
We're happy to share that Boston IT Services is now a Cloudflare Zero Trust partner. That means we can design, deploy, and manage Cloudflare's Zero Trust Network Access (ZTNA) platform for our clients as a fully supported part of our managed service — including licensing, rollout, policy design, and day-two support.
This wasn't a logo swap. It's the result of a year of watching the same problem repeat across client networks: the VPN is the weakest link.
The problem with the VPN you already have
Traditional VPNs were built for a world where the office was the network. Once a laptop connects, it's usually inside — able to reach file servers, management interfaces, and lab systems it has no business touching.
- Too much access. One set of stolen credentials often means access to a flat internal network.
- An appliance to patch. VPN concentrators have been among the most heavily exploited devices of the last three years. If the box is on the internet, it's a target.
- Bad user experience. Split tunneling fights, dropped sessions, slow file transfers from home — and every complaint lands in the helpdesk queue.
- No device posture. A personal laptop with no EDR and an unpatched OS connects exactly like a managed one.
What Zero Trust actually changes
Zero Trust flips the model: nothing is trusted because of where it sits. Every request to every application is authenticated, authorized, and logged.
- Access per application, not per network. A contractor who needs one internal web app gets that app — not a subnet.
- Identity plus device posture. Policies combine your identity provider (Microsoft Entra ID, Google Workspace, JumpCloud) with checks on the device itself: is it managed, encrypted, patched, running EDR?
- Nothing published to the internet. Cloudflare Tunnel creates outbound-only connections from your network, so there's no public VPN endpoint or open firewall port to attack.
- Faster, not slower. Traffic rides Cloudflare's global network instead of hairpinning through one office circuit — a real difference for distributed teams.
- An audit trail. Every access decision is logged per user, per app, which is exactly the evidence auditors and cyber insurers ask for.
Why Cloudflare
We evaluated several ZTNA platforms. Cloudflare won on four practical points:
- It fits SMB budgets. Most Zero Trust platforms are priced and scoped for the enterprise. Cloudflare's per-user model works for a 25-person firm as well as a 250-person one.
- One platform, several problems. ZTNA, DNS filtering, secure web gateway, browser isolation, and CASB come from the same console — replacing two or three separate tools.
- No hardware. Nothing to rack, license, or refresh in four years.
- It maps to frameworks we already support. The controls line up cleanly with CMMC, SOC 2, and HIPAA access-control requirements, and with the questions on cyber insurance renewals.
How we roll it out
We don't cut the VPN over on a Friday afternoon. A typical engagement runs in four phases:
- Discovery (week 1). Inventory what actually needs remote access — apps, servers, lab instruments, vendor connections — and who uses each.
- Pilot (weeks 2–3). Deploy tunnels and policies for one team, run it alongside the existing VPN, tune posture checks.
- Rollout (weeks 4–6). Migrate department by department with the VPN still available as a fallback.
- Decommission. Turn off the VPN, close the firewall ports, and retire the appliance from the patch cycle.
Who benefits most
The gains are biggest for hybrid teams, firms with contractors or offshore developers, biotech and life sciences clients with instruments that must never be internet-facing, and any company with a compliance obligation that needs per-user access evidence. If you run a flat network with a VPN appliance and a handful of shared credentials, this is the single highest-impact security change available to you this year.
Getting started
If you're a current client, your account team can scope a Zero Trust pilot into your existing plan — usually with no new hardware and no change to your identity provider. If you're not, we'll start with a review of how remote access works today and what it would take to retire the VPN.
Get in touch or book a call and we'll walk through it.


