In short
Zscaler’s zero-trust cybersecurity approach and how it protects large enterprises against cyber threats, with a focus on future growth from agentic AI, data security, and integrated SecOps.
Guest backgrounds
Kevin Rubin, CFO of Zscaler; previously CFO at BetterUp and CFO at Alterix.
Key claims
Zscaler prevents breaches by (1) stopping bad actors from entering corporate networks and (2) ensuring sensitive data doesn’t escape. “Genuine” zero trust means least-necessary, one-to-one access via the Zero Trust Exchange, preventing lateral movement. Zscaler’s growth levers include Zero Trust for users, cloud workloads, branch devices, plus data security and extending zero trust to agents. AI models are identifying vulnerabilities faster than teams can patch, so hiding applications reduces blast radius. Red Canary adds detection/response agents and integrates into an upcoming integrated SecOps offering.
Notable examples
one-to-one email access sessions that terminate; branch devices (e.g., door sensors) limited to only required apps; Zscaler processing “half a trillion transactions a day” and operating across 160+ PoPs; Anthropic Project Glasswing and OpenAI Daybreak partnerships.
Written by AI. May contain mistakes. Listen to the episode to check what was said.
Chapters
Tap a time to open that second in VOUnderstanding Zscaler's Role in Cybersecurity
0:45 to 2:55
Discussion on what Zscaler does in the cybersecurity space and the concept of zero trust.
“I'm Jason Moser, and today I'm excited to welcome the CFO of Zscaler, Mr.”
Exploring Zero Trust Principles
2:55 to 7:30
Kevin Rubin explains the principles of zero trust and how Zscaler implements them.
“only for the necessary particular use for either an individual, a workload, or a device that sits within the corporate environment.”
Exploring Zero Trust Principles
7:34 to 7:48
Kevin Rubin explains the principles of zero trust and how Zscaler implements them.
“That's quince.com slash motley for free shipping and 365-day returns.”
Growth Opportunities for Zscaler
7:48 to 12:16
Kevin discusses Zscaler's growth strategy, including targets and market drivers.
“Well, I'm going to get into some numbers here as the CFO.”
Partnerships and Competitive Landscape
12:16 to 14:00
Discussion about Zscaler's partnerships and recent acquisition in the competitive cybersecurity space.
“They can't possibly keep pace in terms of their ability to patch and address these things.”
Zscaler's Acquisition of Red Canary
14:00 to 16:53
Learn about Zscaler's strategic acquisition and its implications for security.
“And so being a participant has, you know, obviously been been very important for us.”
Zscaler's Acquisition of Red Canary
16:57 to 17:26
Learn about Zscaler's strategic acquisition and its implications for security.
“When you need to build up your team to handle the growing chaos at work, use Indeed Sponsored Jobs.”
AI Integration and Cybersecurity Budgets
17:26 to 23:15
Explore the intersection of AI investments and cybersecurity financial strategies.
“This is a job for Indeed sponsored jobs.”
Transcript
Automatic transcript. May contain errors.0:02Jason Moser, there's no going back, if you will. I mean, as an industry, Agentec is going to be as disruptive as, you know, any of the tech waves have been in the past, whether it was mobile, internet, et cetera. I mean, this is just the next frontier of how businesses will need to compete.
0:22That was Zscaler CFO Kevin Rubin on the future of AI security. I'm Motley Fool analyst Jason Moser. I sat down with Kevin to talk about how Zscaler is protecting the world's largest organizations from an exploding wave of cyber threats, and why the rise of agentic AI could be the biggest opportunity the company has ever seen. Enjoy. Welcome to Motley Fool Conversations. I'm Jason Moser, and today I'm excited to welcome the CFO of Zscaler, Mr. Kevin Rubin. Prior to Zscaler, Kevin was the CFO at BetterUp, and prior to that, He served as the CFO of Alterix, a company that Motley Fool members are likely familiar with.
1:02Today, we're diving into the business of cybersecurity and Zscaler's role in this crucial market. Kevin, welcome to the show. Thanks, Jason. Appreciate you guys having us on. Well, really happy to have you here. And I guess the first thing I want to get into here, because when we talk about cybersecurity, most of us, whether we're investors or not, we know that cybersecurity is necessary, area, but we don't exactly understand what it ultimately. There's so many different ways to view it. So first things first, we said at the top Zscaler is a cybersecurity company, but what is it that Zscaler actually does?
