Back
Adam Geller
Chief Product Officer, Zscaler

Continuous Threat Exposure Management | Zscaler Launch Event - Keynote

🎥 Mar 26, 2025 📺 Zscaler Inc. ⏱ 41m
In this Continuous Threat Exposure Management (CTEM) launch event keynote, Zscaler's Chief Product Office Adam Geller ...
Watch on YouTube

About Adam Geller

Adam Geller, who joined Zscaler as chief product officer in September 2024, has been discussing the company's product strategy and cybersecurity approach in recent appearances. On the Zscaler Pulse Podcast in May 2025, Geller said that over 25 years, the main change in security has been how practical it is to implement principles, noting that "things that weren't possible to do before are now doable" but that organizations must factor in whether they can operationalize and afford them. He also stated that Zscaler spends significant time debating which directions to pursue, deciding where to "double down or triple down" and where to reduce effort, and that being clear about what the company will and will not do is important given "limitless opportunities" to engage with customers. In March 2025, Geller delivered the keynote at a Zscaler launch event for new continuous threat exposure management (CTEM) innovations, including a new asset exposure management product. He described Zscaler as known for its "pioneering architecture in zero trust" and said the company has helped thousands of organizations eliminate firewalls and VPNs. Geller cited a Gartner prediction that by 2026, organizations prioritizing security investments based on a continuous exposure management program would be "three times less likely to suffer from a breach."

Source: AI-verified profile updated from Adam Geller's recent appearances. Browse all interviews →

Transcript (13 segments)
J
Joyce0:52
Hello and welcome to today's Zscaler launch event announcing our new exposure management innovations. I'm Joyce, CMO at Zscaler, and I'll be your host today. You'll hear from industry leaders and exposure management experts as they discuss how these new innovations can help organizations like yours build an effective continuous threat exposure management, or CTEM, program. Companies around the world are adopting CTEM to reduce their attack surface, and we're proud to show how we're moving this industry forward in this area. As a part of this launch, we're especially excited to introduce a brand new product: our asset exposure management solution. During this event, you'll have a chance to ask questions and chat with experts live. To ask a question, simply type it in the Q&A window. After the main keynote, be sure to check out our breakout sessions where our product leaders will show you our CTEM innovations in action. Now, it's my pleasure to introduce Zscaler's Chief Product Officer, Adam Geller.
A
Adam Geller2:07
Thank you so much, Joyce. I'm excited about our CTEM launch today, and I'd like to set the stage for these innovations with a little context on Zscaler's approach to cybersecurity. Many of you know Zscaler for our pioneering architecture in zero trust, and we've enabled thousands of companies on their digital transformation journeys, helping them do away with firewalls and VPNs while eliminating tons of cost and complexity. We secure communications between users and workloads, IoT and OT devices, and other entities across the branch, the data center, the internet, and the cloud. And we've done that really well, and we've earned your trust. So it's not really surprising that over the last several years, many of you have been telling us, 'You see our entire environment. You're in the middle of all of these interactions and communications. You're really in the perfect spot to be able to give us a view into risk across our entire estate.' So as we have these conversations, we hear the same questions over and over: Where are all of my assets? Do I even know about all of them? Who are my riskiest users? Where are my biggest security gaps? What everyone is struggling to understand really is this: What is my overall risk posture? Now, it's a real privilege when your customers want you to do more for them, to expand the security practices they can engage in with you. And we kicked off a few initiatives in parallel. First, last year we introduced Risk 360. Risk 360 provides a collective view into your risk posture and security gaps across your Zscaler services. It offers helpful insights, and at its debut, those insights were focused specifically on Zscaler data. Second, we realized that delivering a more complete risk assessment would require input across the breadth of security tools that are surfacing security findings in all sorts of domains, but all that data sits in silos. So we went looking for the best approach for aggregating and synthesizing all of that data, and we found it in Avalor, which had built the industry's first data fabric for security. And we acquired Avalor in March of 2024. We will go into more detail on the power of the data fabric and show it in action later, but let me give you a quick explanation here on why it is so effective at delivering compelling insights into your risk posture and why it's at the heart of our CTEM solution. Lots of industries have used data fabrics for years to aggregate and correlate tons of data. Our technology, however, is a data fabric specifically built to support security insights. It takes in data from hundreds of sources, aggregating and correlating security findings and business context to identify all your security gaps, prioritize which ones are most crucial to your business to fix first, and then to automate workflows to resolve those exposures. With the Avalor acquisition, we also got the first product built on this data fabric for security: