The B2B Podcast Index
Index
All categories
MarketingSalesSaaSFinanceHROpsLeadershipCustomer SuccessAI & DataProductStartups & FoundersRevOpsEngineering & DevTools
MethodologySubmit
Best of:MarketingSalesSaaSFinanceHROpsLeadershipCustomer SuccessAI & DataProductStartups & FoundersRevOpsEngineering & DevTools
An independent project byFame
SearchBest episodesGuestsInsightsMethodologySubmit a podcast
Index/Ops/The Connectivity Cloud Podcast
The Connectivity Cloud Podcast artwork

How Retailers Are Fighting Back Against Fraud with Andy Dean and Christian Reilly

The Connectivity Cloud Podcast · 2025-08-05 · 38 min

0:00--:--

Key moments - from our scoring

Substance score

61 / 100

Five dimensions, 20 points each

Insight Density13 / 20
Originality11 / 20
Guest Caliber14 / 20
Specificity & Evidence13 / 20
Conversational Craft10 / 20

All Saints has undergone significant digital transformation, moving from managed on-premises infrastructure to Google Cloud Platform in 2019 and shifting from homegrown software development to strategic SaaS partnerships. Andy Dean explains the shift from being developer-centric to leveraging purpose-built platforms with thousands of engineers, while maintaining in-house control over differentiating capabilities. A critical challenge for the organization is managing over 100 vanity domains globally - not just the primary brand domain - which creates substantial security risk if misconfigured. Andy details their approach to domain governance using DMARC and SPF records to prevent spoofing and unauthorized email sending, and Cloudflare Workers for edge-based security header injection and geo-redirects without maintaining separate server infrastructure. Christian Reilly contextualizes these moves within broader retail trends: while traditional retailers shift toward e-commerce, some digital-native brands are opening physical stores. The conversation covers how established retailers with legacy homegrown e-commerce platforms are increasingly adopting modern SaaS solutions rather than attempting internal modernization. Simplification of core infrastructure, clear target architectures defined in code (Infrastructure as Code), and strong DevOps automation are essential for managing complexity across physical and digital estates, particularly during M&A and market expansion activities.

Key takeaways

  • →All Saints migrated from managed infrastructure to Google Cloud in 2019 to enable dynamic scaling and reduce costs, then complemented this with strategic SaaS partnerships rather than building all software in-house.
  • →Domain security requires continuous auditing of 100+ vanity domains for proper DMARC/SPF configuration to prevent email spoofing and impersonation, not just monitoring the primary domain.
  • →Cloudflare Workers enable edge-computed security headers and geo-redirects without maintaining vulnerable dedicated servers for every domain, reducing operational overhead and attack surface.
  • →Large retailers increasingly adopt commercial e-commerce SaaS platforms rather than attempting in-house modernization of legacy homegrown systems due to cost, risk, and the complexity of maintaining custom development at scale.
  • →Strong target architecture frameworks, Infrastructure as Code practices, and DevOps automation help manage complexity and drift across physical and digital retail operations while remaining flexible for business requirements.

In this episode

  1. 1Introduction and Guest Backgrounds
  2. 2Technology Innovations Over 20 Years
  3. 3All Saints' Digital Transformation and Cloud Migration
  4. 4Retail Industry Modernization Patterns and E-commerce Platforms
  5. 5Managing Domain Portfolio Complexity and Security
  6. 6DNS Security: DMARC, SPF Records, and Email Authentication
  7. 7Edge Computing and Cloudflare Workers for Domain Management
  8. 8Infrastructure Simplification and Target Architecture Strategy

Mentioned

All SaintsCloudflareGoogle CloudAndy DeanChristian ReillyMarc DemboCloudflare WorkersDMARCSPFAlexaGoogle MapsSAP

Guests

Andy DeanChristian Reilly

Topics in this episode

CloudflareCloudflare WorkersGoogle Cloud platformEdge computingInfrastructure as CodeDMARC recordsSPF recordsAll SaintsE-commerce platform modernizationDomain security management

Questions this episode answers

What are DMARC records and why do retailers need them?

DMARC and SPF records are DNS gateway controls that authorize specific mail servers and IP addresses to send emails on behalf of your domain; without proper configuration, anyone can send emails impersonating your company or executives, creating risk for fraud and malicious payment requests.

How does Cloudflare Workers help manage multiple vanity domains?

Cloudflare Workers provides edge compute capability to add security headers, enforce geo-redirects, and manage configuration for vanity domains without running separate vulnerable servers for each domain, reducing both operational costs and security exposure.

What is the difference between SPF and DMARC?

SPF is an older authorization standard that lists legitimate senders, while DMARC is more strict and requires cryptographic verification from the source domain; DMARC is now the critical standard for email security.

Why are established retailers moving away from homegrown e-commerce platforms?

Legacy homegrown e-commerce platforms built through years of iteration are expensive to maintain, risky to modify, and often require specialized expertise; modern retailers are migrating to configurable commercial SaaS platforms instead of attempting internal modernization.

How do country-based redirects work at the edge?

Cloudflare Workers extract the country code from the user's browser at the edge and make a decision to redirect to localized websites in the user's language and currency without requiring backend infrastructure.

What our scoring noted

Our reviewer’s read on each dimension, with quotes from the episode.

