× Cloudflare
Talk to Cloudflare →
Executive Brief · Zero Trust Expansion

The Zero Trust platform Qualys already runs — extended to every seat, not replaced by Cisco.

Qualys already secures 1,000 seats with Cloudflare Access and Gateway. As Cisco pushes AnyConnect and Umbrella customers onto a new "Secure Client" bundle, extend the platform already proven inside Qualys to the remaining 2,700 seats — and add DLP, CASB and Browser Isolation for all 3,700 — instead of standing up a second Zero Trust stack from the vendor you're trying to leave.

Why now

Two things are true at the same time this quarter — one about Qualys, one about Cisco.

Qualys enters this decision from a position of scale: 3,647 employees (per Qualys's LinkedIn company page, accessed September 2026), 10,000+ subscription customers across a majority of the Forbes Global 100, and 11% year-over-year revenue growth in Q2 FY26 with a 47% adjusted EBITDA margin (Qualys Investor Relations, accessed September 2026). On July 29, 2026, Qualys announced expanded AI governance inside its own TotalAI product — new controls to discover shadow AI, govern AI agents and MCP servers, and prove controls are working to regulators under the EU AI Act (Qualys press release, July 29, 2026).

At the same time, Cisco's own product pages now market "Cisco Secure Client (including AnyConnect)" and cross-sell the "Umbrella Roaming" module and Ivanti-displacement offers on that same page (cisco.com, accessed September 2026) — a clear signal that the VPN and SWG stack Qualys runs today on the other 2,700 seats is being re-platformed by its own vendor, on Cisco's timeline, whether Qualys asks for it or not. The lowest-risk response to a forced vendor migration is rarely "adopt the new bundle from the same vendor" — it's extending the Zero Trust platform that already has a year of production history inside Qualys.

From two Zero Trust stacks to one

What Qualys runs today across its 3,700-seat workforce (*per account-team), plus what Cisco is pushing next. The right is where it all can live.
2 stacks → 1 network
Cloudflare Access + Gateway1,000 seats · today*
Cisco AnyConnectVPN · ~2,700 seats*
Cisco UmbrellaSWG / DNS*
Cisco Secure Clientforced re-platform, incoming
Ungoverned GenAI / agentsshadow AI, per Qualys's own TotalAI PR
Cloudflare One one WARP agent · one console · 3,700 seats
Goal: zero Cisco VPN/SWG seats left to migrate

Seven plays: expand what works, retire what's being forced on you

The first two extend a platform Qualys already trusts. The next three add capability Cisco's stack doesn't give you today. The last two are where GenAI and agentic AI live.
01

Cloudflare Access — expand ZTNA to 3,700 seats

↳ replaces Cisco AnyConnect

The same Access deployment already protecting 1,000 Qualys seats extends to the remaining 2,700 — application-level, identity-aware access instead of a network-level VPN client that has to be reinstalled fleet-wide under Cisco's new bundle.

  • No new agent to roll out — WARP is already on 1,000 devices
  • Per-app access policy, not flat network access like AnyConnect
  • Same admin console Qualys IT already operates today
02

Cloudflare Gateway — expand SWG/DNS to 3,700 seats

↳ replaces Cisco Umbrella

Secure web gateway, DNS filtering and app-category policy move onto the same edge already inspecting traffic for 1,000 users — closing the gap for the 2,700 seats still relying on Umbrella today.

  • DNS + HTTP filtering on one policy engine with Access
  • Category and app controls extend to ChatGPT/Copilot/Gemini-class traffic
  • Removes the separate Umbrella Roaming client Cisco is now upselling
03

Cloudflare DLP — new, 3,700 seats

New capability · not in the AnyConnect/Umbrella stack

Qualys's own product protects customer vulnerability and exposure data — the same discipline is worth applying internally. DLP profiles catch scan results, CVE intel, and customer risk data leaving through unsanctioned channels, including copy/paste into GenAI chat windows.

  • Predefined + custom detections for source code, keys, PII
  • Inline inspection of uploads to unsanctioned SaaS and AI tools
  • Same policy engine as Access & Gateway — no new console
04

Cloudflare CASB — new, 3,700 seats

New capability · SaaS & shadow-AI discovery

API-based CASB scans sanctioned SaaS (Salesforce, Microsoft 365, GitHub) for misconfiguration, and — critically — discovers the unsanctioned SaaS and GenAI apps employees have already connected with a corporate identity, before they show up as a finding in someone else's audit.

  • Out-of-band posture checks across core SaaS
  • Shadow IT / shadow AI app discovery from real traffic
  • Feeds the same policy engine driving Access, Gateway & DLP
05

Browser Isolation — new, 3,700 seats

New capability · isolate high-risk & unmanaged AI browsing

Qualys researchers routinely browse threat intel sources, malware samples and unknown links as part of the job. RBI executes that browsing in a remote, disposable container — nothing risky ever touches the endpoint — and does the same for unmanaged GenAI web apps that shouldn't get local file or clipboard access.

