Welcome to Zcast everyone. I'm Z S Caravella from ZK Research and I'm joined today by Raj Krishna from Zscaler. I believe Raj you're the SVP and new new initiatives. Thanks for joining me. We're going to be talking zero trust and certifications. But before I do that, let me just give a quick shout out to eWeek. eWeek is my media partner. All Zcasts are done in conjunction with eWeek eSpeaks. Raj, can you just give us a quick intro to yourself, what you do at Zscaler, what Zscaler does?
Yeah, absolutely and ZS, thank you so much for for having me on and to eWeek thank you also. So my name is Raj Krishna. I'm the senior vice president of new initiatives here at Zscaler. I just joined Zscaler about six months ago. Prior to Zscaler I was at Meraki for about 10 years where I ran product management, joined Cisco as a part of the Meraki acquisition. I came to Zscaler because I saw a shift happening in the marketplace. I saw more and more cloud SAS adoption as well as companies want to adopt more agile nimble architectures to drive digital transformation.
What does that mean? They wanted to adopt security cloud. They wanted to adopt sassy technologies. They wanted to essentially send their traffic to Zscaler and use Zscaler as a way to get best in class security. So that's what Zscaler does. Zscaler is the world's largest security cloud. We we sit in line. We're a policy enforcement engine. Traffic comes to us. We make sure that nothing good is leaking out. So we do things like data loss prevention and we make sure that nothing bad is coming in.
So we apply best in class security filtering engine. Here at Zscaler I'm tasked with driving some new products and some new markets as well as some key strategic initiatives. Things like for example, this new zero trust certification program that we're going to talk about today. Yeah, you know, it's I was at you guys have grown quite nicely. I was at the very first Zenith Live event. That was a long time ago. Before you guys even IPO'd. I remember one Sizo talking and saying that he was like angry at the security industry.
He said the old model security wasn't working, never working, wasn't ever going to work. And then he moved it to the cloud and of course he was lot you know more happy with that. So and I did want to talk to you. I know you you know you mentioned you're a Meraki or a Zscaler so you got a lot of you know cloud experience in your life and so that's pretty interesting given the relatively new transition security has made there. We are going to talk about your certification but I I first wanted to touch on zero trust, right?
And Zscaler as a company may have actually been the first vendor to start using that term broadly. But it's a term like most terms in tech tend to get overused. So can you help us understand what zero trust is, how you define it and and maybe what you know even what it isn't. Yeah, absolutely. So zero trust is this is the principle of least privileged access. I'm going to default deny all communications, all access until I've verified your identity.
That's what zero trust is. How we talk about zero trust though to our customers and to our partners in the industry just to simplify things and sort of put business context on it is for Zscaler the way that we always describe zero trust it is it is about connecting the right user to the right application based off of a business policy that you define. User to application, application application, machine to machine, whatever it might be, it's all based off of business context and policy that you've defined.
This notion of connect the right user to the right application based off of business policy is fundamentally different than sort of legacy networking architectures. If you think about how networks have evolved over the last 20 30 years, we went from IBM SNA networking to IP networking, Cisco was born, Cisco they job with routers, hubs, switches, and everything was in the data center and you would essentially build a moat around that castle, which was your data center, right?
And you would put firewalls there. And and slowly as branches came to be and as people started to go home, you would VPN in to the data center, right? Now, the problem with VPN and I'm going to draw a contrast to zero trust is that when you connect to VPN, you are by definition on the network. You can move laterally. You can run an Nmap scan. You can discover assets. You can find the crown jewels. You look at almost any of the high-profile breaches in the last 5 years, it's been a contractor's credentials got breached, an employee's credentials got breached, somebody got socially engineered, somebody got fished.
One asset was compromised, somebody got onto the network, they moved laterally, right? So, this is this is why we talk about things in terms of zero trust. Is zero trust is inherently I'm not putting you on the network. That's the fundamental differentiator and key between a legacy firewall-based architecture, a legacy VPN-based architecture, and zero trust. With zero trust, I'm connecting Zayas to this HR application. I'm doing I'm validating Zayas's identity and then then and only then am I allowing him to connect, right?
