Episode 415 ·
Zero Trust Everywhere with Amit Sinha, CTO of Zscaler
Today we’re talking to Amit Sinha, the CTO and President of R&D, Operations, & Customer Service of Zscaler. And we discuss why security should follow users wherever they go. How 5G technology is pushing data and security to the edge, and the 3 P’s of attracting top talent: People, Purpose, and Pay.
All of this, right here, right now, on the Modern CTO Podcast!
To learn more about Zscaler, check them out at https://www.zscaler.com

About Amit Sinha:
Dr. Amit Sinha is a skilled entrepreneur and technology leader who has driven the research and development of disruptive security and wireless technologies at both start-ups and market-leading organizations. Prior to Zscaler, Dr. Sinha served as CTO for Motorola’s enterprise networking and communications business, which he joined via its acquisition of AirDefense where he held the same role. He has also served as Chief Technologist at Engim, which he co-founded.
Amit earned an MS and PhD in Electrical Engineering and Computer Science from the Massachusetts Institute of Technology, and a B.Tech. in Electrical Engineering from the Indian Institute of Technology, Delhi, where he graduated summa cum laude and was awarded the President of India Gold Medal. He holds 27 US patents and has contributed to several books and dozens of conference and journal papers.
About Zscaler:
Zscaler (NASDAQ: ZS) accelerates digital transformation so customers can be more agile, efficient, resilient, and secure. The Zscaler Zero Trust Exchange protects thousands of customers from cyberattacks and data loss by securely connecting users, devices, and applications in any location. Distributed across more than 150 data centers globally, the SASE-based Zero Trust Exchange is the world’s largest in-line cloud security platform.
Transcript
(Intro Narrator at 00:00:03) Hello, my friends. Today, Joel is talking to Amit, the CTO at Zscaler, and they discuss why security should follow users wherever they go, how 5G technology is pushing data and security to the edge, and the three Ps of attracting top talent: people, purpose, and pay. All of this right here, right now on the Modern CTO Podcast.
(Joel Beasley at 00:00:30) Here we go.
(Intro Narrator at 00:00:31) This is the Modern CTO Podcast.
(Amit at 00:00:42) Well, I was born and brought up in India. I was what you would say a classic nerd. I did well in school. I went to IIT Delhi, which is a great engineering school in India, and from there I found my way to MIT in Cambridge.
(Amit at 00:01:03) Did my masters and PhD there. You know, I was working on low-power system design, things that would enhance the battery life of your iPhones today. And that's how I got into the industry. The first company out of MIT was a wireless semiconductor company. It was a company called Enjin. It was what you would call an extended MIT research lab. A lot of my friends, including my faculty advisor, joined. And it's funny because I think we were trying to invent rockets when people really only wanted bicycles. So the company wasn't a huge commercial success, but I learned the importance of product-market fit, right? You don't just design products that are cool but nobody really wants to buy them right away.
(Amit at 00:01:54) One of the interesting problems that we were solving at that time in the wireless world was, you know, how do you scan the entire 2.4 gigahertz RF spectrum and look for all types of activity, whether it's Bluetooth devices or wireless security hacks or rogue access points or whatnot? And the classic challenge in wireless, as you know, is it's half duplex. When I'm talking, you can't listen.
(Amit at 00:02:33) So, you know, either I'm transmitting or I'm receiving. That was one of the core problems that we had solved, and that actually got me introduced to a company called AirDefense. So as my first company, Enjin, was going for an asset sale, this company called AirDefense was struggling with a problem, which was how do I detect rogue wireless devices on the entire 802.11 spectrum? And I said, "Hey, look at the exact problem that we had solved," one of the many problems we had solved. And I became the chief technology officer for AirDefense. That's where I met Jay Chaudhry, who's the CEO and founder at Zscaler. And AirDefense was a huge commercial success.
(Amit at 00:03:25) It was right around the time when wireless hacking had become very prominent. You know, TJ Maxx had been breached by a bunch of hackers sitting in the parking lot and connecting to the wireless systems inside the store. They were able to siphon off 40 million credit cards, and everyone suddenly became hyper-aware of, "Hey, man, we need to do something about wireless security. It just can't be anyone can connect to anything." And, you know, people had rogue wireless access points plugged into the Ethernet jacks under their desks. So AirDefense was essentially looking at solving wireless intrusion and wireless rogue devices. And it got deployed in many, many places—you know, UPS, lots of retail stores and distribution centers—and ultimately got acquired by Motorola, Motorola's Symbol business, which at that time was number two. It was Cisco and Symbol in the wireless LAN world. So I was at Motorola for a bit as their chief technologist for the enterprise networking and communication business.
(Amit at 00:04:38) And shortly thereafter, I joined Zscaler. And Jay Chaudhry was also the founder and CEO of Zscaler. And I've known him and been at Zscaler for eleven years. It's been a wild ride from zero to over $40 billion in market cap. You know, it's one of those rare occasions in your career when you get to build a rocket and fly it. And, you know, you aim for the moon and you get to the moon, and you realize you have four more booster rockets. And so then you aim for Mars. That's how I feel. It's been an exciting ride at Zscaler. I run all of engineering, cloud operations, R&D, and customer service for the company, so sort of the post-sales side of the house.
(Amit at 00:05:29) And, you know, we're very fortunate. We're driving secure digital transformation as a category in the industry. And given where the industry is now, with applications moving to the cloud and users being everywhere, you know, that whole fundamental security paradigm is going through an enormous transformation, and Zscaler is leading the charge there.
(Joel Beasley at 00:05:53) Nice.
(Intro Narrator at 00:05:54) So how do you explain Zscaler? Like, what's your—I'm assuming if you're that large, you have multiple products or lines of business and maybe some consulting in there. What's the simple explanation of it?
