SlideShare uma empresa Scribd logo
1 de 19
Presentation title here—edit on Slide Master
©2018 Zscaler, Inc. All rights reserved. Zscaler™, SHIFT™, Direct-to-Cloud™ and ZPA™ are trademarks or registered trademarks of Zscaler, Inc.
in the United States and/or other countries. All other trademarks are the property of their respective owners.
Rethinking Cybersecurity for the
Digital Transformation Era
Dan Shelton – Director, Product
Management
©2018 Zscaler, Inc. All rights reserved.
What is Changing?
The cloud and mobility are creating a megashift for Digital Business
and IT Transformation
Disrupting 30 years of networking and security architectures
Users have moved
off the corporate network and are
connecting from everywhere
Applications have moved
out of the data center and
into the cloud
©2018 Zscaler, Inc. All rights reserved.
Challenge – The Traditional Hub & Spoke Network
Backhaul Traffic to a Central Datacenter for Security Services
The Castle & Moat Security Architecture
©2018 Zscaler, Inc. All rights reserved.
Challenge – Applications Moved to the Cloud & Users Left the Network
SaaS Open Internet Private CloudPublic Cloud
©2018 Zscaler, Inc. All rights reserved.
Challenge – Internet Gateways in the Data Centers
Aggregation
Firewall Load Balancers
& VPNs
Web Filter
Sandbox
Flow Management
Edge Next-
Gen Firewall
DLP
SSL
DC
11
9
8
7
6
5
4
3
2
1
12
10
13
14
16
17
18
19
20
21
22 2324
25
26
27
28
https://
15
Content Inspection
Internet
Apps moved to a modern platform.
Access is still using 30-year old technology.
©2018 Zscaler, Inc. All rights reserved.
Global LB
DDoS
Ext. FW / IPSInternal LB
Internal FW
RAS (VPN)
Internet
Challenge – Remote Access Gateways in the Data Centers
Site-to-site VPN
Apps moved to a modern platform. Access is still using 30-year old technology.
How do you access internal
apps on Azure or AWS?
©2018 Zscaler, Inc. All rights reserved.
Zscaler enables secure transformation to the cloud
Internet and VPN Gateway
Ext. FW / IPS
URL Filtering
Antivirus
DLP
SSL
Sandbox
Global LB
DDoS
Ext FW/IPS
RAS (VPN)
Internal FW
Internal LB
SaaSOpen Internet
External
APPS
Data CenterIaaS
Internal
Internal (cloud or data center)
Connect a user to an authorized
private app (not network)
Fast and secure policy-based access to apps and services over the Internet
Any device, any location, on-net or off-net
External (open Internet or SaaS)
Nothing bad comes in,
nothing good leaks out
Zscaler
Internet Access
Zscaler
Private Access
HQMOBILE
BRANCHIOT
©2018 Zscaler, Inc. All rights reserved.
The Complex Infrastructure of a Large Global Organization
Open internet
MPLS
MPLS MPLS
MPLS
• 9 Data Centers
• 8 internet egress points
managed by 6 different teams
• 8 email systems managed by 6
different teams
900 locations across
22 countries
10,000 Users
3,000 Remote Users on
5 VPN solutions
17 MPLS providers with
various configurations
Complex | Poor User Experience | Difficult to Manage | Unreliable
Lack of Visibility | Significant CAPEX and OPEX
Fail-Over
EMEA DC
Fail-Over
NA DC
©2018 Zscaler, Inc. All rights reserved.
Cloud Transformation Journey – Phase 1
Four initiatives
1. WAN vendor consolidation
2. Remove branch MPLS and use
IPSEC to MPLS (SDWAN)
3. Embrace Office 365 and phase-
out local email servers
4. Local internet breakouts with
appliances
30 Country &
Regional HQs
870 Branch
Locations
MPLS
WAN Vendor
9 Data Centers
Open Internet
IPSEC-to-MPLS architecture
(No MPLS at braches)
Branch office users complaining their internet experience was poor.
MPLS
WAN Vendor
SaaS
Benefits
• Eliminated branch MPLS costs
• Better internet experience at
country and regional HQs
• Simplified IT by standardizing
email/SharePoint and
reducing MPLS vendors from
17 to 1
1
4
MPLS
WAN Vendor
2
3
©2018 Zscaler, Inc. All rights reserved.
Cloud Transformation Journey – Phase 2
One initiative
1. Implement local internet
breakouts in all branches
30 Country &
Regional HQs
870 Branch
Locations
9 Data Centers
MPLS
WAN Vendor
Open Internet
Option 1: Deploy branch
firewalls in 870 locations.
Option 2: Implement Zscaler
Cloud Security Platform.
XX
Office 365 required more than just traditional proxy ports.
Visibility provided by Zscaler led to Internet policy discussions.
SaaS
Benefits
• Reduction in branch user internet
complaints (less pushback)
• Avoided the cost and overhead of
deploying 870 security appliances
• 60% reduction in Data Center
bandwidth requirements
©2018 Zscaler, Inc. All rights reserved.
Cloud Transformation Journey – Phase 3
Three initiatives
1. Reduce security appliance
requirements at country /
regional HQs and data centers
2. Implement Zscaler Cloud Firewall
and Bandwidth Control for O365
3. Protect mobile users
30 Country &
Regional HQs
870 Branch
Locations
9 Data Centers
MPLS
WAN Vendor
Open Internet
Delivered a consistent end-user experience to IaaS and SaaS applications at all branch and HQ locations,
but the mobile user was still struggling
SaaS
Benefits
• Eliminated security appliances in
country & regional HQs
• Better Office 365 user
experiences in all locations
• Reduced risk by providing
identical security controls to
mobile workers
©2018 Zscaler, Inc. All rights reserved.
9 Data Centers
MPLS
WAN Vendor
Open Internet
SaaS IaaS
5 Data Centers
Cloud Transformation Journey – Phase 4
Three initiatives
1. Migrate apps to IaaS – re-
platform critical apps to be
browser accessible
2. Consolidate data centers
3. Deploy virtual NGFWs and load
balancers to eliminate traffic
tromboning
30 Country &
Regional HQs
870 Branch
Locations
VM
Virtual NGFWs and load balancers were expensive, didn’t scale, and micro-segmentation challenges.
User confusion on when to use VPN and when they could use a browser.
Benefits
• Reduced data center costs
• Provided users better access re-
platformed apps (No VPN)
©2018 Zscaler, Inc. All rights reserved.
MPLS
WAN Vendor
Open Internet
SaaS
5 Data Centers
IaaS
VM
Cloud Transformation Journey – Phase 5
Two initiatives
1. Seamless End-User Experience -
Implement Zscaler Private Access
2. Zero-Trust Network Model
30 Country &
Regional HQs
870 Branch
Locations
Future-proof app delivery strategy with positive end-user experience.
Benefits
• Simplified access to all
applications
• Eliminated the cost and
complexity of virtual firewalls
and load balancers in IaaS
• Enhanced security posture – app
microsegmentation, reduced
inbound attack surface,
enablement of zero-trust
network model
©2018 Zscaler, Inc. All rights reserved.
Transformation Journey – Summary
Cost Savings
$9.66M OPEX Per Year
Cost Avoidance
$2.7M in appliance sprawl
Network transformation – Removal of MPLS at 870 locations and deployment of 30 local breakouts with appliances
Network transformation – ZIA deployed to support local internet breakouts in 870 branch offices around the world
Global collaboration tools – Successfully deployed Office 365
Data center transformation – Moved apps to Azure/AWS and consolidated data centers
Application access transformation –Eliminated VPN, zero-trust network model, positive end-user experience
1
2
3
4
5
Benefits
Simple and agile IT environment
Consistent end-user experience
Reduced business risk
©2018 Zscaler, Inc. All rights reserved.
Every enterprise needs network and application transformation
HQ/IOT
MOBILE BRANCH
Secure Internet Edge
HQ
APJEMEA
BUSINESS VALUE
Better user experience
Reduced Business Risk
Business Agility
Lower TCO
Hub and Spoke to Direct to Cloud
NETWORK TRANSFORMATION
Securely connect the right user and device to the right app and service in the digital transformation era
Data Center to Cloud (SaaS/IaaS)
APPLICATION TRANSFORMATION
©2018 Zscaler, Inc. All rights reserved.
Global Partners
100
Data centers
45B
Daily requests
185
Countries served
Unparalleled Cloud Scale Enterprise Customers
2,800 CUSTOMERS
Over 200 of the Fortune Global 2000
Conglomerates
3 of the top 3
Oil and gas operations
3 of the top 4
Beverage
5 of the top 7
Specialized chemicals
2 of the top 3
Food retail
6 of the top 12
Apparel and accessories
2 of the top 4
Largest Cloud Security Platform in the World
Mature Global Cloud Operations
Zscaler: The market leader in cloud security
©2018 Zscaler, Inc. All rights reserved.
©2018 Zscaler, Inc. All rights reserved. Zscaler™, SHIFT™, Direct-to-Cloud™ and ZPA™ are trademarks or registered trademarks of Zscaler, Inc.
in the United States and/or other countries. All other trademarks are the property of their respective owners.
©2018 Zscaler, Inc. All rights reserved.
Direct to Internet
Block the bad, protect the good
The best approach for SD-WAN and Office 365
Zscaler Internet Access – Fast, Secure Access to the Internet and SaaS
Data Center
APPSMPLS
HQMOBILE
BRANCHIOT
Your security stack as a service
Data Loss Prevention
Cloud Apps (CASB)
File Type Controls
Data Protection
Cloud Firewall
URL Filtering
Bandwidth Control
DNS Filtering
Access Control
Adv. Protection
Cloud Sandbox
Anti-Virus
DNS Security
Threat PreventionReal-time policy engine
Polices follow the user
Changes are immediately enforced, worldwide
Business analytics
Global visibility into apps and threats blocked
Identify botnet infected machines for remediation
Real-time policy and analytics
©2018 Zscaler, Inc. All rights reserved.
Zscaler Private Access
Secure and fast access policy-based access to private apps on Azure, AWS or your DC
Z-APP
2
Datacenter
User
1
POLICY (Brokers)
ID Provider
Windows, Mac, iOS, Android - On-net or off-net
Public Cloud
Connect a named user to a named app, not a network; Direct path to cloud apps without hairpinning through DC. No VPN needed
ZPA replaces the entire inbound gateway/DMZ. Not just a VPN replacement
Reduced cost, complexity, better security and user experience
ZPA: Innovative Design
Cloud-based policy engine – who can
access what apps
1
Z-APP – Request access to app2
Z-Connector – sits in front of apps. Starts
inside out connection
3
Zscaler cloud brokers a secure connection
between the Z-connector and Z-app
Private Apps
Web, TCP, UDP
Z-CONNECTOR
3
3
1. User never on your network
2. Apps are invisible (safe)
3. App segmentation without
network segmentation
4. Use Internet as a secure
network without VPN
Why ZPA is Revolutionary

