This analysis explains why Cloudflare leads in cybersecurity. The guest argues its edge comes from a self-reinforcing cycle: more traffic leads to more data, better service, more paying customers, lower costs, and more network investment—hard for rivals to copy. Key holdings: Cloudflare (over $2B annual revenue but priced for perfection); Akamai (legacy competitor, now surpassed 4x in DDoS capacity); Zscaler (main rival in enterprise security, Cloudflare has room to grow channel sales).
Cloudflare, as a globally leading cybersecurity company, controls over 20% of global web traffic and absorbs 2.5 million cyberattacks per second. This report provides an in-depth analysis of Cloudflare's rise, distinguishing itself from existing competitors and emerging players through differentiate
Guest Sam Eden (Investor at Square Peg Global Tech Fund) provides an in-depth breakdown of Cloudflare's rise from its founding in 2009 to the present day. Core thesis: Cloudflare's competitive advantage stems from a self-reinforcing cycle — more traffic → more data → better services → more paying customers → stronger pricing power → lower costs → more network investment. After 15 years of accumulation, this cycle has become extremely difficult to replicate.
Sam Eden argues that Cloudflare's early innovation lay in replacing the industry's fragmented multi-proxy architecture with a unified reverse proxy.
Before 2009, the website security and acceleration market was dominated by traditional CDN providers like Akamai. Their model required customers to decide which content to place on the CDN and which to handle directly, with configuration requiring sales engineer involvement—complex to implement and costly to maintain. Meanwhile, websites also needed to purchase separate physical firewalls to block malicious traffic. This model served only large enterprises, leaving the long tail of websites unaddressed.
Cloudflare's founder Matthew Prince (with a Harvard Business School background and prior experience founding Project Honeypot—a project that collected blacklists of spam senders) and co-founder Lee Holloway (the technical lead, who later left the company due to frontotemporal dementia) made a key breakthrough: They did not split the network but instead intercepted all traffic, using a single unified reverse proxy to handle everything.
"You don't need multiple reverse proxies for different tasks; you only need one reverse proxy—that is Cloudflare—which can do many things." (Sam Eden)
The power of this architecture lies in the fact that customers only need to point their DNS to Cloudflare, and any subsequent new service (CDN, DDoS protection, etc.) can be activated with a single click, without reconfiguration. This made Cloudflare the first company in the internet services space to truly achieve product-led growth (PLG)—anyone could quickly sign up, including those "weekend hobby projects" and small websites.
The early customer base was surprising: a large number of hackers also registered with Cloudflare to protect themselves. "Because hackers can be hacked too. If they can protect hackers, they can protect even more basic websites." (Sam Eden)
Sam Eden argues that Cloudflare's most formidable moat is its 15-year accumulated reinforcement cycle, a system that is extremely difficult to replicate.
The cycle operates as follows:
1. Low-cost hardware + user-friendly products → Attract long-tail customers: In its early days, Cloudflare decided to use commodity hardware, inspired by Google to build a software-defined network, significantly reducing hardware costs. At the same time, a generous free tier allowed anyone to easily get started.
2. More traffic → More data → Better service: As traffic grows, Cloudflare collects more signals, continuously improving its ability to block malicious activity and optimize network speed.
3. Better service → More paying customers → More traffic: Enhanced service quality attracts enterprise customers, driving higher revenue.
4. More traffic → Stronger ISP bargaining power → Lower costs: Cloudflare has established direct peering relationships with over 13,000 networks globally (ISPs, cloud providers, enterprise networks). For ISPs, this is a win-win—they no longer need to pay for cross-network transit fees, while user experience improves.
5. Cost savings reinvested → Network expansion → More products: Savings on bandwidth costs and revenue are reinvested into expanding the global network, creating more products, and the cycle continues.
The key characteristic of this cycle: the bigger the network, the better. A recent example is Cloudflare winning a large client in a bidding process because its DDoS protection capacity exceeded the combined total of two traditional competitors by four times—over 30 TB/s.
Why don't competitors follow suit? Sam Eden points to two reasons:
Sam Eden divides Cloudflare's product evolution into three phases, each building on the infrastructure of the previous one.
This is Cloudflare's founding business, offering DDoS protection, CDN, bot management, and more. Key differentiator: no traffic-based pricing. Free users receive unlimited DDoS protection and free CDN bandwidth. Cloudflare charges based on complexity—only if you need custom rules and advanced bot management do you need to upgrade to a paid plan.
Cloudflare realized that since it was already intercepting external traffic (reverse proxy), using the same infrastructure to intercept internal employees' traffic to external networks (forward proxy) was a natural extension. This gave rise to the "zero trust" security products.
