2025 Cybersecurity Predictions with Cloudflare’s Grant Bourzikas
Cloudflare Chief Security Officer Grant Bourzikas gives an inside look at his cybersecurity predictions for 2025. Vendor lock-in will drive breaches as organizations struggle with complexity, diverting focus from security priorities.
Transcript
This is Textron tv. Hey everyone. Welcome back here to another Techron TV segment.
You know, I, I was telling this gentleman when IF we first got on before we, you know, we went live here. Uh, it's been too long. He is, he's a force of nature, you know, I love having him on our show.
His name is Grant Zuki, and if I mispronounce your last name, grant, I apologize, but I do my best. Matt. Yeah.
Um, grant is the Chief Security Officer at CloudFlare, and that is not an easy job when you're Cloud flare and 20 plus percent of the Internet's flowing over your wires or, you know, o over your network. And, um, but grant's more than a chief security officer there. As I said, grant's a force of nature.
Has a great story. Grant, welcome back to Text Drunk tv. It's great to have you on.
Thanks, Helen. Wonderful being to be back. It's been too long.
It's been too long. It, it has, like you said, I'm gonna write to you direct from now on and we'll get John here more. Grant.
Um, well, let's start. I, you know, I gave you this big buildup. Don't mean to embarrass you or anything, but tell people a little bit about your journey in security, especially.
Well, thanks. Thanks. Um, so, hi, I'm Grant Bki.
I'm the Chief Security Officer for CloudFlare. So, you know, I always think, you know, my first CISO job was, was in 2004 for Gainy. So, um, going into 2025 you, 21, 22 years doing, being a CISO at seven different places, uh, I've seen a lot of interesting things over the years.
Um, you know, I spent time in, in online brokerage. I spent time in power in nuclear. I spent time, um, at McAfee running labs and artificial intelligence.
I, um, was the group of, so for HSBC in the last of, so four Silicon Valley Bank and now we're CloudFlare. And so I've been doing this a long time, um, super passionate about this topic. Ai, I even got my master's 'cause I thought I was, I wasn't busy enough in artificial intelligence.
And, um, just like this is, you know, security is one of the coolest things. It's something I love. It's something I think I'm good at.
Um, and if you could put those two things together, that's, that's what, you know, can help you drive success as a, as a person in your personal life and in your business life. Absolutely, man. You know what they say.
If you love what you do, you never work a day in your life. Um, grant, I, I mentioned that cloud flare is, uh, you know, I forgot what the exact number was, but I remember it's more than 20% of the internet, uh, flows through the CloudFlare network, if you will, 300 or I forget how many different pops you have and, and everything else. You know, just a shameless plug, we do a show here on text drug TV called The Last Great Cloud Transformation in partnership with CloudFlare.
We talk about the connectivity cloud, right? Because in a world where, where every data and apps are everywhere, the hyperscaler core, the the edge, the endpoint, the on-prem, you need something that connects all of them. If I ask you to describe Cloudflare's mission, right?
I don't know how many times people ask you that. What would you say the mission is? That the mission was simple.
It's that to help build a better internet, and I, you know, this is on my, I think everybody at Cloud Flair, um, is very passionate about. And, and, you know, to help build a better internet means we're, we're really doing things not to just make profit and losses. You know, we are a publicly held organization.
7 billion organization. And, and that's great for a lot of organizations. But what, you know, when, when people come here, it's, I, I wanna make the internet a better place.
I wanna help protect organizations that can't protect itself. And so, um, we have things like Project Alaya where we support over 2000 websites that could be non-for-profit, that we offer all of our services for free. We offer all of our, our services are free for very small schools and, um, education facilities for K to 12.
And so I, I think that's a special place when you start thinking how do we help, um, you know, society from an internet standpoint. We've seen it. Um, we've defended Israeli sites, we've defended Palestinian sites, we defended Ukrainian sites.
