Hey, good morning. Thanks so much for joining us at the Zscaler session. Delighted to have Adam Geller, Head of Product, and Kevin Rubin, CFO, on stage with us. Really grateful to you guys for taking the time.
Thank you.
Adam, I remember the original days of the Zscaler IPO.
One of the most foundational things that Jay and the team drove home was this idea of a true proxy architecture and how taking shortcuts to accomplish what looks like a proxy architecture from the outside in is not the same thing as delivering a true proxy architecture. My question for you is, we're now in a world where there is a decent intellectual argument to be made that agents should communicate on a proxy architecture. As a leadership team and as Chief Product Officer, how do you take a vision that was built for SASE and zero trust and extend it to an agentic proxy architecture?
I wasn't there during the IPO, but I was at companies that were competing with Zscaler without proxy architectures. I certainly know the space well. I think that the argument on all of it when we think from a product perspective is what's right fit for purpose of what problem you're trying to solve. You have to come back to some sort of first principle there. The reason why a proxy architecture is powerful in cybersecurity specifically is because when you get in the path of something, you have the chance to actually see and inspect. The whole point of doing cybersecurity is you're looking for either threats coming in or you're trying to understand where data is moving and should it be moving or not.
Just connecting things serves a purpose that allows you to get from point A to point B, but the whole reason why you have that concept of a proxy is it's an inspection point, and it's a chance to at least see and observe. You can observe, take notes, and take no action, or you have the chance to enforce policy. That architecture, time and time again, comes back up as a staple of cybersecurity products and technology because it works and it's extremely powerful. Now, it's like any security piece, it's friction in a process, so you have to be careful how much friction you introduce into a process. With agents are not operating in silos. They're operating by connecting to other data sources or connecting by working with other agents.
You have a whole interconnection to consider, and that is ripe for where you apply security into that. What do you do at the edge? What do you do in that connectivity path? That's why we think that proxy architecture is very powerful. The challenge will be, and the key is in how do you apply it and what's the same, and then what's different when that traffic is agent traffic versus any other kind of traffic.
Well, let's stay on this thread. I think we're all familiar with classic web proxy, where if I go out to the Internet, the Goldman Sachs policy Zscaler enforcer will be in the middle, and it'll orchestrate or proxy the connection.
With agents, the question we get on agents is both, look, they're ephemeral, they spin up and down much more quickly, and fundamentally, there are things about how an agent runs a session that make it difficult to properly, to your point on earlier, enforce and observe, it becomes different.
Maybe just give us the layman's version of how do you take a tooling that was originally built for web proxy and extend it to agentic proxy?
Sure. I'll give you one very vivid example that'll try to drive that point home. In most communications or most sessions, if a human's driving it, like I was describing before, you want to understand, should I allow something or not? You basically have milliseconds to do that, because anything longer than that, then the user thinks something's wrong and they go away, and they file that IT ticket, or they just find a path around it. You don't get a long time to decide is this a good website or is this a bad website, or should I allow this transaction or not. A lot of, as an example, in inline DLP, you look for a very quick pattern match. Yep, that's sensitive content. My policy says sensitive content isn't allowed out, so it's not allowed. Right? You make that real decision.
In AI, and this can be both human working with, let's say, a generative AI chat interface or an agent, the iteration, the back-and-forth conversation is actually how that works. The intent of a one-line request that mentions cookie, you could say that's a chocolate chip cookie recipe, right? If it's a back and forth over six different turns, it might be about a session cookie that's holding an authentication token for a particular transaction, and that might be much more sensitive information that's being sent out. So you actually have to look at, in using AI terms, a context window, right? Or understand multi-turns of a conversation. So the way you inspect is different, and what you're looking for also starts to change depending on what you're trying to protect.
In more classic world, it's looking for vulnerabilities or is this malware or is this an exploit coming down or is my data leaking? In the AI world, you might be looking at is someone trying to poison my model? Is someone trying to get it to do something it wasn't supposed to do? There's no vulnerability there. There's no signature for I've exploited a vulnerability. That's the way how a lot of cyber works. When you're proxying AI communications, you need different kinds of inspection engines for that traffic.
