In short
Zscaler CEO Jay Chaudhry discusses how Zscaler combats global cyber threats using zero trust, and how AI security and “agentic” AI change enterprise security needs.
Guests
Jay Chaudhry, founder/chairman/CEO of Zscaler (San Jose/San Diego area); Mandeep Singh, Bloomberg Intelligence global head of tech research.
Key claims
Zscaler’s growth is strong despite a slight revenue forecast miss; zero trust (pioneered by Zscaler) is the foundation for AI security; pricing aligns to users and workloads/traffic; Zscaler will build a security-focused LLM using anonymized logs (over half a trillion transaction logs/day from 8,000+ customers).
Notable examples
hackers can use ChatGPT to rapidly enumerate vulnerable firewalls/VPNs; AI can generate targeted phishing emails; AI-driven automation can locate key apps for encryption. Zscaler counters by hiding attack surfaces and enforcing zero-trust “own the network.”
Written by AI. May contain mistakes. Listen to the episode to check what was said.
Chapters
Tap a time to open that second in VOMarket Performance of Zscaler
1:00 to 1:31
Discussing Zscaler's stock performance and market position.
“When you're running a business, the best days are the ones where priorities stay on track.”
Market Performance of Zscaler
2:18 to 3:21
Discussing Zscaler's stock performance and market position.
“with Carol Masser and Tim Stenevek on Bloomberg Radio.”
Interview with Jay Chaudhry
3:21 to 4:44
Jay Chaudhry addresses growth concerns and Zscaler's performance.
“Also, San Jose, excuse me, also with us is somebody who knows this company very well, Bloomberg Intelligence's global head of tech research, Mandeep Singh.”
Understanding AI Security
4:44 to 7:20
Jay explains how AI impacts security and Zscaler's business model.
“you know, do you think investors just got it wrong?”
Zero Trust Architecture
7:20 to 10:00
Exploring the importance of zero trust architecture in security.
“And talking about agents, it sounds like one of your biggest competitors is doubling down on observability and identity, especially on the browser side, as an area of focus for agentic AI.”
Hackers Using AI
10:00 to 12:20
Discussing how hackers leverage AI to enhance attacks.
“But when they talk, Mandeep, about zero trust, this never trust, always verify.”
Zscaler's Approach to Security
12:20 to 14:00
Jay discusses Zscaler's strategies in the evolving security landscape.
“Can you point to specific instances where hackers have actually used AI to enhance their attacks?”
Managing Business Risks
14:12 to 14:42
Understanding how risk impacts organizations and the importance of management.
“For midsize and large companies, risk can affect multiple parts of the organization at once, from property and liability to cyber and regulatory challenges.”
Transcript
Automatic transcript. May contain errors.0:00What if data didn't sit still? What if intelligence moved with us? Not buried in reports, but activated in real time, where lives are being shaped, where decisions are being made. It all starts with a question. Where is the potential? Cotality turns data into clarity, intelligence into insight, insight into action. Because when intelligence moves, we all move forward. Cotality. Intelligence beyond bounds. The thing about AI for business, it may not automatically fit the way your business works. At IBM, we've seen this firsthand. But by embedding AI across HR, IT, and procurement processes, we've reduced costs by millions, slash repetitive tasks, and freed thousands of hours for strategic work.
0:50Now we're helping companies get smarter by putting AI where it actually pays off, deep in the work that moves the business. Let's create smarter business, IBM.
1:00Jay Chaudhry:When you're running a business, the best days are the ones where priorities stay on track. For midsize and large companies, risk can affect multiple parts of the organization at once, from property and liability to cyber and regulatory challenges. At that level, managing risk becomes an ongoing discipline. At the Hartford, the focus is on helping businesses manage risk before it turns into something more disruptive. And when losses do happen, that work is paired with insurance coverage shaped by years of underwriting, risk engineering, and claims experience. Learn more at thehartford.com slash risk mitigation.
1:35Jay Chaudhry:Policies provided by Hartford Fire Insurance Company and its property and casualty affiliates, Hartford, Connecticut. Coffee genius here. Most people see a busy cafe, but I see precision at every step. Thanks to genius from Global Payments. Transactions, instant. Inventory, precise. Operations, in sync. Absolutely genius. From sold-out crowds worldwide to managing the morning rush, Genius keeps operations running smoothly. One portado. Flawless pour, perfectly timed. Just beautiful. Big league reliability for any business. That's Genius. Bloomberg Audio Studios. Podcasts, radio, news. You're listening to Bloomberg Business Week with Carol Masser and Tim Stenevek on Bloomberg Radio.
2:24Shares of the more than$39 billion cloud security and software company Zscaler are easily outperforming both the S &P 500 and NASDAQ 100 today. The stock is up nearly 40 % year to date. And yet we did see shares under pressure today dropping nearly 4 % after Bernstein downgraded the software company to market perform from outperform on growth concerns. Bernstein, by the way, setting its price target on the stock to 264 a share. That's a 5 % increase from the Friday close. I should point out that initially Bernstein, when the company reported earnings last week, they initially maintained their outperform rating.