Insight Density

13 / 20

The episode contains several concrete technical insights (DMARC/SPF records, Cloudflare Workers for edge compute, domain spoofing risks, loyalty program fraud vectors, rate limiting strategies) mixed with substantial filler. The loyalty fraud section citing $4 billion in annual losses and the $10-50 dark web pricing is genuinely novel data. However, roughly 40% of the runtime consists of warm-up questions, congratulatory asides, and generic transformation platitudes that add little analytical value. The build-vs-buy framework and SaaS transition discussion are competent but well-trodden.

compromised loyalty account sells for between 10 and $50 on the dark Web, whereas a stolen credit card information only sells for five
loyalty fraud cost companies about $4 billion globally

Originality

11 / 20

The episode rehashes standard cloud migration narratives (Google Cloud transition, SaaS adoption over homegrown solutions, modernization patterns like strangler fig). The loyalty fraud angle is fresher than typical retail security discussions, but the overall framing - build vs. buy, brownfield complexity, omnichannel strategy - circulates widely in enterprise IT. The AI discussion about virtual changing rooms and voice commerce (Alexa) references well-known examples rather than proprietary insights. Little first-principles thinking or contrarian positioning.

Whether that's backend for front end, whether that's strangler patterns, whether that's containerization, we see that a lot
it's the year of augmented reality. Literally every year for the last year, 10 years

Guest Caliber

14 / 20

Andy Dean has credible depth - 20+ years in ops, leading technical transformations at a known fashion brand, with real responsibility for 100+ domains and migration execution. Christian Reilly as a field CTO at Cloudflare is relevant but carries the typical vendor-speaker risk: his framing naturally centers Cloudflare solutions and he is effectively selling. Both guests have done substantive work, but Christian's role is primarily advisory/sales-adjacent rather than having run multi-year transformations solo. Neither are founders or sole owners making independent decisions.

Andy Dean, head of Technical operations at All Ah Saints
Christian Reilly, field CTO at Cloudflare

Specificity & Evidence

13 / 20

Strong specificity in the domain security section: 100+ vanity domains, SPF/DMARC records, Cloudflare Workers templates, geo-redirect implementation. Loyalty fraud data is precise ($4B globally, $10 - 50 dark web price vs. $5 for credit cards). However, the transformation narrative lacks numbers - no mention of migration timelines beyond "nine months," no cost savings quantified, no performance metrics post-Google Cloud move. AI/virtual changing room discussion remains conceptual. Many claims about customer behavior, omnichannel strategy, and future buying patterns are asserted without supporting data or case studies.

over 100 different vanity domains
loyalty fraud cost companies about $4 billion globally

Conversational Craft

10 / 20

The host (Marc) asks competent clarifying questions (DMARC explanation, Cloudflare Workers in a sentence) and creates space for narrative. However, follow-ups are often surface-level, and he rarely pushes back or probe deeper on claims. When Christian mentions "legacy mindset" and "resistance to change," no one interrogates what that actually looks like or how to measure it. The AI segment lacks critical questions - no challenge on timelines, adoption barriers, or whether these use cases genuinely drive ROI. The "quick fire" closing feels rushed and doesn't probe the non-technical factors claimed. Marc is a capable facilitator but not a sharp interrogator.

Two things. What are DMARC records for?
And Cloudflare workers on a high level. Can you explain it in like a sentence?

Conversation analysis

Computed from the transcript - who did the talking, and the words that came up most.

Share of words spoken

  • Speaker B42%
  • Speaker C35%
  • Speaker A23%

Most-used words

andy24sure19cloud17security16christian16cloudflare16customer16loyalty15technology14interesting14transformation13commerce13tech13different13digital12domain11

Episode notes

In this episode of The Connectivity Cloud Podcast with Cloudflare, host Mark Dembo is joined by Andy Dean, Head of Technical Operations at AllSaints, and Christian Reilly, Field CTO of EMEA at Cloudflare, to unpack what real-world digital transformation looks like, specifically how enterprises can navigate the complex balance between security and scalability, from managing multi-vendor environments to modernizing legacy infrastructure.

Full transcript

38 min

Transcribed and scored by The B2B Podcast Index.

Speaker A: The energy is so great. There's going to be a good episode. I can already tell.

Speaker B: I'm pretty sure nobody would have foresaw being able to order things from a large online retailer using Alexa.

Speaker C: We transitioned uh, into Google Cloud. We needed to be a bit more dynamic, a hell of a lot more efficient. Huge, huge step. We're only as strong as your weakest link, right? So people are not just spoofing domains and phishing, but they're taking over domains that you own.

Speaker A: Welcome to the Connectivity Cloud Podcast, the podcast that provides expert insights into the cloud and IT landscape. I'm Marc Dembo and each month we'll explore key topics like scaling secure infrastructure, tackling emerging risks, and staying ahead of the latest trends. Whether you're managing multi M vendor environments or navigating cloud modernization, this is the show for you, delivering practical advice for today's decision makers. Welcome everyone to the Connectivity Cloud Podcast, your trusted source for insights to the latest trends, strategies and technologies shaping cloud security and infrastructure. I'm your host, Mark Dembo, and today we have two exciting guests. Andy Dean, head of Technical operations at All Ah Saints, and Christian Reilly, field CTO at Cloudflare. Andy has spent over 20 years leading technical operations across multiple industries with a focus on IT transformation and E commerce scalability. At All Saints, he's spearheaded key cloud migrations and security improvements to ensure that the brand remains resilient and high performing even during the busiest sales periods. Christian, with his extensive background in technology leadership, has helped enterprises navigate the complex intersection of performance, security and scalability. As a field CTO at Cloudflare, Christian's work focuses on helping businesses tackle the growing challenges in the digital age, ensuring seamless and secure cloud operations at scale. Today we'll discuss how all science is evolving its digital infrastructure, the role that Cloudflare has in this transformation, and the critical balance between security and performance as both brands continue to scale and innovate in an increasingly connected world. Andy, Christian, welcome to the podcast.

