Motley Fool Hidden Gems Investing - The Invisible Layer Protecting the World's Biggest Companies

Episode Date: June 7, 2026

Every time you log into a corporate network, send a file, or spin up an AI agent, something has to decide what's allowed and what isn't. So what happens when the number of things asking for access goe...s from 50 million users to billions of AI agents — and the bad actors have frontier models helping them find the cracks? Motley Fool analyst Jason Moser talks with Zscaler CFO Kevin Rubin about zero trust security, the agentic AI threat landscape, and why the cybersecurity buildout may be one of the most durable investment themes of the next decade. Host: Jason Moser Guest: Kevin Rubin Producers: Bart Shannon, Lauren Budabin Disclosure: Advertisements are sponsored content and provided for informational purposes only. The Motley Fool and its affiliates (collectively, “TMF”) do not endorse, recommend, or verify the accuracy or completeness of the statements made within advertisements. TMF is not involved in the offer, sale, or solicitation of any securities advertised herein and makes no representations regarding the suitability, or risks associated with any investment opportunity presented. Investors should conduct their own due diligence and consult with legal, tax, and financial advisors before making any investment decisions. TMF assumes no responsibility for any losses or damages arising from this advertisement. We’re committed to transparency: All personal opinions in advertisements from Fools are their own. The product advertised in this episode was loaned to TMF and was returned after a test period or the product advertised in this episode was purchased by TMF. Advertiser has paid for the sponsorship of this episode. Learn more about your ad choices. Visit megaphone.fm/adchoices Learn more about your ad choices. Visit megaphone.fm/adchoices

