**Kevin Rubin** (0:03)
There's no going back, if you will. I mean, as an industry, Agentic is going to be as disruptive as any of the tech waves have been in the past, whether it was mobile, internet, etc. I mean, this is just the next frontier of how businesses will need to compete.
**Jason Moser** (0:23)
That was Zscaler CFO Kevin Rubin on the future of AI security.
I'm Motley Fool analyst Jason Moser.
I sat down with Kevin to talk about how Zscaler is protecting the world's largest organizations from an exploding wave of cyber threats and why the rise of agentic AI could be the biggest opportunity the company has ever seen.
Enjoy.
Welcome to Motley Fool Conversations on Jason Moser. Today, I'm excited to welcome the CFO of Zscaler, Mr. Kevin Rubin. Prior to Zscaler, Kevin was the CFO at BetterUp, and prior to that, he served as the CFO of Alterix, a company that Motley Fool members are likely familiar with. Today, we're diving into the business of cybersecurity and Zscaler's role in this crucial market. Kevin, welcome to the show.
**Kevin Rubin** (1:10)
Thanks, Jason. Appreciate you guys having us on.
**Jason Moser** (1:13)
Well, really happy to have you here. I guess the first thing I want to get into here, because when we talk about cybersecurity, most of us, whether we're investors or not, we know that cybersecurity is necessary, but we don't exactly understand what it ultimately, there's so many different ways to view it. So first things first, we said at the top Zscaler is a cybersecurity company, but what is it that Zscaler actually does?
**Kevin Rubin** (1:40)
Yeah, thanks for the question. It really comes down to two fundamental things in my mind.
Number one is preventing bad actors from getting into your corporate network and being able to access sensitive information or breaching your environment. Number two is ensuring that sensitive data and corporate assets don't escape out of your corporate network. Those are the fundamental things that we seek to solve.
**Jason Moser** (2:09)
Yeah. Well, I can tell you just for my day-to-day, we use Zscaler all the time here at the Motley Fool, and I appreciate that you're looking out for us. So we hear a lot about zero trust, right? That's a word that we hear a lot in the cybersecurity market. Zscaler really pioneered the zero trust model years ago before it became mainstream, but now it seems like everybody claims to offer zero trust. So I guess I'm wondering, can you talk a little bit about what separates genuine zero trust from what other people call zero trust? Because I've heard it called zero trust washing before.
Is there a unique property or quality to Zscaler zero trust dynamic?
**Kevin Rubin** (2:53)
So zero trust is a set of principles that simply mean provide the least amount of access only for the necessary particular use for either an individual, a workload or a device that sits within the corporate environment.
The concept is you should not give access to anything and everything because somebody wants to access a single application. So the principles are clear. Give the least necessary access for what it is that somebody or something is trying to accomplish with that particular request. We architected Zscaler specifically with those principles in mind. So the way that we approach Zero Trust and cybersecurity is through our Zero Trust Exchange. We don't believe in today's environment that companies need to build out large complicated corporate networks, right? That was something that happened 30, 40 years ago when the Internet didn't exist and stable ability to drive traffic didn't exist. But today, those are as common as driving on the interstate, right? If you go back probably 100 years, you had oil drillers who had to build private roads to be able to access their oil fields because general public roads didn't exist. Today, you don't see organizations building basic infrastructure to be able to access certain assets. The same analogy would hold true as you think about corporate access to applications and other corporate sets of data. So, our approach is simple. You allow your users and other resources to access what they need only at the time that they need it, and you go through the Zero Trust Exchange. So, think about it as a one-to-one set of connection. You want to access your email by way of example. You request access to the email server. We authenticate you. We ensure that you're authorized to access that. We allow you to get your email, and then that session terminates when you're done using email. And the next time you come in, you know, in the background, we'll go through that same process. In doing so, you don't have the ability to move laterally within the network. You have no reason or business to go to other applications if all you're doing is, is looking to serve email. And the same would hold true if you're trying to go to your HRIS system, or you're trying to go to your CRM system.
16 more minutes of transcript below
Try it now — copy, paste, done:
curl -H "x-api-key: pt_demo" \
https://spoken.md/transcripts/1000651996090
Works with Claude, ChatGPT, Cursor, and any agent that makes HTTP calls.
From $0.10 per transcript. No subscription. Credits never expire.
Using your own key:
curl -H "x-api-key: YOUR_KEY" \
https://spoken.md/transcripts/1000771558435