SlideShare a Scribd company logo
1 of 23
Going beyond the cloud to modernize
your banking infrastructure
Colin Murray, Solutions Engineer
Derek Yee, Director of Product Marketing
Colin Murray
Solutions Engineer
Cloudflare
Today’s speakers
Derek Yee
Director of Product Marketing
Cloudflare
We are entirely focused on moving to the public cloud.
Everything new we build new on AWS. We have been
migrating legacy applications.
Rob Alexander, CIO, Capital One
Forces of change in banking
Customers
Digital savvy,
multi-channel
customers
Competition
Smaller players
are often more
nimble and
competitive
Legacy apps
Many banking
applications are
dated
Automation
The need for
greater
efficiency and
agility
Modernizing architecture and infrastructure
On Prem Hybrid Cloud Native Multi CloudPrivate Cloud
Modern MicroservicesMonolithic Legacy Stacks
Flexibility
Elasticity
Scalability
Reliability
Agility
Why Cloud?
Challenges of cloud migrations
Integration
How to work with existing
systems, including legacy
or on-prem.
Complexity
How to balance the
benefits of an off the shelf
solution with bespoke
requirements.
Security/compliance
Security is ranked as IT’s top
concern when it comes to the
cloud.
Business alignment
IT and business need to work
hand-in-hand to determine
strategic goals.
We are building a
Global Cloud Network
where anything connected to
the Internet faster, more
secure, and more reliable.
Where Cloudflare sits in your network
Previous Generation
Applications
Network Edge
Store and
compute
NOW
Hardware / Software - Capital expenditures Services / Cloud - Operating expenses
180Data centers globally
2.8BMonthly active visitors
generating 1.4 trillion
page view
8MRequests/second
websites, apps & APIs
in 150+ countries
16M+
2x
Speed up each
request by
Cloudflare’s Global Anycast Network
11
Customer: Large Global Bank
The customer is a long
established New York
based financial institution
with over $1.5 trillion of
assets under
management.
CHALLENGES
• Wanted to replace Akamai Prolexic.
• Required DDoS and infrastructure protection
• Spikes in DNS traffic that customer had not been aware of
• Needed to pass bank’s IT architectural review board
CLOUDFLARE SOLUTION
• Started with DNS
• Always-on, unmetered DDoS solution, no human intervention
required
• Application layer security
DNS performance and scale
Global Anycast network
• 180+ data centers
• 75 countries (including China)
• Over 1.5M queries per second
Record propagation
• Globally in seconds
• P99 < 2 minutes
Deployment models
DNS
Primary DNS
● Records managed via
API/Dashboard/Terraform
● DNSSEC Managed by
Cloudflare
Secondary DNS
● DNS Only
● Records managed via Zone
Transfer (AXFR/IXFR)
DNS Firewall
● DNS Only
● Records
managed/signed at
Origin server(s)
● Does not require NS
change
Cloudflare Load Balancing
Americas
• Health checks with fast failover
• Global and local load balancing
American
Consumers
European
Consumers
Origin pool
Asian
Consumers
Europe
Origin pool
Asia
Origin pool
Configuration made simple
Easy configuration in the Cloudflare
dashboard, or automation through a
powerful API.
DDoS resilient service
Anycast network that is 10X bigger
than the largest DDoS attack ever
recorded ensures traffic continues to
be routed even under stress.
Global DNS network
Health checks from each Cloudflare
data center enables fast failover
unbound by DNS propagation delays.
Security is everyone’s concern
SECURITY
Largest DDoS attack had
1.3 terabits/sec2
Brand Reputation
1 - Google study, 2 - Wired.com, 3- Forrester
Factors increasing exposure to security risks
Greater scrutiny by
government and media
around data, privacy
and security
Greater attack surface area
from more public APIs, moving
to the cloud, and increasing
third-party integrations
Stronger and more
sophisticated attackers
18
Industry Legacy Scrubbing
● Long propagation times (up to 300 sec)
● Asynchronous routing
● Adds significant latency
● Typically requires manual intervention and
regular testing (config drift)
Always-On
● Zero propagation time
● Synchronous routing
● No added latency; ongoing perf. improvements
● Immediate, automated mitigation, with no
“cutover” required
Industry On-Demand vs. Cloudflare Always On
Cloudflare Security Summary
19
Cloudflare continues to
out-innovate the
market, driving growth
in security-only deals
The threat landscape is
exploding with the
growth in new platforms
and devices; security
solution use cases are
expanding to meet
them
Cloud-based solutions
reduce complexity,
improve time to
response and combine
performance and
security in a single,
integrated offering
Data-driven threat
intelligence dynamically
adapts our platform to
meet the ever changing
threat landscape
IDC MarketScape: WW DDoS Prevention Solutions
IDC MarketScape vendor analysis model is designed to provide an overview of the competitive fitness of ICT suppliers in a given market. The research methodology utilizes a rigorous
scoring methodology based on both qualitative and quantitative criteria that results in a single graphical illustration of each vendor’s position within a given market. The Capabilities
score measures vendor product, go-to-market and business execution in the short-term. The Strategy score measures alignment of vendor strategies with customer requirements in a
3-5-year timeframe. Vendor market share is represented by the size of the icons.
Cloudflare is positioned as a
Leader
in the IDC MarketScape:
Worldwide DDoS Prevention
Solutions 2019 Assessment
According to IDC, Cloudflare Strengths are its
"unique architecture" and "rapid on-boarding
process which is considered one of the easiest
and fastest in the industry."
Source: IDC MarketScape: Worldwide DDoS Prevention Solutions 2019
Vendor Assessment, by Martha Vazquez, March 2019, IDC #US43699318
Report Link: here
CDN Web
optimization
Mobile
optimization
WAN
optimization
Traffic
monitoring
Apps
platform
Serverless
compute
Cloudflare Services
PERFORMANCE SECURITY RELIABILITY
PLATFORM
21
DNS
Anycast
network
Load
balancing
Always
online
Perimeter
security
WAFDDoS
IoT
security
Getting started with Cloudflare
Q&A

