Adam Geller2:07
Thank you so much, Joyce. I'm excited about our CTEM launch today, and I'd like to set the stage for these innovations with a little context on Zscaler's approach to cybersecurity. Many of you know Zscaler for our pioneering architecture in zero trust, and we've enabled thousands of companies on their digital transformation journeys, helping them do away with firewalls and VPNs while eliminating tons of cost and complexity. We secure communications between users and workloads, IoT and OT devices, and other entities across the branch, the data center, the internet, and the cloud. And we've done that really well, and we've earned your trust. So it's not really surprising that over the last several years, many of you have been telling us, 'You see our entire environment. You're in the middle of all of these interactions and communications. You're really in the perfect spot to be able to give us a view into risk across our entire estate.' So as we have these conversations, we hear the same questions over and over: Where are all of my assets? Do I even know about all of them? Who are my riskiest users? Where are my biggest security gaps? What everyone is struggling to understand really is this: What is my overall risk posture? Now, it's a real privilege when your customers want you to do more for them, to expand the security practices they can engage in with you. And we kicked off a few initiatives in parallel. First, last year we introduced Risk 360. Risk 360 provides a collective view into your risk posture and security gaps across your Zscaler services. It offers helpful insights, and at its debut, those insights were focused specifically on Zscaler data. Second, we realized that delivering a more complete risk assessment would require input across the breadth of security tools that are surfacing security findings in all sorts of domains, but all that data sits in silos. So we went looking for the best approach for aggregating and synthesizing all of that data, and we found it in Avalor, which had built the industry's first data fabric for security. And we acquired Avalor in March of 2024. We will go into more detail on the power of the data fabric and show it in action later, but let me give you a quick explanation here on why it is so effective at delivering compelling insights into your risk posture and why it's at the heart of our CTEM solution. Lots of industries have used data fabrics for years to aggregate and correlate tons of data. Our technology, however, is a data fabric specifically built to support security insights. It takes in data from hundreds of sources, aggregating and correlating security findings and business context to identify all your security gaps, prioritize which ones are most crucial to your business to fix first, and then to automate workflows to resolve those exposures. With the Avalor acquisition, we also got the first product built on this data fabric for security: unified vulnerability management, or UVM. UVM aggregates exposures found by all of your security systems, it applies your risk factors and mitigating controls to prioritize those exposures, and it automates tickets into systems like Jira or ServiceNow so your teams can close those gaps. In the 10 months since the acquisition, we've been working hard to bring these exposure solutions together. Recently, we've enhanced Risk 360 by moving it onto the data fabric so that third-party data can now inform your risk quantification. So now those financial calculations are far more accurate because they take into account elements like whether EDR is running or if an asset is at greater risk because it is exposed to the internet. We also enhanced UVM by feeding it with Zscaler data, so now your risk prioritization takes into account information about your Zscaler configuration. So for example, elevating the risk of an exposure if the asset it's on is missing a ZIA access control policy or maybe it's missing the ZCC client altogether. Now, that's pretty solid development in just 10 months, but we've been working on even bigger things. And today we're introducing a brand new application built on top of the data fabric focused on helping you understand and address your asset exposures. We will be showing you highlights of this new application, and we have a dedicated breakout with a full solution overview, so stay tuned. We are really proud of this pace of innovation, and it's a direct result of building on top of the data fabric. The fabric supports core functions on behalf of all the applications, so each application can leverage these components and focus their attention on building out their application-specific features. This evolution we've been on, building this family of capabilities to provide you insight into your exposures across your environment, there's a framework for taking this kind of holistic approach to proactive security, to finding and eliminating security gaps, and it's called CTEM: continuous threat exposure management. Gartner coined this term a few years ago and made it one of just six top cyber initiatives to adopt. Now, why is that? It's because proactive security, closing all the doors and windows that can let in the bad guys, it's crucial to protecting your business. But existing vulnerability management solutions alone really have just not been enough. We need to define vulnerabilities in a much broader way. It's not just CVE, but it's also misconfigurations, code flaws, the absence of security software. And