Zscaler kicked off its virtual Zenith Live event by adding zero-trust protection for public cloud workloads and a new push into 5G security as CEO Jay Chaudhry discussed his company’s direction heading into 2021.

“We know that internet is killing the wide area network,” he said during his opening keynote. “Now we see 5G eliminate the need for a local area network.”

“With tons of bandwidth available, 5G is going to push the edge of the cloud further and further out, so you have intelligent edge everywhere,” Chaudhry continued. “You will have a 5G high-speed connection connecting your data center or headquarters to the internet rather than traditional landlines.”

Zscaler is well positioned to secure new applications and services that 5G will enable because its security platform was built on a distributed-cloud architecture, Chaudhry added. “The edge will expand with 5G, and our architecture is ready to support it. It is scalable, it can handle tons of traffic. … We’ll be working with service providers to make sure we are supporting the edge as it’s evolving to enforce policy at the edge, what Gartner called secure access service edge, or SASE.”

And later, during a media Q&A session, Chaudhry fielded questions about his company’s SASE strategy.

Zscaler SASE Strategy

The security vendor started as a secure web gateway provider before adding firewall and zero-trust network access. It then it added out-of-band cloud access security broker (CASB) capabilities to its platform, all of which positioned it perfectly to dive into SASE when Garter coined the term last year.

Earlier this year, Zscaler also acquired Edgewise Networks to add that company’s zero-trust networking and application microsegmentation technologies to its platform, which also give it a SASE boost.

SASE, according to Gartner, consolidates networking and security capabilities into an edge cloud-delivered service. While Zscaler arguably provides a best-of-breed SASE security stack, it doesn’t own a networking piece. Instead, Zscaler partners with all of the SD-WAN vendors including VMware, and, in fact, VMware CEO Pat Gelsinger joined Chaudhry for a video appearance during the virtual keynote to tout the two companies’ SASE partnership.

When asked if Zscaler plans to continue partnering with SD-WAN vendors to provide a full SASE architecture or acquire SD-WAN to provide its own networking capabilities, Chaudhry said there’s no reason for Zscaler to provide SD-WAN. “We believe that the notion that SASE means networking and security coming together is a misinterpretation of it,” the exec said.

Securing the network is an outdated approach, he added, because today’s corporate network is the internet, and thus organizations don’t control the network. “So, in our view, you cannot secure the network,” Chaudhry said. “Network security is not really very meaningful. We decouple network access and application access with zero trust. We don’t put people on the network, we connect a person to particular application or service. If you believe that network and security should be decoupled, there’s no reason for Zscaler to get into the SD-WAN space.”

Zscaler Cloud Protection

Also at Zenith Live, Zscaler launched Cloud Protection, which automates protection for workloads on and between any cloud platform. It essentially combines four existing Zscaler technologies — cloud security posture management (CSPM), identity-based microsegmentation, secure internet and web gateway, and private application security — and pulls in technology acquired from Edgewise and Cloudneeti.

Cloudneeti is a CSPM startup that Zscaler bought earlier this year. This technology ensures continuous, secure configuration and compliance across cloud platforms.

As enterprises move applications from on-premises data centers into multiple clouds, they introduce new security challenges, said Rich Campagna, SVP of cloud protection at Zscaler. “Now these workloads have become user controlled, and this gets the users or the developers involved, and at the same time the speed of development and deployment has increased considerably,” Campagna said. “And finally, there’s the connectivity piece. When you’re dealing with these multi-cloud environments, it’s a real challenge to deploy secure connectivity within and across clouds.”

Zscaler Cloud Protection extends Zscaler’s zero-trust security that it already provides for private applications and internet access to public cloud workloads, Campagna added.

“The idea behind using zero-trust for cloud workloads is that you minimize complexity, No. 1, and No. 2, you reduce the attack surface,” he said. Plus, identity-based microsegmentation ensure can eliminate lateral threat movement inside customers’ cloud environments. “So if they are able to get in, say, through a malicious insider [attack] or compromised credentials, you’re going to minimize their ability to do damage.”