Maybe the other way to talk about this is through a little bit of a customer journey, and Kevin, we'll bring you into the conversation. Talk to us a little bit about when you meet with your large customers in the last five, six months, how is the conversation between Zscaler and the customer changing that addresses some of these new AI risks more comprehensively, and maybe the answer is zero trust architecture. But give us a flavor for what those conversations look like on the ground.
Sorry, she said Kevin three times.
No, either way.
I thought it was coming to you. No, that is okay. Look, I think the conversations have obviously accelerated and have gotten much more intense post- Mythos. Companies are starting to deal with the reality that they have vulnerabilities and exposures, many of which they did not even know they had before, right? Their exposure, their threats are far greater today than it was six months ago. The questions are: how do I deal with that? What do I do? I think the reality is that patching alone is not going to solve the problem. You have old equipment that may not even be in service any longer, you cannot patch. You may have old operating systems that you would have to upgrade before you patch.
The complicated environment of being able to address this with simple, traditional methods is becoming harder and harder, and the exposure and the time to a breach is becoming less and less. The conversations are, what do I do? Our answer is very simple. You need to hide your applications, so completely reduce your attack surface and eliminate the ability of any potential breach to be able to move laterally. A lot of the conversations are around how do we address the risk today and how do we help you, going forward, be able to secure your environment given how everything is changing so quickly.
Your point on patching does not solve the problem. I would love to use it as an opportunity to ask you about frontier models. Adam, this one is probably for you. What do you think the role is of a frontier model in security? Where do you think the swim lanes ultimately converge versus stay separate?
Great question. TBD, and it will evolve just like it has been evolving with cloud for many years, right? The evolution of what should you expect your hyperscaler to do for you. When I was in cyber in that time, in the early 2010s, there was that initial belief was, well, this will all be just baked into the hyperscaler now, so I do not need third-party products anymore. The investor conversations were all about, so when does this degrade the cyber business? Because I was working in another cybersecurity company, and it ultimately did not play out that way, right? There is embedded functionality in the hyperscalers, and the third-party elite and very focused cybersecurity companies have found a way to continue to drive value for their customers. Because that is their core and only focus.
I think we're going to go through a similar pace with that, or evolution with that on the frontier AI models. As an example, every AI model has the concept of guardrails. They also have the concept of running without guardrails. There are baselines, and then there are what other guardrails, what third-party products, like Zscaler makes one, AI Guard, that is a guardrail solution for making sure that your model does not go awry, either shares too much information or gets compromised in some fashion. I think you'll see baseline level of security capabilities will be built into all the foundational model solutions, and then you'll see those natural kinds of extensions. At least maybe 10, 12 months ago, you also saw this angle of will the frontier model companies just build cybersecurity products outright? That's always a risk.
It hasn't quite played out as scary as it was set up 10 months ago. When I say scary, meaning just, oh, there's no need for cyber anymore because everyone can code it themselves on a weekend. That hasn't proven to be true yet. We haven't seen that from any of our customers. Do we see people using it? Absolutely. There's a learning curve there, and there's an investment curve, just like using any powerful technology, and there's a cost benefit of do I want to have an entire cybersecurity product practice in my business, or is my business something totally different than that and I'm going to leverage an enterprise product? I think that from the model companies, there will be the embedded pieces that they do.
They may find certain unique areas where they say, We just think we can be really good at this, and we're going to introduce a competitive cyber product. Every one of the model companies, though, are competing with, sorry, are partnering with the big cybersecurity players, too. Again, just like in the hyperscaler space, it feels like there's going to be room for most. I think the biggest angle or biggest opportunity that I see is in software development.
It's not a particular place that Zscaler plays, but if you're more and more using agent frameworks to write your software. The frontier models, I believe, would argue that the ultimate way in which you get out of this how do I patch vulnerabilities show up model is if you just some level completely give in to AI and say AI is going to basically do almost your entire software development life cycle, because it's the only way you can keep up with the development and then the management and the continuous patching, testing, redeployment of your code. I think that is a very high bar for most organizations to get comfortable with. Certainly large enterprises that we sell to, allowing that level of autonomous changing happening in their mission-critical infrastructure. The human discomfort with that has been a challenge with automation and cybersecurity for many years.
