Tech and Coffee

S2E7 | Building a Safer Internet with James Todd, #Cloudflare CTO, #WSQ2026

Ahmad Zainalabdeen Season 2 Episode 7

Use Left/Right to seek, Home/End to jump to start or end. Hold shift to jump forward or backward.

0:00 | 17:31

Send us Fan Mail

🔒 بناء إنترنت أكثر أماناً | Building a Safer Internet
مع جيمس تود من Cloudflare | with James Todd from Cloudflare


في هذه الحلقة، نستضيف جيمس تود من Cloudflare للحديث عن تأمين الإنترنت على نطاق واسع.

In this episode, we sit down with James Todd from Cloudflare to explore how they're securing the internet at scale.

نناقش في هذه الحلقة | We discuss:
• الحماية من هجمات DDoS | DDoS protection & the threat landscape
• بنية Zero Trust وأهميتها | Zero trust architecture
• الحوسبة الطرفية وتأثيرها على المنطقة | Edge computing in MENA
• كيف تحمي شركتك | How businesses can protect themselves

🎬 تم التسجيل في Web Summit Qatar 2026 🇶🇦
Recorded at Web Summit Qatar 2026

0:00 Intro & Web Summit
1:15 E-commerce Performance
2:30 Handling Black Friday & Ramadan Traffic
4:00 DDoS Protection & Security
6:00 Disaster Recovery
7:30 Cloudflare in Middle East 🇶🇦🇸🇦🇦🇪🇰🇼
9:00 Data Sovereignty
10:30 AI & Bot Detection
12:00 Protecting Content from AI Crawlers
13:30 Future: Agentic Commerce & Payments
15:30 Content Creation & Media
17:00 Closing


🎙️ تك اند كوفي | Tech and Coffee
📺 اشترك | Subscribe: [link|https://youtube.com/@tech.and.coffee]
🎧 سبوتيفاي | Spotify: [link|https://open.spotify.com/show/2qCPRIhCUQt9cb37mV7mgk]
🎧 آبل بودكاست | Apple Podcasts: [link|https://podcasts.apple.com/eg/podcast/tech-and-coffee/id1493504725]


#Cloudflare #الأمن_السيبراني #Cybersecurity #EdgeComputing #ZeroTrust #WebSummitQatar #TechAndCoffee #تك_اند_كوفي #بودكاست