More Related Content

What's hot

What's hot (20)

Cybersecurity 2020 threat landscape and its implications (AMER)
Cybersecurity 2020 threat landscape and its implications (AMER)Cybersecurity 2020 threat landscape and its implications (AMER)
Cybersecurity 2020 threat landscape and its implications (AMER)
 
Strengthening security posture for modern-age SaaS providers
Strengthening security posture for modern-age SaaS providersStrengthening security posture for modern-age SaaS providers
Strengthening security posture for modern-age SaaS providers
 
Kentik and Cloudflare Partner to Mitigate Advanced DDoS Attacks
Kentik and Cloudflare Partner to Mitigate Advanced DDoS AttacksKentik and Cloudflare Partner to Mitigate Advanced DDoS Attacks
Kentik and Cloudflare Partner to Mitigate Advanced DDoS Attacks
 
Stopping DDoS Attacks In South Africa
Stopping DDoS Attacks In South AfricaStopping DDoS Attacks In South Africa
Stopping DDoS Attacks In South Africa
 
Cyber Security 101
Cyber Security 101Cyber Security 101
Cyber Security 101
 
HARTMANN and Cloudflare Learn how healthcare providers can build resilient in...
HARTMANN and Cloudflare Learn how healthcare providers can build resilient in...HARTMANN and Cloudflare Learn how healthcare providers can build resilient in...
HARTMANN and Cloudflare Learn how healthcare providers can build resilient in...
 
Cloudflare Partner Program 2020
Cloudflare Partner Program 2020Cloudflare Partner Program 2020
Cloudflare Partner Program 2020
 
Zero trust for everybody: 3 ways to get there fast
Zero trust for everybody: 3 ways to get there fastZero trust for everybody: 3 ways to get there fast
Zero trust for everybody: 3 ways to get there fast
 
It’s 9AM... Do you know what’s happening on your network?
It’s 9AM... Do you know what’s happening on your network?It’s 9AM... Do you know what’s happening on your network?
It’s 9AM... Do you know what’s happening on your network?
 
Cyber security fundamentals (Cantonese)
Cyber security fundamentals (Cantonese)Cyber security fundamentals (Cantonese)
Cyber security fundamentals (Cantonese)
 
What You're Missing With Your Current WAF Provider
What You're Missing With Your Current WAF ProviderWhat You're Missing With Your Current WAF Provider
What You're Missing With Your Current WAF Provider
 
Application layer attack trends through the lens of Cloudflare data
Application layer attack trends through the lens of Cloudflare dataApplication layer attack trends through the lens of Cloudflare data
Application layer attack trends through the lens of Cloudflare data
 
