Key Takeaways from Cloudflare's 2024 Year in Review - IT Support
All dispatches
Microsoft 3652024-12-188 min read

Key Takeaways from Cloudflare's 2024 Year in Review - IT Support

Joe Welch
Joe Welch
Head of Engineering · Black Sheep Support
Share this dispatch

As a Microsoft Partner and cloud solutions provider, we routinely monitor internet trends and security developments. Cloudflare's annual Year in Review offers a comprehensive snapshot of the internet's state: traffic patterns, the evolving threat landscape, and how we connect. For UK SME businesses, understanding these insights is not merely academic; it is critical for maintaining operational security, optimising infrastructure, and ensuring business continuity in an increasingly connected, yet volatile, environment. This report provides a data-driven perspective on what is genuinely happening online, which directly impacts your day-to-day operations and future planning.

What Cloudflare's Year in Review actually means

Cloudflare operates one of the largest networks globally, sitting between website visitors and the servers hosting those sites. This position gives them a unique, aggregated view of internet traffic, cyber threats, and connectivity issues across the planet. Their "Year in Review" is essentially a detailed analysis of the data collected from this vast network. It covers everything from global internet traffic growth and the types of cyber-attacks observed, to the adoption rates of new internet protocols and the impact of significant outages. For an SME, it translates to understanding the real-world conditions that affect your online presence, your cloud services, and your defence against evolving digital risks. It is a factual report on the internet's pulse, not speculative commentary.

Why it matters for UK SMEs

For UK SMEs, the insights from a report like Cloudflare's are not abstract concepts; they are direct indicators of operational risk and opportunity. Increased internet traffic, for instance, highlights the necessity of robust, scalable internet infrastructure. If your business relies on cloud applications, e-commerce, or remote work, inadequate bandwidth or an unreliable connection can directly impede productivity and customer service.

More critically, the documented rise in the volume and sophistication of cyber threats directly impacts your regulatory obligations and financial stability. The Information Commissioner's Office (ICO) in the UK enforces the UK GDPR, which mandates appropriate technical and organisational measures to protect personal data. A data breach, often stemming from common cyber-attacks such as phishing or ransomware, can lead to significant fines, reputational damage, and loss of customer trust. Compliance frameworks like Cyber Essentials, often a prerequisite for government contracts, also necessitate a proactive approach to cyber security, aligning directly with the defence strategies highlighted in such reports. The National Cyber Security Centre (NCSC) consistently advises UK businesses to implement foundational security controls, many of which directly address the threats Cloudflare observes. Ignoring these trends means operating with blind spots, which is frankly, an unnecessary risk.

How to address the key trends

Understanding the trends is one thing; implementing practical measures is another. Here’s a breakdown of how UK SMEs can respond to the key insights from Cloudflare's report.

Managing Internet Traffic and Infrastructure

The consistent growth in global internet traffic means your business needs to assess its current internet service provision.

  • Review Your ISP Contract: Understand your contracted bandwidth and any fair usage policies. Ensure it aligns with your peak operational demands, considering video conferencing, cloud file synchronisation, and any customer-facing online services.
  • Monitor Usage: Implement network monitoring tools to track your actual bandwidth consumption. This helps identify bottlenecks and informs decisions on upgrades. Many modern firewalls offer this capability.
  • Consider Redundancy: For businesses where internet connectivity is mission-critical (e.g., VoIP, cloud-based ERP), explore options for redundant internet connections from different providers. Technologies like SD-WAN can manage these connections efficiently.

Enhancing Cyber Security Defences

The sustained increase in cyber threats, particularly DDoS attacks, ransomware, and sophisticated phishing, demands a multi-layered defence strategy.

  • Implement Multi-Factor Authentication (MFA) Everywhere: This is non-negotiable. MFA significantly reduces the risk of account compromise, even if credentials are stolen. On a recent client tenant audit for a 60-user engineering firm in Birmingham, we found 25% of their users still lacked MFA enrolment on critical accounts. This is a common oversight, often due to perceived user inconvenience, but the security gain far outweighs it.
  • Advanced Email Filtering and Threat Protection: Standard email filtering is no longer sufficient. Solutions like Microsoft 365 Defender for Office 365 or third-party alternatives offer advanced phishing detection, sandbox analysis for suspicious attachments, and URL rewriting.
  • Endpoint Detection and Response (EDR): Traditional antivirus is largely reactive. EDR solutions provide continuous monitoring, threat hunting, and automated response capabilities on all your devices, offering a more robust defence against modern malware and ransomware.
  • DNS Protection: Implementing DNS-level security blocks access to known malicious sites, preventing malware downloads and phishing attempts before they reach your users.
  • Regular Security Awareness Training: Your staff are your first line of defence. Regular, engaging training on recognising phishing, social engineering tactics, and safe internet practices is crucial. This should include simulated phishing exercises.
  • Patch Management: Ensure all operating systems, applications, and network devices are kept up-to-date with the latest security patches. Unpatched vulnerabilities are a frequent entry point for attackers.

