Zscaler announced a new set of cloud resilience capabilities built on its security services edge (SSE) and zero-trust platform, designed to provide smart traffic steering and disaster recovery capabilities that allows customers to continue their normal operations during a blackout, brownout, catastrophic scenarios, or cyberattacks.

“One question, which every large customer in the last 10 years has asked us, is what does Zscaler do to make sure that your architecture is resilient against attack or denial of service, [and] my business should not get impacted as a result of it?” Zscaler VP and GM Dhawal Sharma told SDxCentral.

To address this concern, Zscaler has built controls and followed industry standards for architectural resiliency. It has also introduced new disaster recovery capabilities, dynamic perforce-based selection, and customer-controlled data center exclusion to give customers “peace of mind.”

“What we have done now is to build disaster recovery capabilities that can take Zscaler cloud out of the equation, but still do policy enforcement and keep the zero-trust architecture in place without compromising the whole premise of giving users access to applications securely, without opening up the entire Internet landscape for them,” Sharma explained.

During an event that affects access to private applications behind the Zscaler cloud, the resilience service can help bypass that outage and connect to a Zscaler Private Service Edge. This is a fully functional single-tenant (per customer) instance broker that is hosted by the customer organization and resides within the customer’s site or in a public cloud service, and is where the most updated security policies are still applied without disrupting the business.

The vendor also claims the Zscaler Resilience service can automatically find the optimal path from user and device to an Application to help recover from brownout scenarios, and set a temporary exclusion period for a data center that experiences connectivity issues.

“It's basically taking the concept of SD-WAN or Software-Defined Networking (SDN) right down to the client level, that it is doing smart traffic steering based on where I'm going,” Sharma said.

Even if the Zscaler control plane gets impacted “we will be able to still provide secure connectivity to private applications as well as a secure whitelisted access to the Internet for these enterprises,” he added.

Zscaler Cloud Resilience Built on Zero-Trust Platform

Zscaler Resilience is baked into the vendor's cloud-native zero-trust architecture and SSE platform, Sharma said.

The resilience capabilities use the Private Service Edge to extend the same Multi-Tenant data plane from the Zscaler cloud to the customers' Enterprise network so customers can get local connectivity with the same zero-trust policy being applied.

“If Zscaler cloud is completely taken out of the equation, what we have done now is building this capability where all the traffic could be sent to customers' private services, and the zero-trust architecture continues to work with the policies that are running on those private service edges,” Sharma explained.

The vendor also introduced its Zscaler Resilience Audit platform, which offers a checklist for configuration options and disaster prevention and recovery tests.