I'm not putting you on the network. So, we talk about network is simply transport. We don't put you on the network, and that's what we mean by zero trust, right? User to right application. Yeah, when I when I think about it, you know, I I think the in some ways it fundamentally redefines how connectivity is done, right? Historically, the internet was built on the concept that anything can talk to anything and frankly that's why it works so well, but it also is why if you get like you mentioned if you get breached in one spot, that threat actor gets access to everything.
And so, instead of everything connects to everything, it's nothing connects to anything unless explicitly allowed. And so, to me what that means is zero trust is a fundamental rethink, you know, of how access is done and connectivity. So, it's not cuz some kind of beefed-up firewall. It's not, you know, the the super VPN and things like that. It's not the evolution of EDR and, you know, and all these different definitions that I've seen. So, um and uh That's exactly right.
That's exactly right. And and I think a couple of things I'll I'll add there, you know, a lot of vendors in the industry, legacy security vendors, legacy firewall vendors, sort of try to confuse the messaging a bit. They call themselves zero trust 2.0 or something. They say, "Oh, yeah, but you can do zero trust with us, too." But really what it is is it's a it's just legacy firewalls or it's virtual firewalls in the cloud. Now, another core challenge with a virtual firewall or a firewall based architecture is you have a public IP address.
You can be discovered, you can be attacked, be DDoS'd, right? So, this is another fundamental um differentiator of Zscaler and and and what we feel is a core tenant of zero trust is hide your attack surface. Completely eliminate any of your public IP addresses. You should not be discoverable. So, even if your server, your Apache web server, for example, has a Log4j vulnerability, you should patch it, but you should not be discoverable from the open internet, right?
And that's another core difference between the Zscaler proxy-based architecture and the firewall legacy-based architecture is you're hidden behind the Zscaler cloud. I'm going to terminate your connection. I'm going to validate identity and a bunch of other attributes that we'll talk about as a part of our zero trust the certification program and sort of how we think about it in terms of the layers. And um then and only then am I going to give you access to where you're going compared to a firewall where it's like, "Okay, IP address check, you're on the network and and you're in." And I'm only going to inspect a limited buffer, right?
So, that's sort of the core difference, whereas Zscaler is terminating that connection. It does make me think, you know, there's that old expression that you can't secure what you can't see, but I guess the corollary is true where you can't breach what you can't see, right? So, if you keep it hidden. So, now, you know, we've been using firewalls and VPNs for a long time. I mean, they a long time. And I know, you know, when the pandemic started, you saw a bit of uptick in zero trust, people looking for better access methods.
But in reality, you know, Zscaler predates the pandemic, obviously, right? And so does zero trust. And so, what are the things that are driving an interest in zero trust today where it wasn't in the past? Yeah, it's a it's a combination of things, Zeus. It's a lot of focus around sort of hybrid workforce, right? So, people have gone remote, everybody's gone home, right? Everybody goes home and you're putting you're putting a VPN client now on a machine and that machine could be anywhere.
It could be in a random cafe, right? You put that person on your network, that machine gets breached, you can move laterally. So, I think that's sort of element number one. Element number two is there's been a lot of high-profile breaches recently. And all it takes is one breach to irreparably damage your brand, to result in ransomware, extortion. Your clients could get extorted if if their data is breached. I think that's driving a lot of awareness around just the notion of like, "Hey, yeah, the way that we're set up with a VPN, we're actually vulnerable and this is this is pretty dangerous." And then I think the third thing is especially in this economic environment and climate, there's a lot of there's a lot of emphasis around, "Yes, we need to implement a best-in-class security architecture.
But we don't want to do it by just slapping in more boxes, adding in more firewalls, adding to our already very very dense network architecture and our sprawl and, you know, building out our our our large-scale DMZs. It's about how do we do this with a nice, clean architecture that's going to actually help me save money. That's going to help me consolidate infrastructure costs. That's going to help me reduce my my my my CapEx spend. And zero trust can provide all of these things.
So, zero-trust is all about helping enable your remote users to go directly to applications without sacrificing security. In fact, while while supplying a best-in-class security posture, and that best-in-class security posture will reduce the chances of a breach. There's also a lot of capabilities that that a vendor like Zscaler provides for for doing things like detecting a compromised user, preventing data loss if you are breached. And then last but not least, and one of the major reasons that customers are so interested in Zscaler and why they pick Zscaler nine times out of 10 when whenever they're looking at all the vendors in the industry is because it results in an infrastructure cost reduction.