Can I trust that decision to be made if it's going to take down the trading desk? Am I willing to say, No, I'm not going to trust that. It can let me know something's bad, and I'll deal with it in off hours. I think that's probably the area where I would expect to see more and more and where I think the frontier models are very well-suited given what they do.
What about for, and this actually comes back to the R&D part of the conversation as well, what about in terms of your own applications of AI within your organization? Any thoughts on how you can apply something like an open source model or even a frontier model to your own rich data sets in-house to have an evolution in data plus model to get to something greater?
Yeah, in terms of just AI internally, I think we're going along the same journey that many companies are. We have a very strong initiative internally to continue to use and deploy AI to improve basically fundamental productivity. We think about it as employees plus AI, not humans or AI. We do think that the pairing of those two are kind of where the powerful combination comes into mix. Some of the early areas where we've had more success, like many companies, customer support, ticket deflection, that has been a very significant kind of continuous evolving area of success. In the go-to-market space, we've been continuing to expand use of AI. In back office, we continue to expand. I think there's a lot of opportunity going forward. I think we're just scratching the surface as to what's available.
In terms of how we use AI and data, maybe Adam, you want to talk about the launch this week?
Yeah. I'm just going to finish one quick point internally, and then I'll talk more externally with customer data.
Yeah.
But I think that Kevin's right. All of the different functions are looking at, well, how do I leverage AI to change how I operate, right? And excuse me, on the engineering side, it's definitely changed how we're developing software. It has not fully changed how it deploys, because that gets back to the humans and the customer side of it. Sorry about this. I'm going to need a quick drink. Tail end of a cold and-
Oh, we've all been there.
Talking for 45 minutes straight.
I get it, yeah.
It's not a great.
Give me a wink and we'll make Kevin answer.
Make Kevin answer more questions.
the technical questions.
But maybe I'll pivot quickly. We do have our Agentic SOC launch today.
Absolutely, yeah.
That is all about taking the 750 billion signals a day that Zscaler sees and running it against an agent framework for helping customers detect, investigate, and respond to security incidents. That's something that we're really excited about. That is not a human-readable problem. It was ripe for agentic transformations, which is true for everyone who's operating in the security operations world right now. The difference for us is that you could maybe joke and say it's a late mover advantage because we know the space is not new. We didn't start with let's just build a giant data lake to collect it and then do a little bit of normalization and then create alerts for humans to look at, which is what the traditional SOC models have been built around. They're all evolving.
We started with how do we build an approach that is set for agent-first interaction? Some of that we got through our Red Canary acquisition, and we've been bringing into this and others, our new agents that we've been building. Our starting point with our Agentic SOC is effectively a family of dozens of agents that are doing that detection, investigation, and response process. We're excited about that.
One of the more common pushbacks we hear on competition in Agentic SOC is, well, there are all of these other companies that have really strong footholds in endpoint and SIEM, and it's a much more natural progression for them to own the Agentic SOC than it is for Zscaler with the network background.
Maybe push back against that a little bit and talk about why your architecture is the right one versus a CrowdStrike or a Palo Alto.
Sure. Having been in the SIEM and SOC space for a long time before Zscaler, too, endpoint data is certainly very valuable. The pushback, though, to that argument immediately goes, look at all the Agentic SOC companies that are in the startup world right now. None of them have an endpoint presence because they're tiny companies, yet they're all claiming they can do Agentic SOC. You do need access to certain data points, and it is true that owning a vantage point is powerful. I think the guess what or the surprise is, well, Zscaler actually owns two vantage points. We certainly own the network vantage point, but we also have 60 million endpoints. Our endpoint presence is probably bigger than Palo Alto Networks endpoint. It's not bigger than CrowdStrike, but it's bigger than Palo's, and it's not an endpoint for just connectivity. Right?