3:00So there's been a lot of movement. Analysts in general, Tim, a flurry of them weighing in, some raising their price targets on the stock, others lowering them. And we should point out the stock did drop about 13 % last week. That was on Wednesday following their earnings. Yeah, the forecast was annual revenue that was only slightly above estimates. For more on the company, we're joined by Jay Chaudhry, founder, chairman, and CEO of Zscaler. He joins us from San Diego. Also, San Jose, excuse me, also with us is somebody who knows this company very well, Bloomberg Intelligence's global head of tech research, Mandeep Singh.
3:32He joins us here in the studio. Jay, I just want to start with you. The growth concerns, the disappointment over the annual revenue forecast that was only slightly above estimates. Is growth slowing? Not at all. We had an outstanding quarter. Our ARR growth, 26%, revenue growth 26%, free cash flow margin 52%, operating margin 22%. We beat all the metrics that Wall Street was looking for. In fact, if you take our free cash flow margin and add it to our revenue growth, that's 78%. That beats the rule of 40 that many investors look for very, very well. And this is at scale of$3 billion or higher.
4:19There are only about five pure play enterprise SaaS companies that are in that unique class. So we've done extremely well. We are very proud of what we delivered. And we passed a meaningful beat with it and raised our annual target. So I think we're very pleased with it. I think investors get it wrong from time to time. This is one of those times. That's what I was going to ask. you know, do you think investors just got it wrong? Because, I mean, 13 % is a pretty big hit. So you think, I mean, that's not like them wavering at all. They really wanted more from you guys. I mean, the expectations were certainly high.
4:59Look, markets do what they do. I have one focus, keep on innovating and serving our customers. And those innovations started with zero trust architecture, which has changed the world of old school firewalls and VPNs. And now as AI security is coming, AI security is becoming a big concern. And zero trust that we pioneered is the foundation of it. So we have amazing interest from our customers. That's why we're able to deliver these strong numbers. Over 45 % fortune 500 companies trust us, depend upon us. So I'm very bullish about our future. So, Jay, talking about AI security, I mean, you have a business model that's reliant on companies hiring more people, and you have a seed-based model.
5:48How does that change with AI security? Because AI, you know, what we are seeing out there is more consumption-based. So how does that impact you and your business? It's a good question. So we started out with bringing zero trust for users so users can access applications without being on the company network. And natural pricing for that is user-based. Then we moved the model to the architecture of the next thing. How about zero trust communication for workloads, cloud workloads? That's actually based on number of workloads and actually amount of traffic. So it's not just user-based. If you think about AI security, there are many facets of AI security.
6:33What one of the biggest thing our customers look for is, as every company starts using a lot of agents, these agents are somewhat like people. They need to access certain applications. They need to talk to other agents. So we are extending our zero trust exchange that are designed for users and workloads and branches Now, do agentic exchange so that right agent can talk to right agent on right application. So, obviously, there's an opportunity for us to secure that communication. Yes, the number of users may not grow significantly, but I believe every company will have scores of agents for every single employee, and they need to be secured, and we are extremely well positioned to handle that.
7:21And talking about agents, it sounds like one of your biggest competitors is doubling down on observability and identity, especially on the browser side, as an area of focus for agentic AI. Is that something you feel is very important to roll out the agents? So some companies try to go and buy, many companies, to create a collection of things. We are very focused on what we want. We will focus on zero trust and then we focused on AI. Regarding observability, we actually do observability for the areas that matter to our customers. We sit between the user and the application. So today we have a sizable business, hundreds of millions of dollar business with a product we call Z-Skill or Digital Experience, where we can tell our customers if any user is having any performance issues as they try to access those applications.
8:24It's integrated with our platform. While many companies have many point products and they are separate, we like to have integrated platform that serves our customers so we not only provide secure and reliable experience. We make sure that it is fast and you can troubleshoot those things. But I'm not going into broad observability, which has become a broad area. We are focused on the areas that are relevant to our customers. And identity, is that something you care about, the identity on the browser? Identity is important. Think about identity for users. We have been working from day one with all leading ID provider for users, whether it's Microsoft and Okta and others.
9:13Now when it comes to identity of agents, I believe there'll be many contenders. Microsoft, Google, AWS, Okta's of the world. Our philosophy is to federate those identity providers, use that identity, and we are the zero trust exchange, the switchboard, to make sure the right AI agent talks to the right agent. In this world, I do not need to own everything. I need to do some of the things I do the best and integrate with partners with proper API integration so our customers get the biggest benefit. We believe in doing a few things but do them extremely well and partner with others. So I do feel like we're all learning as we go.
9:59And, of course, Mandeep and Jay, you guys are ahead of us in a big way. But when they talk, Mandeep, about zero trust, this never trust, always verify. I think about digital touch points, thinking that there are threats within an organization and outside, and you've got to make sure there's security everywhere. Yeah, no matter where you are. And that's where, you know, sassy is a term that gets thrown a lot. And Zscaler is in the leading position in that magic quadrant. So I have one other question, Jay, for you. So, given the amount of data in the world of security and, you know, you guys generate trillions of data points, will the security world have its own LLM?