A Different Approach to Securing Your Cloud Journey
A Different Approach to Securing Your Cloud JourneyA Different Approach to Securing Your Cloud Journey
A Different Approach to Securing Your Cloud Journey
 
Empowering Digital Transformation in Financial Services
Empowering Digital Transformation in Financial ServicesEmpowering Digital Transformation in Financial Services
Empowering Digital Transformation in Financial Services
 
Cyber security fundamentals
Cyber security fundamentalsCyber security fundamentals
Cyber security fundamentals
 
Desafíos de la Ciberseguridad en un ecosistema digitalmente transformado
Desafíos de la Ciberseguridad en un ecosistema digitalmente transformadoDesafíos de la Ciberseguridad en un ecosistema digitalmente transformado
Desafíos de la Ciberseguridad en un ecosistema digitalmente transformado
 
Business Continuity and app Security
Business Continuity and app Security Business Continuity and app Security
Business Continuity and app Security
 
Proteja sus datos en cualquier servicio Cloud y Web de forma unificada
Proteja sus datos en cualquier servicio Cloud y Web de forma unificadaProteja sus datos en cualquier servicio Cloud y Web de forma unificada
Proteja sus datos en cualquier servicio Cloud y Web de forma unificada
 
F5 Networks: The Internet of Things - Ready Infrastructure
F5 Networks: The Internet of Things - Ready InfrastructureF5 Networks: The Internet of Things - Ready Infrastructure
F5 Networks: The Internet of Things - Ready Infrastructure
 
3 Reasons It's Time for a New Remote Access Model
3 Reasons It's Time for a New Remote Access Model3 Reasons It's Time for a New Remote Access Model
3 Reasons It's Time for a New Remote Access Model
 

Similar to Going Beyond the Cloud to Modernize Your Banking Infrastructure

Cloudcomputingppt 12746363271272 Phpapp01
Cloudcomputingppt 12746363271272 Phpapp01Cloudcomputingppt 12746363271272 Phpapp01
Cloudcomputingppt 12746363271272 Phpapp01
Chindala Murali
 

Similar to Going Beyond the Cloud to Modernize Your Banking Infrastructure (20)

Introduction of Cloudflare Solution for Mobile Payment
Introduction of Cloudflare Solution for Mobile PaymentIntroduction of Cloudflare Solution for Mobile Payment
Introduction of Cloudflare Solution for Mobile Payment
 
Optimize the Value of Your Mainframe
Optimize the Value of Your MainframeOptimize the Value of Your Mainframe
Optimize the Value of Your Mainframe
 
MT01 The business imperatives driving cloud adoption
MT01 The business imperatives driving cloud adoptionMT01 The business imperatives driving cloud adoption
MT01 The business imperatives driving cloud adoption
 
Do more clouds = better scalability, availability, flexibility
Do more clouds = better scalability, availability, flexibility Do more clouds = better scalability, availability, flexibility
Do more clouds = better scalability, availability, flexibility
 
Richard Knight: Real world stories from the frontline of enterprise Cloud
Richard Knight: Real world stories from the frontline of enterprise CloudRichard Knight: Real world stories from the frontline of enterprise Cloud
Richard Knight: Real world stories from the frontline of enterprise Cloud
 
#PCMVision: VMware NSX - Transforming Security
#PCMVision: VMware NSX - Transforming Security#PCMVision: VMware NSX - Transforming Security
#PCMVision: VMware NSX - Transforming Security
 
Claire Vyvyan, Embracing the Hybrid Cloud
Claire Vyvyan, Embracing the Hybrid CloudClaire Vyvyan, Embracing the Hybrid Cloud
Claire Vyvyan, Embracing the Hybrid Cloud
 
Accenture & Commvault
Accenture  & CommvaultAccenture  & Commvault
Accenture & Commvault
 
No Cloud is an Island
No Cloud is an IslandNo Cloud is an Island
No Cloud is an Island
 
How to develop a multi cloud strategy to accelerate digital transformation - ...
How to develop a multi cloud strategy to accelerate digital transformation - ...How to develop a multi cloud strategy to accelerate digital transformation - ...
How to develop a multi cloud strategy to accelerate digital transformation - ...
 
