Regaining Control Over your Multi-Cloud Environment – The Last Great Cloud Transformation EP4
In today’s episode, hosts Alan Shimel and Mitch Ashley are joined by Annika Garbers (Cloudflare). As nearly all enterprises embrace multi-cloud strategies, with 98% using or planning to use multiple clouds, they gain access to unique services, cutting-edge technologies, and competitive pricing. However, this approach brings significant security challenges. As organizations expand their cloud usage, they often lose visibility and control over their environments, struggling to manage disparate security tools from various vendors. Meanwhile, cyberthreats continue to rise in number and sophistication. Enter the connectivity cloud—a solution built on a global network that simplifies multi-cloud management. By providing seamless connectivity, unified security policies, and real-time threat intelligence, the connectivity cloud helps businesses regain control, ensuring security without sacrificing performance.
Transcript
Hey everyone, I'm Alan Shival, and welcome to the last Great Cloud transformation. Uh, this is a video series that we do about every two weeks. Um, every two or three shows, though we actually do it with a live studio audience where we ask you to participate and help lead the conversation.
Unfortunately, this isn't one of those episodes. This is just a, a recorded episode with our panel here. But nevertheless, it's a great conversation, especially if interested in what we call, or actually what CloudFlare has come to term, the connectivity cloud, and what do we mean by the connectivity cloud?
You're gonna find out all about that during the course of today's show. In today's shows. In today's show, we're gonna be talking about multi-cloud security.
You know, multi-cloud is, is, is, is quickly becoming the dominant, uh, format in, in cloud usage among enterprises, actually even in small businesses today. But, um, securing multi-cloud has its own set of challenges. We have two other people besides me to discuss this today, and I think we're gonna have a great conversation.
Let me introduce you to them. First of all, I wanna introduce you to Annika Garbers. I hope I got that right.
Annika correct. You Did. Thank you.
Annika, tell us a little or share with our audience a little bit about yourself. Sure. So happy to be here.
Thanks for having me. I'm Annika, I'm on the product team at CloudFlare. I'm a director of product for our network services team.
So my job at CloudFlare, the past, oh, a little bit over four and a half years, has been talking to customers to understand the journeys that they have been on in digital transformation, cloud transformation, and then the challenges that they have experienced in, uh, connecting and securing their multi-cloud environments. Um, so super stoked to be here and to get into that more today. Absolutely.
We're super stoked that you're here. And Ha, and joining us, joining Annika myself is, is my partner, Mitch Ashley. Mitch is the CTO here at Techstar, as well as CTA and Analyst with Futurum Group.
Hey, Mitchell, it's great to have you on. Again, I, I know you are just back, wasn't from Barcelona, Barcelona For a conference out there and you lost your voice. So we, we try, we'll try not to tax you too much today.
Well, it's coming back. It's coming back. Not fully there.
I'll, I'll have my radio voice next Week. Okay, good enough. So, so guys, let, let's talk multi-cloud a little bit.
You know, I'll, I'll be honest, I, I have a confession to make. I didn't see multi-cloud coming. You know, I, I've been involved in security since the cloud first came on the scene 2005, 2006, and I always thought we'd have hybrid cloud, right?
Organizations that run some of their, uh, uh, infrastructure in a private cloud, private data center, and some in a public data center. But I never thought that the multi-cloud, uh, model would be dominant. But yet, you know, I think it's a recent, uh, a recent, uh, Oracle survey, something like 98%, virtually every single 98 out of a hundred enterprises are either currently or plan to have multi-cloud deployments.
You know, we were talking off screen, Oracle themselves now has partnerships with Amazon, Google, and Microsoft, as well as having the Oracle cloud itself. Those are probably the four major clouds, you know, public clouds in, uh, in the, in the western world. Anyway, um, you know who, who saw this coming on ground, Warren?
I'm thinking, I mean, cloud Flare. Did, did you guys sort of anticipate that we've moved to a multi-cloud world quite as quickly as we have, and then of course anticipating what challenges that brings outbreaks? Yeah, I think, um, when we talk to customers, so I have that opportunity occasionally to present to large groups of people at conferences and things like that.
And I always trying to ask an audience question to gauge this because I think it is really interesting understanding the different paths that people have taken to multi-cloud. And so I'll ask as a starting point, you know, how many of you here are dealing with multi-cloud in your environments? And like you said, you know, this bears out in the data, but then also anecdotally, it'll be the vast majority of hands in the audience go up.