10:39Yes, the answer is yes. We are actually working on building our security-focused LLM. And I do not need to have the large, large language model. Security is a very focused set of high-quality data. with over 8 ,000 customers and 45 % of Fortune 500 companies, we generate over half a trillion transaction logs a day. Those logs are anonymized. But they can give us an idea of where the threats are coming from. We can find a needle in a high stack and help all of our customers. So AI is only as good as the data that powers it. and we have the best data and we believe we can help identify some of these threats in almost near real time and provide a closed-loop system so that the threats can't really exploit our customers and provide them benefit at a much faster pace.
11:41That's why we are focused on AI-powered security operations. And our acquisition of Red Canary is part of the strategy because they built some very, very good agentic AI technology that we're integrating with our platform. The use of AI to make the system more robust certainly makes sense. But I got to tell you, Man, Deepar and I are actually moderating some panels next week at a Bloomberg Live event that's focused on cybersecurity. And in the prep that we're doing for that, what I keep hearing from these chief security officers, from these chief information security officers, is the concern about how AI has made the attackers just more robust.
12:18and the attacks more robust. Can you point to specific instances where hackers have actually used AI to enhance their attacks? And did it work? Yes, there are many, many examples. Let me give you a few simple ones. Every attack starts by finding your attack surface where you are. And public IP address is the starting point. Every firewall, every VPN, every application portal is an attack surface. In the past, a hacker may have taken weeks to identify it. Now you can go to ChatGPT and say, tell me all the firewalls and VPNs that have vulnerabilities and give it to me in a nice tabular format. Under 60 seconds you can get that.
13:06Now, the second part hackers would do is these phishing emails. Now they can ask AI to say, write an email that looks like a CFO's writing style. No typos make it very targeted. That's number two. Third, hackers are using automation that AI provides. Once they are on the network, automation can find the key applications and try to encrypt that data. A lot of that is happening. What does Zscaler do in this case? Number one, we hide your attack surface. Your applications are hidden behind our cloud. Bad guys can't even find you. They can find you. They can attack you. And the second is own the network.
13:48The biggest problem with firewalls and VPNs is. Right. They're trying to protect the castle, and we actually make it zero trust. Jay, we've got to run. This was so informative and so enlightening in terms of AI security. We so appreciate it. Jay Taudry, he's founder, chairman, CEO of Zscaler, and, of course, our own Mandeep Singh of V.I.
14:11Jay Chaudhry:When you're running a business, the best days are the ones where priorities stay on track. For midsize and large companies, risk can affect multiple parts of the organization at once, from property and liability to cyber and regulatory challenges. At that level, managing risk becomes an ongoing discipline. At the Hartford, the focus is on helping businesses manage risk before it turns into something more disruptive. And when losses do happen, that work is paired with insurance coverage shaped by years of underwriting, risk engineering, and claims experience. Learn more at thehartford.com slash risk mitigation.
14:47Jay Chaudhry:Policies provided by Hartford Fire Insurance Company and its property and casualty affiliates, Hartford, Connecticut. From game day crowds to memorable meals, Genius by Global Payments keeps your kitchen and floor perfectly in sync. Real-time menus, seamless updates, big league reliability for any business. That's genius. These days, it seems like AI agents are just about everywhere you turn, every field and every function. But without identity, you can't trust they'll serve your business instead of jeopardizing it. Fortunately, Okta helps you get identity right by securing your AI agent's identities, giving you a single layer of control, a single standard of trust.
15:26So whether an AI agent supports a single user or your entire enterprise, with Okta, you'll turn risk into opportunity. Secure every agent. Secure any agent. Okta secures AI. Wise is the smart way to manage the currencies you need around the globe. When you send money abroad using your bank, you could get hit with hidden fees and exchange rate markups. There's a better way. Try Wise. Wise uses the exchange rate you'd usually find on Google, with no unwelcome surprises. plus most transfers happen in under 20 seconds which means your money arrives in less time than you've been listening to me it's simple and free to sign up when you download the WISE app be smart, get wise T's and C's apply
From the publisher
Cybersecurity giant Zscaler is a pioneer and global leader in zero trust security. Many of the world’s largest businesses, critical infrastructure organizations, and government agencies rely on Zscaler to secure users, branches, applications, data & devices, and to accelerate digital transformation initiatives.
The company says its "Zero Trust Exchange" platform is distributed across 160+ data centers globally, and combines with advanced AI to help combat billions of cyber threats and policy violations every day
Jay Chaudhry, Zscaler's Founder, Chairman and CEO, discusses his firm's most recent earnings as well as the landscape for cybersecurity as a service.
Jay speaks with Carol Massar, Tim Stenovec, and Mandeep Singh, the Global Head of Technology Research for Bloomberg Intelligence, on Bloomberg Businessweek Daily.
See omnystudio.com/listener for privacy information.