Connecting the Clouds - RightScale Compute 2013
Connecting the Clouds - RightScale Compute 2013Connecting the Clouds - RightScale Compute 2013
Connecting the Clouds - RightScale Compute 2013
 
SoftLayer Company Overview
SoftLayer Company OverviewSoftLayer Company Overview
SoftLayer Company Overview
 
EMEA Tech Summit Dublin - Winning with SolidFire
EMEA Tech Summit Dublin - Winning with SolidFire EMEA Tech Summit Dublin - Winning with SolidFire
EMEA Tech Summit Dublin - Winning with SolidFire
 
Conquering Disaster Recovery Challenges and Out-of-Control Data with the Hybr...
Conquering Disaster Recovery Challenges and Out-of-Control Data with the Hybr...Conquering Disaster Recovery Challenges and Out-of-Control Data with the Hybr...
Conquering Disaster Recovery Challenges and Out-of-Control Data with the Hybr...
 
Cloudcomputingppt 12746363271272 Phpapp01
Cloudcomputingppt 12746363271272 Phpapp01Cloudcomputingppt 12746363271272 Phpapp01
Cloudcomputingppt 12746363271272 Phpapp01
 
Cloud Computing
Cloud Computing Cloud Computing
Cloud Computing
 
Cloud Computing Ppt
Cloud Computing PptCloud Computing Ppt
Cloud Computing Ppt
 
Vucci IBM Smart Cloud Presentation
Vucci IBM Smart Cloud PresentationVucci IBM Smart Cloud Presentation
Vucci IBM Smart Cloud Presentation
 
Cloud computing by Bhavesh
Cloud computing by BhaveshCloud computing by Bhavesh
Cloud computing by Bhavesh
 
Cloudera + Syncsort: Fuel Business Insights, Analytics, and Next Generation T...
Cloudera + Syncsort: Fuel Business Insights, Analytics, and Next Generation T...Cloudera + Syncsort: Fuel Business Insights, Analytics, and Next Generation T...
Cloudera + Syncsort: Fuel Business Insights, Analytics, and Next Generation T...
 

More from Cloudflare

More from Cloudflare (15)

Succeeding with Secure Access Service Edge (SASE)
Succeeding with Secure Access Service Edge (SASE)Succeeding with Secure Access Service Edge (SASE)
Succeeding with Secure Access Service Edge (SASE)
 
Close your security gaps and get 100% of your traffic protected with Cloudflare
Close your security gaps and get 100% of your traffic protected with CloudflareClose your security gaps and get 100% of your traffic protected with Cloudflare
Close your security gaps and get 100% of your traffic protected with Cloudflare
 
Why you should replace your d do s hardware appliance
Why you should replace your d do s hardware applianceWhy you should replace your d do s hardware appliance
Why you should replace your d do s hardware appliance
 
Don't Let Bots Ruin Your Holiday Business - Snackable Webinar
Don't Let Bots Ruin Your Holiday Business - Snackable WebinarDon't Let Bots Ruin Your Holiday Business - Snackable Webinar
Don't Let Bots Ruin Your Holiday Business - Snackable Webinar
 
Why Zero Trust Architecture Will Become the New Normal in 2021
Why Zero Trust Architecture Will Become the New Normal in 2021Why Zero Trust Architecture Will Become the New Normal in 2021
Why Zero Trust Architecture Will Become the New Normal in 2021
 
Scaling service provider business with DDoS-mitigation-as-a-service
Scaling service provider business with DDoS-mitigation-as-a-serviceScaling service provider business with DDoS-mitigation-as-a-service
Scaling service provider business with DDoS-mitigation-as-a-service
 
Recent DDoS attack trends, and how you should respond
Recent DDoS attack trends, and how you should respondRecent DDoS attack trends, and how you should respond
Recent DDoS attack trends, and how you should respond
 
Cyber security fundamentals (simplified chinese)
Cyber security fundamentals (simplified chinese)Cyber security fundamentals (simplified chinese)
Cyber security fundamentals (simplified chinese)
 
Bring speed and security to the intranet with cloudflare for teams
Bring speed and security to the intranet with cloudflare for teamsBring speed and security to the intranet with cloudflare for teams
Bring speed and security to the intranet with cloudflare for teams
 
Cloudflareのソリューションを使用して悪意のあるBot対策
Cloudflareのソリューションを使用して悪意のあるBot対策Cloudflareのソリューションを使用して悪意のあるBot対策
Cloudflareのソリューションを使用して悪意のあるBot対策
 
Webinar - Cyber Security basics in Japanese
Webinar - Cyber Security basics in JapaneseWebinar - Cyber Security basics in Japanese
Webinar - Cyber Security basics in Japanese
 
