Qualys already secures 1,000 seats with Cloudflare Access and Gateway. As Cisco pushes AnyConnect and Umbrella customers onto a new "Secure Client" bundle, extend the platform already proven inside Qualys to the remaining 2,700 seats — and add DLP, CASB and Browser Isolation for all 3,700 — instead of standing up a second Zero Trust stack from the vendor you're trying to leave.
Qualys enters this decision from a position of scale: 3,647 employees (per Qualys's LinkedIn company page, accessed September 2026), 10,000+ subscription customers across a majority of the Forbes Global 100, and 11% year-over-year revenue growth in Q2 FY26 with a 47% adjusted EBITDA margin (Qualys Investor Relations, accessed September 2026). On July 29, 2026, Qualys announced expanded AI governance inside its own TotalAI product — new controls to discover shadow AI, govern AI agents and MCP servers, and prove controls are working to regulators under the EU AI Act (Qualys press release, July 29, 2026).
At the same time, Cisco's own product pages now market "Cisco Secure Client (including AnyConnect)" and cross-sell the "Umbrella Roaming" module and Ivanti-displacement offers on that same page (cisco.com, accessed September 2026) — a clear signal that the VPN and SWG stack Qualys runs today on the other 2,700 seats is being re-platformed by its own vendor, on Cisco's timeline, whether Qualys asks for it or not. The lowest-risk response to a forced vendor migration is rarely "adopt the new bundle from the same vendor" — it's extending the Zero Trust platform that already has a year of production history inside Qualys.
The same Access deployment already protecting 1,000 Qualys seats extends to the remaining 2,700 — application-level, identity-aware access instead of a network-level VPN client that has to be reinstalled fleet-wide under Cisco's new bundle.
Secure web gateway, DNS filtering and app-category policy move onto the same edge already inspecting traffic for 1,000 users — closing the gap for the 2,700 seats still relying on Umbrella today.
Qualys's own product protects customer vulnerability and exposure data — the same discipline is worth applying internally. DLP profiles catch scan results, CVE intel, and customer risk data leaving through unsanctioned channels, including copy/paste into GenAI chat windows.
API-based CASB scans sanctioned SaaS (Salesforce, Microsoft 365, GitHub) for misconfiguration, and — critically — discovers the unsanctioned SaaS and GenAI apps employees have already connected with a corporate identity, before they show up as a finding in someone else's audit.
Qualys researchers routinely browse threat intel sources, malware samples and unknown links as part of the job. RBI executes that browsing in a remote, disposable container — nothing risky ever touches the endpoint — and does the same for unmanaged GenAI web apps that shouldn't get local file or clipboard access.
TotalAI (announced July 29, 2026) discovers and scores AI/agent risk. AI Gateway and Firewall for AI sit underneath it as the enforcement layer — a governed front door for every outbound LLM call with logging, rate limits and spend caps, plus inline defense against prompt injection and model abuse on any AI endpoint Qualys exposes. Governance layer plus network layer, not one replacing the other.
Every play above runs on the client and control plane already installed on 1,000 Qualys devices — not a second agent, not a second admin console. As Qualys's own engineering teams stand up internal MCP servers and AI agents, front them with Cloudflare Access so only authorized users and agents can reach them — the same identity-aware policy already governing every app today. The result: one vendor, one bill, one set of logs for the SOC — instead of stitching together whatever Cisco bundles into "Secure" next.
| Function | Today | How it was identified | On Cloudflare |
|---|---|---|---|
| Remote access VPN | Cisco AnyConnect acct-team | Account-team input (~2,700 seats) | Cloudflare Access |
| Secure web gateway / DNS filtering | Cisco Umbrella acct-team | Account-team input | Cloudflare Gateway |
| Zero Trust (existing) | Cloudflare Access + Gateway, 1,000 seats | Account-team input | Expand to 3,700 seats |
| Data loss prevention | Not deployed org-wide | Account-team input | Cloudflare DLP — 3,700 seats |
| SaaS / shadow-AI visibility | Not deployed | Account-team input | Cloudflare CASB — 3,700 seats |
| Isolation for high-risk browsing | Not deployed | Account-team input | Browser Isolation — 3,700 seats |
| Vendor re-platform pressure | Cisco "Secure Client" (incl. AnyConnect) + Umbrella Roaming identified | cisco.com/site/us/en/products/security/secure-client (Sept 2026) | N/A — the forcing function |
| Public web edge & DNS (qualys.com) | Cloudflare identified | server: cloudflare; cf-ray; NS = *.ns.cloudflare.com | Already Cloudflare |