A Cloudflare Connectivity Cloud conversation primer for Exponent, Inc.

A Connectivity Cloud · For Hard Questions, Tough Challenges

Hard questions.
Tough challenges.
One network.

Exponent runs 30+ offices, 950+ consultants, and an ISO 27001-certified evidence chain across five continents — currently stitched together with Zscaler, Fastly, Proofpoint, Cisco IronPort, and a legacy VPN appliance. Cloudflare's Connectivity Cloud collapses that into a single programmable platform.

1,500
Seats modeled
30+
Global offices
5→1
Vendor consolidation
exponent-stack.sh — live recon
# Recon · May 2026 · public DNS only
$ dig +short exponent.com NS → ns-1057.awsdns-04.org (Route 53) $ dig +short www.exponent.com → j.sni.global.fastly.net ⚠ FASTLY $ dig +short vpn.exponent.com → 12.47.62.20 ⚠ LEGACY APPLIANCE $ dig +short exponent.com MX → mxa-00195601.gslb.pphosted.com ⚠ PROOFPOINT $ dig +short autodiscover.exponent.com → autodiscover.outlook.com (M365) $ grep -i "iphmx\|pphosted\|exclaimer" spf.txt → IronPort + Proofpoint + Exclaimer chain $ # Zero Trust / SSE incumbent (per Exponent) → Zscaler ZIA + ZPA ⚠ DISPLACEMENT TARGET $ dig +short investors.exponent.com → cloudflare.cdn.web.prd.q4inc.com ✓ ALREADY ON CF
# Expansion path — full Connectivity Cloud
www → Cloudflare CDN / WAF / Bot Mgmt vpn → Cloudflare Access + WARP (ZTNA) mx → Cloudflare Email Security SSE → Cloudflare One (ZIA+ZPA replacement) WAN → Magic WAN across 30+ offices
$ echo "We did the homework. So should the network."
5 vendors detected · 5 displacement opportunities

A 30+ office footprint we're built to secure

Menlo Park Bowie New York Chicago Atlanta Houston Los Angeles Seattle London Edinburgh Basel Mannheim Hong Kong Shanghai Singapore

Every one of these sites is a Cloudflare data center too. We don't add a hop — we are the hop.

Current State · The Stack You Already Own

Five vendors.
Five consoles.
One unhappy network team.

Recon from your public DNS, security disclosures, and the published Zscaler footprint. None of this is a guess — and none of it has to stay.

CDN / Edge
Fastly
www.exponent.com resolves to j.sni.global.fastly.net. Single-vendor lock for marketing + investors traffic.
CF replacement
CDN · WAF · Bot Mgmt · Argo
Zero Trust / SSE
Zscaler
ZIA + ZPA for 1,500 seats. The single biggest line item — and the single biggest opportunity to consolidate.
CF replacement
Cloudflare One (Gateway + Access + CASB + DLP + RBI)
Email Security
Proofpoint
MX → pphosted.com. Layered with Cisco IronPort (iphmx.com in SPF). Two vendors for one inbox.
CF replacement
Cloudflare Email Security (Area 1)
Email Gateway
Cisco IronPort
Found in SPF: spf.iphmx.com. Redundant with Proofpoint — paying twice for the same outcome.
CF replacement
Retire entirely — one ESS
Remote Access
Legacy VPN
vpn.exponent.com → 12.47.62.20. AT&T address space — on-prem appliance still in the path for forensic consultants.
CF replacement
WARP + Access (clientless ZTNA)

The hidden cost isn't licensing. It's five sets of policies, five audit trails, five renewal calendars, five vendor SE teams, and five places a misconfiguration can lose attorney-client privilege.

Interactive · Modeled at 1,500 seats

Zscaler ZIA + ZPA
vs. Cloudflare One.

SSE pricing is opaque on purpose. Here's a transparent 3-year TCO model using public benchmarks from Gartner, public-sector contracts, and Cloudflare One Enterprise list — toggle the assumption you want defended in your renewal meeting.