Support the show

Uh James, how are you doing? Yeah, I am good, thank you. Okay, so uh actually um this is a very good chance that we have web summit here in James as CTO of Cloudflare which is I'm very happy that we have this very quick chat. Hopefully we can have more uh chats and yeah first tell me about uh how do you see uh web summit uh web summit I mean it's the first web summit I've attended and I'm impressed by the size of it and also the breadth of attendees and speakers I think for a company like cloudflare where we have that approach to customers building connecting and securing their web properties on our our infrastructure something like web summit where we have both partners and customers attending. It's a great opportunity for us to to get the Cloudflare message out there. It's it's amazing that we have Cloudflare and as one of the one of the people who use in personal perspective and also business perspective, it's we can say um it's huge in the internet and it's huge in the area. So let's start with the very crucial uh thing which is every single business is caring about which is traffic and performance. So how does cloudflare is helping the e-commerce industry in such a domain which is very crucial for them speed and also performance right and we have a lot of cases in middle east which is we can tackle but at least how cloudflare is providing such a support for this yeah so I mean across across it's commerce spans all all of the four main areas that we focus on so connectivity and application security zero trust building modern applications and also as we move into the sort of agentic web space securing modern agentic commerce. Yeah. Um and particularly from a performance perspective for e-commerce platforms we've effectively designed the Cloudflare infrastructure to support that natively. So our ability to our global content distribution network and our ability to perform load balancing at the global scale allows us to really ensure that spikes in traffic through during events like Black Friday and Ramadan and and towards the holidays the content is equally distributed across our infrastructure. Now that's either from load balancing to the most optimal server or or indeed being able to smart route traffic across our global infrastructure. So that where you have a an e-commerce site that that has a both a local and a global customer base, we're able to distribute that in in in appropriate ways. Now, if it's a if it's a particular e-commerce site where you might have moment in time attractive pricing or a very hot product, we also have things like our virtual waiting room that enables fair um access to that that site for things like purchase now options where ordinarily you might see websites being brought down by surge of traffic for a particular item or a particular event. We're able to sort of balance that out globally but also very specifically for those those websites provide that waiting room function that is fair access to on a a first come first- serve basis to to that that especially we are reaching to holidays in the Middle East Ramadan and so which is very crucial for every single e-commerce platform to serve more customers in more stable way so which is currently as you know there is a lot of uh concerns across Ross all if you can say every single one does have a business blind they are very conscious and they are very very afraid of their security. So how Cloudflare is is helping them to be more you can say relax it a little bit so they cannot be afraid of their security how Cloudflare is helping these platforms to uh to pass the security step right so we I mean so from a we look at it from a different number of threats perspective so during those peak seasons it's very attractive for um particular adversaries to want to disrupt those websites right either hold them to ransom from a DOS perspect perspective. So our global DOS mitigation capability runs in the sort of hundreds of terabits per second. We have a very unique approach to absorbing high volume DOS attacks. We've seen that over recent months where high peaks of of volumetric DOS has been present. So by virtue of hosting or accessing customers accessing your e-commerce websites via Cloudflare, the our ability to absorb high volume DOS is is significant. If we look at other threats such as SQL ejection or carding, we also have things like our built-in web application firewalls and other proxy act event uh capabilities that allow us to and our customers to build a significant security barrier around around their e-commerce website. Yeah, totally absolutely great solutions. However, sometimes some businesses which is it depends on their size. Sometimes they say okay if we if we have this kind of um which is this is situation for sure they became a little bit uh afraid about the alter not alternative solutions but backup scenario or uh disaster recovery issue. So how they can uh or how cloud is mitigating such concerns for them. So in terms of availability yeah so we've seen a number of sort of high-profile outages over the last few months ourselves included. So what we're seeing a lot of our customers looking for is a viable secure fallback solution. So we we've invested significantly over the last two or three months to ensure that we have high availability and resiliency across our infrastructure where we are the primary provider of of services to our customers. But also we will work closely with our customers to build in resiliency and backup solutions should we fail or their other providers fail. So either onboard onto Cloudflare very quickly or provide an alternative where we run in parallel with another provider to ensure that that uptime is maintained. You mentioned a couple of outages which is was somehow everyone was saying okay it's a huge platform which is everyone was waiting for the great updates from the team which is yeah it passed very safely. Okay. So the next thing is um I can see cloudflare booth here for the last web summit and maybe the the one before which is cloud existence in the Middle East especially the Gulf area which is as you know Saudi Arabia and also UAE is is growing fast. How's Cloudflare is doing it in or approaching the existence in this area? Yeah. Yeah. So our our presence in in the Middle East has moved from from being available within the Middle East to having a presence in the Middle East. So we've we've over the last few years we've built out points of presence in data centers in the in the Middle East. So we have uh we have our capabilities our servers hosted within Doha, Riyad, Dubai and Q8 city now. So for and we and we continue to build out our presence. So that sort of really helped our customers have access to our services as local to them and their users as possible. Historically we would have gone to your traffic would have gone to Europe and back again. So we've reduced um latency from sort of 150 milliseconds measured to to the sort of low tens and and and sub 10 millisecond access to to to to global customers. We're also peering. We do this on a global basis. We have regional pairing now with Arrio and STC that allows customers that are served via those providers to get very quick access to Cloudflare infrastructure. So in this case the you know there's some requirements which is access must be inside the same region and J princed places and so I think now everyone is looking for this amazing solution they will be able to reach out to this one. Does it uh now fully rolled out or it's still in kind of uh specific um size of business or anyone can have? So we are I mean so we're what as well as having local presence we're obviously a global provider as well. A number of our customers globally want that regionalbased service and that and protection around data sovereignty. Um, so we're increasing our portfolio of those types of services, which means that if you want to serve a particular customer and have their log data and their telemetry only available within in installed with within one region, we're we're doing that. Equally, if you have users