(Amit at 00:06:05) Well, if you look at the genesis behind Zscaler, you know, back in 2007, it was very straightforward, and that North Star is still true. Back in 2007, there was one cloud application called Salesforce.com. You know, it wasn't much of SaaS.
(Amit at 00:06:22) I think AWS was just taking off. I think the first iPhone had just come around. And at that time, the bold vision was if your workloads move to the cloud and your employees are everywhere and accessing applications on mobile devices, what does that do fundamentally to your security architecture? And, you know, traditionally, security in enterprises is a very network perimeter-centric architecture, right? You have firewalls and you have VPNs to connect into your network. And when you're on the network, you're treated differently and you're secure. And when you're out of the network, you're not.
(Amit at 00:06:49) But the question we asked ourselves was, if the center of gravity moves outside the enterprise, if applications are in the cloud, when users are everywhere—and look at us today, everyone is sitting at home and everyone is accessing applications from anywhere in the world—if that is true, then what does a security architecture look like? And our simple answer was, if that's the world we live in, then security should follow the users wherever they are. Security should be delivered as a cloud service right next to the applications that users are accessing.
(Amit at 00:07:34) Right? If I'm in San Francisco and I'm accessing Office 365, well, Microsoft has a data center in the Bay Area, right? And I'm sitting in San Jose. I should be able to go straight to that application, and all of my security inspection and business policy should be applied on that shortest path.
(Amit at 00:07:54) You know, I shouldn't have to go through my corporate data center, which happens to be in Chicago or New York, and hairpin my traffic just to go through some legacy security appliances that might be sitting in that network-centric model. So I think Zscaler is not a product. It's an architectural transformation of your network and security for a modern, cloud and mobile-first world. And what we do is, essentially, we have built a service across 150 data centers worldwide.
(Amit at 00:08:26) You know, you can't travel faster than the speed of light, so you need a security inspection close to where you are. And that security inspection better be right next to where the bulk of the Internet or where your SaaS applications are hosted. In the example I just described, you know, the user—me being here trying to access an application—so this network across 150 data centers, think of it as a checkpoint. We call it the Zero Trust Exchange.
(Amit at 00:08:56) And what does that checkpoint do? Users and applications connect to Zscaler using the shortest path. You come to us. We terminate that connection. We look at who the user is, what's your context.
(Amit at 00:09:12) We inspect content. And based on business policies, we then connect you to the right applications. And in the process, we're making sure that nothing good is leaking out, nothing bad is coming in. You know, you get a fast user experience. Your attack surface is reduced since you're behind Zscaler.
(Amit at 00:09:34) And it is a security network architecture for a modern workforce that we live in today.
(Joel Beasley at 00:09:41) Nice.
(Intro Narrator at 00:09:42) So what are the problems that people are having? Like, you obviously get to talk to a lot of your customers and go through these implementations and stuff. What's the problems that are causing them that they experience right before they reach out to you?
(Amit at 00:09:56) Well, you know, if you look at just the broad cybersecurity trends, Joel, I mean, it is shocking. I think some of the stats I've read: there's a cyberattack happening every 39 seconds or so. You know, it takes on average over 200 days for organizations to identify—just identify—that they have been actually compromised or breached. One in 13 sites on the Internet have some malware on it.
(Amit at 00:10:24) Right? If you just look at the ransomware damage estimates this year alone, you know, 2021 so far, it's over $20 billion. So I think all organizations are grappling with the fact that their legacy security architecture is just not working anymore.
(Amit at 00:10:46) And that legacy security architecture worked in a world where your applications were in your data center, your employees were on a network inside an office, and your network model was a classic hub-and-spoke model. Right? Here are my branch offices. Here's headquarters. You know, I have expensive MPLS WAN connections that connect all of these offices.
(Amit at 00:11:16) And, you know, once you're on the network, everything is secured. You know, I call it the coconut model of security—sort of hard and crunchy outside and then soft and gooey inside. So once you're inside, everything is available, right?
(Amit at 00:11:27) And that leads to a lot of the problems where one infected machine comes on the network and then, you know, it propagates malware laterally. You look at ransomware infections. You get into the network, and because once you're on the network you're trusted, lateral propagation happens and more machines get infected. Maybe your domain controllers get compromised.
(Amit at 00:11:54) And, you know, that leads to further data exfiltration and some of the issues that we've seen. So our customers who come to us are seeing these challenges where the traditional firewall VPN network-centric approach to security just doesn't work. I think they all are recognizing that the Internet has become the new corporate network. You know, identity is the new perimeter, and sort of zero trust is the new security architecture. And if I could transform my analogy, I'd say, you know, you need to go from that coconut model of security—hard, crunchy outside, soft, gooey inside—to probably more like a guacamole model where you have a hard shell around your core assets, your data that you want to protect, and everything outside is kind of soft and gooey. And that model requires you to change networking, security, mindset. And that's the whole digital transformation that organizations are going through. And with Zscaler, they're going through a secure digital transformation.
(Joel Beasley at 00:13:04) Nice.
(Intro Narrator at 00:13:04) I hope your salespeople use that when they're talking to customers, like, "We're going to convert you from a coconut to guacamole."
(Amit at 00:13:11) You know, sometimes simple analogies work. But it is true. You look at how organizations have set up their security practices. It is a very—you know, there are different names: castle and moat, hub and spoke. Coconut is kind of just a simple way of viewing it. But really, it's designed to be more perimeter-centric.
(Amit at 00:13:26) But if you look at how we operate today and where is the perimeter, you know, Zscaler's customers like Siemens have 300,000 employees worldwide. Every one of them is sitting in their own houses, and, you know, or they can be anywhere.
(Amit at 00:13:53) Are you going to start building a network perimeter that is encompassing everyone? It just won't work. Extrapolate that, Joel, to what happens now when you start thinking of IoT devices and cloud workloads. And one of the bold missions that Zscaler has is to secure 200 million users and 100 million workloads, and you cannot do that with an old network-centric security model.