Almost everyone has a multi-cloud environment. And then I'll ask, okay, for how many of you was that, uh, on purpose in an active choice that someone in your organization made an architect or someone doing a cost analysis or someone doing a capability analysis where you were like, yes, this makes sense for us intentionally, and almost all the hands will almost go, always go down. So people have ended up in multi-cloud environments sometimes because a mergers and acquisitions, sometimes because, uh, one cloud had a feature like that was very specific and needed for some use case that another one didn't, and you had to use it.
Um, but then now security and network and IT teams are really grappling with this, uh, situation that maybe was not necessarily like, thought through or intentionally designed or planned or architected, um, at the front end of an organization starting on their cloud journey. And now they're dealing with sort of the, okay, what do we do about it moving forward? Agreed.
It, it is, uh, so I'm not alone. That makes me actually feel better in some twisted way because I also feel validated a bit too, Alan, because it seemed to me the thing that drags everybody into it is m and a. You can't help that.
You know, it's just like any other, we now have three CRM systems and two ERPs, and which ones do we consolidate and what do we live with or what can we take advantage of, right? So it seemed almost inevitable that we're gonna be multi-cloud just for that reason, rather than there was a day. I think, I think, um, it'd be, appreciate your perspective on this.
I remember the day when we were saying, you know, we should have multiple clouds so that we have vendor diversity and can compete our price. And, you know, so that AWS or Google or, or Azure doesn't kind of get too full of themselves and charges too much money. 'cause we'll just move to the other practicalities of that are of course, much more complex.
That seemed to be the thought when we coined multi-cloud, but now that's not really the reality. Do, do you agree with that? Yeah, Absolutely.
I think, you know, for the few people whose hands remain up when they say, yes, this was an active choice and not just something that I'm dealing with as sort of a, a consequence of m and a, the reason that they, uh, made this active choice within their organization really break down to one, uh, not getting locked into a single vendor for storage and compute, right? Having that ability to shift applications around if you want to in some cases because of cost. Um, and then in other cases, because of redundancy and resiliency, like maybe, maybe they have really business critical applications that have to be able to stay available regardless of what is going on with the cloud provider.
And either internally or because of pressure from like a regulatory body, they've made the decision, okay, we're going to, um, we're gonna have the same application redundantly operating in multiple clouds. The other reason that we hear is because of, um, essentially feature parity or specificity or requirements. Um, and increasingly with developers that are working on, uh, workloads that include ai, we're seeing this as a reason, um, that, uh, folks might choose to go with one cloud provider versus another.
So I think we see a variety of reasons, um, but then the challenges that are then present again for it, uh, and network and security teams, um, look the same regardless of sort of the reasons you ended up in that boat, Right? It doesn't make a difference how you got there, Exactly How you were there. Choose that.
But I, I, I agree with you. I look, I've spoken to a ton of people who, you know, for whatever reason they thought GCP had the best Kubernetes, right? Mm-Hmm.
Support AWS serverless, right? If you were looking to do serverless, you, the AWS and, and then, you know, Azure, believe it or not, Azure DevOps was a, was a big draw for people and for, you know, teams that were doing that in the GitHub IT stuff And integration with the rest of your Microsoft stack, right? Microsoft Or Microsoft shop.
And if you're an enterprise, Microsoft has a lot of enterprise customers, you know, and, and absolutely. But as you said, regardless of what journey or what path they took to multi-cloud, here we are, right? And, and, okay, now we're here.
Now what? Well, there's a couple of things. Connectivity, moving data among a multi, and, and let me throw another wrinkle.
Not only are they multi-cloud, they still have stuff on prep. They still have private cloud, right? So, and that's, I think that's sort of a, a soft white underbelly that we don't talk about.
You still gotta secure that. You still gotta, you still got data there, especially large enterprises. They have their mainframe, they have their, you know, on-prem stuff.
So, you know, this brings up this whole connectivity cloud as, as CloudFlare has, has labeled it the idea of we need yet another cloud, if you will, or at least a service that ties these together, especially as it relates to connectivity and security. Right? And, you know, Mitchell and I, our backgrounds are in security.
We've been in security 30 years. You know, let's talk about specific security challenges within multi-cloud environments and, and maybe some of the ones that Connectivity Cloud is, is hitting head on. Annika, I don't mean to throw it on you, but hey, you are the expert.