Speaker C: Morning, Matt. Morning, Christian.

Speaker B: Good morning, Andy. And good morning, Mark. Thank you for having us both on with you. It's a true pleasure.

Speaker A: The energy is so great. There's going to be a good episode. I can already tell. Typically when I have new guests on, what I like to do is a little bit of like a, uh, light warm up question and it's typically really technology related and this time it's going to be a little bit nostalgic. You both have been in the web and tech space for a long time, each over 20 years, right? I'm curious, like which innovation or change over that time period still blows your mind. I can give an example. Right. So I was born and raised in Germany, but my grandma lived in Canada. And I vividly remember calling my grandma my childhood. It was like crazy expensive. We always use these like weird prefix codes and. And you had to like make sure with time difference that both were at home and it was super tough. Nowadays you can just facetime someone full HD from like a mountaintop to the desert opposite end of the world and it's basically free, right? To me that is mind blowing. Like to me that's such a great shift. Christian, is there something that comes to mind for you?

Speaker B: I always go back to this one mark when people ask me like, what's the most impactful technology you've seen? And I'm going to say gps, right? Because I remember being, well, I guess I sort of remember being young. But like when I first got in a car and passed my driving test and was able to drive, you had to have a little book with you, right, that we used to call in the UK an A to Z, right. And it had like all the road names, all the locations and um, if you were going somewhere you'd never been before, you literally had to figure out how to drive and read the thing at the same time. Right. So if you think about, I mean, I always get really, really, really like blown away when you look at how simple GPS is. Every car, every airplane, every ship, every bus, I mean everything relies on this. And you would think from a technology point of view it must be really complicated. But it's really so simple as an end user. So you get in the car, you use your maps, you use whatever. And the more I think about that, uh, and just think about, you know, there's all these things up there in the low earth and higher orbits that are directing us in milliseconds to destinations no matter what transport we use. To me it's just absolutely staggering. So my favorite thing is GPS for sure.

Speaker A: That makes so much sense. Andy, how does that look like for you?

Speaker C: Well, yeah, and the worst thing is we still get lost, right Christian, Even with GPS and Google Maps. So where's the weak point? For me it's quite similar for me mine is kind of mobile tech and more so security. So I'm sure we all had a particular brand of mobile phone. Where to lock and unlock was just two buttons. It was a two key sequence that anyone could do. So you left your phone out on a table in a pub and anyone can Unlock it and send text messages or do whatever they need to do. Whereas now you've got biometrics, right? You've got fingerprints and you've got face IDs. And I never forget the first time I got a ah, modern phone. I will say, I won't say any brands. I didn't believe it was going to work. I said there's no way this is going to get my fingerprint. And I'm testing on other people's devices and no, that blows my mind still that on a handheld personal device we have got biometric technology that can identify that it's you opening that uh, and not someone else doing the two key sequence. So yeah, mobile tech and security for

Speaker A: me, yeah, I very much remember those clunky, bulky mobile handsets. Extend the antenna, do a phone call. We've come a long way so super interesting. I could geek out on this like all day but frankly speaking we have other stuff. We also want to talk about going perhaps a little bit from like a personal level to the business commerce side of things. Right Andy? Commerce in general, but I guess also all saints. Uh, you've made like lots a lot of progress on digital transformation, right? Going from predominantly brick and mortar retail to more of an omnichannel approach. Can you talk us or walk us through some key technology shifts that enabled this transition for you?

Speaker C: Yes, and I think that there's two major shifts that we made back in 20, um, 19 we transitioned into Google Cloud from a managed supplier which did the job for us on our old tech stack. But we needed to be a bit more dynamic, a hell of a lot more efficient. We needed to kind of absorb new techs really quickly without having to redesign the whole platform. So moving over to Google Cloud platform, huge, huge step, took a while, took about nine months and I was the pm and I'm not a pm, so but we landed, we did it and um, that just opened up so many tech avenues but also cut out a lot of costs. So it was win win. But that was kind of phase one, kind of the bigger phase was using our selection of partners and more specifically SaaS tools. So we were in a very much in house kind of way of working and developing with developer owned software. But we're not a software house, we're a fashion retailer. So we're trying to do a different kind of role that we're probably not really set out to be. Now you need tech resource, right? There's no doubt you can't outsource everything, right? You need to have a Little bit control of what tech you manage. But we weren't big enough to manage a whole software cycle on multiple platforms. So we kind of made a shift as well. Let's choose the right partners, let's move over to SaaS that complement not just picking one because it's what our ex CFO used or somebody who knew someone also uses them. So using it, what's our tech stack like? What does it match? What are we looking to do in the future? Looking at more than, you know, one year, the future plan, uh, what we're looking to integrate into this solution and trying to find a better mix so we don't have to add on additional SaaS to fulfill the requirement that we didn't have at the start kind of thing. So we've still got in house, don't get me wrong, but we've kind of shifted um, some of the big software solutions over to purpose built. They've got thousands of developers working for their platforms. Right. Leveraging their scale and then we just plug in the tailored bit. The niche bit that we want to make is a bit more of a usp. So those two things really leveraging the cloud, getting the most out of it, but then also leveraging the SaaS products that are out there.