(Amit at 00:14:19) You have to do it with a modern zero trust architecture.
(Joel Beasley at 00:14:22) Nice.
(Intro Narrator at 00:14:23) Now, in an effort to better understand this, let's say I'm a Zscaler customer and there is, like, some ransomware they're trying to gain access laterally, get more privileges. Is it part of your services where you guys would actually respond to that attack, or would you notify of that attack? Where would it go in an attack situation?
(Amit at 00:14:46) That's a great question. So, you know, Zscaler sits in-line and we stop attacks. And let's look at it in three buckets. If you're familiar with the cybersecurity kill chain, you know, kill chain is the multiple steps that happen from start to finish for an attack to be successful.
(Amit at 00:15:05) And it could start off with something like a reconnaissance scan where a threat actor is trying to figure out, you know, what's the best way to get into an organization. And then it could start with—that could lead to maybe some sort of phishing email that's targeted towards you, saying, "Look, they use Office 365 and they use Workday. So let me craft an email that sounds like it came from HR with a link that looks like it's coming from Workday from their chief people officer."
(Amit at 00:15:37) So these are examples of targeted reconnaissance and phishing. So the first thing that Zscaler does is to prevent infections. So you want to make sure that your users are protected.
(Amit at 00:15:51) And typically, stage one infections happen through a phishing link of some sort where, you know, you get a link and the user just clicks on it and their machine gets infected. So step one is to prevent that, to neutralize the kill chain early on by preventing infection from happening. Now, that's easier said than done because most of the content today is end-to-end encrypted. More than 90% of the Internet by default has SSL encryption enabled.
(Amit at 00:16:28) So this is where if you think you have a firewall that's protecting you, you know, it's kind of a huge mistake because firewalls are network layer devices. They're looking at packets. And when encrypted TLS connections are flowing through, they're just blind.
(Amit at 00:16:45) So a simple example could be, Joel, I could send you a Google Drive link that has a piece of malware. And, you know, it'll be SSL encrypted. It'll be from a trusted domain, google.com. You'll click on it and you'll get infected.
(Amit at 00:17:00) So it's very important to look at SSL encrypted content, open up TLS connections, see what is coming in into your users' machines, and analyze the content. I could send you an email with an Excel file with an embedded macro virus where, you know, you click and something happens on your machine and it gets infected. So looking at content and analyzing content in real time as it's getting delivered to users is step one of preventing infections to begin with. And Zscaler does it because we are sitting in-line as a proxy. You know, there's no direct path.
(Amit at 00:17:45) Users come to us. We terminate that connection. We proxy those connections on your behalf. We fetch the content. We open up TLS, look at the content, and then say, "Hey."
(Amit at 00:17:56) This is a bad spreadsheet, or this looks like obfuscated JavaScript that's trying to do something malicious, and we stop that from ever getting to the user or the workload. So that's step one. Step two is you want to prevent lateral movement, right?
(Amit at 00:18:13) And the lateral movement problem is when one machine gets infected on a network and you have unrestricted access to move on the network. And that's how that coconut model, the hard on the outside, soft on the inside—
(Intro Narrator at 00:18:25) Inside the coconut, yeah.
(Amit at 00:18:27) Inside the coconut problem happens, right? So your laptop's infected because you clicked on something and you weren't protected. And now one infected machine—I mean, what is the hacker trying to do? They're trying to discover what else is on that network. They're trying to get to perhaps a domain controller to harvest credentials. And if you have that old school model of on the corporate network or not on the corporate network, and once you're on the corporate network, all bets are off and you can do whatever you want, that leads to lateral propagation issues, right? And there's a huge risk. Zscaler eliminates that too.
(Amit at 00:19:02) So step one, you prevent compromise. Step two, you prevent lateral movement. And the way you do it is by user-to-app segmentation, right? Think of it this way. A user comes to Zscaler. Zscaler checks business policies and says, this user is allowed to talk to this internal application. There is no concept of an internal network, right?
(Amit at 00:19:25) Think of how your iPhone would talk to a Nest device on your home network. You're not VPNing to your home network and then roaming around freely on your home network to find that device. No. The Nest device talks to a cloud service. Your iPhone talks to a cloud service. You assert strong identity. And once you've proven who you are, you are connected to the device regardless of the network they are on, right? So that's a classic example of zero trust where you're using identity, you're using policies, and you're not just putting a person on the network and letting them do whatever they want, right?
(Amit at 00:20:03) So step two of what Zscaler does is user-to-app segmentation, and you can extend that to app-to-app segmentation. Why should two apps on your corporate network just be allowed to talk directly without any business policies in between here? Why should this application have unrestricted access to your directory, or why should this UI server have unrestricted access to your SAP system? So user-to-app segmentation, app-to-app segmentation, allowing entities with strong identity to talk to entities based on business policy—that's kind of the name of the game of zero trust segmentation, and that's what we do extremely well.
(Amit at 00:20:48) So that's step two. Remember, first step, prevent compromise. Step two, prevent lateral movement. And step three is you want to prevent data loss or data exfiltration. I mean, what's the ultimate objective for people trying to get into your organization?
(Amit at 00:21:05) It is to—
(Joel Beasley at 00:21:06) Well, data.
(Amit at 00:21:06) Access to your data, right? So I'm gonna get into Joel's laptop, extract information that might be worthwhile. So because, again, we're sitting in line as a proxy, we're making sure that nothing good is leaking out. If you accidentally drag and drop source code into your Box folder or Google Drive folder, it's not just automatically going and getting archived in the cloud because we're sitting in line, and based on your business policies around data loss and exfiltration, we'll stop it.