we need to be running these programs in a continuous fashion. A pen test every six months is just not going to protect you. Gartner summed up the urgency in adopting CTEM like this: By 2026, organizations prioritizing their security investments based on a continuous exposure management program will be three times less likely to suffer from a breach. So now think about that. You could build a program that could make you three times less likely to suffer a breach. That's worth at least your consideration and likely your time and effort too. So what's involved in building an effective CTEM program? It consists of five steps, and we'll look at each one of them now. Step one is scoping. This step is essentially a business decision. Your security and IT leaders should collaborate to decide the scope of your CTEM program. What aspects of the business will you include? Now, most companies, for example, they're going to include traditional vulnerabilities like CVEs and their external attack surface in the initial scope. Other types of exposures will need discussion. Do you want to track your company reputation in online social media? Do you want to monitor whether company credentials are being shared and used on the dark web? You need to recognize that this process is going to be iterative. You'll make one set of decisions for the first version of your CTEM program, and then you'll likely evolve that scope over time. Now, step two is discovery. This step is all about discovering the breadth of the assets in your environment and understanding their risk profile. And you've likely done this for years with classic vulnerabilities and vulnerability tools like Qualys, Rapid7, and Tenable. As we evolve from vulnerability management to exposure management, you'll want endpoint protection software, cloud security tools, identity tools, and application development pipeline tools like static and dynamic application security testing tools to bring in misconfigurations, code flaws, and even user behaviors that introduce risk, such as when users fail phishing tests. Step three is prioritization. The discovery step is going to identify way more security gaps than you'll be able to fix. So where should you focus your company's valuable resources? Lots of teams have historically focused on fixing just the criticals and the highs, but those generic scores cannot account for what actually constitutes risk in your environment. You'll want to know things like: Is there an active exploit for that vulnerability? Do we have compensating or mitigating controls for that gap? Is the asset with this gap sitting in a development or production environment? Context really matters. And we know loads of you have been doing this hard work in spreadsheets, and that's just not really workable or scalable anymore. Step four is validation. In this step, you're simulating how an attacker could exploit an identified security gap through a combination of technologies such as breach and attack simulation or manual assessments like red teaming. You're assessing the likelihood and impact of a given attack. A secondary benefit of this step also simulates attacks so you can appraise how your people and processes would respond to that kind of attack. Are those systems sufficient for protecting your business? That's the work involved in this validation step. Step five is mobilization. This step is all about operationalizing the security findings. This is the actual work of communicating and taking action to reduce risk. One essential element of mobilization is automating workflows for remediation. You need technology to kick off the workstream for teams to close the identified gaps. And another key but less obvious element of mobilization is reports and dashboards. The very act of communicating how the company is faring in reducing risk is an important part of taking action. Sharing status, setting SLAs, and defining how access policies should change in response to elevated risk is all part of mobilization. This step also includes defining processes for reducing friction in remediation approvals, establishing metrics and communications expectations, and documenting responses. So how can Zscaler help you in your CTEM program? We use a combination of native scanning and data aggregation powered by our data fabric for security to provide the most robust discovery, prioritization, and mobilization. I'm going to leave you with one final thought, and it's the power of the Zscaler ecosystem. Each part of our exposure management platform feeds and improves the other parts. Asset exposures will impact risk prioritization. Prioritization will inform risk quantification. So the outputs of each application become inputs to the others, and these powerful feedback loops extend beyond just exposure management. As we determine risky assets or risky users, we can feed these findings over to the Zero Trust Exchange and dynamically adjust access policies on ZIA or ZPA, for example, to lower your overall risk. Now, you'll always be able to run our exposure management solution without any other Zscaler services, but you'll benefit from automatic integrations and pre-built feedback loops as you broaden adoption across the Zscaler ecosystem. Thank you for tuning in to this discussion about how Zscaler provides key capabilities for continuous threat exposure management. And I'm excited to bring up Andy Scree, our VP of Product Management, to go into our new solutions in more detail. Andy, take it away.