unified vulnerability management, or UVM. UVM aggregates exposures found by all of your security systems, it applies your risk factors and mitigating controls to prioritize those exposures, and it automates tickets into systems like Jira or ServiceNow so your teams can close those gaps. In the 10 months since the acquisition, we've been working hard to bring these exposure solutions together. Recently, we've enhanced Risk 360 by moving it onto the data fabric so that third-party data can now inform your risk quantification. So now those financial calculations are far more accurate because they take into account elements like whether EDR is running or if an asset is at greater risk because it is exposed to the internet. We also enhanced UVM by feeding it with Zscaler data, so now your risk prioritization takes into account information about your Zscaler configuration. So for example, elevating the risk of an exposure if the asset it's on is missing a ZIA access control policy or maybe it's missing the ZCC client altogether. Now, that's pretty solid development in just 10 months, but we've been working on even bigger things. And today we're introducing a brand new application built on top of the data fabric focused on helping you understand and address your asset exposures. We will be showing you highlights of this new application, and we have a dedicated breakout with a full solution overview, so stay tuned. We are really proud of this pace of innovation, and it's a direct result of building on top of the data fabric. The fabric supports core functions on behalf of all the applications, so each application can leverage these components and focus their attention on building out their application-specific features. This evolution we've been on, building this family of capabilities to provide you insight into your exposures across your environment, there's a framework for taking this kind of holistic approach to proactive security, to finding and eliminating security gaps, and it's called CTEM: continuous threat exposure management. Gartner coined this term a few years ago and made it one of just six top cyber initiatives to adopt. Now, why is that? It's because proactive security, closing all the doors and windows that can let in the bad guys, it's crucial to protecting your business. But existing vulnerability management solutions alone really have just not been enough. We need to define vulnerabilities in a much broader way. It's not just CVE, but it's also misconfigurations, code flaws, the absence of security software. And we need to be running these programs in a continuous fashion. A pen test every six months is just not going to protect you. Gartner summed up the urgency in adopting CTEM like this: By 2026, organizations prioritizing their security investments based on a continuous exposure management program will be three times less likely to suffer from a breach. So now think about that. You could build a program that could make you three times less likely to suffer a breach. That's worth at least your consideration and likely your time and effort too. So what's involved in building an effective CTEM program? It consists of five steps, and we'll look at each one of them now. Step one is scoping. This step is essentially a business decision. Your security and IT leaders should collaborate to decide the scope of your CTEM program. What aspects of the business will you include? Now, most companies, for example, they're going to include traditional vulnerabilities like CVEs and their external attack surface in the initial scope. Other types of exposures will need discussion. Do you want to track your company reputation in online social media? Do you want to monitor whether company credentials are being shared and used on the dark web? You need to recognize that this process is going to be iterative. You'll make one set of decisions for the first version of your CTEM program, and then you'll likely evolve that scope over time. Now, step two is discovery. This step is all about discovering the breadth of the assets in your environment and understanding their risk profile. And you've likely done this for years with classic vulnerabilities and vulnerability tools like Qualys, Rapid7, and Tenable. As we evolve from vulnerability management to exposure management, you'll want endpoint protection software, cloud security tools, identity tools, and application development pipeline tools like static and dynamic application security testing tools to bring in misconfigurations, code flaws, and even user behaviors that introduce risk, such as when users fail phishing tests. Step three is prioritization. The discovery step is going to identify way more security gaps than you'll be able to fix. So where should you focus your company's valuable resources? Lots of teams have historically focused on fixing just the criticals and the highs, but those generic scores cannot account for what actually constitutes risk in your environment. You'll want to know things like: Is there an active exploit for that vulnerability? Do we have compensating or mitigating controls for that gap? Is the asset with this gap sitting in a development or production environment? Context really matters. And we know loads of you have been doing this hard work in spreadsheets, and that's just not really workable or scalable anymore. Step four is validation. In this step, you're simulating how an attacker could exploit an identified security gap through a combination of technologies such as breach and attack simulation or manual assessments like red teaming. You're assessing the likelihood and impact of a given attack. A secondary benefit of this step also simulates attacks so you can appraise how your people and processes would