Speaker A: Yeah, that boundary of getting built versus buy. Right. I mean like that is so tough as an organization. I think you're always thinking about, okay, cool, we are uh, the special Snowflake. Realistically speaking though, there are so many other customers that also have the same like requirements. Right. And then you just need to customize the market standard or whatever that might be to your needs, which still requires a lot of resources and processes and experience. Right. To get that right and continue iterating. But yeah, super interesting. Christian, you talk to a lot of companies at Cloudflare and I know that because I know your travel schedule. Have you seen other companies, especially retailers, and talk to them? How do they approach this transformation? What are patterns that you've seen from companies like All Saints that have gone

Speaker B: through similar shifts fundamentally, whether it's a, uh, bricks and mortar retailer moving into E commerce, whether it's a full E commerce with less bricks and mortar. And actually those trends are quite interesting because we typically see a lot of uh, our bigger, I'm going to call it retail customers who are very much a mix of traditional bricks and mortar, but then moving more and more of that business to E commerce. And that's really as a result of how the customer builds, behavior is changing, which I think we would all recognize. There are actually a few examples which is kind of a true anti pattern. I think there's a couple of big customers that we have who started off purely online, but the success of certain brands have caused them to think about opening high street versions of the online brand. So that's kind of an interesting dynamic because you would think that from a trend perspective you tend to see less bricks and mortar and more digital. But this particular customer, the trend is reversed there where they were so successful with, with digital that they've brought one of those brands into the high street. So it's kind of an interesting, just an observation going back to E commerce, Matt. I mean I would say that a bit like retail banking, right? Some of the more established, let's say longer term, more recognizable, uh, customers and names that everybody would know, I think they've had very complicated, just as Andy was saying, very complicated homegrown, self developed E commerce platforms, just like we see with retail banking. I'd say that retail banking is one of the most complicated worlds there is because all the traditional systems that have been built on, um, iteration after iteration after iteration. And if you're a COBOL developer now, then God bless you because you're commanding a significant amount of money from a contracting point of view, right? So if you think about that as a parallel, I think modernization of that core E commerce platform is something we see over and over again. Now that could be as Andy was saying, and it's interesting because I think what we've seen is some organizations trying to modernize their own e commerce platforms, you know, and use the same kinds of patterns and things that we would see. Whether that's backend for front end, whether that's strangler patterns, whether that's containerization, we see that a lot. But just as Andy was saying, we see a lot of organizations who are saying, you know what, it's the end of the road for this technology. It just is not sustainable. It's too expensive, it's too risky. And so the core E commerce platforms are being migrated to, just as Andy said, companies who are professional at uh, providing those highly configurable, highly functional E commerce platforms, but without the need for folks like Andy's to be expert on them from a technology point of view, much more at the business configuration level. So that's kind of a couple of

Speaker A: things that we see for sure, that makes sense. One thing that I've been thinking of while you two were talking, right, is like none of this is Greenfield, right? Everyone is dealing with legacy, with brownfield and also like the nature of the business. Right. It is just the amount of complexity. I think if I got this right, we did a little bit of a pre discussion. Andy, your business has over 100 different vanity domains. I can barely imagine how complex it must be to operate at this scale globally and not miss an important piece of misconfiguration or introduce some security vulnerability just by overlooking something. How do you and your organization deal with this insane amount of complexity?

Speaker C: Yeah, it's a good question because like I say, you're only as strong as your weakest link, right? So people are uh, not just spoofing domains and phishing, but they're taking over domains that you own if you don't configure it correctly. So yeah, we're very, very much on it. We do have tools in place that don't just look at our primary domains. Right. Everyone knows our big domain. We use it at all the countries in the world. That's the top one. But like I said, a hundred smaller ones that can be abused. Right. People can see an email come from a domain that we own and well, I've checked on the lookup and it's owned by us, it's retail, so therefore it must be legit. I'm going to respond and whatever. So we have to make sure that they're owned for us. So using tools out there that look at our portfolio, um, our domain portfolio that check for little bits like SPF records, DMARC records, we get an idea of which ones have been missed and if we do have an open door for one of the mail servers, for example, but also the security headers. So even though we generally just forward on these websites to the primary domain, we still have to manage those redirects, manage the, those redirect rules. And uh, that's where we use Cloudflare workers. I have a template that add a route to as and when we buy a new domain and it just pulls in, locks down all the headers, prevents high frames, all that stuff.

Speaker A: Two things. What are DMARC records for? Perhaps people that are not operating on this level, why are they important? And the second thing is Cloudflare workers on a high level. Can you explain it in like a sentence?

Speaker C: Of course. Well, let me start. So dmarc, spf, they're basically gateway records. So when you send mail, you kind of authorize certain systems and even IP addresses to say, these are legitimate senders of emails from my company. If it's not on this list, then your ESP email service provider should Check these DNS variables and say you're not allowed to send on that, therefore I'm going to mark you as spam. So when you get that wrong and when you have it open, basically anybody with a mail server can send on um, behalf of that domain.

Speaker A: Okay. And that is a big, big business security risk, eh?