How to Plan for Performance and Scale for Multiplayer Games
How to Plan for Performance and Scale for Multiplayer GamesHow to Plan for Performance and Scale for Multiplayer Games
How to Plan for Performance and Scale for Multiplayer Games
 
Fight bad bot on the internet
Fight bad bot on the internetFight bad bot on the internet
Fight bad bot on the internet
 
Web Performance Without Sacrificing Security: Featuring Forrester Guest Speaker
Web Performance Without Sacrificing Security: Featuring Forrester Guest SpeakerWeb Performance Without Sacrificing Security: Featuring Forrester Guest Speaker
Web Performance Without Sacrificing Security: Featuring Forrester Guest Speaker
 
Authentication, Security, and Performance for the Internet of Things
Authentication, Security, and Performance for the Internet of ThingsAuthentication, Security, and Performance for the Internet of Things
Authentication, Security, and Performance for the Internet of Things
 

Recently uploaded

+971581248768>> SAFE AND ORIGINAL ABORTION PILLS FOR SALE IN DUBAI AND ABUDHA...
+971581248768>> SAFE AND ORIGINAL ABORTION PILLS FOR SALE IN DUBAI AND ABUDHA...+971581248768>> SAFE AND ORIGINAL ABORTION PILLS FOR SALE IN DUBAI AND ABUDHA...
+971581248768>> SAFE AND ORIGINAL ABORTION PILLS FOR SALE IN DUBAI AND ABUDHA...
?#DUbAI#??##{{(☎️+971_581248768%)**%*]'#abortion pills for sale in dubai@
 

Recently uploaded (20)

Data Cloud, More than a CDP by Matt Robison
Data Cloud, More than a CDP by Matt RobisonData Cloud, More than a CDP by Matt Robison
Data Cloud, More than a CDP by Matt Robison
 
Exploring the Future Potential of AI-Enabled Smartphone Processors
Exploring the Future Potential of AI-Enabled Smartphone ProcessorsExploring the Future Potential of AI-Enabled Smartphone Processors
Exploring the Future Potential of AI-Enabled Smartphone Processors
 
Artificial Intelligence Chap.5 : Uncertainty
Artificial Intelligence Chap.5 : UncertaintyArtificial Intelligence Chap.5 : Uncertainty
Artificial Intelligence Chap.5 : Uncertainty
 
+971581248768>> SAFE AND ORIGINAL ABORTION PILLS FOR SALE IN DUBAI AND ABUDHA...
+971581248768>> SAFE AND ORIGINAL ABORTION PILLS FOR SALE IN DUBAI AND ABUDHA...+971581248768>> SAFE AND ORIGINAL ABORTION PILLS FOR SALE IN DUBAI AND ABUDHA...
+971581248768>> SAFE AND ORIGINAL ABORTION PILLS FOR SALE IN DUBAI AND ABUDHA...
 
Powerful Google developer tools for immediate impact! (2023-24 C)
Powerful Google developer tools for immediate impact! (2023-24 C)Powerful Google developer tools for immediate impact! (2023-24 C)
Powerful Google developer tools for immediate impact! (2023-24 C)
 
Automating Google Workspace (GWS) & more with Apps Script
Automating Google Workspace (GWS) & more with Apps ScriptAutomating Google Workspace (GWS) & more with Apps Script
Automating Google Workspace (GWS) & more with Apps Script
 
Boost PC performance: How more available memory can improve productivity
Boost PC performance: How more available memory can improve productivityBoost PC performance: How more available memory can improve productivity
Boost PC performance: How more available memory can improve productivity
 
Apidays New York 2024 - Scaling API-first by Ian Reasor and Radu Cotescu, Adobe
Apidays New York 2024 - Scaling API-first by Ian Reasor and Radu Cotescu, AdobeApidays New York 2024 - Scaling API-first by Ian Reasor and Radu Cotescu, Adobe
Apidays New York 2024 - Scaling API-first by Ian Reasor and Radu Cotescu, Adobe
 
Apidays Singapore 2024 - Building Digital Trust in a Digital Economy by Veron...
Apidays Singapore 2024 - Building Digital Trust in a Digital Economy by Veron...Apidays Singapore 2024 - Building Digital Trust in a Digital Economy by Veron...
Apidays Singapore 2024 - Building Digital Trust in a Digital Economy by Veron...
 