It is an endpoint that does DLP, that does policy inspection, that does user performance, that does software inventory. We have all that data set, and we were never bringing it together other than for those micro use cases. Like, I have an endpoint, I will use it for endpoint DLP. Now, all of those signals at the endpoint and in the network are coming together. The kinds of incidents that we are seeing our Agentic SOC be able to detect and investigate certainly leverage endpoint data. They certainly leverage EDR data from partners like CrowdStrike and Microsoft Defender and SentinelOne and others. But it is just one of many pieces.
What we think is that, especially in a world where the threats are increasingly going to be less, here is a piece of malware that someone is trying to download, here is a behavioral pattern instead of what happened on this endpoint, what machines did they access? Where did they try to go on the Internet? Zscaler sees all of that telemetry. So we have equal, if not more right to bring that picture together for a customer than someone who is just looking at one of those pieces. That is what we will play out, and we will see how that plays. But we have run a threat hunting service for a number of years on a small scale that has been doing just that for customers.
What we find is that while the red alert sometimes may come from an endpoint trigger, the first thing people look at when saying, Oh, what do I do to investigate this person or an agent? is where did they go? What were they doing? They immediately then go look at the Zscaler logs. That is when it comes in. We have all that together, and we believe that our agents can actually connect that, and then we have our human expertise on top of it.
That all makes sense. Kevin, there is a number of product cycles just in the last 20 minutes that we have hit on. I want to map it a little bit into how the sausage was made as it pertains to FY 2027 guidance. You have also acknowledged that there have been moving pieces to the sales organization. Maybe let us take a step back. How did you think about normalizing, perhaps that is the right word, for some of the changes that you are making in the sales team relative to some of the excitement that Adam and your customers are talking about the various product cycles within Zscaler that are more than just core networking or core SASE.
Yeah. I think we're in a really exciting, interesting time. We've got momentum building from an AI perspective. Adam Geller kind of alluded to it, but I want to make the point a little bit more fine. We now have opportunities with these new products to land customers in ways we didn't before. If we look at where Zscaler was just a few years ago, we were largely going in and starting with prospects in terms of user transformation. Today, we have an opportunity. We can still obviously do user transformation, but we have an opportunity to go in and have a conversation around a manufacturing facility, a branch. We have an opportunity to go in and talk about AI.
W e have an opportunity to talk about, when you think about exposures, as we were talking about with AI, going in and saying, Let us help you solve your inability to patch fast enough and hide your applications so that they cannot be publicly identified. We have an opportunity to go in and talk about the Agentic SOC. The ability for us to go in and have very different conversations with customers and prospects is very different as we think about today versus just a few years ago. Having said that, a lot of these are very new. When we talk about the Zscaler Zero Trust Exchange for AI Agents as an example. That's an early access. It's not actually generally available. A lot of our AI capabilities have been released in just the last six months, so a lot of this is new, building a momentum.
We're very excited with the traction that we're getting, but it's also new, and we have to balance that. The piece of the business that has been very consistent and predictable has been our upsell. We've been able to consistently deliver NRR of 115% for the last four quarters, by way of example. We have confidence in our ability to continue upselling. One of the points we didn't address yet, and I'll just touch on it briefly, is Z Flex. We introduced Z Flex about a year ago. It's our flexible pricing and packaging offer for customers that are looking to make longer term, larger commitments. In those customer contracts, we've seen an uplift of 30% against the before and after ARR picture in that environment. There are a lot of I think real positive signals as we go into the year.
We did obviously raise guidance in the last quarter. We also know that we have an opportunity to do better in new logos, so we've got specific initiatives as we think about FY 2027 go to market around new logos. We have about 25% of the enterprise customers that we target today, about 4,600 against a population of a target audience of about 20,000 customers. That's really where we see opportunity as well.
Give us an example on how you can change the new logo success.
So two things I can point out. First of all, we are investing more in sales reps that are solely focused on enterprise lands. Going after pure prospecting territories as opposed to a blend of those. Along with that, every year you make changes in how you think about monetizing and addressing the sellers to incentivize them to do that. Another example we mentioned was an agreement with Carahsoft, who is going to take a stronger role downmarket for us, where we don't devote a lot of resources, but there's a lot of opportunities. So we're really looking at ways in which we can continue to enhance it, and then back to the ability to land with multiple products, making sure we have clear enablement and sales plays that assist reps as they're having those conversations and making that front and center.