Um, we've, you know, you know, whether it's LGBT, any type of diversity, anybody that is trying to, um, build some sort of a voice that somebody doesn't like that tries to take that down, we step in the middle and, and make sure that, that they have a voice to the internet. And we think that's very critical to what it is. And I think, you know, we do these things called pulse surveys, that's kind of engagement around the organization.
And, and it's think 93% of all of our organization is, is connected and feels connected to that mission. And so it's nice to say, Hey, I by DDoS services, um, and, you know, I think we're the best in the world at this, but to provide 'em for people that can't do anything for themselves or can't even fa pay for our services, um, as they try to get a a, you know, the voice heard be protective. And I, I think that's just such a cool special thing that Kaufler represents.
Absolutely. You know, I I, I went to law school a hundred years ago and one of the principles they teach you in law school is even the most miserable SOB in the world deserves to have a, a competent attorney represent him or her. And because that's just a fundamental part.
Not, I don't wanna call the human right, but it's, it's, it's how the system is supposed to operate. And it's the same thing on the internet. If you, if you're gonna say, I believe in free speech, you can't be selective.
I mean, I'm, I'm not saying yell fire in a crowded theater, right? Obviously there are boundaries, but if you're gonna have free speech, it's free speech for everyone. 'cause if it's not free speech for everyone, it's free.
It's really free speech for no one. And, and you know, so kudos to Cloud Fly. I know you guys have taken Slack over it too.
'cause like I said, Noah wants to be the lawyer representing the serial killer, right? But that serial killer's entitled to a defense and someone's gotta do it. Someone and it, and it should be a competent person, right?
Yeah. And you know, the other one I I think that's super special about this is we've seen big companies, I mean, you know, even these AI companies that have come up, we've seen it where they get extorted for DDoS attacks and they don't, there's no hope for 'em, right? Like there's no, how do I stop this?
And I remember 20 years ago when I was at Scots trade and we got DDoS and went on for a week and I didn't like, how do we stop this and we pay extortion? And that's been a long time ago, but you, you know, we, you've seen this and we've seen this, I mean, twice in the last month that we just stood up our services for an organization and it went away. That's something to be, you know, proud of, of, you know, to to, to be on that receiving side where you're, you're getting beat up and execs are screaming and board's not happy with you and you don't know how to defend it.
And we just stepped in and, you know, we're the person that stops the bully. And I think that's such a, you know, those things feel good. And, you know, we have a 10 minute kinda SLA internally if you call us that locate on the phone in 10 minutes and, you know, having, dealing with complex issues that could take weeks, like 10 minutes, right?
And I, I think that's such a cool thing that we offer. I'm living proof, right? You know, one of our security boulevards, one of our sites, right?
com, but Security Boulevard gets three x the views. DevOps does three x the visitors, three x the traffic. And when you run a security site, you got a big bullseye on your back, right?
And, and we were getting DDOSed and bought, bought it to death, right? And, um, you know, we switched over to Cloud Flare and it worked for a while and then they, the people attacking took it to the next level. And we called CloudFlare and, and literally like flipping a switch went away.
It was, and you know, after a couple of days they stopped doing it because they saw it wasn't a, you know, site was not affected. So, you know, firsthand, firsthand, uh, was it first time, long time or whatever you want to call, you know, they do on radio. Um, it, it's true security's a big part of, of the cloud flare, uh, equation.
There is DDoS, right? Uh, certainly part of it. But yeah.
And you mentioned ai. Look, the, the, uh, the Deepsea company outta China, right? The day after they kind went public, you know, they, they claimed anyway, they were under atti, under attack and their servers were down probably some sort of DDoS or it, it could have been a question of they just weren't set to handle all the traffic, which, so they kind of created their own DDoS, right?
By, by the like the IBM commercial, right? Five, you know, 5,000, 5 million orders. What do I do now?
Um, crazy stuff. But Grant, I, I, you know, as I said, security's a big part of it. Security in 2025, it's kind of a mixed bag.