How to Troubleshoot Apps for the Modern Connected Worker
How to Troubleshoot Apps for the Modern Connected WorkerHow to Troubleshoot Apps for the Modern Connected Worker
How to Troubleshoot Apps for the Modern Connected Worker
 
Boost Fertility New Invention Ups Success Rates.pdf
Boost Fertility New Invention Ups Success Rates.pdfBoost Fertility New Invention Ups Success Rates.pdf
Boost Fertility New Invention Ups Success Rates.pdf
 
Top 5 Benefits OF Using Muvi Live Paywall For Live Streams
Top 5 Benefits OF Using Muvi Live Paywall For Live StreamsTop 5 Benefits OF Using Muvi Live Paywall For Live Streams
Top 5 Benefits OF Using Muvi Live Paywall For Live Streams
 
Axa Assurance Maroc - Insurer Innovation Award 2024
Axa Assurance Maroc - Insurer Innovation Award 2024Axa Assurance Maroc - Insurer Innovation Award 2024
Axa Assurance Maroc - Insurer Innovation Award 2024
 
Polkadot JAM Slides - Token2049 - By Dr. Gavin Wood
Polkadot JAM Slides - Token2049 - By Dr. Gavin WoodPolkadot JAM Slides - Token2049 - By Dr. Gavin Wood
Polkadot JAM Slides - Token2049 - By Dr. Gavin Wood
 
presentation ICT roal in 21st century education
presentation ICT roal in 21st century educationpresentation ICT roal in 21st century education
presentation ICT roal in 21st century education
 
Apidays New York 2024 - The value of a flexible API Management solution for O...
Apidays New York 2024 - The value of a flexible API Management solution for O...Apidays New York 2024 - The value of a flexible API Management solution for O...
Apidays New York 2024 - The value of a flexible API Management solution for O...
 
Strategies for Unlocking Knowledge Management in Microsoft 365 in the Copilot...
Strategies for Unlocking Knowledge Management in Microsoft 365 in the Copilot...Strategies for Unlocking Knowledge Management in Microsoft 365 in the Copilot...
Strategies for Unlocking Knowledge Management in Microsoft 365 in the Copilot...
 
Bajaj Allianz Life Insurance Company - Insurer Innovation Award 2024
Bajaj Allianz Life Insurance Company - Insurer Innovation Award 2024Bajaj Allianz Life Insurance Company - Insurer Innovation Award 2024
Bajaj Allianz Life Insurance Company - Insurer Innovation Award 2024
 
Scaling API-first – The story of a global engineering organization
Scaling API-first – The story of a global engineering organizationScaling API-first – The story of a global engineering organization
Scaling API-first – The story of a global engineering organization
 
Repurposing LNG terminals for Hydrogen Ammonia: Feasibility and Cost Saving
Repurposing LNG terminals for Hydrogen Ammonia: Feasibility and Cost SavingRepurposing LNG terminals for Hydrogen Ammonia: Feasibility and Cost Saving
Repurposing LNG terminals for Hydrogen Ammonia: Feasibility and Cost Saving
 