Speaker C: Huge, huge. Especially when that domain is also used by our senior retailer, so our senior directors and our cfo. So if theory they could then send email as uh, one of our directors, you know, and that could get very dangerous in terms of malicious payments requests, et cetera. So we have to be sure that only authorized mail servers can send emails to internal, external and obviously our customers. So DMARC SPF, SPF's kind of the older version. DMARC's a lot more stricture. It's the key you have to have, um, generated from, from source. But yeah, all for the benefit of ensuring our domain sending emails that are secure. So that's the. So cloudflare workers. It's a tool I've used many, many years. I'm sure Christian's going to correct me when I get it wrong. But it's basically Edge Compute on the network. So we predominantly use JavaScript but very, very heavily customizable. You can do a lot of things in there. Um, we actually do geo redirects. We extract the browser code from so the country code from the user's browser and make a decision. Actually we've got a better website for you that's in your language, in your currency, it will send you there all at the edge. I'm not running that infrastructure within our stack, I'm doing it on the cloudflare edge. So we do that. We also can add uh, security headers. So rather than configure them at a server layer, again inside our stack, we can do them at the edge. And this is especially pertinent when we don't have a server for a vanity domain. We don't want to run a server for a vanity domain because that in itself is cost for one. But it's also vulnerability. Right. I'm having to patch and maintain a server. I'm having to make sure Apache nginx is up to date. I don't want to do that. I'll be honest. Not that I'm lazy, but I'm efficient. So that's again what we use cloudflare workers for. Um, that Edge Compute, that's all managed by cloudflare, but I can configure what I've put in that container and this is where I lock down secure headers, make sure that nobody can iframe in any part of our domain or other domains into those domains that we own. So very simple, you can do it once. Once you get the core worker set up, you're then just adding routes, which is domains or paths. So very quick and eas.

Speaker B: Cool.

Speaker A: So that sounds to me really smart, right? Number one is okay, cool. Use automated tools basically to check that all your properties are like, probably configured ideally, right? Like minimize the human error or have a system check, so to say. And then basically, okay, focus on your core properties out there and for all other things, find a tool that allows you to do the configuration with as little, like, overhead as possible. For this, you use Cloudflare right now with this, like, customizable workers platform. And then basically make sure that you don't have to operate thousands of different services that basically do very little. Just have Cloudflare do the heavy lifting. That makes a ton of sense. I like that. And also like, it's a little bit of a separation of concerns, right? You manage like your business logic in the back end on the cloud, as you say, right, for your core, and then use Cloudflare as a separate, like, configuration layer just before that. And I've always wondered how those like, country redirects work where I'm like, traveling and all of a sudden I get it to get a different website. So that makes a lot of sense. Christian, I'm, um, curious. You've been both on the vendor side and the customer side, right? Do you have any recommendation on what customers can and should do to prevent fragmentation and make large footprints like physical and digital more manageable? Perhaps reduce also exposure, I guess at the same time, right? If you can measure better, most likely you do see, uh, exposure. At least that's my hypothesis.

Speaker B: Yeah, well, I think that might be a detailed answer, Mark. And I think like anything, I think it depends on where each customer's starting from. I'll give you an example of. So the big digital transformation project I did way back when, we started off understanding what we had in terms of the application landscape, right? Because obviously, like Andy was saying before, there's always a decision to be made around what applications do I need for the business. Then there's a strategy around build versus buy, as you said. And of course that buy doesn't always mean SaaS. It can be buy as in a commercial piece of software like SAP. Now, of course there's a cloud version of SAP, but I would say most SAP installations I've ever seen are, uh, still largely on premises, which is totally normal versus creating your own ERP system. So I think there's all sorts of questions there and then the other one with several actually. But I think the other big two, I would say, uh, simplification of core infrastructure is a big one because when you think about large organizations that have, whether that's physical retail stores, offices, factories, whatever, that network gets pretty complicated pretty quickly. Right? And I think when you add in M and A to that, or entering new markets or buying other companies or buying other parts of a business, you always inherit something that you didn't ever design. Right? So you continually in this kind of evolution mode. I just think some really strong fundamentals around understanding simple things like what's the target architecture, how do we get to that target architecture, uh, without allowing too much drift? Because there's always my experience, no matter what you do, no matter how you plan for it, the business always throws you a curveball, right? Whatever that curveball looks like. But I think being able to fit things in that target architecture, and of course we're seeing that from an application point of view relative to some of the things that hopefully are going to evolve in platform engineering and developer portals, all those things where the target architecture is represented in some kind of code. And I'm going to use IAC as an example there. So building up cloud landing zones and making sure that people know what frameworks are permitted, investing a lot in the DevOps toolchain, automation, orchestration, all of that really helps with complexity and drift over time, in my experience. So I think there's a lot to be done there. I'm saying it like it's simple and it's really not. You've got to always balance that question of what the business needs with how fast you can respond, how you deal with those. Only call them exceptions to target architectures. And then of course you've got, and I think this is a really interesting one and maybe Andy can give some comments on this. I think there's always a concern we've had historically and when you're deploying physical hardware and you're deploying things on your own network or at the edge or whatever that you own, you've always got to be worried about the attack surface management, right? So every piece of hardware has another CVE every other week, something else happens, something else happens. When you move that to SaaS and I'm talking, you know, from uh, a sort of an application strategy, there's usually less reliance over time on the Physical hardware, because the way you're connecting and what you put in place, you know, whether that be some secure service, edge stuff, casb, secure web gateways, whatever, you still got the challenge of the attack surface and you've still got the challenge of making sure that you know what's in that estate. But I think what you do over time, and as Andy said, you kind of outsource they trust, not just from a security perspective, but from a performance and an operational point of view. That's a story we talk about a lot. Cloudflaremark, as you know, in terms of the size and the scale of the network that we've got and the no single points of failure. So all of that, and especially when you think about resilience is now the key word, right? Used to be protection, now it's resilience. And when we're thinking about resilience, especially in retail, and I know just few months ago Here in early 2025, we've seen some really bad examples of what can happen when things go wrong in UK retail. So I think everybody kind of knows what happened there. Uh, so I just think complexity is part of life in technology, especially in big companies, and especially in companies who are making more use of digital in different ways. I think we're spreading kind of the complexity out a little bit, but I do think it's possible to tame it as long as you have some of those fundamental pieces in place.

