The Thesis
Zscaler kills the VPN.
In the old world (Castle & Moat), you connected to the corporate network. In the new world (Zero Trust), you connect to nothing; you connect through Zscaler to a specific app. The thesis is that Zscaler is the Switchboard of the Internet for enterprise traffic, sitting between the user and the application, inspecting every packet.
Product Deep Dive: The Exchange
1. ZIA (Internet Access)
- The Product: Secure Web Gateway. Protecting employees browsing the internet (blocking gambling sites, malware downloads).
- The Moat: Proxy Architecture. Zscaler runs inline (Man-in-the-Middle). This is hard to build at scale (150 data centers).
2. ZPA (Private Access)
- The Product: VPN Replacement.
- The Magic: The user never touches the corporate network. Zscaler spins up a dark connection to the app (AWS/Data center). Even if the user is hacked, the attacker can't "move laterally" to other servers.
3. ZDX (Digital Experience)
- The Product: Monitoring why "Zoom is slow."
- The Value: Since Zscaler sits in the middle, they know if the lag is the WiFi, the ISP, or the Zoom server. IT loves this.
The Business Model
- User-Based Licensing: Priced per user/per year (e.g., Business bundle).
- Upsell: Moving customers from "ZIA only" to "ZIA + ZPA + ZDX."
- : High CAC, but very high LTV.