respond to that kind of attack. Are those systems sufficient for protecting your business? That's the work involved in this validation step. Step five is mobilization. This step is all about operationalizing the security findings. This is the actual work of communicating and taking action to reduce risk. One essential element of mobilization is automating workflows for remediation. You need technology to kick off the workstream for teams to close the identified gaps. And another key but less obvious element of mobilization is reports and dashboards. The very act of communicating how the company is faring in reducing risk is an important part of taking action. Sharing status, setting SLAs, and defining how access policies should change in response to elevated risk is all part of mobilization. This step also includes defining processes for reducing friction in remediation approvals, establishing metrics and communications expectations, and documenting responses. So how can Zscaler help you in your CTEM program? We use a combination of native scanning and data aggregation powered by our data fabric for security to provide the most robust discovery, prioritization, and mobilization. I'm going to leave you with one final thought, and it's the power of the Zscaler ecosystem. Each part of our exposure management platform feeds and improves the other parts. Asset exposures will impact risk prioritization. Prioritization will inform risk quantification. So the outputs of each application become inputs to the others, and these powerful feedback loops extend beyond just exposure management. As we determine risky assets or risky users, we can feed these findings over to the Zero Trust Exchange and dynamically adjust access policies on ZIA or ZPA, for example, to lower your overall risk. Now, you'll always be able to run our exposure management solution without any other Zscaler services, but you'll benefit from automatic integrations and pre-built feedback loops as you broaden adoption across the Zscaler ecosystem. Thank you for tuning in to this discussion about how Zscaler provides key capabilities for continuous threat exposure management. And I'm excited to bring up Andy Scree, our VP of Product Management, to go into our new solutions in more detail. Andy, take it away.
A
Andy Scree14:34
Thank you so much, Adam. You've set the stage perfectly for how our customers can tap these new Zscaler capabilities to build an effective CTEM program. I'm Andy Scree, Vice President of Product Management here at Zscaler. We're going to use the last part of today's keynote to show you our solutions in action. I'm joined by Noga Anaby in New York, our product manager for both our new asset exposure management solution and our unified vulnerability management, or UVM, solution. She'll be showing you the key capabilities of our products and how customers are getting the insights and visibility they've always wanted. Adam highlighted our asset exposure solutions are built on our data fabric for security. Let's start our deep dive there. What is a data fabric? Maybe let's start with what it is not. It's not a data lake or a data warehouse. I've spent my entire cyber career using and building products on top of data lakes and warehouses. They're great for aggregating and storing data, but they put the burden on humans to query that data to make sense of it and gain the valuable insights needed to operationalize it. The key attribute of the data fabric is that it takes data from many different sources, it transforms and synthesizes that data to deliver new insights. Now you can finally get value out of all of that data you're collecting without having to know what specific question to ask of the data or which source you need to ask. The data fabric applies four key steps to transforming the data. The first step is to harmonize all of that data. That is, take all of the variants of one term and transform them into a single form. For example, solutions, even different solutions from the same vendor, can designate a Windows operating system with different terms. Some will say Windows, some simply say Win, some are windows with a lowercase w. You need that data cleansed and using the same term so that everything related to that term can be seen as one combined data set. Second, we need to deduplicate the data. Multiple tools will report the same assets, findings, vulnerabilities, users, and so on. The data fabric combines that data so you know all of those findings are related to a single asset, providing a more accurate representation of your environment. Next, we need to correlate the data. Different tools will know different aspects about a given asset. For example, one tool might know its IP address, another might know its OS version, and yet a third might know whether the endpoint protection software is installed. The data fabric seamlessly stitches together all of those related data points and establishes the relationships between them and to a single entity, so you get a complete picture of that entity that any single data source alone could tell you. Finally, we enrich the data by aggregating information about a given entity and seeing the relationships and gaps, like an endpoint that should have EDR installed but doesn't. The data fabric enriches your understanding of every entity in your environment. This enrichment provides important context needed for prioritization and mobilization. Data fabrics have been used in a lot of industries, and the innovation here in building a data fabric is specifically around security. Noga, you've worked on data fabrics for years, both here and at other companies. Can you share what's distinctive about our data fabric and show some of its key capabilities in action?