Mais conteúdo relacionado

Mais procurados

Top 5 predictions webinar
Top 5 predictions webinarTop 5 predictions webinar
Top 5 predictions webinarZscaler
 
Zscaler ThreatLabz dissects the latest SSL security attacks
Zscaler ThreatLabz dissects the latest SSL security attacksZscaler ThreatLabz dissects the latest SSL security attacks
Zscaler ThreatLabz dissects the latest SSL security attacksZscaler
 
Three ways-zero-trust-security-redefines-partner-access-v8
Three ways-zero-trust-security-redefines-partner-access-v8Three ways-zero-trust-security-redefines-partner-access-v8
Three ways-zero-trust-security-redefines-partner-access-v8Zscaler
 
Virtualized Firewall: Is it the panacea to secure distributed enterprises?
Virtualized Firewall: Is it the panacea to secure distributed enterprises?Virtualized Firewall: Is it the panacea to secure distributed enterprises?
Virtualized Firewall: Is it the panacea to secure distributed enterprises?Zscaler
 
3 reasons-sdp-is-replacing-vpn-in-2019
3 reasons-sdp-is-replacing-vpn-in-20193 reasons-sdp-is-replacing-vpn-in-2019
3 reasons-sdp-is-replacing-vpn-in-2019Zscaler
 
Schneider electric powers security transformation with one simple app copy
Schneider electric powers security transformation with one simple app   copySchneider electric powers security transformation with one simple app   copy
Schneider electric powers security transformation with one simple app copyZscaler
 
Get an office 365 expereience your users will love v8.1
Get an office 365 expereience your users will love v8.1Get an office 365 expereience your users will love v8.1
Get an office 365 expereience your users will love v8.1Zscaler
 
Dissecting ssl threats
Dissecting ssl threatsDissecting ssl threats
Dissecting ssl threatsZscaler
 
Migration to microsoft_azure_with_zscaler
Migration to microsoft_azure_with_zscalerMigration to microsoft_azure_with_zscaler
Migration to microsoft_azure_with_zscalerZscaler
 
Ma story then_now_webcast_10_17_18
Ma story then_now_webcast_10_17_18Ma story then_now_webcast_10_17_18
Ma story then_now_webcast_10_17_18Zscaler
 
Secure access to applications on Microsoft Azure
Secure access to applications on Microsoft AzureSecure access to applications on Microsoft Azure
Secure access to applications on Microsoft AzureZscaler
 
Zscaler mondi webinar
Zscaler mondi webinarZscaler mondi webinar
Zscaler mondi webinarZscaler
 
SD-WAN plus cloud security
SD-WAN plus cloud securitySD-WAN plus cloud security
SD-WAN plus cloud securityZscaler
 
What Comes After VPN?
What Comes After VPN?What Comes After VPN?
What Comes After VPN?Zscaler
 
Overcoming the Challenges of Architecting for the Cloud
Overcoming the Challenges of Architecting for the CloudOvercoming the Challenges of Architecting for the Cloud
Overcoming the Challenges of Architecting for the CloudZscaler
 