Your inputs

Defaults sized for Exponent's footprint.

≈ 950 consultants + 550 corporate staff

Public-sector ZIA + ZPA Business bundle, mid-range.

CF One Enterprise bundle (Gateway + Access + CASB + DLP + RBI).

Legacy VPN HW + maintenance + 1 FTE of operational toil.

Retire Cisco IronPort, fold into Cloudflare Email Security.

Z
Zscaler ZIA + ZPA
Current state
SSE seat cost $0/yr
Legacy VPN HW + ops $0
Email gateway redundancy $0
Vendor mgmt overhead $0
3-Year TCO
$0
≈ $0/year all-in
Cloudflare One Enterprise
Proposed
SSE seat cost $0/yr
VPN replaced by WARP (included) $0
Email security (bundled) $0
One vendor, one console $0
3-Year TCO
$0
≈ $0/year all-in

Estimated 3-Year Savings · Conservative · ZIA+ZPA mid-range

$0
0% lower TCO than the current Zscaler-plus-everything-else stack. That's $0/year back to the partnership, not to a vendor renewal.

Plus what's not in this number: free DDoS protection, unmetered Pages + Workers, R2 with zero egress fees, Magic WAN at 30 offices, Cloudflare Stream for client deposition video — all on the same Enterprise contract.

Source notes: Zscaler unit price from Gartner Peer Insights ($6.50-$13.50 ZIA+ZPA range, public-sector contracts via SAM.gov). Cloudflare One Enterprise list from cloudflare.com/plans/zero-trust-services. VPN retirement based on typical mid-size enterprise on-prem ZTNA appliance + 0.5 FTE. Update with your actual contract numbers before walking this into a renewal meeting.

Live · Workers AI + Vectorize

AI for the expert witness.

Try a semantic search over Exponent's public case studies and alerts. Type how a client would describe their problem — not the keywords on your site. If a 200ms edge inference can RAG your public corpus, imagine it on your privileged case files, running inside your network perimeter with zero data egress.

How this works on Cloudflare — at 200ms, inside your network

Step 1
Embed each case study with @cf/baai/bge-base-en-v1.5
Step 2
Store vectors in Vectorize — never leaves Cloudflare
Step 3
Synthesize answer with @cf/meta/llama-3.1-8b-instruct
Step 4
Firewall for AI blocks PII / privileged content leakage at the edge

This demo uses a tag-vector approximation in the browser. The production pattern is identical — but runs on Workers AI + Vectorize, all inside Cloudflare's data-sovereign EU and US regions, with full audit trail in AI Gateway. No data leaves the perimeter. Zero OpenAI roundtrips.

For your CIO + CISO + Information Security team

Cloudflare for Exponent.

Five solution areas. One platform. Built for a 30-office, ISO 27001-certified consulting firm where downtime breaks attorney-client privilege.

01 / 05
Replaces · Zscaler

Zero Trust · The Lead Play

One ZTNA + SWG + CASB + DLP + RBI for every consultant, every case file, every office.

Today, a forensic consultant in your Hong Kong office hitting a client SaaS goes: laptop → Zscaler ZIA → ZPA → SaaS — three hops, two consoles, opaque traffic in a SOC 2 audit. Cloudflare One collapses that to one identity-aware proxy on the world's most peered network, with DLP that understands the difference between "litigation hold material" and "lab Slack."

Gateway (SWG) Access (ZTNA) CASB DLP Browser Isolation WARP Tenant Control

For Exponent specifically

Replace Zscaler ZIA+ZPA at 1,500 seats with Cloudflare One Enterprise. Apply granular DLP policies to matter-numbered SharePoint sites — block AI prompt exfil of privileged work product to ChatGPT, Claude, or Gemini. Browser Isolation for risky expert-witness research (the dark side of materials science forums). All audit-trailed to ISO 27001 and NIST SP 800-171 controls you already attest to.