Sure. What do you see? Yeah, I mean, I think, uh, when we talk to customers that have been through this journey, which is pretty much everyone is somewhere, uh, along the, along the journey of moving from, um, some on-premise data center where there's a traditional castle in model mode for security to, uh, multi-cloud or hybrid cloud.
Um, you mentioned the existence still of the legacy stuff on-prem. We totally see that. We also are increasingly seeing more organizations, um, move toward repatriation projects, at least for some small percentage of their application that move to public cloud.
And then they realize, oh, actually for cost reasons or control reasons or whatever, I need to shift it back. So there's, there's all this mess. I think the, the biggest shift that we've heard people articulate is really, um, in, in security at least, uh, the shift from a very centralized model for security, where you used to be able to sort of draw this neat perimeter around your corporate network and say, okay, everything inside of here is trusted.
Everything outside of here on the public internet is scary. And then I'm gonna put my big stack of defense in depth tools, my firewall, my intrusion detection system, my VPN concentrator, uh, my data loss prevention service, et cetera. Like put that big stack sort of at the, the Castle Moat, watch every packet coming in and out.
Um, and then, uh, and then I, I'm sort of good now. Uh, applications and users are no longer within that defined corporate perimeter, and the lines are not clear anymore at all. Everything is super blurred.
And so we think that, um, this has, has, is going to result in a fundamentally different approach or a different architecture model that security and IT teams need to take to how they connect and, and secure their endpoints. Because if everything used to be centralized and now everything is distributed, it's not enough to just sort of shift, um, uh, approaches that worked in the context of data center security and say, Hey, we'll just deploy those in the public cloud as VMs now I'll deploy a virtual firewall and manage it. Or maybe I'll backhaul traffic, you know, from a cloud environment through my data center security stack.
Those kind of architectures made sense as sort of a middle state band-aid solution. Um, but don't for organizations anymore that are dealing with really, really distributed models, um, for where their sources and destinations of traffic can be, that's users and applications, literally anywhere in the world. Yeah.
Here, You know, one of the differences, Alan, in how we think about cloud today used to be we, we built clouds, you know, connect things together, kind of like at erector set, you know, connect A to B and C two B, and all the different paths of our different places that we need to connect or network we need to interconnect. Uh, is a company like CloudFlare in full disclosure, we're a CloudFlare customer also. We use it for tech strong services.
But it isn't just, um, you have connectivity too, hyperscaler clouds. It's also you, you've already worked with those providers of what their security control plane looks like, what their load balancing and, and uh, kind of management control planes look like. So it's not all left on the customer to go figure out, well, if they're working with CloudFlare, it is not all left on the customer to go figure out.
Now how do I manage all this across multiple hyperscaler cloud vendors? Correct? Yeah, exactly.
The idea, essentially with the connectivity cloud is that you can sort of put Cloudflare's distributed global network in between the users wherever they are on the internet. And that could be like public users that are trying to get to your public facing websites or applications. It could also be your employees working anywhere in the world.
Um, but you, instead of sending all the traffic from those users to some centralized location where you apply all of your security filters through maybe that traditional stack of hardware firewalls and things like that, instead of doing that, you can enforce security at a location that is super close to them, like just milliseconds away from wherever they are in the world. And then CloudFlare network or our connectivity cloud can help accelerate that traffic from that point close to the user where we reinforce the security controls all the way to wherever the traffic's destination is in the world. And that could be somewhere in a data center, it could be somewhere in one of multiple public clouds, it could be somewhere else on the public internet in the case where we're helping secure a SaaS app.
So that's, this is kind of like a, the, the, as the, um, the way that we think about compute and security has been flipped on its head from this centralized to distributed model, fundamentally, we're approaching security from a really distributed, um, sense as well. And it's not just deploy a bunch of virtualized firewalls and different clouds. It's actually this fundamentally different like edge security based way to think about it.
You know, I, I, I agree with that a lot. We, um, when you, when you think about that whole old model of back hauling traffic back, you know, to the central place, I think Covid spelled the death nail of it, right? All of a sudden no one was in the office anyway.
So what, what sense did it make to back haul all that traffic there, to run it through those big honking machines when no one was there? 'cause we was just sending it back out. You wanna talk about waste and, and so, you know, like the movie, anything from anywhere, anytime or whatever, that, I always got that movie's name wrong, but it, that's the model today we're, we want to do anything from anywhere at any time, Everything everywhere, all in one.
