Enterprise

Cloudflare launches an eSIM to secure mobile devices

Comment

Cloudflare headquarters in San Francisco
Image Credits: Michael Short/Bloomberg / Getty Images

Are smartphones ever entirely secure? It depends on one’s definition of “secure,” particularly when dealing with corporate environments. Most companies with bring-your-own-device policies install apps or agents on workers’ smartphones to help secure them, leveraging the management capabilities built into operating systems like Android and iOS. But those might not be sufficient.

That’s what Cloudflare argues, anyway, in the pitch for the new services it’s launching this week. Today, the company announced Zero Trust SIM and Zero Trust for Mobile Operators, two product offerings targeting smartphone users, the companies securing corporate phones and the carriers selling data services.

Let’s start with Zero Trust SIM. Designed to secure all data packets leaving a smartphone, Zero Trust SIM — once launched in the U.S. (to start) — will be available as an eSIM deployable via existing mobile device management platforms to both iOS and Android devices. It’ll be locked to a specific device, mitigating the risk of SIM-swapping attacks, and usable either in a standalone configuration or in tandem with Cloudflare’s mobile agent, WARP.

In a recent email interview, Cloudflare CTO John Graham-Cumming made the case that Zero Trust SIM can accomplish what VPNs and other secure layers can’t: cell-level protection. A SIM card can act as another security factor, and — in combination with hardware keys — make it nearly impossible to impersonate an employee, he argued.

“Zero Trust SIM provides defense in depth. A VPN layer is one of those components, but doesn’t remove the need to still deploy cellular connectivity across all of your mobile devices today, and traditional ‘AnyConnect-style’ VPNs do nothing to stop attackers moving laterally once they’re inside the VPN,” Graham-Cumming said. “We continue to see organizations breached due to challenges securing their applications and networks, and what was once a real-estate budget is quickly becoming a ‘secure my remote and distributed workforce’ budget from an IT security perspective.”

Specifically, Graham-Cumming said that Zero Trust SIM will enable Cloudflare to rewrite DNS requests leaving a device to instead use Cloudflare Gateway for DNS filtering. It’ll also support validating every host and IP address before it reaches the internet and identity-based connectivity to services and other devices, and it can be used as a second factor for authentication, he added.

While pricing hasn’t been decided, Zero Trust SIM — which will launch in the next few months — will be treated as a part of Cloudflare’s Zero Trust platform from a billing perspective — Graham-Cumming says it’ll be an extension of the per-seat pricing Zero Trust customers have today. He expects that most devices will be compatible, and even more once Cloudflare begins providing physical SIM cards for the service, which it plans to do in the near future.

“Our intent is to start in the U.S., but quickly work to make this a global service — running a global network is a core part of what we do,” Graham-Cumming said. “Although we’re early in development here, we’re already working on parallel initiative in the industrial internet of things (IoT) space (e.g., vehicles, payment terminals, shipping containers, vending machines). The Zero Trust SIM is, itself, a foundational piece of technology that unlocks a lot of new use cases.”

On the subject of IoT, Cloudflare today previewed a platform for IoT devices — aptly called IoT Platform — with the goal of providing a single pane-of-glass view over a fleet of connected devices. Meant to compete with IoT management services from Microsoft Azure, Amazon Web Services and Google Cloud, Cloudflare’s offering handles ordering, provisioning and managing cellular connectivity and security for IoT.

Every packet that leaves each IoT device can be inspected, approved or rejected by policies customers create before it reaches the Internet, cloud, or other devices, according to Cloudflare. Moreover, devices can be locked to a specific geography to ensure that sensitive traffic doesn’t reach public channels.

More information will be available in the coming months as the formal launch of IoT Platform approaches, Cloudflare says.

Cloudflare had less to share on the Zero Trust for Mobile Operators front. A carrier partner program, Zero Trust for Mobile Operators will allow service providers to offer subscriptions to mobile security tools from Cloudflare’s Zero Trust platform, Graham-Cumming said. Interested operators can sign up starting today for more information.

One presumes that Zero Trust for Mobile Operators — and, for that matter, the new Zero Trust SIM — is pilot in what could become a lucrative line of business for Cloudflare beyond WARP, which the company launched on a freemium model three years ago. According to Allied Market Research, the global mobile security market was valued at $3.3 billion in 2020 and could reach $22.1 billion by 2030.

IoT Platform makes sense for Cloudflare, too, given the robustness of the IoT market. According to one source, enterprise IoT spending grew 22.4% in 2021 to $158 billion as tailwinds like supply chain challenges strengthened. The segment’s rife with incumbents, but Cloudflare’s evidently betting it can throw around enough weight to make a sizeable dent.

More TechCrunch

Today’s scams can be as simple as picking up a phone call. To avoid the next fraud, there are good reasons to let your calls run to voicemail.