Three ways-zero-trust-security-redefines-partner-access-ch
Three ways-zero-trust-security-redefines-partner-access-chThree ways-zero-trust-security-redefines-partner-access-ch
Three ways-zero-trust-security-redefines-partner-access-chZscaler
 
Moving from appliances to cloud security with phoenix children's hospital
Moving from appliances to cloud security with phoenix children's hospitalMoving from appliances to cloud security with phoenix children's hospital
Moving from appliances to cloud security with phoenix children's hospitalZscaler
 
O365 quick with fast user experience
O365 quick with fast user experienceO365 quick with fast user experience
O365 quick with fast user experienceZscaler
 
Office 365 kelly services
Office 365 kelly servicesOffice 365 kelly services
Office 365 kelly servicesZscaler
 
Alpha & Omega's Managed Security
Alpha & Omega's Managed SecurityAlpha & Omega's Managed Security
Alpha & Omega's Managed SecurityDarryl Santa
 

Mais procurados (20)

Top 5 predictions webinar
Top 5 predictions webinarTop 5 predictions webinar
Top 5 predictions webinar
 
Zscaler ThreatLabz dissects the latest SSL security attacks
Zscaler ThreatLabz dissects the latest SSL security attacksZscaler ThreatLabz dissects the latest SSL security attacks
Zscaler ThreatLabz dissects the latest SSL security attacks
 
Three ways-zero-trust-security-redefines-partner-access-v8
Three ways-zero-trust-security-redefines-partner-access-v8Three ways-zero-trust-security-redefines-partner-access-v8
Three ways-zero-trust-security-redefines-partner-access-v8
 
Virtualized Firewall: Is it the panacea to secure distributed enterprises?
Virtualized Firewall: Is it the panacea to secure distributed enterprises?Virtualized Firewall: Is it the panacea to secure distributed enterprises?
Virtualized Firewall: Is it the panacea to secure distributed enterprises?
 
3 reasons-sdp-is-replacing-vpn-in-2019
3 reasons-sdp-is-replacing-vpn-in-20193 reasons-sdp-is-replacing-vpn-in-2019
3 reasons-sdp-is-replacing-vpn-in-2019
 
Schneider electric powers security transformation with one simple app copy
Schneider electric powers security transformation with one simple app   copySchneider electric powers security transformation with one simple app   copy
Schneider electric powers security transformation with one simple app copy
 
Get an office 365 expereience your users will love v8.1
Get an office 365 expereience your users will love v8.1Get an office 365 expereience your users will love v8.1
Get an office 365 expereience your users will love v8.1
 
Dissecting ssl threats
Dissecting ssl threatsDissecting ssl threats
Dissecting ssl threats
 
Migration to microsoft_azure_with_zscaler
Migration to microsoft_azure_with_zscalerMigration to microsoft_azure_with_zscaler
Migration to microsoft_azure_with_zscaler
 
Ma story then_now_webcast_10_17_18
Ma story then_now_webcast_10_17_18Ma story then_now_webcast_10_17_18
Ma story then_now_webcast_10_17_18
 
Secure access to applications on Microsoft Azure
Secure access to applications on Microsoft AzureSecure access to applications on Microsoft Azure
Secure access to applications on Microsoft Azure
 
Zscaler mondi webinar
Zscaler mondi webinarZscaler mondi webinar
Zscaler mondi webinar
 
SD-WAN plus cloud security
SD-WAN plus cloud securitySD-WAN plus cloud security
SD-WAN plus cloud security
 
What Comes After VPN?
What Comes After VPN?What Comes After VPN?
What Comes After VPN?
 
Overcoming the Challenges of Architecting for the Cloud
Overcoming the Challenges of Architecting for the CloudOvercoming the Challenges of Architecting for the Cloud
Overcoming the Challenges of Architecting for the Cloud
 
Three ways-zero-trust-security-redefines-partner-access-ch
Three ways-zero-trust-security-redefines-partner-access-chThree ways-zero-trust-security-redefines-partner-access-ch
Three ways-zero-trust-security-redefines-partner-access-ch
 
Moving from appliances to cloud security with phoenix children's hospital
Moving from appliances to cloud security with phoenix children's hospitalMoving from appliances to cloud security with phoenix children's hospital
Moving from appliances to cloud security with phoenix children's hospital
 
O365 quick with fast user experience
O365 quick with fast user experienceO365 quick with fast user experience
O365 quick with fast user experience
 
Office 365 kelly services
Office 365 kelly servicesOffice 365 kelly services
Office 365 kelly services
 
Alpha & Omega's Managed Security
Alpha & Omega's Managed SecurityAlpha & Omega's Managed Security
Alpha & Omega's Managed Security
 

Semelhante a Rethinking Cybersecurity for the Digital Transformation Era

PLNOG 22 - Sebastian Grabski - Is your network ready for application from the...
PLNOG 22 - Sebastian Grabski - Is your network ready for application from the...PLNOG 22 - Sebastian Grabski - Is your network ready for application from the...
PLNOG 22 - Sebastian Grabski - Is your network ready for application from the...PROIDEA
 
A New Approach to Continuous Monitoring in the Cloud
A New Approach to Continuous Monitoring in the CloudA New Approach to Continuous Monitoring in the Cloud
A New Approach to Continuous Monitoring in the CloudNETSCOUT
 
Hybrid Cloud Keynote
Hybrid Cloud Keynote Hybrid Cloud Keynote
Hybrid Cloud Keynote gcamarda
 
How sdp delivers_zero_trust
How sdp delivers_zero_trustHow sdp delivers_zero_trust
How sdp delivers_zero_trustZscaler
 
Cisco Connect 2018 Thailand - Enabling the next gen data center transformatio...
Cisco Connect 2018 Thailand - Enabling the next gen data center transformatio...Cisco Connect 2018 Thailand - Enabling the next gen data center transformatio...
Cisco Connect 2018 Thailand - Enabling the next gen data center transformatio...NetworkCollaborators
 
What is ThousandEyes Webinar
What is ThousandEyes WebinarWhat is ThousandEyes Webinar
What is ThousandEyes WebinarThousandEyes
 
The evolving CIO|CISO relationship
The evolving CIO|CISO relationship  The evolving CIO|CISO relationship
The evolving CIO|CISO relationship Zscaler
 
EMEA What is ThousandEyes? Webinar
EMEA What is ThousandEyes? WebinarEMEA What is ThousandEyes? Webinar
EMEA What is ThousandEyes? WebinarThousandEyes
 
Making Money in the Cloud
Making Money in the CloudMaking Money in the Cloud
Making Money in the CloudGravitant, Inc.
 
