SASE / Cloudflare One · concept brief for SK pharmteco

Converge the network and the security across every site.

SK pharmteco runs manufacturing and labs across the US, Europe, and Asia — and is already on Cloudflare. The next step isn't another point tool; it's collapsing VPN, site-to-site networking, and a stack of security products into one platform. Cloudflare One connects every plant and secures every user — employees, contractors, and partners touching client IP — on a single policy plane and a single audit trail, alongside the Microsoft stack you already run.

VPN + MPLS → one
Retire point tools + private circuits for one network
Every site
US · Europe · Asia connected on Cloudflare
One audit trail
Access + data movement logged for GxP / Part 11

A global CDMO's network and security grew one tool at a time. VPN for remote and contractor access. MPLS or SD-WAN between plants and labs. Separate products for web filtering, SaaS control, data loss, and isolation. Each was bought to solve one problem — and together they're expensive, slow to change, and impossible to audit as one. Meanwhile the thing that matters most — clients' crown-jewel IP: formulations, process data, batch records — is reached every day by a workforce spread across countries, on access rules that are hard to prove in a GxP or 21 CFR Part 11 audit. SASE collapses that sprawl into one converged platform.

Network and security, on one platform.

SASE = the convergence of how you connect (network) and how you protect (security). Cloudflare One delivers both — start with access, expand across the whole platform.

Security services (SSE)

  • ZTNA — per-app, least-privilege access; replaces VPN
  • SWG — secure web gateway + DNS filtering for every user
  • CASB — visibility + control over M365 and SaaS
  • DLP — keep formulations, batch records & client IP in-bounds
  • Browser Isolation — sandbox the web away from regulated endpoints

Network services

  • Magic WAN — connect every plant & lab over Cloudflare
  • Retire MPLS / legacy SD-WAN — branch security built in
  • One global backbone — 330+ cities, low-latency between sites
  • Unified policy — one control plane for traffic + security
  • One audit trail — every access + flow logged for compliance

Start with one site. Converge from there.

No rip-and-replace. Land with the fastest win, expand across the same console.

01 — Start here

ZTNA — replace VPNLand

Identity-aware, least-privilege access to the systems holding client IP — every employee, contractor, and partner reaches only what they're entitled to, fully logged for GxP / 21 CFR Part 11. The fastest, most measurable first win.

02

Secure the web + data

Add SWG, CASB, DLP, and Browser Isolation from the same console — web filtering, SaaS control, and data-loss prevention that keep crown-jewel IP inside sanctioned apps and off exposed endpoints.

03

Connect the sites — Magic WAN

Bring the global plants and labs onto Cloudflare's network. Modernize or retire MPLS/SD-WAN, with branch security built in. This is the network half of SASE — and where the consolidation savings get large.

04

One plane, one audit trail

Network and security policy in one console, every access and data flow logged together — so proving who reached what, when, is a query, not a forensic project. Built for a regulated, audited environment.

Built to sit alongside what you run today.

SK pharmteco already runs on Microsoft 365 and Entra ID for identity — and on Cloudflare for DNS today. Cloudflare One integrates with Entra (identity) and Intune (device posture), so this strengthens your Microsoft investment rather than replacing it. Cloudflare and Microsoft are partners. And because it's one platform, the move consolidates spend — VPN, SD-WAN, and point security tools collapse into a single subscription, instead of adding another.

From a tool per problem to one network for the company.

SK pharmteco is trusted with the most sensitive IP in medicine, across sites on three continents. SASE is how that becomes one connected, secured, auditable network instead of a stack of tools — starting with Zero Trust access and expanding to the whole platform. 30 minutes to map it to your footprint.

Matt Holscher · Cloudflare Digital Native team