Speaker A: Yeah, makes ton of sense. Christian, we also talked before this, right. And you mentioned a little bit like there are concerns around security, right. You mentioned resiliency. Already one particular story or angle you had in mind, I guess, protecting loyalty programs and the attack vector from there. Just because there's like high value customer data. Can you talk a little bit about that? I'm super curious. I found this quite interesting, but we only reached the surface, so we'd love to learn more there.

Speaker B: Yeah, absolutely. I mean, it's interesting. The whole thing around loyalty programs and loyalty activity, uh, comes up in a lot of conversations with CISOs, not just in retail, but anybody that has E Commerce. I think a few years ago there was a famous attack where an airline had had its loyalty scheme compromised because there was no sort of real time detection on that and because the techniques and the tactics that were used were kind of novel in a way that what was happening was things like passwords playing, credential stuffing were being used for account takeover, in essence. But then once the bad actors were in, they were using the loyalty points to exchange for things like gift cards or other things that then had a whole other transaction that wasn't really traceable. And so I think I was reading something a few weeks ago that said, I think it was in 2024 that loyalty fraud cost companies about $4 billion globally, which we always talk about credit card fraud and everybody points to PCI DSS and that sort of thing. I think we're probably getting better at that, uh, in general. But what was really interesting was the data told me that a compromised loyalty account sells for between 10 and $50 on the dark Web, whereas a stolen credit card information only sells for five. And I think the reason for that is that there's a lot more sort of, let me say, focus and a lot more fraud detection on credit card because it's been the number one thing that we've seen get used versus this. You know, I'm going to use this to create other transactions and almost create this swap market when I've got a, uh, compromised loyalty scheme. And so the third bit of that mark, which I think is really interesting, and again, maybe Envy has a view on this, but what some of the forensics told us was that those loyalty accounts were not only compromised using the, let's say, really unsophisticated things like password spraying or credential stuffing, they were actually exposed via poor API security and poor API management. So you think about, like, what happens with loyalty schemes. Oftentimes they're actually separate from the core systems, so there's kind of some kind of integration. And, uh, that integration oftentimes extends out into third parties. In doing so, the API piece becomes really important. And so going back to say, let's say 2023, 2022, whatever, PCI DSS in its version then didn't actually include API control in the spec. So it was all about securing that credit card transaction. Again, what's been interesting to see, and again, I'm sure Andy has a view on this that PCI DSS 4 and 401 now has controls in there about API access, which I think is great from a security perspective. It's great from us, for us, because obviously we talk about API security a lot in the context of Cloudflare's overall portfolio, what we do there. But I just think it's been really interesting. Every time I go to a supermarket, every time I go online, there's always the loyalty bit. So I think the loyalty element, whether that's to get instant access to special offers or whether that's to get literally more points so I can get some Free, whatever a bit later on. I think that to me anyway, as a consumer it's become really important in where I go. So if I go to the same supermarket, the reasons for that are so I can get better deals and I can get whatever and save money somewhere along the line. It's the same with fashion, it's the same with electronics. It's the same, it's the same, it's the same. So I'd be interested to get Andy's view on that because obviously customer loyalty is a key part of customer retention, but it's also a key part of customer trust. And if that trust is broken as a result of an exposed loyalty scheme, I think there's a whole reputation risk element there that perhaps is more important to the providers than many might recognize.

Speaker C: Yeah, 100% Kristen. I mean we are early days in our loyalty program and I think one of the enablers was moving over to a SaaS provider. That helped. But historically we found our uh, I guess our bad actors have focused on our gift cards. I guess it's quite similar. So you're right with PCI DSS you're generally locked in, right? You've got, you're using iFrames that are hosted by your payment gateway or APIs or cartridges. So it's, you're safe, you're protected, the liability shift, you're done. However, the gift cards is not as simple as that, doesn't fall into that category. It's a different provider. It's generally a pin, a carving a pin versus a CV2 a ah, billing address. Right. So it's a bit more uh, exposed. So this, this is another area where in the past where we've seen abuse or attempted abuse and um, this is where we kind of leverage our rate limiting as well. So if we see endpoints being particular harassed by certain user agents ip' we can just write them it off. We can identify that someone's having a go without impacting our customer. Because this is the balance, right? You don't want to annoy a legitimate customer who just wants to spend their birthday money on your website. You don't want to have to jump through hoops and gates and you want to make it as easy as possible for the good, but really hard for the bad. Right. So leveraging stuff, I mean through Cloudflare as well, the rate limiting endpoints that particularly susceptible to this kind of mass abuse will rate limit and block them at the edge IPs we're not Truman, because downstream now it happens with payment gateways as well, as giftcraft were paid per transaction, so that was a fiscal risk. Even though. Yeah, great. Hey, you got blocked. That's the wrong pin. You know, uh, we haven't been defrauded. You still cost us a bit of money because you're hitting these endpoints that are, uh, transactional based. So there is a risk there. That's why it's important to safeguard. Like I said, APIs, they all have an M endpoint, but they've got to be public, right? Because it's coming from a browser or an applications. So it's getting that balance right. You've got to mitigate that risk. You've got to make sure you put the safeguards in. You've got to do what you need to do for PCI dss, but you've also got to make it as easy as possible for your consumer. Right? Because they're the boss, as my CEO always says.