Totally. That is how our customers want it. And I think you're so right that Covid was kind of like the last nail there.
Yeah. I mean, the shift of storage and compute to the public cloud certainly led the charge. And I think a lot of organizations have been, um, resistant or kind of lagging in their approach to moving networking and security also to the cloud.
Because from a feature, a feature perspective, the public cloud's invested primarily in the experience, developer experience and the features around the storage and compute capabilities. But then with users also now moving to, uh, an ability to be distributed anywhere, the, the, um, the chips have kind of started to fall and people are recognizing, okay, we need this different model now. But, you know, the way of the world is maybe for those laggards who were late, like that, it actually worked out for them because they didn't have a connectivity cloud two, three years ago to do this.
That's A good point. We, we talked to some organizations that are, uh, able to kind of skip a little bit of those middle steps where they've deployed a bunch of the sort of bandaid solutions and didn't pay taxes and actually taking the opportunity to reimagine it. Yeah.
Yeah. Right. Trying to put this together, you know, point by point in finding out, you know, and we, I call it idiot taxes, right?
You're paying 'cause you just learned those lessons over and over. Um, so I mean, obviously a big part of it is having a CloudFlare like, uh, point of, you know, point of contact network where you are never too far from any edge or any end user. And then of course, going back to these hyperscaler centers, um, security's only one piece of this though.
It's basic connectivity as well, right? I might be running my, my Kubernetes stack in one cloud, but you know, or maybe it's my, uh, systems of engagement is in one cloud, but my system of record is back at my data center and my front end web servers are somewhere else, right? That, to pull that off, given latency the way it is, right?
You need a connectivity cloud, right, to optimize the A to B2C to the end user experience. How, how do you guys do that? Ika?
It seems like, you know, either a lot of AI or black magic or a little of both. What do you think? Sure.
I mean, uh, cobbler's mission overall is to help build a better internet. And this started with a focus on public facing application. So things that are already on the internet, public facing website or other, other apps that you might use as an organization to serve like your end users.
How do we make those things faster, more secure, more reliable? And then as we started learning from larger and larger organizations about the challenges that they're having, not just on the public facing infrastructure side, but also the internal infrastructure, everything kind of within the remit of like the CIO or the ciso. Um, they were articulating many of these same challenges with security, connectivity, reliability, and the desire to use the public internet for more of the apps.
Like you've heard maybe the phrase like the internet is the new corporate network, but the internet wasn't built to be a corporate network was not built with the kind of security and reliability requirements, um, in mind for really, really business critical traffic. And so we think about it as how can we help, uh, act as sort of an, an overlay for the internet in many ways. Um, not building a separate internet, but helping make the internet as it is, uh, today, uh, high quality enough, reliable enough, secure enough, performant enough in order for companies to trust even their most business critical workloads, um, to send over that traffic.
And that looks like things like having lots and lots of different connectivity options. Every one of those points of presence on the map. And so if one upstream transit provider is having a bad day, there's some congestion, there's a route leak, there's some other problem, no worries.
There's tons of redundancy and other options for how to route traffic around. Um, and it's, it's the depth of connectivity, like all of those different interconnections, uh, global backbone that connects them as well, which is just sort of another tool in the toolkit to use, um, to, to help accelerate traffic performance. But then also the intelligence that sits on top of that, of, uh, how do we not just pick the best path based on sort of default BGP routing, but actually apply, um, smarter ways of making traffic steering decisions based on the intelligence that we have across the view of the global network.
Um, so connect at all of the places have lots of different options for how to get traffic from A to B, but then make smarter decisions for how to route it. And that's based on both sort of synthetic and then real information about the traffic routing across the network. Do all that in real time, right?
With near no latency law than everything else. It's gotta be, That's, that's the black magic part, But, well, I think, I think too, also you have to deal with it in two worlds, right? You want the sort of simplicity of it, right?
I won't have to worry about all the details of what interconnects with what I just want my bot management done this way, or my web application firewalls set up this way. And if I want to take it more detailed, I can say this is, I want it done differently in different locations. But then you also, if you take it a layer down, well, okay, well what if I wanna do application security?
I wanna be able to do API management across all these locations. I don't wanna have to do it different in every cloud provider I'm interconnected with. So are there some ways that I can, it may not be centralized that, but but do that in one consistent way across a connectivity cloud, like with, with CloudFlare.