(Amit at 00:21:41) That also prevents threat actors from leveraging exfiltration holes and being able to copy out data either for extortion or other purposes, right? So it is—
(Intro Narrator at 00:21:57) I've got a question there. Yeah. I've got a question there. All right. So let's say it's a policy. I don't know a whole lot about how this works, but let's say I accidentally dropped my source code into Google Drive, right? And then there's some policy set up that's watching that traffic and watching that content and it says no, right? How does it delineate between, like, if I actually want to put something on Google Drive or if it's something that should or shouldn't be put on Google Drive? How does it know that?
(Amit at 00:22:29) It's a great question, right? So that is what I mean by business policies, right? Maybe your policy is that source code should always be in a sanctioned GitHub account, right? And nowhere else outside the organization. So then any source code from an authorized machine and an authorized user going to any other destination is a policy violation and it will get stopped. Maybe you have a policy that you can archive certain types of content on Google Drive. Maybe then you're looking for, well, is this my corporate Google Drive account or my personal account? So you want to do tenant level separation, right? Like, all of us now have here's my personal Gmail, here's my work Gmail, right?
(Amit at 00:23:14) How do I—
(Joel Beasley at 00:23:15) Yeah.
(Amit at 00:23:16) How do I separate all of them? Those are examples of policies, right? And then there are, of course, workflows associated with it. And you want to simplify. I mean, the challenge for security is always how do you reduce business risk without just becoming the Department of No all the time, right? Like, you gotta—you have to be pragmatic, reduce business risk, deliver outstanding user experience, right?
(Amit at 00:23:44) And really make a meaningful impact on securing the enterprise. And so we do that in spades, and it boils down to how effective your policies are, how easily you can administer it, right? And one of the things that Zscaler has done very well is simplify those policies. If you look at firewalls, just to make an application like Office 365 work, you might have a thousand firewall rules.
(Amit at 00:24:16) With Zscaler, you can enable a single checkbox that says enable Office 365. Because we are a proxy, we understand applications, we understand the underlying configurations that have to happen to make it work. And so if you're able to simplify policy management, improve workflows, you can have very effective business policies like the example you were trying to describe, where you meet your risk objectives without compromising user experience.
(Intro Narrator at 00:24:51) I don't want to get hung up on this code question, but like how would I—you know, background software engineer, right? Like let's say I have a folder and it's just my root GitHub project and it's on my local machine. Like how would you define—and keep in mind too, I have no understanding of really defining policies other than like AWS type policies. Like I've never worked in a large corporate environment, but how would you say in that policy or define it to say that this code can't go out to Google Drive? Like, would it take a copy of that code and like, look for it being streamed somewhere it shouldn't? Like, help me understand that.
(Amit at 00:25:32) It's a great question, right? So you're talking about how data loss prevention actually works within Zscaler, right? So there are multiple layers to it, right? You can look at data loss policies as based on either exact data match, indexed data match, or regular expressions at a very broad level, right? So in the source code example, Zscaler will have what we call DLP dictionaries that understand looking at content that this looks like Python code. This looks like R. This looks like Golang, right? So it has dictionaries that can look at content and say this looks like code, right?
(Amit at 00:26:18) You then have the ability to do indexed data matches. You can take repositories, folders, files, and index them and say, if this exact file is going somewhere, match it, and then take a policy action. You know, that's looking at the entire files. You can also do what we call EDM, which is exact data match for certain types of records. Now they're a billion records of account numbers and names, and I want to specifically match this 16-digit account number associated with Joel. And I want to make sure none of these—and JPMorgan Chase, and here are my account numbers. And I want to make sure these specific account numbers are never seen in any outbound stream, right? So the short answer to your question is a combination of either regular expressions, prebuilt dictionaries, indexed documents, or exact data match of specific records. And you can craft policies with context.
(Amit at 00:27:26) And context could be users, departments, locations. You can say, these users or these departments with these DLP dictionaries, here's a policy action that you might want to take. And that's how you would build a rule set. And because there's no path to the Internet without going through Zscaler, in your developer example, all of those will just transparently get applied, right?
(Amit at 00:27:54) So you could say, my engineering department or this developer group or this specific developer, right, allow access to GitHub but block any source code or anything that matches these source code dictionaries or these indexed documents from ever getting to these categories of destinations. Does that make sense?
(Joel Beasley at 00:28:14) Yeah.
(Intro Narrator at 00:28:14) That's brilliant. Oh, yeah. That's—you know what? As you were talking about it, I was like, that's exactly what you would need to do because some people would want exact source code matches. Other people would not want you to have that inside of your systems. Some people would need different ways to do it, like more fuzzy ways to do it. That's brilliant, man. This is actually a really cool product. I'm getting kind of excited about it.
(Amit at 00:28:37) Yeah. I'm happy to hear. Look, we've been at it for over a decade, and there's no compression algorithm for experience. And we've been chipping at it and refining it. And it's come a long way.
(Joel Beasley at 00:28:51) Yeah.
(Intro Narrator at 00:28:51) So my next question, and I hope you don't mind that the interview's turned into me just like quizzing you on things I want to know as an engineering leader. Okay. So you're doing all of the—you've got these policies, you're monitoring this traffic. I think objectively, you would have to say at some infinitesimal scale, there is a slowdown to some degree, right? Rather than being unfiltered, even if it's like in the real time that we live in, if it's unnoticeable, it still mathematically would be there because it's doing something else. How do you get that down? Like, how are you doing all of these things without slowing people's traffic down to the point where they're like, screaming at their MacBook?
(Amit at 00:29:34) Yeah. No. I think it's a great question. So, yeah, this is where you start with good architecture, right? And there's no substitute for good architecture. And, you know, fundamentally, Joel, I often say Zscaler solves two problems, and both are hard problems. One is a physics problem, and one is an engineering problem, right? Now if you look at the old hub-and-spoke model that we talked about, it has a fundamental physics problem, which is just untenable in today's world, right? Most organizations that have that hub-and-spoke model, if you're a developer in a big bank, right, you might be anywhere in the world. You are coming back to a couple of data centers. You're hairpinning all that traffic. Those WAN links are getting choked, right?