Episode 1: Transition to Iaas
Episode 1: Transition to IaasEpisode 1: Transition to Iaas
Episode 1: Transition to IaasBenoitFindeis
 
Cisco Connect Toronto 2018 sd-wan - delivering intent-based networking to t...
Cisco Connect Toronto 2018   sd-wan - delivering intent-based networking to t...Cisco Connect Toronto 2018   sd-wan - delivering intent-based networking to t...
Cisco Connect Toronto 2018 sd-wan - delivering intent-based networking to t...Cisco Canada
 
Contrail Launch: Capitalize on SDN and Cloud. Now.
Contrail Launch: Capitalize on SDN and Cloud. Now.Contrail Launch: Capitalize on SDN and Cloud. Now.
Contrail Launch: Capitalize on SDN and Cloud. Now.Juniper Networks
 
Introduction to ThousandEyes
Introduction to ThousandEyesIntroduction to ThousandEyes
Introduction to ThousandEyesThousandEyes
 
Aerohive Networks e ZScaler, le soluzioni tecnologiche per il nuovo ecosistem...
Aerohive Networks e ZScaler, le soluzioni tecnologiche per il nuovo ecosistem...Aerohive Networks e ZScaler, le soluzioni tecnologiche per il nuovo ecosistem...
Aerohive Networks e ZScaler, le soluzioni tecnologiche per il nuovo ecosistem...Miriade Spa
 
Cisco Meraki Overview
Cisco Meraki OverviewCisco Meraki Overview
Cisco Meraki OverviewSSISG
 
01-Chapter 01-Introduction to CASB and Netskope.pptx
01-Chapter 01-Introduction to CASB and Netskope.pptx01-Chapter 01-Introduction to CASB and Netskope.pptx
01-Chapter 01-Introduction to CASB and Netskope.pptxssuser4c54af
 
Introduction to ThousandEyes
Introduction to ThousandEyesIntroduction to ThousandEyes
Introduction to ThousandEyesThousandEyes
 
AWS re:Invent 2016: Future-Proofing the WAN and Simplifying Security On Your ...
AWS re:Invent 2016: Future-Proofing the WAN and Simplifying Security On Your ...AWS re:Invent 2016: Future-Proofing the WAN and Simplifying Security On Your ...
AWS re:Invent 2016: Future-Proofing the WAN and Simplifying Security On Your ...Amazon Web Services
 
Introduction of Cloudflare Solution for Mobile Payment
Introduction of Cloudflare Solution for Mobile PaymentIntroduction of Cloudflare Solution for Mobile Payment
Introduction of Cloudflare Solution for Mobile PaymentJean Ryu
 

Semelhante a Rethinking Cybersecurity for the Digital Transformation Era (20)

PLNOG 22 - Sebastian Grabski - Is your network ready for application from the...
PLNOG 22 - Sebastian Grabski - Is your network ready for application from the...PLNOG 22 - Sebastian Grabski - Is your network ready for application from the...
PLNOG 22 - Sebastian Grabski - Is your network ready for application from the...
 
A New Approach to Continuous Monitoring in the Cloud
A New Approach to Continuous Monitoring in the CloudA New Approach to Continuous Monitoring in the Cloud
A New Approach to Continuous Monitoring in the Cloud
 
Hybrid Cloud Keynote
Hybrid Cloud Keynote Hybrid Cloud Keynote
Hybrid Cloud Keynote
 
How sdp delivers_zero_trust
How sdp delivers_zero_trustHow sdp delivers_zero_trust
How sdp delivers_zero_trust
 
Cisco Connect 2018 Thailand - Enabling the next gen data center transformatio...
Cisco Connect 2018 Thailand - Enabling the next gen data center transformatio...Cisco Connect 2018 Thailand - Enabling the next gen data center transformatio...
Cisco Connect 2018 Thailand - Enabling the next gen data center transformatio...
 
What is ThousandEyes Webinar
What is ThousandEyes WebinarWhat is ThousandEyes Webinar
What is ThousandEyes Webinar
 
The evolving CIO|CISO relationship
The evolving CIO|CISO relationship  The evolving CIO|CISO relationship
The evolving CIO|CISO relationship
 
EMEA What is ThousandEyes? Webinar
EMEA What is ThousandEyes? WebinarEMEA What is ThousandEyes? Webinar
EMEA What is ThousandEyes? Webinar
 
Making Money in the Cloud
Making Money in the CloudMaking Money in the Cloud
Making Money in the Cloud
 
Episode 1: Transition to Iaas
Episode 1: Transition to IaasEpisode 1: Transition to Iaas
Episode 1: Transition to Iaas
 
Cisco Connect Toronto 2018 sd-wan - delivering intent-based networking to t...
Cisco Connect Toronto 2018   sd-wan - delivering intent-based networking to t...Cisco Connect Toronto 2018   sd-wan - delivering intent-based networking to t...
Cisco Connect Toronto 2018 sd-wan - delivering intent-based networking to t...
 
Contrail Launch: Capitalize on SDN and Cloud. Now.
Contrail Launch: Capitalize on SDN and Cloud. Now.Contrail Launch: Capitalize on SDN and Cloud. Now.
Contrail Launch: Capitalize on SDN and Cloud. Now.
 
Introduction to ThousandEyes
Introduction to ThousandEyesIntroduction to ThousandEyes
Introduction to ThousandEyes
 
Aerohive Networks e ZScaler, le soluzioni tecnologiche per il nuovo ecosistem...
Aerohive Networks e ZScaler, le soluzioni tecnologiche per il nuovo ecosistem...Aerohive Networks e ZScaler, le soluzioni tecnologiche per il nuovo ecosistem...
Aerohive Networks e ZScaler, le soluzioni tecnologiche per il nuovo ecosistem...
 
Cisco Meraki Overview
Cisco Meraki OverviewCisco Meraki Overview
Cisco Meraki Overview
 
Transformation As A Service
Transformation As A ServiceTransformation As A Service
Transformation As A Service
 
01-Chapter 01-Introduction to CASB and Netskope.pptx
01-Chapter 01-Introduction to CASB and Netskope.pptx01-Chapter 01-Introduction to CASB and Netskope.pptx
01-Chapter 01-Introduction to CASB and Netskope.pptx
 
Introduction to ThousandEyes
Introduction to ThousandEyesIntroduction to ThousandEyes
Introduction to ThousandEyes
 
AWS re:Invent 2016: Future-Proofing the WAN and Simplifying Security On Your ...
AWS re:Invent 2016: Future-Proofing the WAN and Simplifying Security On Your ...AWS re:Invent 2016: Future-Proofing the WAN and Simplifying Security On Your ...
AWS re:Invent 2016: Future-Proofing the WAN and Simplifying Security On Your ...
 