We still got this same old, same old, it's the same here. You look at the O wash top 10 or top 2017 or 18 of them, and the same ones that have been there for 20 years, but there's some new threats and new vectors and new attack surfaces. AI you mentioned is a big one.
If, you know, we're sitting here now almost the middle of February, man years going quick. What do you, you know, RSAs, in three or four months, the world will be gathering to talk security. What do you, what's your predictions for what we need to be on, on top of?
I I think the AI is still the big topic anywhere that's being launched around, I was just in Davos and, and you know, it, it seemed very similar to last year, AI, quantum, um, cyber, our big topics. But I think, you know, I'll call this maybe year two-ish on how I kind of think about ai. We, you know, last year was really a good introduction to all the things we're gonna solve with ai.
I think we're still trying to solve things with ai, but actually not doing the, we're not solving anything. We're not just talking about it. Um, but I I think you're starting Yeah, we're still in the planning stage.
Yeah. Yeah. We, we have, we have all these wonderful ideas, right?
And we're gonna solve global warming with ai, but we're not quite sure how to do it yet. Um, and so I, but I do think, um, as, as, as you, as we look at these lms, you're starting to see some practical applications and you're seeing much more experimental, um, usage of 'em. And I think this is where we're starting to see that.
We see this internally, you know, another company, you know, tried to take our data and put it in their LLM. And so you, you're seeing this, you know, back in the old day, data protection, you know, you have a little bit of data loss now. People are actively trying to take your sales logs, your customer logs to be able to generate these models.
Um, and so you see this as a, a big threat perspective. We talked, I talked to about assos and third party risk is this big one because of AI and the generational of AI models. Um, but, you know, I think the thing that I, I, I always get worried about is even employees, you know, misusing the AI models, like putting things into data that they shouldn't or building an LLM that may not give you the right answers, right?
And I think just as we're still experimenting with the technology, you know, we, we, you know, I think when I always talk to people, I always say, well, what is, what is, what does an LM what does AI mean? Like, what does that mean to you? And, and it's simple asking questions, right?
I mean, you can pull up CloudFlare workers, pull down any of the models, claw philanthropic chat GVT deep seek and, and query them and see what kind of response. And then well that's ai. And I'm like, well, that's, you're just asking them a, a model questions and it's giving you answers.
How are you gonna use it? And so, you know, I think when we start thinking about what data goes in where it is, is, is still a large problem that every organization's facing. And that, I think that's compounded with a vendor community trying to build their own level and models to be competitive in the space and, and creating a lot of risk, um, in kind of data convergence around the world.
You know, we were discussing this on the text on gang showed this morning, grant, I've been in security a long time. As long as you or more even. I bet there's usually someone with a big stick that helps security enforcement.
Sometimes it's the government, Graham Leach fly Lee, GDPR in the eu, uh, you know, a government regulation. Other times industry councils, the PCI, you know, stuff like that. Uh, cyber insurance.
The cyber insurance industry has been a big stick for the last couple years. You want cyber insurance. This is, you know, they do their audit.
They want to make sure you have everything that they need or they claim you need. When it comes to this AI issue though, if like respecting ip, not use, not sucking your data into my, your, you know, my LLM to use as I want. Actually, I thought it was pretty funny that open AI use the, uh, deep seek people of doing that when, you know, cat, cat pots fail load to kettle.
Um, but the, the we, the EU did pass some AI regulations. As you probably know yesterday, the vice president of the US asked in France, who's in France at a conference, said, the EU should back off that. We need to let this thing just run wild because it's a race for supremacy.
Um, I saw today a report out of the EU that because they don't think that the individual nations are going to enforce or or pass the a EI enforcement, they, they may be backing off who's the big stick that's gonna help us with ai. Like the, the problem you just outlined. Yeah, I think it's, I think you will see it at the country level, but it's, it's things that people don't always think about, which is, you know, what's gonna happen?