N
Noga Anaby17:53
Absolutely, thanks Andy. Andy made a great distinction in his last point there. He talked about generic data fabric versus our data fabric for security. What makes ours tailored for security? How we built the data model at the heart of our data fabric. Data models have historically been either flexible—you can expand them and apply them to solve lots of different problems—or they've been opinionated, which means they're built to provide value in a particular domain. By building a data fabric for security, we've delivered both advantages at once. Our data model is both flexible and opinionated. It's opinionated in the sense that it comes with a set of meaningful entities and relations that correspond with different security use cases: assets, findings, vulnerabilities, software, etc. But it's also flexible in the sense that you can expand and customize our data model. The combination of these two qualities allows us to apply it to solve exposure management problems today and easily extend the same core capabilities to address more security use cases tomorrow. So let's look at how our data model is built for security. The connectors we've built all draw data sources that help you address security use cases. You see here pre-built connectors into vulnerability scanners, cloud systems, endpoint security tools, identity tools, etc. If you have any data that is sitting somewhere in a file or in a database or in an S3 bucket, you can also use our any-source connector to bring that in. You could do a one-off pull or even retrieve it on a regular basis from wherever it is. We talk about the data model at the heart of our data fabric as being opinionated, that is, designed to address security use cases. You can see that as I show you the mapping capability. So our data model, as we said, is opinionated. It's pre-populated with a list of entities and attributes and relationships that have meaningful existence in the security world. This could be assets, findings, vulnerabilities, software, etc. Every data source that we bring into the platform goes through this practice of mapping. We take the schema of the source data here on the left side and we map it into the right side, into our standardized data model. This would be pre-built for an existing pre-built connector; we would have a default mapping where everything is already ingested. Or for an any-source, you can always add that in with some suggestions. Now, this is also flexible in the sense that you could really map any type of field that you want or any piece of data from the source data into our data model. So mappings could be simple—a simple field-to-field mapping—or you can go as complex as doing a Python script to extract any piece of data that could be sitting in a tag somewhere in your vulnerability scanner or your EDR. Another way that this is flexible is that you could easily extend the data model. So you can create new fields on any of the entities if you need to populate custom logic for your organization, or you could add entities and really tie them together with our pre-existing data model using relationships. The standardization of the data is key to a clean view of assets and exposures you can use as a base for prioritization. So these are some good examples of the functionality of the data fabric itself. Andy, back to you.
A
Andy Scree21:12
Thanks, Noga. It's super helpful to see the power of the data fabric in action to help bring clarity and consistency across all that data that organizations have. Next, we want to showcase how our solutions help you achieve those three CTEM steps that Adam highlighted: discovery, prioritization, and mobilization. Let's start with discovery. The first use case for our new asset exposure management solution is to create a complete and accurate inventory of all of your assets. Organizations of all sizes and levels of sophistication struggle with one foundational question: How many assets do we actually have? This is a simple question, but often it's an expensive question to answer when you need to pivot across multiple tools. Given the adage that you can't protect what you can't see, it's clear an accurate asset inventory is the foundation to a robust security program and why discovery is such a critical step in CTEM. Zscaler leverages our data fabric to synthesize assets across dozens of data sources: your CMDB, your endpoint protection software, and your cloud security tools. For Zscaler customers, we augment these sources with the data from our inline technologies. Watching traffic from the Zscaler client connector and network traffic across the Zero Trust Exchange can potentially identify assets not included in any of the other data sources, providing a more robust inventory. Noga, can you walk us through some of the key features of our new asset discovery capabilities?