1:40Yeah, thanks for the question. It really comes down to two fundamental things in my mind. Number one is preventing bad actors from getting into your corporate network and being able to access sensitive information or breaching your environment. And number two is ensuring that sensitive data and corporate assets don't escape out of your corporate network. Those are the fundamental things that we seek to solve. Yeah, well, I can tell you just from my day to day, we use Zscaler all the time here at The Motley Fool. And I appreciate that you're looking out for us. So we hear a lot about zero trust, right?
2:20That's a word that we hear a lot in the cybersecurity market. And Zscaler really pioneered a zero trust model years ago before it became mainstream. But now it seems like everybody claims to offer zero trust. So I guess I'm wondering, can you talk a little bit about what separates genuine zero trust from like what other people call zero trust, right? Because I've heard it called zero trust washing before. Is there a unique property or quality to Zscaler's zero trust dynamic? So zero trust is a set of principles that simply mean provide the least amount of access only for the necessary particular use for either an individual, a workload, or a device that sits within the corporate environment.
3:12The concept is you should not give access to anything and everything because somebody wants to access a single application. So the principles are clear. Give the least necessary access for what it is that somebody or something is trying to accomplish with that particular request. We architected Zscaler specifically with those principles in mind. So the way that we approach zero trust and cybersecurity is through our zero trust exchange. We don't believe in today's environment that companies need to build out large, complicated corporate networks. Right. That was something that happened, you know, 30, 40 years ago when the Internet didn't exist and stable ability to drive traffic didn't exist.
4:02But today, those are as common as is driving on the interstate. Right. If you go back probably 100 years, you had oil drillers who had to build private roads to be able to access their oil fields because general public roads didn't exist. Today, you don't see organizations building, you know, basic infrastructure to be able to access certain assets. And the same analogy would hold true as you think about corporate access to applications and other corporate sets of data. So our approach is simple. You allow your users and other resources to access what they need only at the time that they need it.
4:45And you go through the Zero Trust Exchange. And so think about it as a one to one set of connection. You want to access your email by way of example. You request access to the email server. We authenticate you. We ensure that you're authorized to access that. we allow you to get your email and then that session terminates when you're done using email and the next time you come in you know in the background we'll go through that same process in doing so you don't have the ability to move laterally within the network you have no reason or business to go to other applications if all you're doing is is looking to serve email in the same would hold true if you're trying to go to your hris system or you're trying to go to your crm system, access what you need, be able to do the work that you need to do, but then get off the network and become invisible again.
5:37So that's how we've philosophically approached zero trust. If you are largely building corporate networks and providing network-based security architecture, your application of zero trust is likely through very complicated policy-driven zero trust principles. And our argument would be, to your point about zero trust washing, it's probably not effectively zero trust, but you can brand it as zero trust and go to market that way. We are actually living, breathing, and applying the principles in how we've architected our zero trust exchange and our cybersecurity service.
6:22Summer always changes how I get dressed. I want pieces that feel lighter and more breathable, things that are easy but still put together. That's why I keep coming back to Quintz. They focus on high-quality essentials that feel and look amazing. Think breathable linen and soft organic cotton. Well-made basics but without the luxury markup. It's that rare balance where everything feels elevated but still effortless. Quintz European linen pants and shirts are perfect warm weather upgrades to add to your rotation starting at just$34. Their tees are soft and easy to wear and their lightweight cotton sweaters are perfect for cooler summer nights.
6:59Everything at Quince is priced 50 to 80 % less than similar brands. They work directly with ethical factories and cut out the middlemen, so you're paying for quality, not brand markup. Quince goes way beyond clothing. Custom upholstered sofas, ceramic cookware, premium bedding, it's the kind of brand you'll end up recommending to everyone for everything. As the summer is heating up, I'm really loving my Flow Knit Breeze Performance Teas and my ProTech golf pants. My son is a huge fan of the kids' organic cotton ankle socks. Elevate your summer wardrobe. Go to quince.com slash motley for free shipping on your order and 365-day returns.