You know, you take, um, GOBA, you take any of the regulations around data sharing, data sovereignty, you know, there's lots of places to, to drive on this. We're seeing regulations outta Singapore, Australia, us, Canada, Europe. And so you're seeing it where we don't want the data to leave the country.
And, and we get a lot of customers that ask this, you know, I operate in Canada, I don't want my data to leave Canada or US or Mexico or France. And so I think we're, we're gonna see some of these that actually are relatively rudimentary from a data detection standpoint. Things we you should have been doing for 20 years.
I always think, you know, we, we've not maybe done 'em well for 20 years. Um, maybe years 21 and 22 will be better. But I think, you know, these are still very principle based things that companies have to do.
It's, I, you know, I think is like CloudFlare, like I have the need fiscally worried about the data, my customer data, my certificates and getting those into models. And so I think there will be a little bit of a, uh, you know, we all have to kind of take granted, you know, or or take ownership for what we are doing with our own models. And think about it, even the ethics side.
I had a fascinating conversation when I was in Davos. Um, it was a security and ai, um, panel and it turned into what's the future of AI based on humanitarian and reasons and what's, what's, what's the world gonna look like in 25 years with cyber and AI and robots? And it, it's very interesting.
I think this'll be, there'll be some societal, um, implications of what goes on with ai. Just, I always think like, it'd be great for somebody to come clean my house, right? Like, do I need a housekeeper and what's the implications on somebody to cut grass or what, you know, do I need to cook anymore and do I, do I, you know, the cars are down the path.
I don't think we'll be all having autonomous cars in five years, but eventually we won't drive cars instead five years, 10 years, 25 years. Those implications are gonna be very interesting. And so I think as we look at how we operate as humans is gonna be very interesting over the period of time.
And the implication of AI on this as well. I, I don't disagree. I don't disagree.
You know, the problem with ai we have over here, grant, it sucks the oxygen at every conversation I have. Let me, let me, whatever time we've got left, let me pivot. non-AI cybersecurity issues think that we've gotta be looking at in 2025.
I still think that the, the number one thing is that we have to get rid of some of this complexity. Um, and I, I talk to CISOs all the time and you know, it's, it's the, you know, 60% of all CISOs had more than 50 security tools. You, you just, you can't defend the organization with that complexity.
You know, I I, I've gotten to work on a couple of major breaches this year and I, I go in and trying to help 'em with, you know, what kind of telemetry can cloud off for you to find the attackers. And I don't know how, how an organization can operate with the, the security controls that are there. And I think, you know, trying to simplify the environment is gonna be something that's there, the drive complexity down to drive costs down so we can make these investments into our favorite topic of ai.
Because I think ai, like, I think we all have to embrace it and spend a lot of time and resources in ai, but it's really hard to do that when you have complex security organizations. And the other piece I always talk about this is there's a lot of business transformation, you know, old at, you know, outdated technology from a business standpoint. But we're there from a cyber standpoint too, that there's a lot of tools.
You know, the, the vendor community has, you know, we've done this for 25, 30 years, is there's a new tool and a new widget and we buy it. And then there's a new, new tool and a new widget and we buy it. And now you have this complexity and I have more tools than people on an organization and it makes it hard.
So I think this reducing complexity, going through a security transformation to support the things that are there. 'cause uh, we're just spending a lot of money and I, I, you know, you look at the data, we're not winning, right? And so we have to do something fundamentally different to support that.
I, I, I do, I don't disagree there. We've gotta do something fundamentally different. Brings me to another question.
You know, one of the things I, from where I sit, right? I, I get all these inputs from all different around the industry and end users is innovation dead in cyber, right? Where's the innovation now?
You know, we've got more venture backed cybersecurity companies than we've ever had, right? There's all kinds of startups, there's all, you know, but where is the innovation? Do you to, you know, and, and you know how it is Grant, most innovation and security is not at the public company level.
It's at the startup level. And then the public companies, you know, usually acquire them. Are you seeing innovation out there?