N
Noga Anaby22:44
Sure, Andy. And you're absolutely right that we see even the most sophisticated companies struggle with just knowing their asset inventory. Let's take a look at how our solution works. As we showed in the previous step, we pull in all of your asset data from all of your different tools. Could be your security tools, your EDRs, your vulnerability scanners. Could also be your CMDB, maybe identity management platforms, maybe endpoint management. And then we go through the process of deduplication. The process of deduplication allows me to see this one asset that was reported by three different tools, and I was able to aggregate attributes reported by the different tools into one single view. Deduplication means I'm reconciling that this is the same asset across these different tools. It can be done based on shared attributes and fields by default, but it could also be customized like anything else in a data fabric. So I can go in there, add a rule for deduplication, and make sure that this specific asset type is merged by a specific logic that I want it to be. Now, this clean asset inventory is crucial for the next step of CTEM, which is prioritization, but it also brings value in other security-related operations. A continuous inventory provides anyone in my security or IT organization the opportunity to search for an asset or filter for it, find it, and learn everything there is to know about it. It also means different teams across the org can look at the same data as their source of truth, speak the same language, and generate new insights based on the combination of different data points. Meaning proactive teams focused on exposures can prioritize based on real threats, and reactive teams focused on investigating incidents get full context and visibility into the attack surface. Finally, it allows me to find answers to questions that sound simple yet are hard to answer, like how many assets do I have in my environment or in this specific geo, or which assets have this piece of software installed. You can fully operationalize these efforts by automatically triggering CMDB updates or risk mitigation for high-risk assets, and easily track your progress against these policies with pre-built KPIs and dashboards. I show those capabilities in the breakout session immediately following this keynote. I hope you join me there.
A
Andy Scree25:00
Thanks, Noga. Having an accurate asset inventory is not only critical to CTEM, but it's valuable context for other parts of your security program like your SOC. Understanding the assets in your environment and the context related to these assets is critical during an incident or a breach. Now we want to dig into how Zscaler can help you prioritize the risks your discovery phase uncovered. As Adam mentioned, risk does not live in a vacuum. It's derived from the conditions of your particular environment. No company can fix every problem, not even the criticals and highs. So you need to prioritize these security findings. That prioritization must take into account your risk factors, mitigating controls to truly understand the potential business impact and given exposure. For example, imagine you have two assets with vulnerabilities that have the same severity score. In one case, let's say you learn that asset has endpoint protection software installed and it's sitting in a dev environment. You're much less worried about that exposure. For the second asset, the same score, let's say you learn it's open to the internet, it's got a known active exploit in the wild, the asset has PII based on data from a DSPM system, and the user of this asset is known to routinely fail phishing tests. This exposure you're much more concerned about. Both findings share the same starting point, but with risk context is king, and the context shows the risk posture for these two to be very different. Noga, can you show us how we help customers prioritize their exposures?
N
Noga Anaby26:32
Great examples, Andy. And yes, let's look at how we apply risk factors and mitigating controls to contextualize and prioritize risk. So here's a set of discovered vulnerabilities. You can see here the original severity score and next to it the adjusted score taking into account your context. You can click through each of these findings and understand, first of all, anything there is to know about this finding, and also get a full explanation of the scoring logic. We take in industry scores like CVSS, EPSS, or the score given by the scanner, and we then add on context about the asset, the vulnerability in the wild, maybe even user context or organizational context—anything that could really speak to the risk that this vulnerability specifically is going to introduce to the environment. Every single finding in the platform will get this adjusted scoring, and just like anything else in our data fabric, this is completely customizable with our score calculator. You can use any field that you incorporated in that mapping stage. Maybe you created a new field, maybe you added in something from a tag somewhere. All of these can become score factors or mitigating factors if you want to also reduce risk when you see something is already protecting this specific asset. So to make prioritization of findings more efficient, we automatically group like findings into tickets that can be used as work items in downstream platforms. So the whole point in deduplicating like findings into tickets is to narrow down the noise and essentially help teams that need to prioritize vulnerabilities need to prioritize less things. So after we've grouped findings into tickets, we've reduced the noise. Now we can sort these grouped items based on two measurements that are used for prioritization. The first one would be severity score, which would be the highest severity of all the findings in a specific ticket. This one is a critical because I have a critical finding in this ticket. The second measurement we would use is risk mass, and that is supposed to take into account the volume of findings and not just their criticality. So this would help me differentiate between these three criticals. They're all three of them are nine severity, but I can see that this specific ticket only has one finding versus this one has four different findings, several criticals and highs. So it will make more impact if I fix this one first. If you want to see more of UVM in action, check out the second breakout presentation where our field CISO, Aiz Kapadia, provides a complete overview of the solution. Andy, back to you for an overview of the third step of CTEM where we provide a ton of value: mobilization.
