With smarter evasion techniques and automated attacks, malicious actors are making life difficult for IT security professionals. Zscaler hopes to thwart these threats using its own telemetry, external models, and unified workflows.
Zscaler Agentic SecOps is a new solution that consolidates Zscaler features with external LLMs. Zscaler provides in-house telemetry, the world’s largest decoy mesh network, and zero-trust management across all IT layers. Customers can integrate their own tools and leverage AI models from Anthropic and OpenAI within Agentic SecOps.
“Machine speed” protection
A security term that has become increasingly relevant is “machine speed.” It refers to attacks that, thanks to AI systems and existing scripts, can execute both simple and complex actions as fast as a computer can compute. Logically, that’s faster than a normal human can react without assistance. Zscaler’s “AI-first” approach aims to provide that assistance through Agentic SecOps.
The language used resembles that of Red Canary, which was acquired by Zscaler in the middle of last year. In the announcement, Zscaler states that threat hunting and expert support are also provided by Red Canary. Ideally, human interaction isn’t necessary for day-to-day defense; the data from the threat landscape via ThreatLabz would already make much of the knowledge inherent to the platform.
Telemetry as the foundation
This translates to so-called “inline” remediation: all suspicious signals are detected as part of 750 billion daily zero-trust transactions. Where a threat appears to exist, Zscaler isolates compromised users, blocks C2C connections, and prevents lateral movement across the network.
Next, tasks are distributed among AI agents. They handle triage, root-cause analysis, and assess threats without human intervention whenever possible. Where human intervention is required, agents can take charge of the initial steps of response workflows. Zscaler states that, thanks to training on data, these agents effectively bring ten years of SOC, MDR, and threat hunting experience to the table.
Next step?
It’s a well-known phenomenon that security personnel are buried under a deluge of noise, often containing only limited signals. Aside from improving the signal-to-noise ratio, there appears to be no alternative but to expand the role of AI, partly due to the malicious use of AI itself. This means that research data, such as that from Zscaler, becomes more valuable to the end user. This is because attacks are evolving faster and are harder to trace; after all, AI-powered endpoints may have little to do with the human cyber actors who created them.
An abundance of data is less of a problem for AI, with Zscaler now able to consult OpenAI and Anthropic in ways that regular users cannot easily replicate. For most users, the best LLMs from these providers refuse to conduct extensive security research, particularly to detect vulnerabilities, for example. Within a security platform, the risks of misuse are lower, and the data is already available, whether directly through Zscaler or via a connector. This means that machine speed reinforces the importance of a solution like Agentic SecOps.