For security, we have to stop picking up the phone

Featured Article

How a viral AI image catapulted a Mexican startup to a major adidas contract

Antonio Nuño, Fatima Alvarez, and Enrique Rodriguez have been friends since they were five years old. As teenagers, they became volunteers helping indigenous communities — first in Mexico, then in other countries — and saw that many of the women were artisans.  The trio came to realize that these artists…

How a viral AI image catapulted a Mexican startup to a major adidas contract

BDO, the auditor for Indian edtech startup Byju’s, has resigned with immediate effect, marking the second auditor departure for the embattled startup in about a year and further intensifying concerns…

Second Byju’s auditor exits in a year amid bankruptcy proceedings

A federal judge says he will deliver a punishment in Google’s antitrust case by August 2025, according to The New York Times, after ruling earlier this month that Google had…

Google to receive punishment for search monopoly by next August, says judge

ChatGPT, OpenAI’s text-generating AI chatbot, has taken the world by storm since its launch in November 2022. What started as a tool to hyper-charge productivity through writing essays and code…

ChatGPT: Everything you need to know about the AI-powered chatbot

The world will have to wait a little longer to see Blue Origin’s massive New Glenn rocket fly for the first time. That rocket had been scheduled to launch two…

The maiden voyage of Blue Origin’s massive new rocket won’t be for NASA

After 93 days on orbit, Starliner is coming home.  The spacecraft is a “go” for undocking from the International Space Station at 6:04 p.m. EST, though it will be leaving…

Watch live as Boeing and NASA attempt to bring empty Starliner back to Earth

Some of Vice President Kamala Harris’ wealthier donors are informally asking for FTC Chair Lina Khan to be replaced, reports Bloomberg. It’s not really surprising: Her expansive definition of antitrust…

Wealthy Harris donors are reportedly pressing for ouster of FTC Chair Lina Khan

Mangomint seeks to make it easier for spa and salon owners to run their businesses.

How a cold email to a VC helped salon software startup Mangomint raise $35M

The honors program is one of the first in the U.S. that allows incoming freshmen to apply for the program as part of their initial admission application.

University of Texas opens robotics program up to incoming freshmen

By using readily available natural gas as the feedstock, C-Zero hopes to produce emission-free hydrogen for less than other green hydrogen startups.

C-Zero is raising $18M to make emission-free hydrogen using natural gas, filings reveal

Meta on Friday published an update on how it plans to comply with the Digital Markets Act (DMA), the European law that aims to promote competition in digital marketplaces, where…

Meta will let third-party apps place calls to WhatsApp and Messenger users — in 2027

At the annual Roblox Developers Conference, the company announced on Friday a series of changes coming to the platform in the next few months and years. Most notably, Roblox is…

Roblox introduces new earning opportunities for creators, teases generative AI project

Apple is likely to unveil its iPhone 16 series of phones and maybe even some Apple Watches at its Glowtime event on September 9.

How to watch the iPhone 16 reveal during this year’s big Apple Event

Welcome to Startups Weekly — your weekly recap of everything you can’t miss from the world of startups. Want it in your inbox every Friday? Sign up here. You won’t…

Startups have to be clever when fighting larger rivals

The Philadelphia Eagles and the Green Bay Packers will face off tonight in their first game of the NFL season. But this season opener is a bit different. As the…

NFL kicks off in Brazil for the first time, but reporters and fans can’t post on X due to nationwide ban

Venture capitalist Tim Draper’s international pitch competition, “Meet the Drapers,” is partnering up with TikTok as it heads into its seventh season. Under the new tie-up, entrepreneurs will pitch their…

VC pitch show ‘Meet the Drapers’ partners with TikTok

It’s tempting to think the trend of EV startups merging with special purpose acquisition companies (SPACs) to go public has ended, seeing how many of them are struggling or defunct.…

Public EV startup with an indicted CEO is looking to raise an additional $100 million

In the world of modern AI, data is more than just a resource — it’s the fundamental core that aligns decision-makers, supports processes and enables innovation. As AI applications become…

The New Data Pipeline: Fivetran, DataStax and NEA are coming to TechCrunch Disrupt 2024

In a brief update ahead of the weekend, the London transport network said it has no evidence yet that customer data was compromised.

Transport for London outages drag into weekend after cyberattack

Meta-owned Instagram is jazzing up the inbox by adding new features for photo editing, sticker creation and themes. The company is trying to make Instagram more appealing as a messaging…

Instagram jazzes up its DMs with stickers, photo editing, and themes

Keep the excitement of TechCrunch Disrupt 2024 alive by hosting an exclusive Side Event after hours. Don’t miss out — today is the final day to apply for free! Maximize…

Last call: Boost your brand by hosting a Side Event at TechCrunch Disrupt 2024

Today’s your final chance to secure your TechCrunch Disrupt 2024 Student Pass with a $200 discount! Maximize your savings by opting for the Student 4+ Bundle and bring four or…

Students and recent grads: Last day to save on TechCrunch Disrupt 2024 Student Passes

The Equity podcast crew is wrapping up another eventful week, with real estate, AI agents, gambling and secondary markets — which are, of course, a form of legalized gambling. Mary…

Real estate revolutions and beanie baby economies

More antitrust woes for Google. The U.K’.s competition watchdog said on Friday that it suspects the company of adtech antitrust abuses. The tech giant will now have a chance to…

Google faces provisional antitrust charges in UK for ‘self-preferencing’ its ad exchange

You can build a reminder and task management system for yourself, and use a service that works for your team. But it might not be easy to get your family…

Karo is a to-do app that lets you assign tasks to your friends and family

Earlier this week, the EU’s lead privacy regulator ended its court proceeding related to how X processed user data to train its Grok AI chatbot, but the saga isn’t over…

Elon Musk’s X could still face sanctions for training Grok on Europeans’ data

Telegram has updated its website to explicitly allow users to report private chats to its moderators, the company said in its FAQ page, as it updated some of its other…

Telegram quietly updates website to allow abuse reports following founder’s arrest

SpaceX President Gwynne Shotwell made a public plea to one of Brazil’s top judicial figures on Thursday, asking him to “please stop harassing Starlink” amid the ongoing battle in the…

‘Stop harassing Starlink,’ SpaceX president tells Brazilian judge

OSOM always had a difficult road, with plans to launch a privacy-focused handset.

Osom is shutting down on Friday, as it had ‘no customers for a mobile phone’