Introduction of Cloudflare Solution for Mobile Payment
Introduction of Cloudflare Solution for Mobile PaymentIntroduction of Cloudflare Solution for Mobile Payment
Introduction of Cloudflare Solution for Mobile Payment
 

Mais de Zscaler

Top 5 mistakes deploying o365
Top 5 mistakes deploying o365Top 5 mistakes deploying o365
Top 5 mistakes deploying o365Zscaler
 
Zenith Live - Security Lab - Phantom
Zenith Live - Security Lab - PhantomZenith Live - Security Lab - Phantom
Zenith Live - Security Lab - PhantomZscaler
 
Office 365 deployment
Office 365 deploymentOffice 365 deployment
Office 365 deploymentZscaler
 
Adopting A Zero-Trust Model. Google Did It, Can You?
Adopting A Zero-Trust Model. Google Did It, Can You?Adopting A Zero-Trust Model. Google Did It, Can You?
Adopting A Zero-Trust Model. Google Did It, Can You?Zscaler
 
Top reasons o365 deployments fail
Top reasons o365 deployments failTop reasons o365 deployments fail
Top reasons o365 deployments failZscaler
 
GDPR - are you ready?
GDPR - are you ready?GDPR - are you ready?
GDPR - are you ready?Zscaler
 
Maximize your cloud app control with Microsoft MCAS and Zscaler
Maximize your cloud app control with Microsoft MCAS and ZscalerMaximize your cloud app control with Microsoft MCAS and Zscaler
Maximize your cloud app control with Microsoft MCAS and ZscalerZscaler
 
DNS Security, is it enough?
DNS Security, is it enough? DNS Security, is it enough?
DNS Security, is it enough? Zscaler
 

Mais de Zscaler (8)

Top 5 mistakes deploying o365
Top 5 mistakes deploying o365Top 5 mistakes deploying o365
Top 5 mistakes deploying o365
 
Zenith Live - Security Lab - Phantom
Zenith Live - Security Lab - PhantomZenith Live - Security Lab - Phantom
Zenith Live - Security Lab - Phantom
 
Office 365 deployment
Office 365 deploymentOffice 365 deployment
Office 365 deployment
 
Adopting A Zero-Trust Model. Google Did It, Can You?
Adopting A Zero-Trust Model. Google Did It, Can You?Adopting A Zero-Trust Model. Google Did It, Can You?
Adopting A Zero-Trust Model. Google Did It, Can You?
 
Top reasons o365 deployments fail
Top reasons o365 deployments failTop reasons o365 deployments fail
Top reasons o365 deployments fail
 
GDPR - are you ready?
GDPR - are you ready?GDPR - are you ready?
GDPR - are you ready?
 
Maximize your cloud app control with Microsoft MCAS and Zscaler
Maximize your cloud app control with Microsoft MCAS and ZscalerMaximize your cloud app control with Microsoft MCAS and Zscaler
Maximize your cloud app control with Microsoft MCAS and Zscaler
 
DNS Security, is it enough?
DNS Security, is it enough? DNS Security, is it enough?
DNS Security, is it enough?
 

Último

Call Girls In Model Towh Delhi 💯Call Us 🔝8264348440🔝
Call Girls In Model Towh Delhi 💯Call Us 🔝8264348440🔝Call Girls In Model Towh Delhi 💯Call Us 🔝8264348440🔝
Call Girls In Model Towh Delhi 💯Call Us 🔝8264348440🔝soniya singh
 
All Time Service Available Call Girls Mg Road 👌 ⏭️ 6378878445
All Time Service Available Call Girls Mg Road 👌 ⏭️ 6378878445All Time Service Available Call Girls Mg Road 👌 ⏭️ 6378878445
All Time Service Available Call Girls Mg Road 👌 ⏭️ 6378878445ruhi
 
DDoS In Oceania and the Pacific, presented by Dave Phelan at NZNOG 2024
DDoS In Oceania and the Pacific, presented by Dave Phelan at NZNOG 2024DDoS In Oceania and the Pacific, presented by Dave Phelan at NZNOG 2024
DDoS In Oceania and the Pacific, presented by Dave Phelan at NZNOG 2024APNIC
 
Call Girls Dubai Prolapsed O525547819 Call Girls In Dubai Princes$
Call Girls Dubai Prolapsed O525547819 Call Girls In Dubai Princes$Call Girls Dubai Prolapsed O525547819 Call Girls In Dubai Princes$
Call Girls Dubai Prolapsed O525547819 Call Girls In Dubai Princes$kojalkojal131
 
Call Girls In Ashram Chowk Delhi 💯Call Us 🔝8264348440🔝
Call Girls In Ashram Chowk Delhi 💯Call Us 🔝8264348440🔝Call Girls In Ashram Chowk Delhi 💯Call Us 🔝8264348440🔝
Call Girls In Ashram Chowk Delhi 💯Call Us 🔝8264348440🔝soniya singh
 
Call Girls In Defence Colony Delhi 💯Call Us 🔝8264348440🔝
Call Girls In Defence Colony Delhi 💯Call Us 🔝8264348440🔝Call Girls In Defence Colony Delhi 💯Call Us 🔝8264348440🔝
Call Girls In Defence Colony Delhi 💯Call Us 🔝8264348440🔝soniya singh
 
Call Girls In Pratap Nagar Delhi 💯Call Us 🔝8264348440🔝
Call Girls In Pratap Nagar Delhi 💯Call Us 🔝8264348440🔝Call Girls In Pratap Nagar Delhi 💯Call Us 🔝8264348440🔝
Call Girls In Pratap Nagar Delhi 💯Call Us 🔝8264348440🔝soniya singh
 
Lucknow ❤CALL GIRL 88759*99948 ❤CALL GIRLS IN Lucknow ESCORT SERVICE❤CALL GIRL
Lucknow ❤CALL GIRL 88759*99948 ❤CALL GIRLS IN Lucknow ESCORT SERVICE❤CALL GIRLLucknow ❤CALL GIRL 88759*99948 ❤CALL GIRLS IN Lucknow ESCORT SERVICE❤CALL GIRL
Lucknow ❤CALL GIRL 88759*99948 ❤CALL GIRLS IN Lucknow ESCORT SERVICE❤CALL GIRLimonikaupta
 
Hot Call Girls |Delhi |Hauz Khas ☎ 9711199171 Book Your One night Stand
Hot Call Girls |Delhi |Hauz Khas ☎ 9711199171 Book Your One night StandHot Call Girls |Delhi |Hauz Khas ☎ 9711199171 Book Your One night Stand
Hot Call Girls |Delhi |Hauz Khas ☎ 9711199171 Book Your One night Standkumarajju5765
 
Nanded City ( Call Girls ) Pune 6297143586 Hot Model With Sexy Bhabi Ready ...
Nanded City ( Call Girls ) Pune  6297143586  Hot Model With Sexy Bhabi Ready ...Nanded City ( Call Girls ) Pune  6297143586  Hot Model With Sexy Bhabi Ready ...
Nanded City ( Call Girls ) Pune 6297143586 Hot Model With Sexy Bhabi Ready ...tanu pandey
 
𓀤Call On 7877925207 𓀤 Ahmedguda Call Girls Hot Model With Sexy Bhabi Ready Fo...
𓀤Call On 7877925207 𓀤 Ahmedguda Call Girls Hot Model With Sexy Bhabi Ready Fo...𓀤Call On 7877925207 𓀤 Ahmedguda Call Girls Hot Model With Sexy Bhabi Ready Fo...
𓀤Call On 7877925207 𓀤 Ahmedguda Call Girls Hot Model With Sexy Bhabi Ready Fo...Neha Pandey
 
