Cloudflare: Leading Cybersecurity [Business Breakdownes Ep 241]Cloudflare Final
Cloudflare: Leading Cybersecurity [Business Breakdownes Ep 241]Cloudflare Final
Summary
- Cloudflare now runs over 20% of the world’s web traffic through “a single global private network,” absorbing “over 2 and a half million cyber attacks every single second,” on $2B+ of annualized revenue. Sam Eden of Square Peg’s Global Tech Fund frames the whole business as one insight compounding for 15 years: intercept everything once, then layer product after product on the same commodity hardware.
- The moat is a reinforcing loop, not a product: cheap hardware plus a generous free tier attracts the long tail, more traffic means more threat data and more peering leverage with 13,000+ networks, driving costs down and quality up. “This network gets better as it gets bigger” — and legacy players like Akamai couldn’t follow because simple interception threatened their enterprise revenue, while scaling it technically was difficult.
- The three “acts” — website services (~2/3 of revenue), zero-trust corporate security (~30%, highest incremental gross margin), and the developer platform — all run on the same boxes, diversifying capex ROI. Cloudflare won one large customer because its DDoS capacity was “over four times the two legacy competitors combined,” absorbing 30+ Tbps; 3M+ developers build on Workers, many entirely within the free tier.
- The enterprise go-to-market rebuild is the near-term inflection: after 2023 rep-productivity declines and layoffs, ex-Palo Alto sales president Mark Anderson has large-customer revenue growth accelerating from ~30% to 40% YoY, and Q3 NRR jumped from 112% to 119%. “Pool of funds” bundling (one $130M/5-year deal) is already low double digits of ACV, RPO grows ~40% YoY, and channel-partner revenue at 30% of total vs. ~90% for Zscaler/Netskope implies a long runway.
- Latest reporting put 80% of top AI-native companies among Cloudflare’s customers, and Workers AI serves inference from GPUs across 330 cities — enabled because Cloudflare’s motherboards “left an empty slot open” for an unknown future use case. But Eden flags this as the strategic divergence risk: GPU ROI is concentrated in one product rather than split across all services, and inference was pursued as a market opportunity rather than emerging from internal tooling.
- The outage “wasn’t an attack… it was a process error” — an upstream error doubled the bot-management model’s features, and a corrupted file was pushed every five minutes until servers ran out of memory — and Eden argues the transparent same-day report, like CrowdStrike 2024, leaves the franchise intact. Matt Reustle’s frame: like Moody’s or Equifax, “if it doesn’t kill them it kind of proves the moat.”
- Valuation is the honest sticking point: ~25x NTM revenue at the start of the year means “there’s effectively no margin for execution error… this is priced for pretty flawless execution.” Getting comfortable requires modeling Act 2 catching up to and perhaps surpassing incumbents and Act 3/inference becoming very large; FCF margins near 10% (capex 11–14% of revenue) are guided to 25%+, which Square Peg thinks they can exceed.
Deep dive
1. The postal-service model: speed and security for anything with a URL
- Eden’s opener: Cloudflare’s original product protects any public website — “your weekend hobby project” or the largest sites on earth — from DDoS floods, traffic interception, and bot scraping. His analogy: Cloudflare is a sorting factory intercepting all your mail, blocking junk and organized spam attacks, scanning packages, then extending to “local warehouses” (CDN caching) and “dedicated fast freeways” across the postal network.
- The Shopify example, on Matt’s prompt: a botnet hits a merchant storefront on Black Friday; without Cloudflare the servers overload and the store goes dark — “if your website’s down, well, you’re not making any revenue.” Cloudflare absorbs the attack at the edge.
- Scale, before anything else: over 20% of world web traffic and “an average of over 2 and a half million cyber attacks every single second” absorbed and blocked. Matt’s reaction: “somewhat frightening.”
2. The world before, and Project Honeypot
- Cloudflare was founded in 2009 by Matthew Prince, Michelle Zatlyn, and Lee Holloway. Pre-2009, legacy CDNs like Akamai split the network: customers decided what went on the CDN vs. direct, bought physical firewalls separately, and needed sales engineers for complex implementations — enterprise-only, with “no solution for the long tail of websites.”