And then the other is, well, I do wanna get into the detail. I do want to put workers out on the edge of the network that are gonna do these kind of things. They're gonna be running my code as part of the network as well as in the, in the hyperscaler environments.
So you, you want the connect and go sort of the simplicity of it, but when you need the detail, when you need the control and you need to get into the depths of it, like every enterprise is gonna do, I'm sure I doubt there's any enterprise customer says, yeah, just connected it up and we're good, right? They're always worrying about performance of this and that and security and this data, uh, data sovereignty and localization and what has to be where and what network, how we do production. That's where the rubber meets the road is you've gotta handle all of those use cases at an enterprise level, but not make it so that, well, it's just easier to do this myself.
Why, you know, now that you're not doing any, managing any of the complexity for me, but you, you do, you are, you have to do that for your customers. Yeah, absolutely. I think, uh, uh, our goal is to provide an abstraction layer that simplifies management and configuration for customers as much as possible.
Like it should come out of the box super easy to set up logical defaults that makes sense for all the things. So the abstraction is there, but not, um, uh, a black box in that you don't, uh, have the controls if you want them, and you need the visibility to, to understand what's going on. So you should be able to connect and have sort of like logical, um, uh, uh, you know, smart controls in place for your traffic and for security as a baseline.
But then you're right, enterprises need and want the deep visibility into everything that's going on, the ability to get packet captures of all of their traffic as it's distributed across their network, the ability to see logs of all the information analytics reporting, and then also dig in and, and kind of tune all the little buttons in their knobs for the places where they want customization that is there for their environment. So it's a balance for sure. Um, but we know that it's really important to be able to do both of those things in order to again, build that trust that organizations lacked today or have lacked in the past about shifting those really business critical workflows to use the public internet as their underlay.
Yeah. You mentioned logs and that brings up incident management, incident response kind of things, right? Where I'm, if I do all that connectivity myself, I've gotta intersect with everything and what went where to which provider and try to trace that back down.
Versus if I'm going through clear of a common cloud that's doing my inner connectivity, I've got a way to pull that together more easily. Not saying it's always gonna be easy right there, there's some challenging situations to really kind of put it all back together, but I'm not tracing down every place it might have touched just to begin, starting to put together an incident management, uh, you know, what the kill chain was for a particular attack. I've got a place to start where it might've traversed across one or multiple clouds.
Yeah. And that's something that we hear customers really struggle with a lot with this shift from the, the very centralized to distributed model for a security is, okay, maybe I've put some bandaid solutions in place where I have one secure web gateway solution to help with internet traffic filtering. I've got another solution that replaces my VPN, I've got another solution over here that does some data loss prevention for me.
And when you zoom in on any of those individual points in the architecture graph, like maybe those solutions make sense, but then when you zoom out and look at the full picture and as an IT or security or network admin who is just trying to troubleshoot a problem, you have like eight or nine or 20, or actually, I talked to a CISO recently that said 80 different security tools to contend with, um, to just even try and start understanding what went on in a situation. And hopefully you're not at the point where you're, um, investigating like a, a breach scenario, but um, maybe even something that's as simple as just a, a connectivity loss. A user says, Hey, um, zoom's really slow for me today.
Where do you even start at, uh, at, at solving that problem? We think that the way to do it has to be this fundamental rehaul of the architecture where you're thinking about security and connectivity in a distributed sense, but then the visibility is still centralized, right? All of those different nodes that are enforcing the policy and making the connectivity citizens have to sort of report back to one place where you can actually go and see all of the things.
Um, 'cause otherwise it is just impossible to actually control or manage in, in, um, you know, in a practical scenario. An I've got another question for you, and I'm sorry that we, we, it's only me, you and Mitchell. So you know, you, we got you on the hot seat today, I apologize.
But let me, let me ask you another question. One of the things that I've always valued is I wanna choose my partners, right? Maybe CloudFlare is my partner, you know, for connectivity cloud, but I like company a's identity security company bs, other security company sees, uh, you know, I like to pick my own vendors.
How, how hard is it? So do I give that up when I say, Hey CloudFlare, I need your help with, I I need a connectivity cloud. I'm, I'm all over the place and I want to kind of centralize things.
Oh, but by the way, I do have maybe not 70 or 80 vendors, but I, and I got a dozen, Pardon? Yeah, totally. Uh, so our intention is not to even attempt to be all things to every single company.