✂️ 👅 Independent Andheri Escorts With Room Vashi Call Girls 💃 9004004663
✂️ 👅 Independent Andheri Escorts With Room Vashi Call Girls 💃 9004004663✂️ 👅 Independent Andheri Escorts With Room Vashi Call Girls 💃 9004004663
✂️ 👅 Independent Andheri Escorts With Room Vashi Call Girls 💃 9004004663Call Girls Mumbai
 
CALL ON ➥8923113531 🔝Call Girls Lucknow Lucknow best sexual service Online
CALL ON ➥8923113531 🔝Call Girls Lucknow Lucknow best sexual service OnlineCALL ON ➥8923113531 🔝Call Girls Lucknow Lucknow best sexual service Online
CALL ON ➥8923113531 🔝Call Girls Lucknow Lucknow best sexual service Onlineanilsa9823
 
AWS Community DAY Albertini-Ellan Cloud Security (1).pptx
AWS Community DAY Albertini-Ellan Cloud Security (1).pptxAWS Community DAY Albertini-Ellan Cloud Security (1).pptx
AWS Community DAY Albertini-Ellan Cloud Security (1).pptxellan12
 
'Future Evolution of the Internet' delivered by Geoff Huston at Everything Op...
'Future Evolution of the Internet' delivered by Geoff Huston at Everything Op...'Future Evolution of the Internet' delivered by Geoff Huston at Everything Op...
'Future Evolution of the Internet' delivered by Geoff Huston at Everything Op...APNIC
 
GDG Cloud Southlake 32: Kyle Hettinger: Demystifying the Dark Web
GDG Cloud Southlake 32: Kyle Hettinger: Demystifying the Dark WebGDG Cloud Southlake 32: Kyle Hettinger: Demystifying the Dark Web
GDG Cloud Southlake 32: Kyle Hettinger: Demystifying the Dark WebJames Anderson
 

Último (20)

Call Girls In Model Towh Delhi 💯Call Us 🔝8264348440🔝
Call Girls In Model Towh Delhi 💯Call Us 🔝8264348440🔝Call Girls In Model Towh Delhi 💯Call Us 🔝8264348440🔝
Call Girls In Model Towh Delhi 💯Call Us 🔝8264348440🔝
 
Russian Call Girls in %(+971524965298 )# Call Girls in Dubai
Russian Call Girls in %(+971524965298  )#  Call Girls in DubaiRussian Call Girls in %(+971524965298  )#  Call Girls in Dubai
Russian Call Girls in %(+971524965298 )# Call Girls in Dubai
 
All Time Service Available Call Girls Mg Road 👌 ⏭️ 6378878445
All Time Service Available Call Girls Mg Road 👌 ⏭️ 6378878445All Time Service Available Call Girls Mg Road 👌 ⏭️ 6378878445
All Time Service Available Call Girls Mg Road 👌 ⏭️ 6378878445
 
DDoS In Oceania and the Pacific, presented by Dave Phelan at NZNOG 2024
DDoS In Oceania and the Pacific, presented by Dave Phelan at NZNOG 2024DDoS In Oceania and the Pacific, presented by Dave Phelan at NZNOG 2024
DDoS In Oceania and the Pacific, presented by Dave Phelan at NZNOG 2024
 
Call Girls Dubai Prolapsed O525547819 Call Girls In Dubai Princes$
Call Girls Dubai Prolapsed O525547819 Call Girls In Dubai Princes$Call Girls Dubai Prolapsed O525547819 Call Girls In Dubai Princes$
Call Girls Dubai Prolapsed O525547819 Call Girls In Dubai Princes$
 
Call Girls In Ashram Chowk Delhi 💯Call Us 🔝8264348440🔝
Call Girls In Ashram Chowk Delhi 💯Call Us 🔝8264348440🔝Call Girls In Ashram Chowk Delhi 💯Call Us 🔝8264348440🔝
Call Girls In Ashram Chowk Delhi 💯Call Us 🔝8264348440🔝
 
Rohini Sector 22 Call Girls Delhi 9999965857 @Sabina Saikh No Advance
Rohini Sector 22 Call Girls Delhi 9999965857 @Sabina Saikh No AdvanceRohini Sector 22 Call Girls Delhi 9999965857 @Sabina Saikh No Advance
Rohini Sector 22 Call Girls Delhi 9999965857 @Sabina Saikh No Advance
 
Call Girls In Defence Colony Delhi 💯Call Us 🔝8264348440🔝
Call Girls In Defence Colony Delhi 💯Call Us 🔝8264348440🔝Call Girls In Defence Colony Delhi 💯Call Us 🔝8264348440🔝
Call Girls In Defence Colony Delhi 💯Call Us 🔝8264348440🔝
 
Call Girls In Pratap Nagar Delhi 💯Call Us 🔝8264348440🔝
Call Girls In Pratap Nagar Delhi 💯Call Us 🔝8264348440🔝Call Girls In Pratap Nagar Delhi 💯Call Us 🔝8264348440🔝
Call Girls In Pratap Nagar Delhi 💯Call Us 🔝8264348440🔝
 
Lucknow ❤CALL GIRL 88759*99948 ❤CALL GIRLS IN Lucknow ESCORT SERVICE❤CALL GIRL
Lucknow ❤CALL GIRL 88759*99948 ❤CALL GIRLS IN Lucknow ESCORT SERVICE❤CALL GIRLLucknow ❤CALL GIRL 88759*99948 ❤CALL GIRLS IN Lucknow ESCORT SERVICE❤CALL GIRL
Lucknow ❤CALL GIRL 88759*99948 ❤CALL GIRLS IN Lucknow ESCORT SERVICE❤CALL GIRL
 
Hot Call Girls |Delhi |Hauz Khas ☎ 9711199171 Book Your One night Stand
Hot Call Girls |Delhi |Hauz Khas ☎ 9711199171 Book Your One night StandHot Call Girls |Delhi |Hauz Khas ☎ 9711199171 Book Your One night Stand
Hot Call Girls |Delhi |Hauz Khas ☎ 9711199171 Book Your One night Stand
 
Nanded City ( Call Girls ) Pune 6297143586 Hot Model With Sexy Bhabi Ready ...
Nanded City ( Call Girls ) Pune  6297143586  Hot Model With Sexy Bhabi Ready ...Nanded City ( Call Girls ) Pune  6297143586  Hot Model With Sexy Bhabi Ready ...
Nanded City ( Call Girls ) Pune 6297143586 Hot Model With Sexy Bhabi Ready ...
 
𓀤Call On 7877925207 𓀤 Ahmedguda Call Girls Hot Model With Sexy Bhabi Ready Fo...
𓀤Call On 7877925207 𓀤 Ahmedguda Call Girls Hot Model With Sexy Bhabi Ready Fo...𓀤Call On 7877925207 𓀤 Ahmedguda Call Girls Hot Model With Sexy Bhabi Ready Fo...
𓀤Call On 7877925207 𓀤 Ahmedguda Call Girls Hot Model With Sexy Bhabi Ready Fo...
 