Speaker A: Well, well, uh, put. That actually is the perfect segue to a topic that I've been curious to talk about. And it's 2025, so you can already guess, I guess where I'm going. AI is changing the world, right? It's everywhere. Just this morning I used AI for coding. Frankly speaking, I'm pretty sure like my dad, like he uses AI to learn Spanish right now. I think it's becoming more and more part of everyone's life. Right. I'm curious. My hypothesis is, and uh, would love to get your thoughts on this is I think we're a few months away that we most likely will buy items through an AI interface of our choice. Whatever your personal assistant is or uh, chat tool, doesn't really matter. I think it's quite natural, right, that I go in and say, hey, I have my intent, I want to do this. And you just do it. And you never ever go to the store's website potentially, Right. Maybe for the checkout, I don't know exactly right. When I say that. What is your take on that? And I would love to hear, like you mentioned, like the balance between what the user wants, right? The user wants to have the simplest way to actually do something at the same time balancing with risk and security at the same time. Right. So would love to hear a little bit more about that. Andy, is there, uh, like when you hear that, what do you think of.

Speaker C: Definitely, right. It's become so much easier if you look over the past, like pre apps, right. You very rarely transact on a website. You might put an inquiry in, but then you probably rang up and paid over the phone. Right. So I think the ease to transact certainly smaller items with your digital wallets, right. Sometimes you don't even have to put in your address, it just pulls it all down from your digital wallet. Right. So I was fraud because it's not going to be deviated to a different address.

Speaker A: Right.

Speaker C: So there's that benefit there. But it also helps you because it's like literally a double click on your phone and I didn't really need that extra pair of trousers, but I've got it anyway. But I think the twofold AI is helping us as a company in terms of our day to day. You know, we're a Google house where we leverage Gemini. I actually use Gemini to tweak my cloud workers. I'll uh, be honest. Right. So it's there to help developers, non developers like myself, there to help people in the office just optimizing efficiencies. So there's everyday uses that indirectly helps our customers because we get better, we get more efficient. But then the edge stuff, right, the stuff that they're exposed to, um, it's all about content at the moment in my opinion. It's like we've got a product that we need to show at its best. So using AI and that's something we're looking at currently using an AI for a virtual changing room. So by not everyone's to upload their picture or their shape into AI, but those who do it will allow them to change different clothes on and impose their face. And I'm not sure if I suit that color. Let me. Oh actually I do actually suit that color. So that there's a sales benefit, right. Obviously we want to show off our products in the best way and put you in it, right. So you can envisage and understand what it looks like with you on. And not just a model that doesn't look like you has a different skin complexion, different hairstyle, you know, so it's kind of making it as real as possible. And there's other benefits in that, right. Aside from the sales. But returns, right. I think everyone returns products, right. They buy it, they buy the two different sizes or two different colors and the way to see what it looks like. So if we can reduce the, that waste in returns so the amount of packages that go back, I know it's small but there's a carbon footprint improvement there, right. And there's a cost improvement because the companies are paying for these free returns. Then they've got to reprocess the package, put it back on the, you know, so Yeah, I think customer first, as I mentioned, customer's boss. But then also if we can be more efficient as an organization by reducing these returns and there's a knock on improvement for the end user of the company. So yeah, I think multiple facets in how AI will help us. There's more to come, but I think we've got to walk before we can run. And I think that those virtual payments, whilst I love it, Christian and I can definitely see it, I think it's going to be a little bit further down our journey before he grows that one.

Speaker A: That makes sense, Christian.

Speaker B: It's funny, I mean as a technologist and when you step back from things, you kind of always wonder, have we seen this movie before? Right. And it's always interesting when I think about like your direct question about the way we buy things going to change. And I think the answer is undoubtedly yes. But again, if you asked this question a decade ago, I'm pretty sure nobody would have foresaw being able to order things from a large online retailer using Alexa, right? So suddenly you've moved the human compute interface away from the keyboard and the mouse to voice, which in itself, when you think about the technology behind the nlp, I mean that to me is nearly as mind blowing as GPS going right to the start of today's conversation. So you look at that and you say, okay, well that changed and that was pretty cool. And did everybody do it? Well, maybe, maybe not. And then you think about what Andy, um, was just talking about with virtual changing rooms, right? And for the last decade it's been the year of augmented reality. Literally every year for the last year, 10 years. This is the year of augmented reality. This is why we have the Metaverse. And it didn't quite do it. And so you kind of look at those things and you think, so what's next? And I actually think just from my own point of view, when I sort of step back and look at this, I think it's going to come from this notion of hyper personalization, from the touch point with the end user and meeting that end user, or let's say end customer, wherever they want to be met. And that's where the omnichannel strategies are important. That's where understanding the buying intent, the buying factors, just making things so irresistible as a consumer and irresistibly simple to complete the transaction. I think to me that's the exciting bit. And then if you move to the sort of the backend question, AI, ML, whatever we want to call it, for optimizing Supply chain for doing the things like Andy's talking about, how can I get things to the customer quicker and um, more complete, more fit for purpose. I think all of that is going to be predicated upon a whole new set of, let's say data driven insights. I'm going to use that term really, really loosely. That optimize the backend and it can be right the way from manufacturing if you keep pulling on that thread, not to use a fashion pun, but if you keep pulling on that thread, you go all the way to where do these things get manufactured? You know, where do we source the materials? How does that be more sustainable? How does that be more fair for those who are providing that service? Right the way through to when does it turn up at my door? And all points in between. I think if I look at that, uh, from a technology perspective, it's like, wow, that's going to be significantly impacted. So you've got literally people growing the cotton all the way through to people wearing it and all of the stuff you need to do in between to get that from a fashion point of view to be more immersive and more complete and more successful for the customer and for folks like All Saints, I just think it's a super cool set of challenges ahead.