A
Andy Scree29:21
Thanks, Noga. Indeed, curating the most accurate prioritized list of recommended fixes does nothing to reduce risk if those fixes are never applied. That's why the mobilization step is so crucial. Adam touched on the reality that some of the work in mobilization has to do with communication and documentation, but technology can help with some of the most critical steps in mobilization. Beware of vendors that promise to fully automate remediation, but you should absolutely be looking for technologies that can automate workflows for remediation. Every company has different organizational structures and processes, so make sure you've got the flexibility to tailor your workflows to meet your company's needs. Also bear in mind, reporting itself is the beginning of mobilization. Defining the metrics that matter, tracking SLAs, and capturing risk posture over time are foundational to operationalizing your exposure management findings. Noga, can you give us just a taste of the ways that our solutions help organizations take action and improve their security posture?
N
Noga Anaby30:26
Yes, I can. And you make some great points about striking the right balance between being too rigid and not fitting your needs, and being so loose and programmable that it takes months of costly professional services to get workflows built. We build the right balance of capabilities for remediation workflows. The first step for remediation is to assign work items to the right team. How does that happen? With grouping. So we already looked at the findings that become tickets. If I click on any of these tickets, I see they have specific qualities like an owner or an SLA, a status. It's already pre-populated with these, and all of this is controlled by the grouping rules. If you see here, every single ticket will have the grouping details, and I can click on it and see exactly which rule grouped these group of findings into this specific ticket. So grouping rules allow me to make sure that my work is grouped and assigned at scale. I don't have to go in and tag every group of findings based on their similarities. I just set specific filters that identify relevant findings for this grouping mechanism, and then I say, okay, let's group all my Linux findings that are talking about Adobe Acrobat into one ticket. But I can make it into a rule that runs on a regular basis. I don't have to be specific about this being Linux or that being Adobe, but we just set one rule that says group by the asset type and the software name. Now let's look at what info the team gets to start the remediation. We already saw each team has an SLA, but they also get an aggregated view of all the fixes required to apply in order to completely remediate this ticket. You can slice and dice this by the component name, the software, the OS, whatever you need to make sure you have all the information you need to initiate remediation. And of course, there's no remediation if we don't send over the tickets to the right case management platform. We have bidirectional integration with Jira, ServiceNow, and any other third-party provider. The auto reconciliation is a huge time saver. We talk to teams all the time that spend several hours a week just logging updates on remediation statuses. Andy talked about how reporting is a crucial aspect of mobilization. Let me share a few reports here. So first, you can track the remediation efforts of your teams. Look at mean time to remediate, mean time to assign, look at tickets that are over their SLA, or different teams on how they're delivering. You can also report on the risk posture of your environment across different asset types, data sources, and even teams to see how the risk posture is changing over time. You can also build your own reports. Here's an example of a custom report that took about 15 minutes to build. You can see I can easily click into this, start editing. I only have to click around. I don't have to do any coding or any queries to apply any of the logic that I want. I can actually even create custom KPIs if I need to, and everything is fully interactive. I can click into any bar or slice and see all the items related to this number that explain the context behind it. I hope these highlights of our exposure management solution have helped you see the benefits. It can be even more useful to learn from the customer perspective. Let's hear how the team at LifeLabs sees the value of these capabilities.