✂️ 👅 Independent Andheri Escorts With Room Vashi Call Girls 💃 9004004663
✂️ 👅 Independent Andheri Escorts With Room Vashi Call Girls 💃 9004004663✂️ 👅 Independent Andheri Escorts With Room Vashi Call Girls 💃 9004004663
✂️ 👅 Independent Andheri Escorts With Room Vashi Call Girls 💃 9004004663
 
CALL ON ➥8923113531 🔝Call Girls Lucknow Lucknow best sexual service Online
CALL ON ➥8923113531 🔝Call Girls Lucknow Lucknow best sexual service OnlineCALL ON ➥8923113531 🔝Call Girls Lucknow Lucknow best sexual service Online
CALL ON ➥8923113531 🔝Call Girls Lucknow Lucknow best sexual service Online
 
AWS Community DAY Albertini-Ellan Cloud Security (1).pptx
AWS Community DAY Albertini-Ellan Cloud Security (1).pptxAWS Community DAY Albertini-Ellan Cloud Security (1).pptx
AWS Community DAY Albertini-Ellan Cloud Security (1).pptx
 
VVVIP Call Girls In Connaught Place ➡️ Delhi ➡️ 9999965857 🚀 No Advance 24HRS...
VVVIP Call Girls In Connaught Place ➡️ Delhi ➡️ 9999965857 🚀 No Advance 24HRS...VVVIP Call Girls In Connaught Place ➡️ Delhi ➡️ 9999965857 🚀 No Advance 24HRS...
VVVIP Call Girls In Connaught Place ➡️ Delhi ➡️ 9999965857 🚀 No Advance 24HRS...
 
'Future Evolution of the Internet' delivered by Geoff Huston at Everything Op...
'Future Evolution of the Internet' delivered by Geoff Huston at Everything Op...'Future Evolution of the Internet' delivered by Geoff Huston at Everything Op...
'Future Evolution of the Internet' delivered by Geoff Huston at Everything Op...
 
Rohini Sector 6 Call Girls Delhi 9999965857 @Sabina Saikh No Advance
Rohini Sector 6 Call Girls Delhi 9999965857 @Sabina Saikh No AdvanceRohini Sector 6 Call Girls Delhi 9999965857 @Sabina Saikh No Advance
Rohini Sector 6 Call Girls Delhi 9999965857 @Sabina Saikh No Advance
 
GDG Cloud Southlake 32: Kyle Hettinger: Demystifying the Dark Web
GDG Cloud Southlake 32: Kyle Hettinger: Demystifying the Dark WebGDG Cloud Southlake 32: Kyle Hettinger: Demystifying the Dark Web
GDG Cloud Southlake 32: Kyle Hettinger: Demystifying the Dark Web
 