Speaker A: I fully agree. Andy, Christian, I have one last question for you guys and this one will be what I call a bit like the quick fire round. So I'll ask you a question and I want you to answer in like 2, 3 sentences. The main theme, uh, I think from our conversation today was transformation. And that is like going from perhaps on um, prem to the cloud, going maybe from where we are today and what we, how users buy today to where, how they might buy in the future and also how we as businesses operate, becoming more efficient and all these kind of things. It's constant transformation, right? As the technology changes. However, I'm curious what is like the most crucial non technical factor that you see that contributes to an organization's success in transformation? What should leaders put emphasis on? Andy, I'll uh, put you first on the spot here.

Speaker C: To me it's collaboration. I think quite often tech gets the pressure, right? What's tech going to do for me? How can tech change this? And it's like, well, tech can empower a lot of things, but it's going to be driven by the business, right? They've got to say this is what I want to do. How can you help me? M more so than retrospectively, I've got this really good tech. How can we put it in our business. It should be what am I trying to achieve first. Right? And I think that's where a lot of. And we've done it. We've got kind of lost in the toys and the tools, but not actually thought, well, what do we need? Need, Do I actually need that? Do we need robots in our warehouse picking everything up? Because we're only doing 20 orders of doubted, bad example. So I think collaboration, working with all departments, right. It's not just what finance want, it's not what marketing wants or customer experience collectively. What do we want to deliver, uh, with technology, what we're trying to improve, what we're trying to enhance. So working together is my key non technical buzzword.

Speaker A: Awesome. Christian.

Speaker B: It's similar to Andy's but maybe a different spin. I mean, I think first and foremost, I would say having gone through my own transformation and then worked with many other on many others, there is no end to transformation. Right. First of all, that's the key takeaway because there are projects that have an end. There are initiatives that are, uh, groups of projects that have an end by definition. But transformation, just like we've seen in the 50, 60 years of modern technology, there is no end. I think what we still have a lot of is resistance to change and a lot of legacy mindset. Call it institutional memory, call it institutional knowledge, call it what you like, but I think as we have a shift now where there's uh, an older demographic moving out of the workforce and ever younger demographics coming in, so you've kind of got the digital immigrants versus the digital natives. I think you can call it that without too much geopolitical concern. What happens in this left hand end are, uh, natural change agents. And I think if organizations can find and strategically deploy those change agents, I think that's where we really see great successes in transformation. It's no good just having it on a whiteboard and an aspiration and a statement. It needs to live and breathe at all levels of an organization. And um, my experience is that there's a lot of resistance to change up and down in technical and non technical. And I think anytime you can find and deploy the change agents, and I'm giving you a line in there, Mark, to talk about agents in general, but the change agents are key to any transformation in my experience. And that's very much a cultural shift.

Speaker A: This was awesome. Andy, Christian, thank you so much for being on. I learned a lot. I enjoyed this a lot. Thank you so much for uh, joining us.

Speaker B: The pleasure.

Speaker A: Thank you for having us and to the listeners. Also, thanks for listening in. Stay subscribed. Join us for the next episode. Thank you so much. See you soon. Cheers. Thank you for tuning in to the Connectivity Cloud podcast. If you found today's episode valuable, be sure to subscribe so you won't miss future updates. Stay ahead of the curve, stay connected and stay secure. As always with cloudflare,

Related episodes across the Index

Other episodes covering the same guests and topics, from across The B2B Podcast Index.

  • Eric Ries on Why Good Companies Go BadPodcast Archives · on Cloudflare92 / 100
  • OpenAI launches Daybreak with Cisco, Cloudflare and CrowdStrike, Vapi wins Amazon Ring as it raises $50M Series B, JPMorgan picks Mistral as $430bn sovereign-AI rival, Isomorphic Labs banks $2.1bn led by Thrive CapitalThe Daily Marketing Brief · on Cloudflare88 / 100
  • Sam Goodwin - Alchemydevtools.fm · on Infrastructure as Code87 / 100
  • Mahdi Yahya (Ori / Radiant) on Getting Acquired by Brookfield, Building the Backbone of Sovereign AI, and Why Intelligence Is InfrastructureFWDstart · on Edge computing86 / 100
  • Everybody Wants AI. Who's Paying for It?AI Proving Ground Podcast · on Edge computing85 / 100
  • 270: How We Actually Use Claude to Run Our Businesses (With Real Workflows)Creator's MBA · on Cloudflare85 / 100

More from The Connectivity Cloud Podcast

All episodes →
  • Cybersecurity Predictions 2026: What Security Leaders Learned in 202566 / 100
  • Inside Cybersecurity's New Arms Race with Vladimir Krupnov and Blake Darché74 / 100
  • How This Bank CISO Can Redeploy His Infrastructure in Minutes61 / 100
  • Why the Next Big App Might Be Built by an AI Agent57 / 100
  • How to Build a Security Team That Actually Enables the Business with Olivier Busolini
Explore the best B2B Ops podcasts →
All The Connectivity Cloud Podcast episodes →