02 / 05 Replaces · Fastly

App Security & Performance

CDN, WAF, bot management — for exponent.com and every client portal.

www.exponent.com is on Fastly today. Consolidate edge, WAF, bot, and DDoS into a single contract with global anycast at 330+ cities. investors.exponent.com is already on Cloudflare (via Q4 Inc.) — extend that footprint across every property.

CDN WAF Bot Mgmt DDoS Rate Limiting Argo Page Shield

For Exponent specifically

Protect www.exponent.com, careers.exponent.com, and the alerts + case-studies verticals on one WAF. Bot Management blocks AI scrapers harvesting your public expertise content for competitor training data.

03 / 05 Replaces · Legacy VPN + SD-WAN

Network as a Service

Magic WAN across 30+ offices, North America to Singapore.

Today: vpn.exponent.com → 12.47.62.20 — an AT&T-fronted box that's the only path home for consultants in Basel, Edinburgh, Shanghai. Replace with Magic WAN: every office becomes a Cloudflare PoP, every laptop a WARP endpoint, all under one routing fabric.

Magic WAN Magic Transit WARP Connector Tunnel Spectrum

For Exponent specifically

Connect Menlo Park, Bowie, Natick, Basel, London, Shanghai, Singapore as one virtual fabric. Retire the on-prem VPN appliance entirely. Forensic engineers in the Natick or Phoenix testing labs get the same latency to lab instruments whether on-site or remote.

04 / 05 Net-new capability

AI Security & Performance

Practice what your AI Consulting practice preaches.

Exponent sells AI consulting — battery thermal AI, autonomous driving AI, healthcare AI risk. Run your own AI on infrastructure that meets the bar you set for clients: AI Gateway audit trail, Firewall for AI for PII / privileged content leakage, Workers AI for private inference inside your perimeter.

AI Gateway Workers AI Vectorize AutoRAG Firewall for AI AI Crawl Control

For Exponent specifically

Internal RAG over 50+ years of case files without sending a byte to OpenAI. AI Audit catches every consultant prompt that contains a matter number or client name before it leaves your perimeter. Block AI scrapers training on your published expertise.

05 / 05
Replaces · Proofpoint + IronPort

Email Security + Developer Platform

The forensic inbox is the #1 phishing target. So protect it like one.

Expert witnesses get spear-phished daily — opposing counsel, "court clerks," fake retainer requests. Cloudflare Email Security (formerly Area 1) sits in front of M365 and catches the targeted, low-volume social-engineering attacks Proofpoint + IronPort miss. Plus everything else on the platform — Workers, Pages, R2, D1 — so when Information Resources needs a custom client portal, intake form, or deposition exhibit viewer, it ships in days, not quarters.

Cloudflare Email Security Workers Pages R2 (zero egress) D1 Durable Objects Stream (depositions)

For Exponent specifically

Retire Proofpoint + Cisco IronPort. Stream secure deposition video to client counsel without Vimeo licensing. Workers + R2 host expert-witness exhibit repositories with per-matter access control. Free DDoS-protected Pages for every conference microsite Exponent's marketing team has to spin up.

Where to start · No big-bang migration

First 90 days.
Three deployments.
Zero risk to the Zscaler renewal clock.

Cloudflare One runs in parallel with Zscaler during cutover — no big-bang, no rip-and-replace, no forklift. You decommission Zscaler on your renewal date, not ours.

Week 1-2

Step 01

Land & expand.

Stand up Cloudflare One tenant. Deploy WARP to 50 IT + Security pilot users in Menlo Park. Mirror Zscaler ZIA traffic for shadow comparison — no user impact, full visibility.

Reversible — Zscaler stays live
Move investors.exponent.com fully to CF (already there via Q4)
Cloudflare Email Security in monitor-mode parallel to Proofpoint
Week 3-6

Step 02

Retire the VPN. Replace ZPA.

Migrate top 25 internal apps (SharePoint, file shares, lab instrumentation, expert-witness portals) from ZPA to Cloudflare Access. Cut over vpn.exponent.com to WARP Connector. Decommission the on-prem VPN box.