It actually helps customers save money, right? So, not only can you architect for zero-trust, we can also reduce your footprint and your spend, and you can drive simplicity into your environment. Yeah, I think if I were to sum up what you said in two words, it would be scale and sophistication, right? I know historically when I was back in corporate IT, we only had a handful of people VPNing, and those were pretty tech-savvy people as well, folks like you and I.
So, if you couldn't access or, you know, you you you understood how to change the settings of the VPN client, and and but today, you know, think of as you mentioned, everyone's working from home. You've got contact center agents, you got customer success people, you got sales people, you got a lot of people that really aren't very tech-savvy, and and you can't rely on their, you know, intuition to know what's good and what's bad. And so, uh, you know, I think um, you know, a lot of things that we took for granted maybe with remote workers, you you can't anymore.
So, uh, so, you know, I I think that's certainly true. Now, if when we look ahead to zero-trust, um, it is a different way of thinking about security, right? And I know there's a big skills gap in the industry today, and so, can you can you talk about, you know, what some of those missing skills are, how much of a skills gap there are, you know, things like that? Yeah, absolutely. So, I think the um ISC squared or a similar organization ran a survey recently and they determined that there's I think something like a 3.6 million job shortfall in cybersecurity.
And this is also why the White House recently announced um um their their sort of cyber defense task force where they're partnering with industry to try to close this gap. I was actually just with a with a college um CISO recently and he was talking about how they're pivoting all their courses to try to be a little bit more practically oriented and try to place their students directly into industry straight out of college for cyber. So, there's a there's a huge sort of focus around this right now because because of all the things we've talked about, right?
The the the sort of architecture is shifting, right? You you you no longer want to just deploy more firewalls because of the fact that firewalls are inherently vulnerable and they don't give you the best-in-class capabilities. The security landscape is um becoming very, very, let's say, just uh dangerous in terms of all these sophisticated advanced persistent threat actors and um nation-state actors in some cases who are attacking organizations. So, as a result of this, like there's a heightened demand, but there hasn't necessarily been um a set of training programs or just a a set of capabilities that have been disseminated to people at scale.
So, this is becoming a much, much bigger focus at Zscaler right now. So, we're, for example, having conversations with state-level governments in the in in the US, colleges, um all kinds of different institutions so that we can start to train the workforce of tomorrow. So, we already have a very rich program of certifications, but one new certification that we've just put together is our new zero trust certified architect program, ZTCA. This is a brand new certification that's geared specifically to be both a high-level overview what is zero trust as well as a as well as a very detailed nuanced look at how zero trust all the different layers within zero trust and how to implement zero trust.
And furthermore, comparing and contrasting legacy zero trust with real zero trust. And and and we try to design ZTCA to to be a little bit more agnostic than our usual product trainings. So, there is there is obviously Zscaler is in there and we talk about for example how you implement with Zscaler, but we also are very very detailed and and went out of our way to abstract Zscaler out and to say this is what zero trust is and these are the core tenets of zero trust.
So, the the this program is the first of many and it's being very well received by industry. In fact, I would love to show you a couple of things Sure. Sure. in terms of this program if that's okay. So, this is our ZTCA landing page. So, this is Nathan Howe, he's our VP of Emerging Technology. He actually recently wrote a book on zero trust and the book and the course are sort of interwoven. When you take the course, you get a copy of the book. And essentially, what we've done is we've we sort of defined what is zero trust.
This is very interesting. We we we we define it in seven layers and the first layer is who's connecting. I'm going to validate your identity. I'm going to check against your IDP, Okta, Ping Federate, whatever it might be. The second is what is the access context. So, where are you connecting from? What device type are you connecting from? Is it a managed device? Is it an is it an unmanaged device? What's your location for example? Where are you going?
Right? So, you might be safe. You might have an agent on your device. You might be running all kinds of checks, but you might be going to a very risky destination. So, the first sort of key area is verify and within verify we verify the identity. The second is control, which is all about all right, I'm going to assess for risk. Is this person logging in from multiple places? Is this person, for example, logging in from a jailbroken device? We integrate with vendors like CrowdStrike, Microsoft Sentinel, for example, to be able to Microsoft Defender to be able to check device posture.