Three main use cases:
Why does Cloudflare have an advantage? Because the enterprise security perimeter has expanded to the entire internet (remote work, cloud adoption), and Cloudflare's global network happens to cover this scope. These products have the highest incremental gross margins because they leverage existing network infrastructure.
Cloudflare developed a large amount of proprietary software while building its own infrastructure (unable to rely on third parties like AWS). They realized these tools could also be offered to external developers. The flagship product is Cloudflare Workers—a serverless function service.
Key characteristics:
A specific use case: When a user loads a website, Workers can quickly execute localization tasks at the edge node (e.g., switching currency and language based on user location) without querying a central database.
Sam Eden believes Cloudflare plays four roles in the AI ecosystem, three of which involve direct participation.
1. Adjacent Tailwind: As enterprises adopt AI, they require more efficient data strategies (fast reading of large datasets, avoiding high egress fees). Cloudflare’s architecture is naturally suited for this.
2. Serving AI Companies Themselves: The latest data shows that 80% of top-tier AI-native companies are Cloudflare customers. This provides a customer base for Cloudflare to offer AI services.
3. AI Inference (Edge Inference): Cloudflare has launched the Workers AI product, providing AI inference services at edge nodes. Key detail: When designing server motherboards, Cloudflare reserved an empty slot—"not knowing what it would be used for in the future, but keeping it open." When the need for AI inference emerged, they simply inserted GPUs into all servers. Deployment has now been completed across servers in 330 cities worldwide.
4. Inference Differentiation: Unlike hyperscale cloud providers, Cloudflare’s inference service does not require pre-purchasing or pre-provisioning capacity; it charges based on actual usage. If not used for a day, no cost is incurred.
However, Sam Eden also points out risks: The AI inference strategy differs slightly from Cloudflare’s previous product launch approaches. Previously, Act 2 and Act 3 products "naturally grew out of internal needs"—observing utilization differences between day and night on servers, then seizing the opportunity. AI inference, in contrast, feels more like "actively entering after recognizing market importance." Additionally, the ROI of GPUs can only be borne by the AI inference business, unlike other hardware that can be allocated across all product lines, making the ROI more concentrated and the risk higher.
Sam Eden believes that Cloudflare is undergoing a transition from product-led growth to enterprise sales, and that the "wallet" bundling strategy is key to accelerating growth.
In 2023, Cloudflare encountered a decline in sales representative productivity, leading to a reduction in its sales team. In 2024, the company hired Mark Anderson as its new President of Revenue (formerly Sales President at Palo Alto Networks and CEO of Alteryx). The transformation focuses on:
Initial results: The growth rate for large customers (with annual revenue exceeding $100,000) has increased from approximately 30% to over 40%.
Historically, Cloudflare's three product lines (Act 1, 2, and 3) were purchased by different buyers who lacked communication with each other. The "wallet" strategy addresses this issue: large customers sign multi-year contracts (e.g., a recent $130 million, five-year contract) and receive a wallet that can be used across all product lines.
Key advantage: Customers plan to allocate 80% of the wallet to Act 1, while the remaining 20% can be flexibly used to try Act 2 and Act 3 products. This encourages the adoption of new products. The strategy was launched in 2024 and currently accounts for a low double-digit percentage of total annual contract value. Remaining performance obligations (RPO) have grown approximately 40% year-over-year, and the net revenue retention rate has recovered from 112% to 119%.
For Act 2 (internal security products), channel partners are critical—buyers typically procure these through system integrators and consulting firms. Cloudflare hired Tom Evans (formerly Head of Global Channel Sales at Palo Alto Networks) to lead partner relationships.
Results: Growth driven by channel partners has maintained approximately 65% year-over-year growth over the past two years, and the share of incremental revenue contributed by the channel has risen from 20% to over 40%. However, there remains significant room for expansion—Zscaler and Netskope generate approximately 90% of their revenue through channels, while Cloudflare currently generates only about 30%.
Sam Eden believes that Cloudflare’s valuation (25x forward revenue) requires flawless execution, but multiple growth levers support the high valuation.
| Metric | Data |
|---|---|
| Annualized Revenue | Over $2 billion |
| Non-GAAP Gross Margin | 75%-78% (including equipment depreciation) |
| Cash-Based Gross Margin (Adjusted) | Approximately 83%-85% |
| Capital Expenditure / Revenue | 11%-14% |
| Free Cash Flow Margin | Approximately 10% (Management target: over 25%) |
| Sales & Marketing Expense / Revenue | 35% |
| Net Revenue Retention Rate | 119% (Q3 2025, up from 112%) |
| Large Customers (>$100k/year) Share | Less than 1.5% of customers, contributing approximately 75% of revenue |
| Million-Dollar Customers | Fewer than 200 (compared to Zscaler’s approximately 500 in the same period) |
"Cloudflare’s valuation is among the highest in the industry—approximately 25x forward 12-month revenue at the start of the year. To accept this valuation, you must model two variables: the pace at which Act 2 catches up to and surpasses incumbents (the trajectory is solid), and the scale of Act 3 in the AI inference market (which we believe can become a very large business)." (Sam Eden)
Key Risk: There is no room for execution missteps. The stock price has already priced in flawless execution.