I don't think that there is a, a world where, except for maybe very, you know, niche scenarios, small, small startup companies that only have some, some very specific security needs where you're managing less than, you know, three or five security vendors. We actually view ourselves as enabler, um, for, uh, customers who want multi-vendor environments for redundancy and for resiliency, especially for the components where that makes a lot of sense. So we think, um, connect, uh, or excuse me, cloud environments, so public clouds, we wanna be an enabler absolutely.
For organizations that are pursuing a multi-cloud or hybrid cloud strategy. The idea there is you can use CloudFlare as sort of a, a unified control plane for the security controls for all of those public clouds so that you have consistent web application firewall rules, DDoS protection policies, maybe bot management strategy, et cetera. But then you can actually shift around the storage and compute that lives in the different public clouds and or your on-premise environments.
Um, use the best of breed capabilities in those clouds, as we were talking about earlier. Um, but your security team doesn't have to worry about sort of like the, the attack surface looking different depending on where you deploy your applications. So that's one example.
Um, but I think even within the internal connectivity context, you know, we, we partner really deeply with, uh, lots of different identity providers. If you have a one or multiple and you wanna integrate those in, we play nice with all of those providers. If you wanna keep your existing on-premise gear and use that to connect into us, you've got, you know, investment in an existing SD WAN provider, you wanna continue to use it, that's cool too.
So we recognize it's super important for us to, uh, to not just say, Hey, you're gonna, you know, burn down everything you have and, and start fresh. That doesn't work for anyone, especially large enterprises. And so it's really about where do we invest deeply in strategic partnerships with, uh, tech providers that we view as sort of, um, working with us in the, in the way that we wanna help customers adopt this new architecture that we're helping them shift to.
Um, and then where are there places that having a multi-vendor strategy actually does make customers' lives harder? And how can we make that easier for them over time? Love it.
I get another sort of conceptual question for you and then, and you know, you've got your cloud flare hat on, so you're speaking on behalf of CloudFlare now. Um, so we look at the cloud landscape. I mentioned AWS, Google, Microsoft, Oracle, right?
Those are the four big ones for most of us. How do, how does cloud flare think of connectivity cloud? Is it a fifth cloud or is it something that just sits on top of these other clouds?
Mm, big question. Uh, so we are increasingly seeing organizations build more and more of their applications actually directly on Cloudflare's network. So we initially built out the global network infrastructure primarily, again, for connectivity and security for, uh, our customers public facing applications.
Then sort of extended that into the quote unquote internal facing, but is increasingly becoming public facing, um, the sort of era. And then, uh, as we explored more and more of those use cases too, we kept finding these places where customers are like, Hey, I actually want to run part of, or in some cases my entire application on the edge close to users. Um, AI inference is a really great example of this, where you have to make a trade off sometimes as a developer of how much of that workload can you run on the user device versus sending back to a centralized cloud and then sacrificing like the latency in the application.
And so CloudFlare sits in this kind of great Goldilocks place to be able to do that specific kind of of application. So I think we think about, um, you know, what, what we're doing is different. Fundamentally, if you just look at the picture of the, the dots on the map, the connectivity, the types of services that we offer, um, is not a one for one copy or intended to be of the folks that you listed as sort of the four major public clouds.
And again, we view ourselves as actually an enabler of multi and hybrid cloud environments for our customers, but we are seeing increasingly places where customers are like, yeah, actually that computer storage workload makes a ton of sense to deliver super close to users wherever they are in the world. And we're really excited to work with, uh, developers to continue to enable those kind of use cases. Um, and I think we'll see more of that moving forward.
Yeah. I know your, your offering there has evolved a lot in the last three or four years. Absolutely.
Yeah. It's been interesting to watch it too, because when you talk about working with developers, um, I mean, there are, can, can be some basic things you might be able to allow or enable them to, to build or run in the cloud, but you're, you know, you're talking about supporting frameworks, you know, things like react, uh, or, uh, you know, no JS or things like that, next JS pages, whatever it might be. Um, so the more you can provide a familiar environment, not saying it's exactly the same as you're gonna run in your own, you got a cloud instance inside of a hyperscaler, but to build applications, to run in, in cloud flares environment, um, you have to offer some of those same capabilities.
You gotta offer storage, you gotta offer some serverless options, things like that and frameworks that they can operate in. So, uh, that, that takes some thought. You don't just jump into that, into the pool and say, Hey, we have developer support.