25 apps behind Access · clientless ZTNA
VPN appliance + maintenance contract retired
Move www.exponent.com from Fastly to CF
Week 7-12

Step 03

Full SSE cutover. Zscaler off.

All 1,500 seats on Cloudflare One. DLP policies live for matter-numbered data. Browser Isolation for high-risk research. Cisco IronPort retired. Trigger the Zscaler non-renewal letter.

1,500 seats on Cloudflare One Enterprise
DLP + RBI active · ISO 27001 controls mapped
3-year savings clock starts

No-regret order: CF Email Sec (monitor) → WARP pilot → Access for top apps → VPN retired → full Zscaler cutover at renewal.

End-to-end Mapping

Exponent on Cloudflare.

Each tile maps a current vendor or capability to a Cloudflare equivalent — sized to a 1,500-seat, 30-office, ISO 27001 environment. Replaces · Augments · Net-new badges based only on what we actually detected on your public infrastructure.

Replaces · Zscaler ZIA+ZPA

Cloudflare One

One SSE platform for all 1,500 seats: Gateway (SWG), Access (ZTNA), CASB, DLP, Browser Isolation, Tenant Control.

Replaces · Fastly

CDN + WAF + Bot Mgmt

Move www.exponent.com off j.sni.global.fastly.net. Free DDoS, unmetered, 330+ cities.

Replaces · Proofpoint + IronPort

Cloudflare Email Security

Drop-in MX in front of M365. Detects targeted BEC + spear-phish the legacy gateways consistently miss.

Replaces · vpn.exponent.com

WARP + Access (clientless ZTNA)

12.47.62.20 is an AT&T-fronted on-prem box. Retire entirely. Identity-aware proxy with full posture checks.

Augments · AWS Route 53

Cloudflare DNS

Keep Route 53 if you want, or consolidate. Cloudflare DNS is the world's fastest authoritative resolver, free at any scale.

Augments · Microsoft 365

Identity + CASB integration

Native Entra ID SCIM. CASB scans M365 / SharePoint / OneDrive for misconfig + data exposure. No new IdP.

Net-new · 30 offices

Magic WAN + Magic Transit

Every office a Cloudflare PoP. Single routing fabric. DDoS-protected origin IPs for any colocated infrastructure (Natick, Phoenix labs).

Net-new · AI practice

Workers AI + Vectorize + AI Gateway

Internal RAG over 50+ years of case files. AI Gateway logs every prompt. Firewall for AI blocks privileged data exfil.

Net-new · IR build velocity

Workers + Pages + R2 + D1

Client portals, intake forms, deposition exhibit viewers — ship in days. R2 with zero egress for case file archives, replacing S3.

Business Case · For the CIO Memo

Three outcomes.
One contract.

Each number cites its source so it survives a CFO read.

$108K

Year-1 SSE savings

Conservative scenario: 1,500 seats × ($9 − $7) × 12. Aggressive (ZIA+ZPA+ZDX): 4-6× this. From the calculator above, your scenario.

5 → 1

Vendor consolidation

Zscaler, Fastly, Proofpoint, Cisco IronPort, on-prem VPN → one Cloudflare Enterprise contract. One console, one audit trail, one renewal cycle.

~50ms

to 95% of internet users

330+ Cloudflare cities. Your Hong Kong consultant gets the same SaaS latency as your Menlo Park partner. Per Cloudflare's published Radar measurements.

Next Step

Ready to walk through this
for Exponent?

60-90 minute workshop with your Information Security + Information Resources teams. We'll plug Exponent's actual Zscaler contract into the calculator, map the 5 pillars to your ISO 27001 control set, and sketch the Week-1 WARP pilot.

Your Cloudflare contact

Andrew Geiser

ageiser@cloudflare.com

I cover scientific & engineering consulting accounts. I've already done the public-DNS recon — bring me your Zscaler renewal date and I'll bring you the migration plan.