Navigating AI's Dual Nature

AI presents both opportunities for defence and new avenues for attack.

  • Leverage AI-Powered Security Tools: Many modern security solutions, including Microsoft Defender products, incorporate AI for anomaly detection, threat analysis, and automated responses. Ensure your security stack is configured to utilise these capabilities.
  • Educate on AI-Enhanced Threats: Inform your team that AI is making phishing emails and deepfake scams more convincing. Verify unusual requests, especially financial ones, through a secondary, established communication channel.
  • Assess AI Tool Usage: If your business is adopting AI tools (e.g., Microsoft Copilot, other AI assistants), understand their data handling policies. Ensure sensitive company data is not inadvertently exposed or used to train public AI models without proper controls.

Building Business Resilience Against Outages

Internet outages, whether local or global, highlight the need for robust business continuity planning.

  • Cloud-First Strategy for Critical Services: Migrate critical applications and data to reputable cloud providers. This inherently offers better resilience, redundancy, and geographic distribution than most on-premises setups.
  • Comprehensive Backup and Disaster Recovery (BDR): Implement a robust backup strategy (e.g., 3-2-1 rule: three copies of data, on two different media, one offsite). Crucially, regularly test your recovery procedures to ensure they work when needed.
  • Offline Workflows: Identify key business functions that can operate offline or with limited connectivity. Have procedures in place for staff to continue working if internet access is temporarily lost.
  • Monitor Uptime: Utilise tools that monitor the availability of your critical online services and internet connection, providing alerts for any disruptions.

Addressing IPv6 Adoption

While IPv4 is still dominant, IPv6 adoption continues to gain momentum.

  • Infrastructure Assessment: Have your IT provider assess your current network infrastructure (routers, firewalls, servers) for IPv6 compatibility.
  • ISP Support: Confirm that your Internet Service Provider supports IPv6 and whether it is enabled on your connection.
  • Future-Proofing: While not an immediate crisis for most SMEs, ensuring your systems are IPv6-ready avoids potential compatibility issues or performance bottlenecks as the internet evolves.

Common mistakes we see

Even with the best intentions, SMEs often fall into predictable traps when addressing these concerns.

  1. Underestimating User Error: Concentrating solely on technical defences while neglecting regular, practical security awareness training for staff leaves a significant vulnerability.
  2. "Set and Forget" Security: Implementing security solutions but failing to regularly review configurations, monitor alerts, or update policies allows new threats to bypass old defences.
  3. Ignoring Backup Testing: Having a backup solution is prudent, but assuming it works without periodic restoration tests is a common and potentially disastrous oversight.
  4. Over-reliance on a Single Internet Connection: For critical operations, a sole reliance on one ISP for internet connectivity creates a single point of failure that can halt business.
  5. Lack of Clear Incident Response: Not having a defined plan for what to do during a cyber-attack or significant outage can turn a manageable incident into a full-blown crisis.

Key Takeaways

  • Prioritise MFA: Implement Multi-Factor Authentication across all accounts immediately.
  • Invest in Layered Security: Combine advanced email filtering, endpoint protection, and DNS security.
  • Train Your Staff: Regular security awareness training is your most effective human firewall.
  • Ensure Business Continuity: Plan for internet outages and regularly test your backup and recovery procedures.
  • Review Infrastructure: Periodically assess your internet bandwidth and network hardware for scalability and modern protocol compatibility.

When to call in help

The scope of managing these technical challenges, from advanced security configurations to ensuring network resilience, often exceeds the internal capabilities or time availability of most UK SMEs. Attempting to manage these complex areas without dedicated expertise can lead to significant vulnerabilities, operational inefficiencies, or simply a misallocation of valuable internal resources. Engaging an experienced managed IT and cyber security provider ensures that your business benefits from up-to-date knowledge, enterprise-grade tools, and proactive management, allowing you to focus on your core business activities.

To take the next step

Book a Discovery Call

Back to all dispatchesEnd of Intelligence · BSS Digital Dispatch
Monthly IT briefing

The three things worth knowing this month

One short email a month: what broke, what got patched, and what we would change in a small business this week. No sales pitch, unsubscribe in one click.

We only use your email for the briefing. See our privacy policy.