- Founding trio: Matthew Prince (childhood computer tinkerer, literature degree, lawyer, ducked out of taking over the family business — including a Hooters — for HBS), Michelle Zatlyn (met at HBS; “Matthew brings the vision, Michelle brings the operational rigor”), and technical co-founder Lee Holloway, later diagnosed with frontotemporal dementia — “his technical influence remains strong throughout Cloudflare today.”
- Project Honeypot, the precursor: tracker email addresses that spammers scraped, building “effectively a do not call list for spammers.” Hundreds of thousands installed it, and the network-effect DNA was set: “the more users, the better the service because the list got bigger.”
3. The breakthrough: one proxy that intercepts everything
- Rather than multiple reverse proxies with split rules, customers just say “my new mailing address is Cloudflare” — every service can then be toggled on without a sales engineer, making Cloudflare “the first real product-led growth company for internet services.” Matt’s question — were they getting paid? — draws the recurring theme: no, the generous free tier is the moat-builder.
- Why incumbents didn’t copy it: revenue (“a classic case of the innovator’s dilemma” — enterprises didn’t want simple interception) and cost — intercepting all traffic at scale is difficult, solved with commodity hardware and a software-defined network “inspired by Google.”
- Early adopters were nonprofits (high traffic, no budget) and the hacker community protecting itself — “if they could protect hackers, then they could protect a more basic website as well.”
4. Peering leverage and the reinforcing loop
- Aggregating the long tail gave negotiating power with ISPs: “why don’t I just put my server next to yours?” — the ISP escapes transfer fees, its internet speeds up, and Cloudflare often doesn’t have to pay bandwidth fees. Matt asks whether the ISP is the loser; Eden insists it is win-win, since customers blame slow internet on the ISP. Today the single network connects directly to over 13,000 networks.
- The flywheel Eden calls the most important part of the business: cheap hardware and easy product → long-tail adoption → more traffic and threat signal → better blocking and optimization → more enterprise customers → more peering leverage and lower costs → reinvestment into more products. “This network gets better as it gets bigger… an incredibly difficult system to replicate” after 15 years.
5. Three acts on one network
- Act 1 hit a tipping point where capacity and services beat the legacy vendors: a recent large-customer win came because DDoS protection capacity was “over four times the two legacy competitors combined” — over 30 terabytes per second absorbed easily.
- Act 2 flips the proxy: the same hardware inspects outbound corporate traffic instead of inbound website traffic. Zero trust means “just because you could access app number one doesn’t mean you can access app number two” — every web request inspected every time, “which looks a lot like their original services.” Three buckets: employee-to-public-internet traffic, internal app access, and adjacencies like phishing/email security.
- Act 3 grew from Cloudflare’s internal tooling: nobody else, including AWS, could handle their scale, so they built proprietary software — then realized developers could build powerful products with the same tools. Workers serverless functions, storage, lightweight databases; 3M+ developers; free tier of 100,000 Worker queries/day and 10GB storage with zero egress fees. Canonical use case: an edge script swapping local pricing or language faster than querying a central database.
6. AI: everywhere around the market, plus one deliberate bet
- Eden’s map: adjacent tailwinds (agents reading data without egress fees), serving AI companies directly — latest reporting put 80% of top AI-native companies among Cloudflare’s customers — and inference itself via Workers AI.
- The empty-slot story is the tell on long-term strategy: when designing their motherboards, “they left an empty slot open because they didn’t know what the use case would be… it turns out AI inference was that something.” GPUs plugged into servers across 330 cities, with no pre-provisioning — “you only pay for the AI inference that you use.”
- His flagged risk: this diverges from the model where every box runs every product. GPU ROI “is just from the AI inference — a more concentrated ROI risk,” and unlike Acts 2 and 3, which emerged from what Cloudflare was already doing internally, “they just saw the importance of the market and decided to go after it.”