(Amit at 00:30:20) You might be sitting in Ukraine or the Bay Area or Bangalore, and you're still coming to one or two of these data centers and then routing your traffic to wherever else you were going, right? That hairpin causes excessive latency. Those WAN links are getting choked. When we entered the pandemic, all of the users went remote. And suddenly, you can imagine the pressure on a couple of these choke points because you're trying to come onto the network because there's no path without coming to those hubs. With Zscaler, you go direct to your destination. That's a fundamental thing that we change, right?
(Amit at 00:31:01) Whether you are in the office, whether you are at home, whether you're traveling anywhere in the world, we will geolocate you and automatically send you to the nearest Zscaler data center. So when you are in San Francisco, you go through a San Francisco site. When you're in New York, you go through a New York site. When you're in Johannesburg, you go through a Johannesburg site, and you get the idea. You have 150 of these data centers. That itself solves a huge latency problem, right? Because you're going straight to your destination. And we do it in a way that you still get consistent policies no matter where you are. So, you know, CSOs and CXOs are happy that my users are getting the same consistent identical protection, and they're getting the shortest path to the destination.
(Amit at 00:31:49) Now, there's a lot of actual cloud challenges that you have to solve. We don't operate a service in AWS or GCP, right? Why? Because we have to be cloud neutral and destination neutral, right? You might be trying to go to Azure because that's where your dev stack is or you might be using Office 365 or you might be trying to access applications in AWS. So we have built data centers where the bulk of the Internet is pulsing through. We use carrier neutral sites that provide the maximum connectivity options in the region. We could use Equinix in North America, Telstra in Australia, China Telecom in China, so on and so forth.
(Amit at 00:32:40) Once we have those sites, we then bring in tier one ISPs that provide best connectivity options in the region, right? Why? Because there's no one global service provider that makes up the Internet. The Internet is a collection of these loosely coupled networks. So we might use a GTT or a Zayo in North America. We might use an Airtel in India. We might use a different provider in EMEA, right? So all of these 150 data centers are built at strategic locations on the Internet in a cloud neutral, carrier neutral way with maximum connectivity options.
(Amit at 00:33:23) We then go ahead and peer with content providers like Office 365, with Google, right? So we might be in a data center with Internet exchanges where Office 365 is present or Google is present. And we'll do BGP peering with them so that you're a millisecond hop away from them, right? All of this is solving that first problem I told you about, the physics problem. How do I take a user or a workload and get them to the destination in the fastest path possible, right? And that alone, you know, forget inspection. The fact that we have removed all the hairpinning and the choke that you had in the hub-and-spoke model, it gives you, in many cases, an order of magnitude better performance because you're just using the direct path.
(Amit at 00:34:10) Now once you come to Zscaler, then your next question becomes applicable. How can I do all this inspection, all this scanning? You know, I'm looking at opening up SSL connections, looking at content. I might be looking for source code. I might be looking for malware. I might be looking for policy violations. How are you able to do that? And that's why we use what we call our single scan, multiple action, right? Like, one of the engineering problems that we solved was, how do I do this inspection rapidly in memory, right, with blazing performance?
(Amit at 00:34:47) So when we started the company, the first thing we did was look at the TCP/IP stack, right? I mean, you don't know many security companies that start off by saying we need to redo the network stack because it's very slow. And what did we do? We moved the entire TCP stack into user space, because the standard stack that you get is designed for just generic, multipurpose networking.
(Amit at 00:35:13) And here, we're looking at being a high-speed proxy. So we want to reduce packet buffers from being copied from kernel space to user space and all of that. We want to reduce memory copies. We want to be able to assemble content in memory and fire all DLP engines and all malware engines, everything on it in a single-pass architecture. And that's where we gain enormous performance advantages because we're not service chaining.
(Amit at 00:35:42) And in a traditional appliance world, what happens is you take a box. This box does DLP, looking at, for example, your source code. This box does AD scanning. This box does advanced sandboxing. And when you do service chaining like that, what are you doing?
(Amit at 00:36:00) You're—everyone is doing a network stack, has their policy engine. 80% of the functions get repeated in a redundant way over and over again when you're going through a daisy chain of boxes, each one doing 10% of the things you want to do. Right? So we've collapsed all of that into an architecture that we call single scan, multiple action, that gives you the engineering boost that you need. So when you combine that physics boost with the engineering boost, you actually get enormously better user experience.
(Amit at 00:36:33) And one of the core benefits of Zscaler is not only do you get outstanding security with massively reduced attack surface, you've—refreshingly for a change—you get very, very good user experience because of the benefits I talked about.
(Intro Narrator at 00:36:53) That's brilliant how you guys move the TCP/IP up there. That is awesome. You got me. I don't want to get too nerdy. I like to keep the conversation higher level, but my brain is very excited at that from a geek standpoint about how you guys did that. I have a lot of detailed questions, but I'm not going to go into them.
(Intro Narrator at 00:37:16) I am curious. Have you come across some of the newer technologies like the IPFS, the Interplanetary File System?
(Amit at 00:37:24) Yeah. You know, we're always looking at new ways to do the services that we do. In fact, you know, two new areas that we've expanded into—one I've mentioned is around digital experience. And, you know, one of the things that our customers came back and said, "This is great. You know, you're sitting between users, workloads, and destinations and providing a zero trust exchange and all the benefits that we talked about. But how do you solve my experience problem?" In the sense, you know, "I'm the CIO, and now my applications have moved to a cloud service that I don't control. My users are using the internet as their transport, and I don't control that either. And in many cases, users might be bringing their own devices. I don't even control the device."
(Amit at 00:38:20) So in a world where, you know, I have literally no control on anything, if my execs call me and say, "Hey, Zoom had an issue. Office 365 had an issue. Where do I start troubleshooting?" And so one of the things that we launched was Zscaler Digital Experience.