M
Mike Mello33:50
Hi, I'm Mike Mello, and I'm the Chief Information Security Officer and the Vice President of IT Shared Services with LifeLabs. LifeLabs is the largest medical lab diagnostic company in Canada, servicing over 15 million customers. Part of my accountabilities is that I own cybersecurity services, data center services, the ITSM practice, and end-user compute. One of the common challenges that we face as security professionals and IT professionals is truly understanding our risk landscape. We've been on a multi-year journey trying to tackle the very challenge of asset management as it correlates to risk, and we've leveraged numerous industry-best products, and we've had a lot of struggles over the years, ultimately trying to ensure enforcement of policy to manage configuration drift, but also to get true data deduplication and a confident view into what our actual asset landscape truly looks like. One of my mandates is to ensure that we can attest to the security configuration of all of our different assets, particularly in our labs. One of the biggest challenges we've had with that is the need to survey and pull different lab workers and also send security professionals into the lab environment to test and look at these assets themselves, and it's just not a scalable solution. We needed something that was going to allow us to have real-time and credible data that we could trust in order to avoid any sort of, I would say, security risk implications or even fines. After many tries and years of struggling with the challenges of assets, we finally found a great solution with Zscaler Asset Exposure Management. What really makes it different is its unique ability to focus on security as a data problem rather than as a holistic security problem. With the Zscaler data fabric solution, we're getting all of the data that we need and all of the context in which comes from our organization to give us a truly meaningful and unique understanding of what our security risk is. What I mean by that is we can really delineate all the different data types and gather all the different data components, deduplicate that, and truly represent what we're seeing at all of the asset landscape. Three core things that I really take to heart in my philosophy of security are visibility, trust, and remediation. And what do I mean by that? When I think of visibility, it's giving me the entire landscape. So when we look at all of our different assets from multiple different data points, and then we need to be able to trust that the information that we have is accurate and that we can act upon it, which then gets us into the remediation. Having this philosophy is one thing, but being able to actually trust my technology to deliver on that and align to that is a completely different thing. And that's what Zscaler is able to deliver for us. With Zscaler, we're getting all of this. We're able to identify a trusted inventory, we're able to track and log all of our control gaps, and we're even able to remediate in an automated fashion all of the risks we've identified, including updating our CMDB in an automatic way. One important value driver that we look for security tooling is in the ROI. What kind of value am I driving to the business, and also what kind of money can I save the organization? With the Zscaler solution, we're identifying things that are able to reduce manual overhead from our IT service desk, improve customer experience with our end users, and also being able to identify duplicative software that we might not need and potentially have liability or a potential for a fine of misuse of software. One of the greatest business drivers that I find with the Zscaler Asset Exposure Management solution is it makes me a better CISO. I'm able to now have confidence when I go and report and speak to the executive leadership team or even the board on what is our current state of affairs when it comes to risk exposure. How do we leverage our asset inventory as a prescriptive methodology and also a means to tell and narrate a story of where we've kind of come from in security, the investments, and how we're continuously improving our security risk reduction, fostering a much greater cybersecurity culture when it comes to understanding risk and how we can ultimately reduce that risk for the organization.
A
Andy Scree38:46
It is truly gratifying to see our solution serving the LifeLabs team so well. Noga, back to you. Thanks, Noga. I hope these quick peeks into our solution and the power of our data fabric for security give you a good sense of how Zscaler can help you build and evolve a more effective CTEM program. We've been able to move fast with these innovations, and we look forward to bringing you additional security capabilities that leverage the data fabric in the future. With that, back to you, Joyce.
J
Joyce39:20
Thank you, Andy. You just heard how Zscaler can provide foundational technologies for building a CTEM program across discovery, prioritization, and mobilization to improve your security posture. Today, with our flexible approach, we can meet you where you are. You can start at whatever level your company is ready to support, and we can grow with you over time. But this isn't the whole story. Dive deeper into our solutions with the breakout sessions. Our asset exposure management breakout shows how you can get a more complete and accurate asset inventory, identify and close your coverage gaps, and mitigate asset risk. Our unified vulnerability management breakout highlights how you can get customizable risk prioritization, automated remediation workflows, and dynamic reporting and dashboards to improve your security posture. You'll find more resources on zscaler.com/ctem-launch. To learn even more about how Zscaler can protect your business, please join us at Zenith Live in June. We're currently offering a deal where you can sign up to attend and bring a colleague at no additional cost. Thank you for your time today, and we'll see you in the technical breakout sessions starting right now.