Rethinking Cybersecurity for the Digital Transformation Era

  • 1. Presentation title here—edit on Slide Master ©2018 Zscaler, Inc. All rights reserved. Zscaler™, SHIFT™, Direct-to-Cloud™ and ZPA™ are trademarks or registered trademarks of Zscaler, Inc. in the United States and/or other countries. All other trademarks are the property of their respective owners. Rethinking Cybersecurity for the Digital Transformation Era Dan Shelton – Director, Product Management
  • 2. ©2018 Zscaler, Inc. All rights reserved. What is Changing? The cloud and mobility are creating a megashift for Digital Business and IT Transformation Disrupting 30 years of networking and security architectures Users have moved off the corporate network and are connecting from everywhere Applications have moved out of the data center and into the cloud
  • 3. ©2018 Zscaler, Inc. All rights reserved. Challenge – The Traditional Hub & Spoke Network Backhaul Traffic to a Central Datacenter for Security Services The Castle & Moat Security Architecture
  • 4. ©2018 Zscaler, Inc. All rights reserved. Challenge – Applications Moved to the Cloud & Users Left the Network SaaS Open Internet Private CloudPublic Cloud
  • 5. ©2018 Zscaler, Inc. All rights reserved. Challenge – Internet Gateways in the Data Centers Aggregation Firewall Load Balancers & VPNs Web Filter Sandbox Flow Management Edge Next- Gen Firewall DLP SSL DC 11 9 8 7 6 5 4 3 2 1 12 10 13 14 16 17 18 19 20 21 22 2324 25 26 27 28 https:// 15 Content Inspection Internet Apps moved to a modern platform. Access is still using 30-year old technology.
  • 6. ©2018 Zscaler, Inc. All rights reserved. Global LB DDoS Ext. FW / IPSInternal LB Internal FW RAS (VPN) Internet Challenge – Remote Access Gateways in the Data Centers Site-to-site VPN Apps moved to a modern platform. Access is still using 30-year old technology. How do you access internal apps on Azure or AWS?
  • 7. ©2018 Zscaler, Inc. All rights reserved. Zscaler enables secure transformation to the cloud Internet and VPN Gateway Ext. FW / IPS URL Filtering Antivirus DLP SSL Sandbox Global LB DDoS Ext FW/IPS RAS (VPN) Internal FW Internal LB SaaSOpen Internet External APPS Data CenterIaaS Internal Internal (cloud or data center) Connect a user to an authorized private app (not network) Fast and secure policy-based access to apps and services over the Internet Any device, any location, on-net or off-net External (open Internet or SaaS) Nothing bad comes in, nothing good leaks out Zscaler Internet Access Zscaler Private Access HQMOBILE BRANCHIOT
  • 8. ©2018 Zscaler, Inc. All rights reserved. The Complex Infrastructure of a Large Global Organization Open internet MPLS MPLS MPLS MPLS • 9 Data Centers • 8 internet egress points managed by 6 different teams • 8 email systems managed by 6 different teams 900 locations across 22 countries 10,000 Users 3,000 Remote Users on 5 VPN solutions 17 MPLS providers with various configurations Complex | Poor User Experience | Difficult to Manage | Unreliable Lack of Visibility | Significant CAPEX and OPEX Fail-Over EMEA DC Fail-Over NA DC
  • 9. ©2018 Zscaler, Inc. All rights reserved. Cloud Transformation Journey – Phase 1 Four initiatives 1. WAN vendor consolidation 2. Remove branch MPLS and use IPSEC to MPLS (SDWAN) 3. Embrace Office 365 and phase- out local email servers 4. Local internet breakouts with appliances 30 Country & Regional HQs 870 Branch Locations MPLS WAN Vendor 9 Data Centers Open Internet IPSEC-to-MPLS architecture (No MPLS at braches) Branch office users complaining their internet experience was poor. MPLS WAN Vendor SaaS Benefits • Eliminated branch MPLS costs • Better internet experience at country and regional HQs • Simplified IT by standardizing email/SharePoint and reducing MPLS vendors from 17 to 1 1 4 MPLS WAN Vendor 2 3
  • 10. ©2018 Zscaler, Inc. All rights reserved. Cloud Transformation Journey – Phase 2 One initiative 1. Implement local internet breakouts in all branches 30 Country & Regional HQs 870 Branch Locations 9 Data Centers MPLS WAN Vendor Open Internet Option 1: Deploy branch firewalls in 870 locations. Option 2: Implement Zscaler Cloud Security Platform. XX Office 365 required more than just traditional proxy ports. Visibility provided by Zscaler led to Internet policy discussions. SaaS Benefits • Reduction in branch user internet complaints (less pushback) • Avoided the cost and overhead of deploying 870 security appliances • 60% reduction in Data Center bandwidth requirements
  • 11. ©2018 Zscaler, Inc. All rights reserved. Cloud Transformation Journey – Phase 3 Three initiatives 1. Reduce security appliance requirements at country / regional HQs and data centers 2. Implement Zscaler Cloud Firewall and Bandwidth Control for O365 3. Protect mobile users 30 Country & Regional HQs 870 Branch Locations 9 Data Centers MPLS WAN Vendor Open Internet Delivered a consistent end-user experience to IaaS and SaaS applications at all branch and HQ locations, but the mobile user was still struggling SaaS Benefits • Eliminated security appliances in country & regional HQs • Better Office 365 user experiences in all locations • Reduced risk by providing identical security controls to mobile workers
  • 12. ©2018 Zscaler, Inc. All rights reserved. 9 Data Centers MPLS WAN Vendor Open Internet SaaS IaaS 5 Data Centers Cloud Transformation Journey – Phase 4 Three initiatives 1. Migrate apps to IaaS – re- platform critical apps to be browser accessible 2. Consolidate data centers 3. Deploy virtual NGFWs and load balancers to eliminate traffic tromboning 30 Country & Regional HQs 870 Branch Locations VM Virtual NGFWs and load balancers were expensive, didn’t scale, and micro-segmentation challenges. User confusion on when to use VPN and when they could use a browser. Benefits • Reduced data center costs • Provided users better access re- platformed apps (No VPN)
  • 13. ©2018 Zscaler, Inc. All rights reserved. MPLS WAN Vendor Open Internet SaaS 5 Data Centers IaaS VM Cloud Transformation Journey – Phase 5 Two initiatives 1. Seamless End-User Experience - Implement Zscaler Private Access 2. Zero-Trust Network Model 30 Country & Regional HQs 870 Branch Locations Future-proof app delivery strategy with positive end-user experience. Benefits • Simplified access to all applications • Eliminated the cost and complexity of virtual firewalls and load balancers in IaaS • Enhanced security posture – app microsegmentation, reduced inbound attack surface, enablement of zero-trust network model
  • 14. ©2018 Zscaler, Inc. All rights reserved. Transformation Journey – Summary Cost Savings $9.66M OPEX Per Year Cost Avoidance $2.7M in appliance sprawl Network transformation – Removal of MPLS at 870 locations and deployment of 30 local breakouts with appliances Network transformation – ZIA deployed to support local internet breakouts in 870 branch offices around the world Global collaboration tools – Successfully deployed Office 365 Data center transformation – Moved apps to Azure/AWS and consolidated data centers Application access transformation –Eliminated VPN, zero-trust network model, positive end-user experience 1 2 3 4 5 Benefits Simple and agile IT environment Consistent end-user experience Reduced business risk
  • 15. ©2018 Zscaler, Inc. All rights reserved. Every enterprise needs network and application transformation HQ/IOT MOBILE BRANCH Secure Internet Edge HQ APJEMEA BUSINESS VALUE Better user experience Reduced Business Risk Business Agility Lower TCO Hub and Spoke to Direct to Cloud NETWORK TRANSFORMATION Securely connect the right user and device to the right app and service in the digital transformation era Data Center to Cloud (SaaS/IaaS) APPLICATION TRANSFORMATION
  • 16. ©2018 Zscaler, Inc. All rights reserved. Global Partners 100 Data centers 45B Daily requests 185 Countries served Unparalleled Cloud Scale Enterprise Customers 2,800 CUSTOMERS Over 200 of the Fortune Global 2000 Conglomerates 3 of the top 3 Oil and gas operations 3 of the top 4 Beverage 5 of the top 7 Specialized chemicals 2 of the top 3 Food retail 6 of the top 12 Apparel and accessories 2 of the top 4 Largest Cloud Security Platform in the World Mature Global Cloud Operations Zscaler: The market leader in cloud security
  • 17. ©2018 Zscaler, Inc. All rights reserved. ©2018 Zscaler, Inc. All rights reserved. Zscaler™, SHIFT™, Direct-to-Cloud™ and ZPA™ are trademarks or registered trademarks of Zscaler, Inc. in the United States and/or other countries. All other trademarks are the property of their respective owners.
  • 18. ©2018 Zscaler, Inc. All rights reserved. Direct to Internet Block the bad, protect the good The best approach for SD-WAN and Office 365 Zscaler Internet Access – Fast, Secure Access to the Internet and SaaS Data Center APPSMPLS HQMOBILE BRANCHIOT Your security stack as a service Data Loss Prevention Cloud Apps (CASB) File Type Controls Data Protection Cloud Firewall URL Filtering Bandwidth Control DNS Filtering Access Control Adv. Protection Cloud Sandbox Anti-Virus DNS Security Threat PreventionReal-time policy engine Polices follow the user Changes are immediately enforced, worldwide Business analytics Global visibility into apps and threats blocked Identify botnet infected machines for remediation Real-time policy and analytics
  • 19. ©2018 Zscaler, Inc. All rights reserved. Zscaler Private Access Secure and fast access policy-based access to private apps on Azure, AWS or your DC Z-APP 2 Datacenter User 1 POLICY (Brokers) ID Provider Windows, Mac, iOS, Android - On-net or off-net Public Cloud Connect a named user to a named app, not a network; Direct path to cloud apps without hairpinning through DC. No VPN needed ZPA replaces the entire inbound gateway/DMZ. Not just a VPN replacement Reduced cost, complexity, better security and user experience ZPA: Innovative Design Cloud-based policy engine – who can access what apps 1 Z-APP – Request access to app2 Z-Connector – sits in front of apps. Starts inside out connection 3 Zscaler cloud brokers a secure connection between the Z-connector and Z-app Private Apps Web, TCP, UDP Z-CONNECTOR 3 3 1. User never on your network 2. Apps are invisible (safe) 3. App segmentation without network segmentation 4. Use Internet as a secure network without VPN Why ZPA is Revolutionary

Notas do Editor

  1. File servers, print services, MPLS was supposed to fix this – SD WAN was supposed to fix it
  2. All users get identical protection, on-net or off-net
  3. This slide provides Context to the discussion as the Largest Cloud Security Platform in the World Talk about the 1Gbps per second metric – Trends – challenges – from the enterprise customers – they are about end-user experience – The software Defined Perimeter is well-positioned to help organizations improve their end-user experience