(Amit at 00:38:39) And what it does is it is looking at every user every minute for all the applications that you care about and giving you an experience score that you can then look at in aggregate for your organization, your location. You can compare to peers and say, "Well, Zoom in New York is indeed having a problem," or "Teams was down in the Frankfurt area, and it's not just me." So, you know, as we look at some of these newer services, we are constantly looking at newer technologies, you know, whether it's IPFS or newer ways to do analytics or real-time time series data ingestion. You know, a lot of things that we do are around leveraging machine learning. Because if you look at it, we now have over 200 billion transactions per day that's being processed on the platform.
(Amit at 00:39:35) 200 billion transactions per day. To put that in perspective, Google—you know, they don't officially report it, but if you search online, you'll see that they do about seven to eight billion searches a day. So the raw volume of traffic that the Zscaler platform is processing is about 20x the number of Google searches done on a daily basis. So it kind of gives you an idea of the scale at which we are operating. Now when you have that kind of data, you can use machine learning to drive very powerful outcomes, whether it is better security.
(Amit at 00:40:11) Right? You know, if you've seen all ransomware strains out there, can you predict the next one? You know, if you have good models, you could. How do I derive better user experience? Again, if I see those main transactions and I have good time series models, I can look at anomalies and say, "This doesn't look good compared to a baseline that I've learned. You know, Joel's experience on Tuesdays tends to be this, and I see it's suboptimal." Right? So whether it's better security or better anomaly detection or better content classification—I mean, that's a basic thing.
(Amit at 00:40:52) Right? Every day, lots of new websites are popping up. Right? How do I know this is a phishing website? How do I know this is a blog about gambling and not a gambling website? Right? So you can really throw a lot of machine learning when you see data at that scale. And all of this requires us to constantly evaluate the core technology stack that we're using, not just the file systems, but also more importantly, you know, what kind of modern processing stacks we should use that give us the performance we need at the cost we need to operate under. Hopefully that answers your question.
(Intro Narrator at 00:41:35) Yeah. It's pretty exciting what you guys are doing over there. Do you have like a team, like a skunkworks-type team that's working on super top-secret stuff?
(Joel Beasley at 00:41:43) Do you—
(Intro Narrator at 00:41:43) Have you gotten there yet?
(Amit at 00:41:45) Yeah. Yeah, we do. You know, we have a fair number of what we call emerging technology initiatives. And some of these are under the radar.
(Amit at 00:41:55) A few that we have talked about publicly—I'd mentioned, for example, you know, we're doing a huge push into OT and IoT. Right? You can imagine if IT is this big, operational technology is that big, and it has far more significant challenges from a cybersecurity perspective. Like, imagine if you're a big auto manufacturer and your assembly line is brought down because of an attack or some sort of an extortion attempt. And the OT systems tend to be much older from a patching and from a vulnerability perspective.
(Amit at 00:42:39) Why? Because, you know, I could have an MRI machine that's running on Windows, and nobody can touch it because, well, you know, one patient's dying because you did an update. Right? So it's running a system that is not being patched. You could have a robot arm in an auto manufacturing assembly plan that's running some version of software that nobody can touch. So OT becomes a big challenge.
(Amit at 00:43:04) How do I provide secure remote access? How do I make sure there's no privilege escalation? How do I make sure that I can operate these old machines, transformers, and whatnot over RDP sessions and SSH sessions without causing gigantic security holes? So that's one area that we've extended our zero trust exchange to allow secure remote access to OT environments, using identity and principles of least privilege that are fundamental to zero trust. Another area that we publicly talked about is 5G.
(Amit at 00:43:44) I mean, you hear a lot of 5G buzz, Joel. I'm sure a lot of your podcasts probably talk about it. But, fundamentally, what is 5G doing? It's pushing compute to the edge. Right?
(Amit at 00:43:56) So, you know, I want my content cached right in my 5G tower. Right? When I'm watching my Netflix, I want the movie coming from there and not from some server that is downstream. So if content and compute is being pushed right in the tower, shouldn't security be sitting right there? Right?
(Amit at 00:44:18) So, again, the same problems that we've solved by moving security closer to users and destinations just becomes, you know, hyper-visible when you start talking about a 5G architecture where you're pushing more and more out there close to the user.
(Intro Narrator at 00:44:42) Yeah. You just reminded me three or so years ago, I got to have the CTO of Verizon on right when 5G was launching. They were doing their first towers, I think in Texas or something like that.
(Joel Beasley at 00:44:54) And—
(Intro Narrator at 00:44:55) He was explaining to me all the benefits and how 5G is going to change everything. And now it's been on my phone for a while now. And I'll tell you what, for my experience, it's a lot faster.
(Amit at 00:45:05) Yep. Yep. Absolutely. And I think one of our missions is to make sure it remains faster, if not become even more fast, while being secure. Right?
(Amit at 00:45:17) So that's kind of the—that's that's the big challenge.
(Intro Narrator at 00:45:21) Can we talk a little bit about leadership? I like to help out like the next generation of technology leaders grow and learn from great leaders like you. Is that cool?
(Amit at 00:45:30) Yeah, absolutely.
(Intro Narrator at 00:45:32) Okay. So, Kevin Kane is the CEO of Dasein. I did an episode with him a few months ago and their company does like, you know, SAP, Microsoft partner, government contracts, enterprise-type stuff. But when we were talking about leadership, he was talking about this concept of how he schedules reflection time for self-improvement. And I was curious, how do you go about carving out time for self-improvement?
(Amit at 00:46:01) Yeah. That's a great question. I am a huge believer in the power of marginal gains. You might have seen this amazing numerical statistic which says if you improve 1% every day, right, over 365 days, that's a 37x improvement. It's actually shocking.