7:36Now available in Canada too. That's quince.com slash motley for free shipping and 365-day returns. quince.com slash motley. Well, I'm going to get into some numbers here as the CFO. I think you'll like that. But you set a target of$5 billion and beyond an annual recurring revenue here over the next several years. You're guiding for$3.75 billion in revenue this year. As an investor, that's an exciting growth prospect. But I wonder, what are the drivers that will get you there? Yeah, thanks for the question. So we have a series of growth levers that are available to us as we think about our path to$5 billion and more.
8:16First off, you know, we started with Zero Trust for users. So the ability to protect user communication traffic between users and applications. We then extended that to Zero Trust Cloud. So being able to provide the same Zero Trust principles to workload-to-workload communication. So think about that as an application, talking to an application. And then more recently, we extended that to Zero Trust Branch. The idea that organizations have, branch offices. You can think about a bank and having branches around the country. All of those branches need to ultimately connect into other systems and resources.
8:55And we don't think that they all need to connect to each other and form kind of a mesh network as is traditionally thought, but connect each individual device in a branch to only the application that it needs. So if it's a door sensor to monitor access, have it connect to the application that monitors access. It doesn't need to connect to other applications, and it certainly doesn't need to connect to other branches, as is the case today. And if one of those devices were to get breached in the traditional sense, it has the ability to infect your entire web network. In the zero trust branch situation, if one particular device gets breached, it's limited the attack surface to that particular device.
9:39The other area of growth opportunity for us is data security. So we have seen significant momentum in our ability to protect data. As a service, we sit in the path of traffic. And so we have an ability to inspect that traffic as it's going back and forth. We have an ability to apply policy. That's how we determine what is and isn't acceptable use. And on top of that, now we can also provide data security. So looking at the data that is being transacted back and forth and what is and isn't acceptable to go in and out of the organization, as we kind of talked about at the upfront of the conversation.
10:18And then lastly, AI. AI is a very significant tailwind for us from a couple of different dimensions. First is we're going to be extending zero trust for users branching cloud into zero trust for agents. So the ability to orchestrate from a cybersecurity perspective, the communication between an agent and another agent or an agent and an individual, as well as machine to machine communication, and ensure that the same principles of one to one communication, lease permissioning is adhered to. We think that's a huge opportunity. You have, you know, today we protect more than 50 million users, and tomorrow that could be millions or billions of agents that are doing work on behalf of organizations.
11:06And if one rogue agent got breached or hacked, imagine the damage that they could produce in an organization if it had the ability to move throughout that corporate network and have access to things that it never needed to. So, again, applying those zero trust principles to agents is something that is near and dear to us. Lastly, and, you know, we've all heard a lot about mythos and these frontier models that have been introduced more recently, and just the proliferation of vulnerability identification. Palo Alto was identified just this week as having, you know, a vulnerability that had been unknown for years that got exposed by one of these models.
11:51And it just reinforces the fact that companies today have got a backlog of vulnerabilities that they need to patch. And that's just what's known on their plate today. These models are identifying vulnerabilities at a rate and a pace that is at machine pace, right? So we're talking about volumes of vulnerabilities that, you know, we can't even solve the vulnerabilities that were already identified previously. And now we're just piling on significantly more vulnerabilities that were unknown for decades. And it's overwhelming IT organizations. They can't possibly keep pace in terms of their ability to patch and address these things.
12:31So our solution is very simple. hide your applications behind Zscaler Exchange. What you can't see, you can't breach. And so in our architecture approach to cybersecurity, you hide your applications and you only provide access to what is needed at that time. And so your blast radius gets minimized to a single device. This is a great segue. I'm glad you got us into the AI conversation because that's really where I wanted to go next. And one thing I noticed in this recent earnings call, You know, you talked about joining the partnership with Anthropoc via Project Glasswing. And I think that's a really interesting concept.
13:12We're seeing tech companies of all walks joining into that consortium, so to speak. I wonder what kinds of opportunities does that partnership offer Zscaler? Yeah, I mean, I think we're still uncovering all of the opportunities to be candid, right? These are models that weren't specifically developed initially to identify vulnerabilities, and yet they were doing so at machine speed and at scale that nobody anticipated. We were an early partner with Anthropic and Glasswing. We're an early partner with OpenAI on Daybreak, and it really does give us an opportunity to understand these models. We get to apply those models internally and understand how it would affect us.
