology and enjoys mountain biking, snowboarding, and spending time traveling with his family.
