What it is and what it does
Zero trust means access is checked against explicit rules. Cloudflare Access can give a person access to a particular private application, using their identity and device condition. Cloudflare Gateway addresses a different task: controlling staff traffic to the internet. Your proposal should state which services are included. Cloudflare: identity and device based private access.
What that means for your business
A maintenance supplier may need one service portal for a scheduled job. Give that named person access for the job, then remove it. Avoid allowing the same login to reach finance, unrelated servers, or the entire plant network.
Is this a baseline system?
Controlled remote access is a baseline when employees or suppliers connect remotely. A particular zero trust vendor is an implementation choice. Start with strong sign-in checks, limited permissions, prompt removal of old access, and a record of connections.
Will insurance ask about it?
Expect to discuss MFA for remote access and how outside parties connect. A zero trust purchase is not a substitute for proving that those checks apply to every relevant entry point. More complex sites should be ready to describe device checks, supplier access limits, and monitoring.
See the insurance sources and how to interpret the levels.
Minimum operating position
Named accounts, MFA, access to approved applications, an owner for exceptions, and an access removal process.
When the business needs stronger protection
Use phishing-resistant sign-in where practical, device health checks, time-limited supplier access, and monitored connection records. Test how staff work during an identity or connectivity outage.
Evidence to request from IT
- Remote access inventory, including older VPNs and vendor tools.
- A sample approved supplier account and its exact access.
- A test showing that a removed account can no longer connect.
What belongs in the budget
Include identity licenses, endpoint setup, supplier onboarding, connector maintenance, and support. Test old plant applications before replacing their existing access path.
A documented incident
Change Healthcare, 2024: one remote entry point lacked MFA
UnitedHealth’s CEO testified that attackers used compromised credentials to access a Citrix portal without MFA. The ransomware incident disrupted health care payments and claims. UnitedHealth CEO testimony to the Senate, May 2024 (PDF).
What this case shows: The documented gap was missing MFA on that entry point. The case supports checking every remote connection; it does not prove that Cloudflare was required to prevent the attack.
Sources and scope
- Cloudflare: identity and device based private access
- CISA: require multifactor authentication
- UnitedHealth CEO testimony to the Senate, May 2024 (PDF)
The baseline and stronger-protection positions are editorial planning guidance. Confirm your company’s required controls and insurance answers with the accountable IT owner and broker.