Sam Eden believes the outage exposed the fragility of a single global network, but Cloudflare’s transparent handling won customer trust.
The cause of the outage was not a security attack or data breach, but a process error: Cloudflare’s bot management software (a machine learning model) updates threat signatures every five minutes. An upstream error caused the signature file size to double, leading to insufficient server memory and service disruption.
Similarity to CrowdStrike’s 2024 outage: Both were process errors rather than security vulnerabilities, and both made the market realize how deeply embedded these companies’ systems are.
Positive aspect: Cloudflare released a detailed and transparent report on the same day, which was highly appreciated by its engineering-oriented customer base. The company has implemented process improvements to prevent similar incidents from recurring.
Historical precedent: A previous minor outage (triggered by a Google Cloud KV cache issue) actually accelerated Cloudflare’s internal project to reduce third-party dependencies—migrating more systems to proprietary in-house software.
| Position | Analyst View | Key Data |
|---|---|---|
| Cloudflare | Bullish, but valuation requires flawless execution | Controls >20% of global network traffic, absorbs 2.5 million cyberattacks per second, annual revenue >$2 billion, 25x forward revenue |
| Akamai | Traditional competitor, but has been overtaken | Cloudflare's DDoS mitigation capacity exceeds the combined capacity of two traditional competitors by 4x (>30 TB/s) |
| Zscaler | Main competitor in Act 2, Cloudflare is the second mover | At the same $2 billion revenue scale, Zscaler had nearly 500 million-dollar clients (Cloudflare had fewer than 200); ~90% of Zscaler's revenue comes through channels (Cloudflare ~30%) |
| Netskope | Competitor in Act 2 | ~90% of revenue through channels |
| Shopify | Customer case study | Used Cloudflare to defend against massive bot attacks during Black Friday |
| Canva | Customer case study | Used Cloudflare Act 2 products to provide secure access for Southeast Asian contractors (no agent installation required) |
| CrowdStrike | Analogy | The 2024 outage event is similar in nature to Cloudflare's 2025 outage |
| Snowflake | Analogy (product simplicity) | Powerful engine + simple query interface |
| Datadog | Analogy (product simplicity) | Easy to get started but flexible enough to serve large enterprises |
| Palo Alto Networks | Background reference | Former employer of Mark Anderson and Tom Evans |
1. "Cloudflare's moat is a 15-year reinforcement cycle: more traffic → more data → better service → more customers → lower costs → more investment." (Sam Eden) — The core of this cycle is a single global network + universal hardware + software-defined architecture, which competitors cannot quickly replicate.
2. "Cloudflare charges by complexity, not by traffic. Free users get unlimited DDoS protection — they do not penalize websites that are frequently attacked." (Sam Eden) — This stands in stark contrast to industry norms and is a key design element of product-driven growth.
3. "Cloudflare reserved an empty slot on the server motherboard — not knowing what it would be used for in the future, but keeping it open. When AI inference demand emerged, they simply plugged in a GPU." (Sam Eden) — A reflection of long-term strategic thinking, enabling rapid deployment of AI inference capabilities across 330 cities.
4. "Cloudflare's AI inference strategy differs from previous product launches: earlier products grew organically from internal needs, while AI inference feels more like an active entry after recognizing market importance." (Sam Eden) — This introduces a more concentrated ROI risk, as GPU returns can only be borne by the AI inference business.
5. "Cloudflare's channel revenue accounts for about 30%, while Zscaler and Netskope are around 90%. This implies significant room for growth." (Sam Eden) — The new channel head, Tom Evans (former global channel sales head at Palo Alto Networks), is driving this transformation.
6. "The pool strategy allows customers to flexibly experiment with new products: 80% of the plan is allocated to Act 1, and the remaining 20% can be used to experiment with Act 2 and Act 3. This has driven net revenue retention from 112% back to 119%." (Sam Eden) — The bundling strategy is yielding results.
7. "Cloudflare's valuation (25x forward revenue) demands flawless execution with no room for error. However, multiple growth levers (Act 2 catch-up, Act 3 AI inference, channel expansion) support sustained high growth." (Sam Eden) — Investors need to model the catch-up pace of Act 2 and the market size of Act 3.
8. "The outage was not a security attack but a process error — the machine learning model updated features every 5 minutes, and an upstream error caused the feature file to double, leading to insufficient server memory." (Sam Eden) — Similar in nature to the CrowdStrike 2024 outage, Cloudflare's transparent handling won customer trust.