Prevent compromise. Step number five is so key. Whenever someone asks me, "What's the sort of one core thing I should think about when I'm looking at a security vendor?" I always tell them, "Can they inspect traffic at scale?" Right? And when I say inspect traffic, I'm talking about 90% of traffic on the internet is now SSL encrypted including Google searches. The ability to actually open up that SSL connection using a man-in-the-middle technique and and look inside that connection and make sure that someone isn't just downloading an encrypted uh file, an encrypted zero-day, for example, from from a OneDrive instance, right?
Prevent data loss. So, we've spent the last 8 years building out a rich set of capabilities so that we can, for example, inspect the traffic and tell you, "Hey, there's credit card information flying out the door. Hey, there's PCI information or PII information." Or you can upload your own intellectual property documents. And the last thing is we enforce policy. Now, enforcing policy is not just about allow or deny, it used to be. You can get a lot more nuanced.
For example, uh one of the Zscaler features is the ability to run an isolated session. So, let's say it's a known user, but they're visiting a risky destination, but that's okay. You can actually say, "Well, you know what? I want to protect the user. I'm going to I'm going to create I'm going to run that session in the Zscaler cloud and I'm only going to stream down pixels to the device. So, the device never actually has the ability to download any infected payload, for example.
So, this is the sort of high-level seven steps of a zero trust architecture. I know I digressed, but um it was here, so I thought I'd cover it. So, this website describes the certification program and there's a special emphasis around what this means in terms of your career and what skills it'll give you. So, what will you learn? You know, you'll you'll learn the ability to apply strategic networking and security concepts. Um this is a course outline.
We talk about who this course is relevant for. And by the way, um in in the early early sort of adoption of this course by enterprise customers and and partners, they've absolutely loved it. They talk about how it empowers them to learn what zero trust is and it gives them the practical tools to actually be able to implement zero trust in their environment. So, you know, it's a it takes about 5 to 6 hours to complete. It's a very very good comprehensive program.
And just to give you a flavor of what this program looks like, here's sort of an inside look at at what this is. So, it's a combination of multi-modal design, lots of lots of, you know, very visual, very very colorful, and also it's very rich on on on lectures. So, so what what we actually have in here is we have our VP of emerging technology give very detailed lectures. And also whiteboard things out. the right environment. So, let's dive into dynamic risk and talk about what that really is.
In life, we really are only judged by our last performance. Value So, we actually whiteboard things out architecture. Again, that's what we don't know about right now. all of the sort of traditional elements in an architecture versus some of the new elements in a in a in a zero trust architecture. We've also put together this very nice one-page study guide that we make available to anyone who's taking the course. And what's what's cool about this course is because we're we we want to invest, we're partnering with colleges, we've made available a badge.
You once you get certified, you can post this badge on LinkedIn. You can post an encrypted URL on LinkedIn similar to how you would post for your AWS or GCP certificates. And the other thing that we're doing is for the first several thousand people that go through this that that that go through the course, they'll get a free t-shirt, they'll get a free printed copy of the book. And just in our in our passion to to get the word out about this program, we are also giving out a a promo code.
And we're going to say as for you and your readers, give you a promo code so that you can so that you can waive the $300 fee. So, you all you do is you use that promo code, you can get full access to everything that I've showed you, you can get certified, you can you'll you'll get the badge, the cert, and if you're one of the first uh thousand people to go through it, then you'll also be able to uh get that t-shirt and that book. So, we're going to great lengths here because we recognize that um that there's more that we need to do in this area, and um that's why we're very excited about this.
Well, thank you very much for the promo code, and uh I'll make sure that in the link uh to the site are included in the YouTube YouTube description down below. Uh you know, Roger reminds me a lot of uh you know, the certification programs that Cisco had, CCNA, CCIE, things like that, because, you know, those programs, um although they were, you know, ultimately Cisco-centric, uh they were uh and I remember doing those tests, they were 90% you know, uh education on you know, how routing works, how switching works, and then there was a little bit of how you do it on Cisco devices at the end.