(Amit at 00:46:25) You know, 1.01 raised to 365 is a number that is 37x. Now, obviously, it's very hard to sustain a continuous 1% improvement. But I do believe in the power of just—better, better, never done. Right? So, you know, constantly encourage that across all teams and personally in my life.
(Amit at 00:46:47) You know, what can I do better today? How can I improve? And that happens when you're honest and you quietly reflect on things that you did well. You do a small pat, but then focus more on things that you could have done better. And that marginal continuous improvement stacks up over time to just stupendous gains.
(Amit at 00:47:12) So that's, you know, one thing that we encourage all the time. You know, we call it the philosophy of better, better, never done. And when you run the kind of service that we do, growing—Zscaler is a billion dollars in ARR, growing at 55-ish percent at that scale and that growth. What was awesome last year is barely gonna work this year, and sure as hell, it's not gonna work a year from now. Right?
(Amit at 00:47:46) So, you know, challenging the teams to continuously improve, to never stop and, you know, keep them motivated and passionate and dedicated and fired up is the rocket fuel you need to sustain that kind of growth.
(Intro Narrator at 00:48:03) I love it. You remind me—it's like I was watching, I think it was either Atomic Habits or somebody. And they did this equation where it was like an hour a day, 365 hours a year. You divide that by a 40-hour work week. It's like nine full-time work weeks.
(Intro Narrator at 00:48:21) And so if you want to do something, I've used this. I've used this to write a book. I've used this to start multimillion-dollar business. I've used this—and I don't work insane amounts. I definitely was working the 16-hour days and stuff until I figured out how not to, right?
(Intro Narrator at 00:48:40) Because that's the time you make as the investment—
(Joel Beasley at 00:48:43) Right.
(Intro Narrator at 00:48:44) To learn how to work smarter. But it's so amazing. It's like Warren Buffett talking about the compounding nature of interest. And I don't know, it's hard for our brains to compute and it's easy to forget, but one hour a day being nine full-time work weeks to get a project done. I mean, everyone's got an hour in their day to improve themselves, whether it's their fitness, right? Or learning and education. So—
(Amit at 00:49:09) Yeah, absolutely. I'm a firm believer in that.
(Intro Narrator at 00:49:12) Let's talk—I got a couple more leadership questions for you. Is that cool?
(Joel Beasley at 00:49:16) Yeah.
(Intro Narrator at 00:49:16) All right. We're helping people right now, Amit. So if you could design the perfect leadership training program for your direct reports—so this is the context. I know you're up at this company. It's this large company. So your direct reports are on like a high-end level. So that's the context for this one. What would be in that training program?
(Amit at 00:49:37) Yeah. I mean, it's a big question. I'll share a couple of my thoughts there, Joel. Ultimately, you know, when you talk to people, why they join companies, why they are motivated, it just boils down to what I call the my rule of three Ps. You know?
(Amit at 00:49:57) The first P, when someone joins a company, it's largely because of the people. Right? You often hear in the industry that people might join companies, but they quit managers. Right? So, knowing that you're working with great people is very important, especially when you're going to spend more time with your colleagues and your teams than you probably will with your friends or even your family.
(Amit at 00:50:26) Right? So, you know, making sure that you have outstanding people—and outstanding people attract outstanding people, right—becomes a kind of a core aspect. So that's the first P. The second P is purpose. Right?
(Amit at 00:50:40) I think more and more, you want to give people a purpose. Right? Early on in Zscaler, yeah, you know, I'd have super bright engineers come, and they would say, "Hey, why should I join Zscaler? I have an offer from Google or some big company. Right? And look at all the benefits that they offer and free food and free laundry and whatnot." And and then, you know, you kind of go back to the purpose. And purpose quite simply is, "Hey, the work that I do matters."
(Amit at 00:51:09) Right? And it's visible and it's impactful. And, you know, I am contributing to something that's bigger than myself. And, you know, if you're if you're an engineer in a 5,000-person organization, you're a little cog in a wheel. Right?
(Amit at 00:51:23) I mean, it's like sitting in a big cruise ship versus being in a white-water rafting expedition with a fun group of friends where everything that you do has a direct bearing on the momentum and the direction of your ship. So, you know, giving people that purpose, that clarity—this is what I'm doing, this is why I'm doing it, this is how it has a direct bearing on the outcomes for the company, and I believe in that. And then the third P is pay.
(Amit at 00:51:57) Right? Everyone wants to make money. Right? And I think the issue of money, generally speaking, if the first two Ps are met, it's only as important as to take that issue of money off the table. Right?
(Amit at 00:52:08) And I often tell people, if you have those three P's, if you're chasing after just one, you know, that high from the 10% rise is just going to go away very quickly if the people around you suck and you don't feel that passion and purpose for what you're doing. Right? So that's kind of just general, you know, how do we motivate teams and make sure we hire the best and brightest and align them to participate in the company's success. Overall training, you know, Zscaler, our core values are summarized by one word called TOPIC, T-O-P-I-C. It's not one of those things that HR puts on a board and a few people, you know, stare at a chart.
(Amit at 00:52:57) I think we live and breathe that every day. And it's part of a core training for managers. The five words that make up TOPIC: T is teamwork, O is open communication, P is passion, I is innovation, and C is customer obsession. If there's one thing that I think defines Zscaler, it's customer obsession. Right? It starts with our CEO founder, Jay.
(Amit at 00:53:27) You know, we'll cancel a board call to take a customer meeting if it's important. Right? That's kind of how obsessed we are about making sure that our customers are successful and they get value. And that trickles down. I mean, it trickles down to engineers and operations folks.
(Amit at 00:53:44) And if there's a customer issue, they'll drop whatever it is and try to help. Right? So that's an important core value for Zscaler. You know, innovation, I think, you know, I described many things that we have done and it won't happen if you're not innovating at a furious pace.