13:57And then we get to learn and be able to apply those learnings to our customers and prospects so that we can provide the best cybersecurity for them and their environments. And so being a participant has, you know, obviously been been very important for us. And we have a great relationship with with the frontier model companies. OK, so this is obviously a very competitive space. You've got incumbents out there that are building integrated security platforms and just really going all in. Zscaler is not the most acquisitive company in the world, but you recently made a fairly big acquisition in Red Canary.
14:32I wonder if you could just talk a little bit about why y 'all did that and what you think the challenges and the opportunities there are. So one of the areas of opportunity that we've seen for a bit of time is the fact that we sit on an incredible amount of high fidelity, rich security oriented data. We process a half a trillion transactions a day through the Zero Trust Exchange, orders of magnitude greater than even Google searches in a given day to kind of put a context to how much volume of traffic goes through our security cloud each and every day. And we believe we have a unique position to provide our customers with an understanding and a perspective and a context around that data that is unique to us as a vendor.
15:19The rationale behind Red Canary was they had a decade-plus experience doing detection and response. They had taken that experience and established dozens of agents that were being able to scale that experience across a wide population of data. And if we could pair that with our rich data set, that does provide a very unique set of information and insights to our customers. And that was the ultimate approach and philosophy. Red Canary, after evaluating a variety of vendors in the space, surfaced as the right partner for us in being able to integrate their technology into what we will ultimately launch in the near term, which is our integrated SecOps solution.
16:11And the goal is to migrate legacy Red Canary customers into this new integrated solution as well as offer it to existing customers. And we think it's a very differentiated opportunity to provide that insight.
16:41Real College Deal. Everything you need to study and play with select Windows 11 PCs. Eligible students get a year of Microsoft 365 Premium and a year of Xbox Game Pass Ultimate with a custom color Xbox wireless controller. Learn more at windows.com slash student offer. While supplies last, ends June 30th. Terms at aka.ms slash college PC. When you need to build up your team to handle the growing chaos at work, use Indeed Sponsored Jobs. It gives your job post the boost it needs to be seen and helps reach people with the right skills, certifications, and more. Spend less time searching and more time actually interviewing candidates who check all your boxes.
17:18Listeners of this show will get a$75 sponsored job credit at Indeed.com slash podcast. That's Indeed.com slash podcast. Terms and conditions apply. Need a hiring hero? This is a job for Indeed sponsored jobs. I want to go back to AI for just a second because I think one of the headlines that we're seeing a lot these days is companies starting to question the return on investment in regard to AI, right? Token usage is eating up budgets left and right. You're starting to question whether what's cheaper, the employee or the AI. And it used to be that that was the argument was AI is going to make it cheaper.
17:56But now the employees are starting to look like maybe that's not a bad option after all. I wonder, do you feel like Zscaler, are you recognizing clear ROI on these AI investments today? Or is this more of an investment in the future that you are sort of have faith that it will pay off? So it's a little bit of both if we're being, you know, completely candid. I mean, we're at early innings as an industry around AI. We have seen significant productivity using AI in areas like engineering and product development. We've seen significant benefits in customer support and some of the other areas that early successes have been realized by others as well.
18:40So those are real tangible benefits that we have been seeing and taking advantage of. Our approach internally to AI is not human or AI. It's really human and AI, right? How do we best pair agents, excuse me, AI and agentic technology with our existing workforce to provide the best productivity and outcomes for customers? And that's the lens at which we look at AI use. It certainly is exploding internally in terms of the various different teams that are using it. You know, we are very focused on how we balance between token usage and what those outcomes are, right? Certain models are much more expensive in terms of tokens than others.
19:28So we're trying to be very mindful in what models we use for what use cases and what outcomes. But there's no going back, if you will. I mean, as an industry, Agentec is going to be as disruptive as, you know, any of the, you know, tech waves have been in the past, whether it was mobile, internet, etc. I mean, this is just the next frontier of how businesses will need to compete. Yeah, I like that. AI plus the person, right? It does seem to work really well. Just speaking as an analyst here at The Fool, I mean, I use those tools every day. I mean, they are absolutely helpful. I mean, I still like to do my own writing, but it's like search 2.0, right?
20:10I've always kind of viewed it as sort of this evolution of search and we're just have access to more information than ever before and it can put things together so much more quickly. So, yeah, I like that. The AI plus the person. That's a good perspective there. OK, so as CFO, right, cybersecurity budgets are one of the last things that are ever cutting a downturn, right? I mean, this is just mission critical stuff. You can't go without it. But by the same token, I mean, we're seeing a macro environment where I think CFOs across the board are having to scrutinize every dollar that's going out the door.