  • Isolates threat-research and unknown-link browsing by default
  • Clipboard, download and print controls for unmanaged AI sites
  • Pairs with CASB findings to auto-isolate newly discovered shadow apps
06

AI Gateway + Firewall for AI

Augments Qualys TotalAI · network enforcement layer

TotalAI (announced July 29, 2026) discovers and scores AI/agent risk. AI Gateway and Firewall for AI sit underneath it as the enforcement layer — a governed front door for every outbound LLM call with logging, rate limits and spend caps, plus inline defense against prompt injection and model abuse on any AI endpoint Qualys exposes. Governance layer plus network layer, not one replacing the other.

  • One log of every model call, for the same auditors Qualys already serves
  • Cache & rate-limit to control token spend across providers
  • Inline prompt-injection and abuse defense at the network edge
07

One WARP agent, one console, one audit log — secure Zero Trust access for MCP and agents too

↳ retires the dual AnyConnect + Umbrella Roaming agents Cisco ships today

Every play above runs on the client and control plane already installed on 1,000 Qualys devices — not a second agent, not a second admin console. As Qualys's own engineering teams stand up internal MCP servers and AI agents, front them with Cloudflare Access so only authorized users and agents can reach them — the same identity-aware policy already governing every app today. The result: one vendor, one bill, one set of logs for the SOC — instead of stitching together whatever Cisco bundles into "Secure" next.

  • Single WARP client replaces AnyConnect + Umbrella Roaming
  • Zero Trust in front of internal MCP servers and agent endpoints
  • One commercial relationship covering all 3,700 seats across 5 modules

Expansion roadmap

Sequenced around the seats Qualys already has live, ahead of Cisco's own Secure Client migration timeline.
Next 90 days

Expand to full coverage

  • Extend Access + Gateway from 1,000 → 3,700 seats
  • Pilot DLP + CASB with security, R&D and finance teams
  • Map Cisco AnyConnect concentrators & Umbrella policies for cutover
  • Inventory GenAI tools already in use (CASB discovery pass)
By 6 months

Retire the Cisco stack

  • Roll DLP, CASB and Browser Isolation to all 3,700 seats
  • Decommission Cisco Umbrella DNS policies & AnyConnect profiles
  • Consolidate to a single WARP agent fleet-wide
  • Unify Zero Trust logging into one SOC-ready dataset
By 12 months

Govern GenAI & agentic AI

  • Turn on AI Gateway + Firewall for AI for internal & product LLM traffic
  • Front internal MCP servers and agents with Cloudflare Access
  • Pair with TotalAI's discovery/scoring for a full govern + enforce loop
  • One Zero Trust vendor, one contract, ahead of Cisco's forced deadline

Consolidation snapshot

Current-state Cloudflare and Cisco footprint is account-team input; the Cisco re-platform signal and Qualys scale figures are public record.
FunctionTodayHow it was identifiedOn Cloudflare
Remote access VPN Cisco AnyConnect acct-team Account-team input (~2,700 seats) Cloudflare Access
Secure web gateway / DNS filtering Cisco Umbrella acct-team Account-team input Cloudflare Gateway
Zero Trust (existing) Cloudflare Access + Gateway, 1,000 seats Account-team input Expand to 3,700 seats
Data loss prevention Not deployed org-wide Account-team input Cloudflare DLP — 3,700 seats
SaaS / shadow-AI visibility Not deployed Account-team input Cloudflare CASB — 3,700 seats
Isolation for high-risk browsing Not deployed Account-team input Browser Isolation — 3,700 seats
Vendor re-platform pressure Cisco "Secure Client" (incl. AnyConnect) + Umbrella Roaming identified cisco.com/site/us/en/products/security/secure-client (Sept 2026) N/A — the forcing function
Public web edge & DNS (qualys.com) Cloudflare identified server: cloudflare; cf-ray; NS = *.ns.cloudflare.com Already Cloudflare

How we know

Public signals are from DNS, HTTP headers and vendor-published pages. Internal footprint and seat targets are marked as account-team input.
Cloudflare already fronting qualys.com (cf-ray, cloudflare NS) Cisco Secure Client folded AnyConnect + Umbrella Roaming, cisco.com Proofpoint MX / SPF (email) Microsoft 365 spf.protection.outlook.com Salesforce include:_spf.salesforce.com 1,000 seats Access + Gateway *per account-team Cisco AnyConnect / Umbrella ~2,700 seats *per account-team
LIVE Checking the Cloudflare edge serving this page…