As a secure access service edge (SASE) and zero-trust service vendor, Zscaler fully embraced these technologies to fortify its own security systems and ecosystems. Global CISO Deepen Desai revealed the key lesson learned from its implementation and noted it's a carefully planned and executed journey but not a simple “flip-a-switch.”
Desai claims Zscaler “was born with” the zero-trust concept and that its architecture has always been cloud-native, proxy-based and in line with SASE principles. Zscaler has enhanced its model, adding controls and building an ecosystem with partners like CrowdStrike, Microsoft and Okta to extend its functionality through native API-based integrations.
Zscaler’s development and security teams have implemented SASE using its own products built on zero-trust fundamentals.
“There is a corporate environment where we're full SASE adoption and then there is the production environment, which is the SASE offering itself,” Desai told SDxCentral. “We're leveraging SASE to protect our infrastructure, to protect our own employees, to protect our counter applications – no VPN, reducing the external attack surface, applying consistent security to all the employees whether they're working from home or the office, reducing that lateral propagation.”
Desai strongly advocates for a two-level segmentation approach – keeping endpoints separate from applications and not on the same network; and keeping each machine isolated, much like devices on a public Wi-Fi network.
Zscaler’s lessons learned from SASE, zero-trust implementationThe most important lesson Zscaler learned from its SASE and zero-trust adoption is that “it’s a journey,” Desai noted.
“There is this false notion that maybe some of the vendors are to blame for it like it's not a flip-a-switch and you are now zero trust,” he said.
The first step of the journey is that organizations need to implement consistent security measures for all users and assets. They should use a cloud-native proxy-based architecture with full transport layer security (TLS) for any connection going to the internet.
“You shouldn't be constrained by the limitations of on-prem firewall devices. You should be able to harness the power of the cloud that will allow you to make sure you have full grip, full visibility into everything that's coming in and out of your environment,” Desai said.
Secondly, companies need to “draw a circle” around their “crown jewels” such as the most valuable applications, code base and/or data whose loss or compromise would cause significant harm. Then they should implement the two-level and zero-trust segmentation rule, keeping user devices off the same network as these crucial applications and data.
“Even if one of my laptops were compromised, my crown jewels are saved because of how I have implemented my controls. And then you obviously want to inspect over there as well,” Desai explained.
Finally, he noted the importance of data loss prevention (DLP) rules, particularly with the emergence of large language models and artificial intelligence (AI) and machine learning (ML) technologies. “Having a consistent data loss [prevention] in line as well as out of band is important,” Desai said.
“So lessons learned: start with one thing which is protecting the internet-bound access and then move to your crown jewels. Those two things can happen in parallel," Desai said. "Then extended to a broader application base where it may not have sensitive data but then those applications may be talking to something sensitive, so you really want to secure that as well. And then make your DLP rules as mature as possible to counter things like large language models."
Comments