20:41So I just wonder, how is this macro environment affecting your company's decision making over the past years? Is it something that's keeping you up at night? Well, there's two dimensions or two ways in which I think about it. But from a commercialization, Zscaler is an incredible value proposition to a large organization that has built its cybersecurity based on traditional network-based security, hardware, and the like. So if you look at the ROI of deploying Zscaler in a large network infrastructure, it is significant. You are deprecating a bunch of firewalls, VPNs, SD-WANs, MPLS devices, and you are replacing those with a service that provides you with your traffic and your inspection and your security.
21:35So those customers who have deployed Zscaler benefit from a significantly lower total cost of ownership under Zscaler. So as I think about the opportunity in this environment, it's only becoming more evident that customers and prospects need to be looking outside the box, both figuratively, literally, in terms of how they approach cybersecurity. And those conversations are incredibly compelling when we sit down with customers and prospects and spell out what they can get rid of in their corporate network by deploying Zscaler. So it's a highly cost-efficient way to provide, frankly, better service, right?
22:14If we think about, again, this idea that, you know, vulnerabilities are being identified faster and deeper than ever before, your best defense of that is being able to hide behind a service like ours. and we're uniquely positioned the largest security cloud in the world. We operate a security cloud across 160 plus points of presence. So there's a deep amount of expertise and scale that sits behind Zscaler. Internally, we also benefit from the fact that our entire business runs on Zscaler. So my cost of cybersecurity is going to naturally be less than a competitor or another vendor that is, you know, using traditional cybersecurity.
22:59You know, the other tension point today is, as we talked about, it's AI and the cost of AI relative to your overall financial model. And those companies that are best able to manage that balance will be the most competitive companies in, you know, in the market today. Yeah, well, I mean, clearly, your customers like what you're giving them. I mean, I saw in this recent earnings call, I mean, customers that are generating over$1 million in annual recurring revenue that grew 18 % from a year ago to 748. So I just I think that's really encouraging. We'll leave it there. He's the CFO of Zscaler. Mr.
23:37Kevin Ruman, thank you so much for joining us today. Thank you for having me. I appreciate it. As always, people on the program may have interest in the stocks they talk about and The Motley Fool may have formal recommendations for or against. so don't buy or sell stocks based solely on what you hear. All personal finance content follows Motley Fool editorial standards and is not approved by advertisers. Advertisements are sponsored content and provided for informational purposes only. To see our full advertising disclosure, please check out our show notes. For the Motley Fool Hidden Gems Investing Team Podcast, I'm Jason Moser.
24:09Thanks for listening. We'll see you next time.
24:19Thank you.
From the publisher
Every time you log into a corporate network, send a file, or spin up an AI agent, something has to decide what's allowed and what isn't. So what happens when the number of things asking for access goes from 50 million users to billions of AI agents — and the bad actors have frontier models helping them find the cracks? Motley Fool analyst Jason Moser talks with Zscaler CFO Kevin Rubin about zero trust security, the agentic AI threat landscape, and why the cybersecurity buildout may be one of the most durable investment themes of the next decade.
Host: Jason Moser
Guest: Kevin Rubin
Producers: Bart Shannon, Lauren Budabin
Disclosure: Advertisements are sponsored content and provided for informational purposes only. The Motley Fool and its affiliates (collectively, “TMF”) do not endorse, recommend, or verify the accuracy or completeness of the statements made within advertisements. TMF is not involved in the offer, sale, or solicitation of any securities advertised herein and makes no representations regarding the suitability, or risks associated with any investment opportunity presented. Investors should conduct their own due diligence and consult with legal, tax, and financial advisors before making any investment decisions. TMF assumes no responsibility for any losses or damages arising from this advertisement.
We’re committed to transparency: All personal opinions in advertisements from Fools are their own. The product advertised in this episode was loaned to TMF and was returned after a test period or the product advertised in this episode was purchased by TMF. Advertiser has paid for the sponsorship of this episode.
Learn more about your ad choices. Visit megaphone.fm/adchoices
Learn more about your ad choices. Visit megaphone.fm/adchoices