(Amit at 00:54:03) Innovation happens in quantum jumps. You know, innovation happens when you think outside the box. While we're obsessed with customers, you know, if you only listen to what customers want, you'll never be able to innovate in quantum jumps. Right? Like, I think there's a famous Henry Ford saying that if I just listen to my customers, I would be breeding faster horses.
(Amit at 00:54:28) Right? Not come up with an automobile. Right? So I think innovation, we have, you know, well over 300 plus patents that are filed or are granted, and it comes with that core DNA of how do we solve this problem in a better way. And passion.
(Amit at 00:54:45) I think the one thing I look for when we are hiring is passion. Right? If you have the drive, the passion, if you're sharp, if you're going to do a quick study, you know, the years of experience don't matter. Right? In fact, if someone says I have twenty years of experience, I say, well, you probably have one year of experience learning and then nineteen years of experience coasting on it.
(Amit at 00:55:07) So tell me what you've done that was outside your comfort zone where you, you know, had some passion. So I choose passion and drive any day over experience. You have to have some basic experience. Right?
(Intro Narrator at 00:55:20) Well, passion, if you have passion and drive, you—
(Amit at 00:55:22) You would be able to figure it out. Right? Yeah. I mean, look, some amount of experience is necessary. You won't go to a neurosurgeon and say, hey, you have no medical degree, but you have passion, you know, operate away. So I mean, you need some skills, but you get the idea. And then I think, you know, open communication is something that's very important in today's world, especially when employees are remote. And, you know, you wonder whether people have legs because you only see them on Zoom. You know?
(Amit at 00:55:53) And just their face and torso. Right? So I think it's important to have frequent all-hands communications and lots of one-on-ones and check-ins. Otherwise, you know, your teams can drift. And, you know, and all that leads to good teamwork.
(Amit at 00:56:08) I think at the end of the day, making sure that everyone is aligned and rowing in one direction is kind of the biggest challenge of a growing organization. You know, when you—I think Steve Jobs said it well. You have a team of five people and they are working wonders, and then you have a team of 50. And they're producing less than the team of five did because, you know, of the communication overhead and different people pulling in different directions. So, you know, aligning teams and making sure that they're all unified with one purpose and marching and, you know, excelling in the same direction becomes a very important attribute for success.
(Intro Narrator at 00:56:48) When you started, how many employees were there and how many are there today?
(Amit at 00:56:52) When I joined, there were just maybe around 50-ish people, right? Just the early crew had grouped together and now we are north of 3,500.
(Intro Narrator at 00:57:05) So you've seen that growth as the engineering lead.
(Amit at 00:57:07) Yeah.
(Intro Narrator at 00:57:08) That's awesome, man. That is so cool. And so if I were to ask you—I don't want to put words in your mouth—communication during that expansion period is one of the most important things?
(Amit at 00:57:20) I think, yeah. Communication, there's not one thing, but yes, you know, you have to have open communication. People have to trust you. People have to, you know, people have to believe. I mean, it starts with you believing and then it kind of diffuses into the team.
(Amit at 00:57:37) So open communication, very important. I wouldn't say it's the most important, but definitely amongst the top two, three.
(Intro Narrator at 00:57:45) Nice. Everybody wants the buzzword though, man. Everybody wants the headline, the one thing they can do to be successful.
(Amit at 00:57:52) It's just like, I wish it was that simple. Right? I think at the end of the day, if you have to pick one thing that makes a business successful, I mean, the things that you control. Right? You can't control timing and markets.
(Amit at 00:58:09) But the one thing that you can control is relentless execution. Right? And the one thing that matters most for long-term success is execution. And execution doesn't happen if you don't have all those other things. Right?
(Amit at 00:58:21) If people are not motivated, you know, you don't have teams that are aligned. And they're not aligned because you don't have good communication practices. You know, passion is depleting because nobody feels like they're doing anything purposeful. Right? All of these things have to come together.
(Amit at 00:58:40) They become ingredients. But the thing that matters above all else, if I have to choose one thing, it would be execution.
(Intro Narrator at 00:58:46) Yeah. That's in line with, you know, everybody was asking me when I was doing talks, you know, they say, oh, you talked to all these leaders. Like, what's the one thing? And so I kept having to like avoid—I was avoiding the question because I couldn't give them one thing or I just randomly picked something. And so I sat down intentionally for a couple weeks and was like, all right, what's my answer to this question when people ask me?
(Intro Narrator at 00:59:05) And I put it all out there and it's a similar thing to execution. I just came up with persistence because my logic there to back up the argument is, as long as you have reasonable amount of intelligence, like you can wake up, you can put on your shoes, you can go to the grocery store, you can take care of yourself, you can learn. And, uh, and then you have this drive, this thing you're going after. And as long as you don't give up, you're going to learn all the lessons. Like I would do a thing where I'd want to research and know everything ahead of time and think I'm set.
(Intro Narrator at 00:59:39) And I got security in that. And then I go into it and I get punched in the face. And I was like, okay, well, then I did it again and again. And finally, after several times of doing that, I realized, look, I just have to go do it. I just have to go do it.
(Intro Narrator at 00:59:51) I'm going to run into a bunch of problems. And I know I can't predict the problems along the way. It doesn't matter how many people I talk to. I find it's a rare thing. Somebody gives me advice and it matches up perfectly with my situation.
(Intro Narrator at 01:00:03) So, yeah, persistence is what I came to.
(Amit at 01:00:05) Yep. Kind of one. Yeah. Persistence delivers execution. Right?
(Intro Narrator at 01:00:09) Yeah. They're tied. Yes.
(Amit at 01:00:11) And at the end of the day, I always say you either did it or you just have excuses. So—
(Intro Narrator at 01:00:20) Thank you so much for listening. And if you found this episode useful, please share it with a friend or colleague who you think would get value from it. And if you have topics that you would like to hear discussed on the podcast, either add me on LinkedIn or send me an email: [email protected]. Every time I get an email or LinkedIn message, it absolutely makes my day and inspires me to keep going.