'cause developers say say, no, you don't because you're missing 25 things I need. Well, you got 20 of 'em, so you're close. Let me get started.
Mm-Hmm. I mean, talk, talk about that journey, especially the security of apps that you build in a, in a CloudFlare cloud. Yeah, I mean, it's the long game for sure, but I think we're really encouraged seeing the number of developers that continue to build full stack applications on the CloudFlare platform or really critical components of their applications.
Again, with things like our, our AI for developer stack. Um, but you mentioned, you know, security and connectivity that's sort of like the baseline if you're a developer that's working on, uh, building an application that leverages some or all of our developer stack security and connectivity and, uh, and traffic performance is just built in, like that should be, uh, not even a, a, um, a thought process that you have to have of like, okay, then how do I add this to my application? It's already there.
And that include, that's, uh, in addition to things like the visibility, the multi-level of controls, um, and then the guarantees around sort of performance and user experience, again, of delivering those pieces of the application as close as they can possibly be to users. So if your developer, um, uh, uh, working on a new application that that uses our stack security and performance, um, are, are essentially just built in, that's sort of the guarantee from, from moment one. And then it's really about, okay, how, uh, how creative can you get?
Like what are the types of really exciting things that you can then build, um, knowing that some of those constraints are free or you get that time back in your developer experience. Sure. Fair guys, we're almost outta time here, but um, time goes quick 'cause we were just, I mean, I think we've ran through a hundred different things.
I light headed swimming from everything we discussed. One last question for you, Ann. How's that?
Sure. Security never gets easier. It security seems to be, yeah.
You know, as much progress as we make and, and I'm talking as a security person, as much progress as we make, it always seems like there's more in front of us than there is behind us. Uh, security never gets easier. ai all these new technologies, you know, are double-edged swords.
There's good and bad that comes with the not, you know, what have you done for us lately? What do you, what do you see coming down the pike here, maybe with connectivity cloud type of operationally that, that will help us going forward, right? What, where's the cutting edge?
No pun intended. Where's the cutting edge for you? Yeah, sure.
Um, yeah, I think you make a great point. We have seen this shift, right from really centralized to distributed, uh, users and, and applications and requirements for security. We think that that's only gonna get more complex.
So more and more distributed world, more threat vectors to be worried about everyone is being asked to do more with less. Um, and so then how do we en enable that? That's the big question.
I think for us, uh, we're doing a good job if we're helping security teams spend less time on just day-to-day operations and management of the stuff they already have. Like if they spend, you know, a hundred hours a week managing their tool stack, how can we help dramatically reduce that? Spend 10 hours a week on managing the things that you already have and the rest of your time on actually engineering on, uh, the full list of things that you have, uh, demands from the organization, um, about all of these new types of threat vectors that people don't even have the chance to get to today.
I've never met a single CISO that said, yeah, my team has free time. Like everyone always has a list of many, many more items long than there's hours in the day. And so there's so much opportunity we think to, to reduce the operational overhead just by consolidating, removing that complexity.
And again, thinking through this architecture from a perspective of what are the actual challenges that we have now and where do we need to be in the future and what are the aspects of the ways that we've thought about security for a long time that just don't make sense given that reality. And so the distributed nature of the approach that we've taken to everything we build, we think is really core to that. Very Cool, very cool.
Annika, thank you. We, as I said earlier, you know, it's just you, I and Mitchell. So unfortunately we, we kind of are sitting here grilling you with, you're the person with the answers, but man, great.
I is just fine. That was great. We loved it.
Um, I hope our audience out here appreciated it. Where's the one to go get more information on this? Where would you send them?
com, tons of public facing resources in both of those places. Um, and also you can feel free to reach out to me too if you've got questions, wanna connect with someone at cloud play that can help you, uh, talk through or solve a problem that you've got in the network connectivity or security space. It's very kind to you.
Thank you Annika Mitchell, thanks for joining me on here. We hope you've enjoyed this, uh, episode of the last great cloud transformation. And make no mistake, it is a great cloud transformation, right?
There's a lot going on here and we'd love to hear from you about what you are doing in your last great cloud transformation. And the best way to do that is to join one of our live sessions of this show where you'll have a chance to, to do that. Uh, we'll put the information in the notes here for our next episode.
But until then, on behalf of Textron Group at Cloud FLA and Annika and Mitchell and myself, have a great day everyone. Thanks for joining us.

