ChannelLife Australia - Industry insider news for technology resellers
Australia
Zscaler takes zero trust beyond the corporate network

Zscaler takes zero trust beyond the corporate network

Wed, 23rd Sep 2026 (Today)
David Shilovsky
DAVID SHILOVSKY Interview Editor

Zscaler is expanding its focus on cellular connectivity and security as critical infrastructure operators increasingly connect vehicles, traffic systems, energy networks and other operational technology to the internet.

The security requirements of a connected world are changing as organisations move beyond traditional office-based networks and increasingly rely on distributed infrastructure.

Speaking at Zenith Live 26 in Sydney, Senior VP, Innovation & Product Management, Zscaler, Nathan Howe, said conversations with customers and partners are playing a central role in shaping the company's product roadmap.

The Zscaler Cellular offering was developed in response to customers seeking a way to connect and secure infrastructure such as trucks, vehicles and traffic lights.

Howe said customer conversations provide insights that are difficult to replicate through market research or hypothetical scenarios.

"We need that full visibility from our customers as to what comes next," he said.

Critical infrastructure moves beyond corporate network

The growing digitisation of critical infrastructure is creating a larger attack surface for organisations responsible for energy, transport and other essential services.

Rail networks, for example, increasingly rely on distributed connectivity to support signalling, telemetry and energy systems. Cellular networks have provided a way to connect these systems without requiring organisations to build dedicated connectivity infrastructure everywhere.

The next challenge for Zscaler is securing that connectivity.

Its cellular service allows customers to use SIM cards to connect devices and infrastructure to their backend systems, with traffic passing through the company's security platform.

It is designed to operate across multiple carriers, allowing connections to switch between networks if an outage occurs. Howe said the ability to move between carriers has been particularly relevant in Australia, where recent well-documented telco outages have highlighted the importance of resilient connectivity.

Customers can also use the SIMs internationally, with the service intended to provide a consistent zero-trust security model across different locations and networks.

Zscaler has observed use cases spanning gas pipelines, energy infrastructure and government environments.

"We're living in a connected, digitised world," Howe said.

"But if we start scratching beneath the surface, it's no longer just about people working from home. 

"It's about being able to run a business end to end."

The combination of connectivity and security also provides organisations with greater visibility into what is happening across their infrastructure.

One customer with hundreds of thousands of SIMs had identified previously unknown malicious Russian and Chinese activity after routing traffic through Zscaler.

The example illustrates how visibility can become a security capability in its own right, particularly for organisations managing large numbers of distributed devices.

"Visibility is now bringing in some pretty scary stuff," Howe said.

From visibility to automated response

Zscaler's next phase of development will involve using the information collected from connected devices to automatically respond when something changes.

For example, a SIM card being removed from an authorised device and inserted into another device.

Another is a device changing location unexpectedly.

Howe explained that organisations could use those changes as signals to modify access policies automatically.

A device that is known to be operating at one location could have its access restricted if it suddenly appears somewhere else.

Zscaler is also exploring deception-based security techniques, where a suspicious device is allowed to believe it still has access to an application while being redirected to a honeypot.

The approach would allow security teams to study bad actors while simultaneously protecting the genuine application and underlying systems.

The capability has potential applications across sensitive sectors like government, military and financial services environments, Howe noted.

He cited ATMs as an example of infrastructure where a change in physical location could represent a significant security signal.

"ATMs shouldn't move," he said. "If they do move, something needs to be done about it."

The broader objective is to use information generated across Zscaler's platform to make security decisions automatically.

Zscaler's cloud processes around 750 billion transactions each day, creating a significant pool of intelligence that can be used to identify anomalies and trigger security responses.

AI accelerating both attack and defence

Artificial intelligence is also changing the cybersecurity threat landscape, with warnings that attackers can now automate activities that previously required significant time and expertise.

Howe previously worked as a penetration tester and said tasks that could once take months to prepare can now potentially be completed in minutes.

"It's absolutely a threat," he said.

At the same time, Howe sees AI as an opportunity for organisations to modernise legacy technology and strengthen security rather than just a new source of risk.

He argued the technology should not become a marketing justification for replacing existing systems - instead, it should prompt organisations to rethink how their environments are architected. 

His primary concern is the increasing ability of AI systems to operate beyond the immediate instructions given to them.

In an internal security assessment, Zscaler's internal AI security tooling identified vulnerabilities, but Howe said what happened next was more significant.

The system assessed the structure of the application, built a clone of it, used multiple AI agents to attack the clone, validated the vulnerabilities and then tested whether the same approach could work against the original application.

"We didn't ask it to do that," Howe said.

"That's the thing that worries me: that it has this ability to go beyond."

Companies will need to establish appropriate boundaries around increasingly autonomous AI systems, particularly as they gain the ability to plan and execute multiple steps independently.

The challenge will not be simply teaching employees how to use AI tools, Howe noted, but ensuring organisations are clearly cognisant of what those systems are permitted to do.

Innovation driven by customer requirements

The increasing convergence of cellular connectivity, zero-trust security and AI in 2026 represents an extension of Zscaler's broad approach to removing the need for traditional physical security infrastructure.

Howe's product team regularly starts by asking what could be technically interesting before determining whether it can be turned into a product, process or customer capability.

The goal, however, remains focused on customer outcomes.

"I think that's where (founder and CEO Jay Chaudhry) has built a paradigm-shifting platform," Howe said.

"The whole Zscaler world is not about physical infrastructure; it's about taking away all the physical infrastructure and simplifying the security process."

Zscaler's next steps will involve making greater use of the intelligence generated by its global platform, including cellular telemetry, to help customers make more automated and informed security decisions.

For customers, that could mean moving beyond simply connecting distributed assets to ensuring those connections can be continuously monitored, authenticated and acted upon when their behaviour changes.

As more physical infrastructure becomes digitally connected, the distinction between connectivity and cybersecurity will continue to narrow.