Yeah, well, I think we do see innovation. I know we just rolled out AI firewall in, uh, in a way to stop AI bots. And I think this is, I think you're seeing as technology changes, especially in the AI world, um, you've kinda have three a AI products with the AI firewall, AI gateway, and, and to stop all these followers.
And, you know, that's, that's a very easy innovation. 'cause I think you're seeing the market change, um, where there's more bots than users. Um, you know, it's, it's, it's significantly more than than users.
And so that, that's an easy way of a place of innovation. I think the thing that I see, and I see that this with ourself, um, I see it with the CrowdStrike of the world. I see it with the bigger players that it used to be.
If you were a large security organization, you know, you didn't do it. You did one thing very well on a bunch of things, mediocre. Um, you know, using our technology as an example, if you put CloudFlare on the internet and buy all of our services, I you're gonna be protected.
And I, you couldn't have said that maybe five or 10 years ago. And I think this innovation is, you know, take, you know, our services like a DDoS I think they're world class, but we have web application firewalls that I think are world class. I think you have API and so you're starting to see innovation by reducing complexity, which I think is good in simplicity.
And so, you know, I think that is one of the areas that you're seeing. And then you're seeing products integrated much simpler to use, easier to operate. And then based on data telemetry with machine learning, you'll use the AI word.
Um, 'cause I think that's where you're seeing, you know, better models that can really drive what goes on. And I think that's something I, you know, I'm proud of. Even in our environment.
I'm, I don't, I have less than 10 vendors. We use them heavily. I feel very protected, um, with what we do.
But it's, it's this kind of integration component because, you know, 15 years ago I might've had 30 or 40 products to do what I'm doing. That creates that complexity. And so I think this innovation of kind of this collaboration is something that I am very interested in.
Um, and I think it's rudimentary we're seeing that scale because I think some of the data sets that we have, right, we, to your point, we have almost a quarter of the internet come through as well. We should be good at math, we should be good at DDoS, I, you know, we should be good at API protection. We should be good at, you know, kind of our turnstile cap placement.
And I think those are the things that we're seeing that, hey, like before, well, I want a layered defense and I want these things. But layered defense cost you a lot of things. And know, I think the last time I was on here, I, one of the organizations I worked with had six.
I walked in and had six web application firewalls. I, I don't, you know, innovation, to me, when you go from six to one, simplified terraform, automated shift left, whatever words you say that to me is you're seeing the vendor community really solve problems versus come up with something that's a widget is the widget problems. I remember, I remember at McAfee we looked at a company that was doing just kernel protection and I'm like, well, press check does that pretty well said, no one does that pretty well, you know, and so we're finding that the, the, the, you know, the playing field is a lot closer to par and you're seeing the larger companies actually be able to innovate quicker because of the resources and the telemetry that they're getting.
It, it's a bigger, it's a bigger commitment to, to innovate today. That, that's for sure. The, the, the barrier to entry is much higher.
Grant, we're outta time, man. I apologize, but these are supposed to be 15 minutes. We probably are 20 something.
Dude, I'm not gonna let you go this long without being back on. I promise you, I'm gonna, how'd you till I get you back on here? Uh, it's always great, but people wanna get more information about, specifically about CloudFlare security solutions.
com or is there a section of the site? com as least as you can fill out, um, different forms. I mean, you always reach out.
I mean, you always reach out to me. I'm on LinkedIn, I can get you to the right places. Um, but take a look, see what, see what's out there.
I think, you know, it's, it's, if if you don't know about us, you should look. 'cause it's, you know, having a quarter to the internet, um, come through us as something that is, I think very key and should be strategic to every organization. Absolutely.
You can be at RSAI will be at RSA. Yes, sir. I hope to see we're at text, uh, text.
We are text truck. We're at, we're at broadcast alley all week doing videos streaming. So, but we'll do on that weekend.
Have you stop by all. Awesome. Thanks everyone.
Thanks Alan. Thank you. Grant BCUs, chief Security Officer CloudFlare here on Textron tv.
We'll take a break. We'll be back.