Uh but this seems very similar. Now, now those programs had different levels, and are you considering that as well? We are. So, when I when when when we built ZT um ZTCA, we very much modeled it after see the some of the classic certs of our time, right? CCNA, CCIE, CCSK, CISSP, um and we wanted to build a cert that would be as iconic as those, right? Hence the Hence the four-letter acronym. Now, this is the start of a journey. Um we are going to probably build out more versions of uh and deeper level versions of zero trust, but also we're building out sort of a new generation of product programs, because what's happening is networking and security are sort of merging, and um you know, a lot of the traditional sort of networking capabilities are becoming redundant, and now people need to know more about cloud and how to deploy some of these web proxy architectures, and how do you deploy not just for users, for your corporate users, but also for your workloads, for example, or for your IoT or OT assets, for example.
One of the big areas, I'll just give you one example of probably 20 discrete um high-profile projects that we're working on right now at Zscaler is operations technology. So privilege remote access. There's an entire industry around this for providing contractors who need to get into a factory floor environment very very controlled access that's time bound where you can record the session and you can you can do things like you know, if someone is uploading a file you send that to your sandbox.
You make sure that you're inspecting it and all these types of capabilities, right? Like it's called privilege remote access. This is a capability that Zscaler has built. So RDP and SSH sessions will render them in our cloud and we'll stream down pixels. That's one example of like an entire ecosystem of capabilities for which we're going to build a certification. So that is going to be one of many, but but to answer your question in a little bit more of a succinct way, yes, we're going to build more programs like this.
Yeah, you know, it's interesting too because other than CISSP, there aren't really that many security certifications, you know, compared to what what what there are in networking There aren't. There aren't. You know, and and furthermore, I was surprised by this. When I was interviewing at Zscaler, okay, I was like, all right, like let's let's learn about cyber. I'm like Googling and I'm trying to find I'm trying to find good courses on like just that that give you a baseline.
They're not out there. So I I I actually think Zscaler is well positioned to solve this problem of like getting you know, build something that can be consumed by by the masses to to to gain this baseline understanding, but it's not out there. I was surprised myself when I was yeah, joining Zscaler. Yeah, well kudos, you know, to you for doing that. 67 hours certainly seems like a pretty, you know, modest investment considering the education you get back.
Now, is there any prerequisite level of security or networking knowledge that the people taking this must have? I think I think we do sort of assume a prerequisite level of networking knowledge like sort of an entry-level like uh understanding of basic networking concepts. So, do you know what an IP address is, a VLAN, do you know what a data center is, do you know what a what a subnet is? I think we sort of assume that as a baseline, so that is I think important.
Um but, you know, in the future we could create an even simpler version as well. Yeah. Well, um you know, from my perspective, uh you know, the world is changing. Obviously, if we're moving things to the cloud, people are moving out of offices, that does require different skills. So, even if you're a seasoned security professional, I'd I'd recommend you you take a look at something like this. So, uh any Anyways, anything else you want to add, Rod?
No, I think um there's a lot of confusion out there. And um I'd I'd say just just be skeptical, right? Um get your training. As you're taking the training, be skeptical because it's a training by Zscaler and we're one of the vendors in this industry, but I think what you'll find is it's a good agnostic high-level overview. And I would say as you think about architecting for the future, you think about networking and security, um really think about uh how you build something in a way that's going to give you best-in-class security posture as well as um improve either either keep the same or improve your user experience.
And the third big thing, right? So, number one, ideal cybersecurity posture, number two, improve user experience, and number three, reduce your costs. If you think about these three things and and achieving these three things, this that is what is what you get with Zscaler. That's why uh every enterprise customer on the planet right now has either deployed Zscaler or is thinking about deploying Zscaler is because of those three things. So, I would urge you to take a take a look with a critical eye because you know, everyone says the same thing and there's a lot of confusion in the industry.
All right. Well, on on that note, uh thank you, Rod, for joining me on the Zcast. Uh I think it's uh you know, a certification is always a great way way validate skills and it's a great way to show employers you have those skills. So, any kind of certification I'm always a big fan of. So, on behalf of Raj Krishna, I'm Z Ace Carol from CK Research. Don't forget to hit that subscribe button and I'll see you next time on another Z Cast.
This transcript was generated automatically from the
video's captions and may contain errors.