As an analyst, we sometimes try to predict the inflections in sales and marketing product cycles, which as you can imagine, a little bit of fool's errand from the outside in. If you were to help us out here, talk to us about when you think we might start to see a more meaningful change in productivity or ramped reps or-
Yeah
however you think of it from a cohort standpoint.
Q4, as I mentioned on the call, was the highest quarterly productivity within the sales organization that we've seen. Very proud of the continued improvements in sales productivity in the business. Fiscal 2026, on an annual basis, was the highest productivity since 2022, so about four years. We are seeing significant productivity improvement that we do carry into the fiscal year. Very pleased with where we are and the improvements we've made. We do have two leader transitions that we are going through at the moment. One was a vertical leader, where we promoted an internal candidate who's now responsible for that piece of the business. The other was a geo leader, where we've identified a candidate. That candidate has accepted. We just need to go through the onboarding process. It's outside the U.S., so it takes a little bit longer to land.
I think we are seeing all of the right signals in terms of going forward. It's just that as we think about the products, how they land, and how they build momentum, the pacing of that is different. The Agentic SOC is an example. We think that that's probably a bigger 2028 event as we roll that out into market today and start to build momentum. Zero Trust Exchange for AI Agents, again, is probably a back half of the year phenomena. As these things stack upon themselves, we'll start to really continue to build on the momentum we saw last year.
We'd be remiss not to spend a couple of minutes on ZIA and ZPA.
There are two schools of thought. There's the bear school that, look, the best part of this product cycle is behind you. You've already gotten really good penetration, and enterprise, there's a bunch of new competition. Then there is, I think, what is the more balanced view, which you would subscribe to, which is we might actually have a renaissance on SASE with things like sovereign SASE and network traffic going up. Maybe just flesh out some of the pieces of the bull case for the core Zero Trust business, ZIA, ZPA, into 2027.
Well, I will start to give Adam some more time to rest his voice. I think it goes back to a couple of things that we have talked about. First of all, within our target market, we only have 25% penetration in those customers, which means we have 75% of customers who have yet to adopt and deploy Zscaler. That, to me, is a large opportunity for us that we see as an opportunity. Within our existing customers, if we are going in for user transformation, we will generally consume the user population, but that does not mean that it is a one for one with ZPA. I still think there is significant opportunity within the existing customer base around ZPA, ZDX, and then some of the other components.
We touched on it a little bit earlier, but as it relates to AI and how do you get your hands around potential threats in, I think Adam used the terminology line speed, but moving at agent speed, it is going to renew interest in zero trust and how do you build a security environment that can operate at speeds that human can't. I think that that will turn the conversation back to the zero trust architecture that we have adopted and deployed.
Maybe one thing I will just add to that and tie back to your earlier question about how Zscaler is using AI internally, right? This is going to be true at every company, I believe, or many companies. We have people this past year who built applications who are not developers. Someone on my team who built an entire operating system for how product management works, and it is an incredible application. It ties together Jira, Slack, Salesforce, and it was built by three people.
That application is becoming critical for my team to run. It needs to be protected. It is behind ZPA. That is a new application in our company that we did not buy, but it absolutely needs to be protected. It has an AI interface to it. I need to make sure that when a salesperson chats with it, they get what is publicly available. They do not get the whole roadmap.
By the way, the model knows the entire roadmap that is there, right? All of those protections that we have been using, they actually need to now protect that application. Back to that case of will there be a renaissance? Well, if you tie in and say, what is AI going to make easier? The generation of software and code, it has to run somewhere, and it needs to be protected. I think certainly, even if you could say user accounts might not go up or go up dramatically, the application proliferation is going to be huge, and those all need to be protected.
Fantastic. Kevin, were you about to-
I was just going to say, and if Jay was sitting here with us-
Yeah
kind of calling on his point of view, he would say that the opportunity to secure agent-to-agent communication is, in his mind, significantly larger than the opportunity to secure users. That's an important piece of-
That's the perfect place to end it. Please join me in thanking Adam and Kevin for their time. Thank you, gentlemen.
Thank you.
Thank you so much.