or customers of of your infrastructure and they are outside of your region, but you still want them to be served with local content, then we we have a solution for that as well. Yeah. Yeah. And our sovereignty portfolio is is growing with cryptographic solutions and things like that to build that for most of the kind this kind of uh restriction or something like that. So um yeah now we have we are in the AI era they can say and the BS and the agents and sub agents and all that stuff. So Cloudflare how uh is the AI currently and all this kind of uh artificial intelligence based everything. Yeah. how cloudare is positioned there, how they are using it, how it's getting going to be leveraged or available. So we are we've been using AI and machine learning in our in our own services for a long time. So you mentioned bots. We do a lot have and have done a lot in terms of being able to classify bot behavior um versus what would be observed from a normal user. So we have a number of tiering of classifications to look at whether the activity is by a human or a bot. And then once that's classified, we are able to look at whether that bot traffic is legitimate or malicious. Yes. And we continue to train those models with what we observe across our our global global network. very crucial because sometimes you know it's very difficult to differentiate between is it about something which is automatically working and taking us which is making a lot of issues or something which is yeah we have hype or we have a spike in our customers or our business is now booming uh and it's making making it for more of the people who having business like that which is they are very uh keen about such a thing and worried about are we going to be just AI is going to make all of these issues for us or it's something which is cloudflare is taking the advantage to help us to be more um secure and more um performing as better as the platform can do. Yeah, exactly. So we we're we're really focused on not only providing secure delivery of services via Cloudflare but also providing efficient and performant services as well. So you mentioned there that the the rise of bot traffic has an implication on both of those. So that's our real focus really. Amazing. So next is um some people and all everyone is asking okay what is next after AI is taking over if if it's going to take over. So what is the f the the future tech what is cloudflare technology is going to have in the future or is going to help us in the future and this maybe the e-commerce because this is the current race uh in the future. So cloud flare in the future how it's going to help. So we we're we're looking at research and investment in a number of fronts that will secure and and help the delivery of e-commerce. So you might have seen in the last 6 months or so we've we had a heavy focus around the sort of the change in the way that the internet the construct of the internet is being used. So we've got a heavy focus on AI crawlers at the moment and we'll continue to evolve that. So what we mean by that is being able to enable content creators and potentially e-commerce providers where you might have unique product set, you might have images that you want to protect your other content or uh you might want to um ensure that your pricing is up to date and and is and if you have an advantage competitively over pricing that you're not continuously being cruled by AI large language models as part of training or AI enabled search. you want users to view that traffic, not necessarily the the the the AI bots or agents, right? So, we we're putting in place crawl control that allows the content and the prov the content owners to take back control over who can scrape and access their website. And we're doing that dynamically. So, initially it's about being able to control who can do that and observe it uh and and limit limit their use usage. but also more and more is how we're helping evolution towards the agentic web and agentic commerce. So we've partnered with uh a number of organizations in the development of webbot orth which allows which will allow agents to transact and do microp payments for um on on user initiated commands. Right? So I'm looking for a gray jumper. It's in this price range. Go and find it for me. I need it to be in this size, this material, and go and buy it, right? And and that's what we want, right? From a from a an agentic commerce style environment. But at the moment, the mechanics aren't quite there to enable that payment. So, Webot or and trusted agent protocol and uh others from other um payment providers like Mastercard, MX, American Express, we're working with them so that the framework is underneath beneath that. So what that means is that anyone who's building an e-commerce agent on the Cloudflare platform will soon be able to take advantage of those major card and payment providers including other payment mechanisms like PayPal built into the agent that they create. So immediately building a commerce agent you'll be able the the users of that will be able to transact securely with the with the um uh storefront or e-commerce uh environment will have the same advantages of the security layers and all of the stuff which is and performance availability as well. I I think uh we'll not never stop here but actually our time is uh is a little bit uh limited. So I would like to have final uh thing which is uh you mentioned the content and serving content and all the stuff uh there is another part of the industry uh which is related to media production which is currently as you can see uh there is a lot of content creation right even AI is getting used heavily in content creation and publishing stuff so if we are if we're going to give an an opportunity if we if we can say how cloudflare will help uh the content creators right and medium producers to uh to be more um available uh more faster more high quality um material if there is something which is going uh to be there or already there in cloudflare which is can support so we've got a number of solutions so within our cloudflare developer platform we've built a number of composable primitives that allow developers to create capabilities for a number of different reasons right and you mentioned multimedia a lot of commerce sites that we have now are mediarich either in imagery or video. Um so we've put together a number of workloads that are now allow um developers let's say e-commerce sites to quickly create contentrich environments. Let's take images and video for example and and the content creation one go go goes down this route as well that to be able to upload create imagery and dynamically resize those for publication on a particular site and also pro dynamically provide more video content or dynamic content performance that is suitable for particular user. Right? So if they're on a low speed collection connection they might get a a lower quality image. someone on a higher quality connection will get a higher quality image and that's all dynamically done through our images and stream capability. The other thing that is also relevant is content personalization. So if you're an e-commerce site and you want for a particular user to serve particular content based on their browsing history or their their historical interaction with you, they would get different content versus someone else. Also geographically if you want if you had a users from from a different region um you would serve up potentially could dynamically serve up different content. So we have the construct to enable quick and easy development and publication of multimedia c uh content but also provide that multimedia content in a slightly different way based on who is accessing your site and where they're accessing it from. Amazing by the end of our uh podcast and interview. So I really thank you for this opportunity and looking forward to have uh more uh discussions around the the the region and technologies and yeah much appreciated. Thank you for I appreciate you for having me. Thank you very much. Thank you. Thank you.