Going Beyond the Cloud to Modernize Your Banking Infrastructure

  • 1. Going beyond the cloud to modernize your banking infrastructure Colin Murray, Solutions Engineer Derek Yee, Director of Product Marketing
  • 2. Colin Murray Solutions Engineer Cloudflare Today’s speakers Derek Yee Director of Product Marketing Cloudflare
  • 3. We are entirely focused on moving to the public cloud. Everything new we build new on AWS. We have been migrating legacy applications. Rob Alexander, CIO, Capital One
  • 4. Forces of change in banking Customers Digital savvy, multi-channel customers Competition Smaller players are often more nimble and competitive Legacy apps Many banking applications are dated Automation The need for greater efficiency and agility
  • 5. Modernizing architecture and infrastructure On Prem Hybrid Cloud Native Multi CloudPrivate Cloud Modern MicroservicesMonolithic Legacy Stacks
  • 7. Challenges of cloud migrations Integration How to work with existing systems, including legacy or on-prem. Complexity How to balance the benefits of an off the shelf solution with bespoke requirements. Security/compliance Security is ranked as IT’s top concern when it comes to the cloud. Business alignment IT and business need to work hand-in-hand to determine strategic goals.
  • 8. We are building a Global Cloud Network where anything connected to the Internet faster, more secure, and more reliable.
  • 9. Where Cloudflare sits in your network
  • 10. Previous Generation Applications Network Edge Store and compute NOW Hardware / Software - Capital expenditures Services / Cloud - Operating expenses
  • 11. 180Data centers globally 2.8BMonthly active visitors generating 1.4 trillion page view 8MRequests/second websites, apps & APIs in 150+ countries 16M+ 2x Speed up each request by Cloudflare’s Global Anycast Network 11
  • 12. Customer: Large Global Bank The customer is a long established New York based financial institution with over $1.5 trillion of assets under management. CHALLENGES • Wanted to replace Akamai Prolexic. • Required DDoS and infrastructure protection • Spikes in DNS traffic that customer had not been aware of • Needed to pass bank’s IT architectural review board CLOUDFLARE SOLUTION • Started with DNS • Always-on, unmetered DDoS solution, no human intervention required • Application layer security
  • 13. DNS performance and scale Global Anycast network • 180+ data centers • 75 countries (including China) • Over 1.5M queries per second Record propagation • Globally in seconds • P99 < 2 minutes
  • 14. Deployment models DNS Primary DNS ● Records managed via API/Dashboard/Terraform ● DNSSEC Managed by Cloudflare Secondary DNS ● DNS Only ● Records managed via Zone Transfer (AXFR/IXFR) DNS Firewall ● DNS Only ● Records managed/signed at Origin server(s) ● Does not require NS change
  • 15. Cloudflare Load Balancing Americas • Health checks with fast failover • Global and local load balancing American Consumers European Consumers Origin pool Asian Consumers Europe Origin pool Asia Origin pool Configuration made simple Easy configuration in the Cloudflare dashboard, or automation through a powerful API. DDoS resilient service Anycast network that is 10X bigger than the largest DDoS attack ever recorded ensures traffic continues to be routed even under stress. Global DNS network Health checks from each Cloudflare data center enables fast failover unbound by DNS propagation delays.
  • 16. Security is everyone’s concern SECURITY Largest DDoS attack had 1.3 terabits/sec2 Brand Reputation 1 - Google study, 2 - Wired.com, 3- Forrester
  • 17. Factors increasing exposure to security risks Greater scrutiny by government and media around data, privacy and security Greater attack surface area from more public APIs, moving to the cloud, and increasing third-party integrations Stronger and more sophisticated attackers
  • 18. 18 Industry Legacy Scrubbing ● Long propagation times (up to 300 sec) ● Asynchronous routing ● Adds significant latency ● Typically requires manual intervention and regular testing (config drift) Always-On ● Zero propagation time ● Synchronous routing ● No added latency; ongoing perf. improvements ● Immediate, automated mitigation, with no “cutover” required Industry On-Demand vs. Cloudflare Always On
  • 19. Cloudflare Security Summary 19 Cloudflare continues to out-innovate the market, driving growth in security-only deals The threat landscape is exploding with the growth in new platforms and devices; security solution use cases are expanding to meet them Cloud-based solutions reduce complexity, improve time to response and combine performance and security in a single, integrated offering Data-driven threat intelligence dynamically adapts our platform to meet the ever changing threat landscape
  • 20. IDC MarketScape: WW DDoS Prevention Solutions IDC MarketScape vendor analysis model is designed to provide an overview of the competitive fitness of ICT suppliers in a given market. The research methodology utilizes a rigorous scoring methodology based on both qualitative and quantitative criteria that results in a single graphical illustration of each vendor’s position within a given market. The Capabilities score measures vendor product, go-to-market and business execution in the short-term. The Strategy score measures alignment of vendor strategies with customer requirements in a 3-5-year timeframe. Vendor market share is represented by the size of the icons. Cloudflare is positioned as a Leader in the IDC MarketScape: Worldwide DDoS Prevention Solutions 2019 Assessment According to IDC, Cloudflare Strengths are its "unique architecture" and "rapid on-boarding process which is considered one of the easiest and fastest in the industry." Source: IDC MarketScape: Worldwide DDoS Prevention Solutions 2019 Vendor Assessment, by Martha Vazquez, March 2019, IDC #US43699318 Report Link: here
  • 21. CDN Web optimization Mobile optimization WAN optimization Traffic monitoring Apps platform Serverless compute Cloudflare Services PERFORMANCE SECURITY RELIABILITY PLATFORM 21 DNS Anycast network Load balancing Always online Perimeter security WAFDDoS IoT security
  • 22. Getting started with Cloudflare
  • 23. Q&A