7. The go-to-market rebuild: Anderson, pool of funds, partners
- The PLG-to-enterprise transition stumbled — 2023 rep productivity dropped and much of the sales team was let go — before Mark Anderson (ex-president of sales at Palo Alto Networks, CEO of Alteryx) arrived in 2024. Hiring shifted to majority-enterprise reps; large-customer revenue growth inflected “from around 30% up to 40% year-over-year.” Customers over $100K are under 1.5% of the base but ~75% of revenue, and at a $2B run-rate Cloudflare has under 200 $1M+ customers vs. Zscaler’s ~500 at the same size — the runway.
- Pool of funds fixes the three-buyer friction: multi-year commitments (one $130M five-year contract) drawable against any product, encouraging experimentation with newer Acts. Rolled out in 2024, already low double digits of total ACV, with RPO growing ~40% YoY and NRR reaccelerating from 112% to 119% in Q3.
- Channel partners, under new hire Tom Evans (ex-Palo Alto worldwide channel lead): partner-led growth ~65% YoY for two years, incremental revenue from partners up from ~20% to over 40%. At 30% of total revenue vs. ~90% for Zscaler and Netskope, “they’re just getting started.” Since larger partners often monetize implementation services rather than product cuts, that can help protect Cloudflare’s margins; Act 2 is the highest-incremental-gross-margin business.
8. The model in numbers: charge for complexity, not volume
- Freemium is doctrinal: free users get unmetered DDoS protection and free CDN bandwidth — “they’re not going to punish you” for being attacked — with monetization on complexity (rules, bot management) via subscription tiers in Act 1 and usage pricing in Act 3. Eden’s proof point: Square Peg built “quite sophisticated AI products” internally on Cloudflare and “our bills have been remarkably low.” Revenue splits roughly two-thirds Act 1, ~30% Act 2, with Act 3 still smaller but growing very quickly; there are 55+ revenue-generating products, and customers with 10+ products are the fastest-growing category.
- Margins need adjustment: non-GAAP gross margin of 75–78% carries ~6% of revenue in equipment depreciation — cash-basis comparison lands at 83–85%. Capex runs 11–14% of revenue, FCF margins ~10% with management guiding to 25%+, and sales & marketing at 35% of revenue is the main opportunity for operating leverage.
- Capital allocation discipline: “investing behind the demand curve,” commodity hardware, and — the key — every server runs every product, so each capex dollar’s ROI is split across Acts 1, 2, and 3.
9. Outage, Zscaler, and a valuation with no room for error
- On the outage: “it wasn’t an attack. It wasn’t a security breach… it was a process error” — an upstream error doubled the bot-management model’s features, and a corrupted file was pushed every five minutes until servers ran out of memory. Eden’s parallel is CrowdStrike 2024, and the transparent same-day incident report was appreciated by the engineering-focused community; an earlier Google Cloud KV-cache outage even accelerated the migration off third-party software. Matt’s framing — Moody’s, Equifax — “if it doesn’t kill them it kind of proves the moat.”
- Act 2 is more competitive and Cloudflare is admittedly the second mover behind Zscaler, which has an incumbent advantage with large enterprises. But the network argument bites: a request routed through Zscaler may still end at a Cloudflare-protected site — “we’re processing all of this traffic anyway, why don’t we process it on the way out as well?” The Canva example carries it: Southeast Asian design contractors get agentless inline access with low latency because Cloudflare has peering relationships and has improved connectivity in those markets for years, while Zscaler’s direct app-peering model may work less well in certain markets.
- Eden’s intellectually honest close on valuation: ~25x NTM revenue at the start of the year, “one of the highest in the industry,” sustained ~29–30% growth, but “there’s effectively no margin for execution error — this is priced for pretty flawless execution.” You must believe Act 2 can catch up to and perhaps surpass incumbents and Act 3 inference “can be a very large business.” Matt compared it with headlines implying ~100x sales for a SpaceX IPO: it “makes it look cheap.”
- The pattern-recognition takeaways, mapped to Square Peg’s theme/team/model/moat framework: founder DNA, product simplicity atop technical sophistication (Snowflake, Datadog analogies), multiple growth levers, and the contrarian one — “capex in software can be okay provided that it has that very high ROI.” The thesis in one line: “a business that gets better as it gets bigger.”