Transcript
Discussion (0)
Starting point is 00:00:00 There's no going back, if you will. I mean, as an industry, agentic is going to be as disruptive as any of the tech waves have been in the past, whether it was mobile, Internet, etc. I mean, this is just the next frontier of how businesses will need to compete. That was Zscaler CFO,
Starting point is 00:00:24 Kevin Rubin on the future of AI security. I'm Motley Fool analyst, Jason Moser. I sat down with Kevin to talk about how Zscaler is protecting the world's largest organizations from an exploding wave of cyber threats, and why the rise of agentic AI could be the biggest opportunity the company has ever seen. Enjoy. Welcome to Motley Fool Conversations. I'm Jason Moser, and today I'm excited to welcome the CFO of Zscaler, Mr. Kevin Rubin. Prior to Zscaler, Kevin was the CFO at BetterUp. And prior to that, he served as the CFO of Alterix, a company that Motley Fool members are likely familiar with. Today, we're diving into the
Starting point is 00:01:03 business of cybersecurity and Zscaler's role in this crucial market. Kevin, welcome to the show. Thanks, Jason. Appreciate you guys having us on. Well, really happy to have you here. And I guess the first thing I want to get into here, because when we talk about cybersecurity, most of us, whether we're investors or not, we know that cybersecurity is necessary, but we don't exactly understand what it ultimately, there's so many different ways to view it. So first things first, we said at the top, Zscaler is a cybersecurity company, but what is it that Zscaler actually does? Yeah, thanks for the question. It really comes down to two fundamental things in my mind.
Starting point is 00:01:46 Number one is preventing bad actors from getting into your corporate network and being able to access sensitive information or breaching your environment. And number two is ensuring that sensitive data and corporate assets don't escape out of your corporate network. Those are the fundamental things that we seek to solve. Yeah, well, I can tell you just from my day to day, we use Zscaler all the time here at The Motley Fool. And I appreciate that you're looking out for us. So we hear a lot about zero trust, right? That's a word that we hear a lot in the cybersecurity market. And Zscaler really pioneered a zero trust model years ago before it became mainstream.
Starting point is 00:02:29 But now it seems like everybody claims to offer zero trust. So I guess I'm wondering, can you talk a little bit about what separates genuine zero trust from what other people call zero trust? I guess I've heard it called zero trust washing before. Like, is there is there a unique property or quality to Z scale or zero trust dynamic? So zero trust is a set of principles that simply mean provide the least amount of access only for the necessary particular use for either an individual, a workload or a device that sits within the corporate environment. The concept is you should not give access to anything and everything because somebody wants to access a single application. So the principles are clear. Give the least necessary access for what it is that somebody or something is trying to accomplish with that particular request. We architected Zscaler specifically with those principles in mind.
Starting point is 00:03:38 So the way that we approach zero trust and cybersecurity is through our zero trust exchange. We don't believe in today's environment that companies need to build out large, complicated corporate networks. That was something that happened 30, 40 years ago when the Internet didn't exist and stable ability to drive traffic didn't exist. But today, those are as common as driving on the interstate, right? If you go back probably 100 years, you had oil drillers who had to build private roads to be able to access their oil fields because general public roads didn't exist. today, you don't see organizations building, you know, basic infrastructure to be able to access certain assets. And the same analogy would hold true as you think about corporate access to applications and other corporate sets of data. So our approach is simple. You allow your users and other resources to access what they need only at the time that they need it, and you go through the zero trust exchange. And so think about it as a one-to-one set of connection. You want to access your email by way of example. You request access to the email server. We authenticate you. We
Starting point is 00:05:00 ensure that you're authorized to access that. We allow you to get your email. And then that session terminates when you're done using email. And the next time you come in, you know, in the background, we'll go through that same process. In doing so, you don't have the ability to move laterally within the network. You have no reason or business to go to other applications if all you're doing is looking to serve email. And the same would hold true if you're trying to go to your HRIS system or you're trying to go to your CRM system. Access what you need, be able to do the work that you need to do, but then get off the network and become invisible again. So that's how We've philosophically approached zero trust.
Starting point is 00:05:42 If you are largely building corporate networks and providing network-based security architecture, your application of zero trust is likely through very complicated policy-driven zero trust principles. And our argument would be, to your point about zero trust washing, it's probably not effectively zero trust, but you can brand it as zero trust and go to market that way. We are actually living, breathing, and applying the principles in how we've architected our zero trust exchange and our cybersecurity service. Well, I'm going to get into some numbers here as the CFO. I think you'll like that.
Starting point is 00:06:27 But you set a target of $5 billion and beyond in annual recurring revenue here over the next several years. you're guiding for $3.75 billion in revenue this year. As an investor, that's an exciting growth prospect, but I wonder what are the drivers that will get you there? Yeah, thanks for the question. So we have a series of growth levers that are available to us as we think about our path to $5 billion and more. First off, you know, we started with zero trust for users. So the ability to protect user communication traffic between users and applications. We then extended that to Zero Trust Cloud. So being able to provide the same Zero Trust principles to workload to workload communication. So think about that as an application talking to an application.
Starting point is 00:07:14 And then more recently, we extended that to Zero Trust Branch. The idea that organizations have, you know, branch offices. You can think about a bank and having branches around the country. All of those branches need to ultimately connect into other systems and resources. And we don't think that they all need to connect to each other and form kind of a mesh network as is traditionally thought, but connect each individual device in a branch to only the application that it needs. So if it's a door sensor to monitor access, have it connect to the application that monitors access. It doesn't need to connect to other applications and it certainly doesn't need to connect to other branches as is the case today. And if one of those devices were to get breached
Starting point is 00:08:00 in the traditional sense, it has the ability to infect your entire web network. In the zero trust branch situation, if one particular device gets breached, it's limited the attack surface to that particular device. The other area of growth opportunity for us is data security. So we have seen significant momentum in our ability to protect data. As a service, we sit in the path of traffic. And so we have an ability to inspect that traffic as it's going back and forth. We have an ability to apply policy. That's how we determine what is and isn't acceptable use. And on top of that, now we can also provide data security. So looking at the data that is being transacted back and forth and what is and isn't acceptable to go in and out of the organization as we kind of
Starting point is 00:08:52 talked about at the upfront of the conversation. And then lastly, AI. AI is a very significant tailwind for us from a couple of different dimensions. First is we're going to be extending zero trust for users branching cloud into zero trust for agents. So the ability to orchestrate from a cybersecurity perspective, the communication between an agent and another agent or an agent and an individual, as well as machine-to-machine communication, and ensure that the same principles of one-to-one communication, lease permissioning, is adhered to. We think that's a huge opportunity. You have, you know, today we protect more than 50 million users, and tomorrow that could be millions or billions of agents that are doing work on behalf of organizations. And if one rogue
Starting point is 00:09:45 agent got breached or hacked, imagine the damage that they could produce in an organization if it had the ability to move throughout that corporate network and have access to things that it never needed to. So again, applying those zero trust principles to agents is something that is near and dear to us. And lastly, and we've all heard a lot about mythos in these frontier models that have been introduced more recently, and just the proliferation of vulnerability identification. Palo Alto was identified just this week as having a vulnerability that had been unknown for years that got exposed by one of these models. And it just reinforces the fact that companies today have got a backlog of vulnerabilities that they need to patch. And that's just what's known on
Starting point is 00:10:37 their plate today. These models are identifying vulnerabilities at a rate and a pace that is at machine pace, right? So we're talking about volumes of vulnerabilities that, you know, we can't even solve the vulnerabilities that were already identified previously. And now we're just piling on significantly more vulnerabilities that were unknown for decades. And it's overwhelming IT organizations. They can't possibly keep pace in terms of their ability to patch and address these things. So our solution is very simple. Hide your applications behind Zscaler Exchange. What you can't see, you can't breach. And so in our architecture approach to cybersecurity, you hide your applications and you only provide access to what is needed at that time. And so
Starting point is 00:11:28 your blast radius gets minimized to a single device. This is a great segue. I'm glad you got us into the AI conversation, because that's really where I wanted to go next. And, you know, one thing I noticed, you know, in this recent earnings call, you know, when you talked about joining the partnership with Anthropic via Project Glasswing. And I think that's a really interesting concept. We're seeing tech companies of all walks joining into that consortium, so to speak. I wonder what kinds of opportunities does that partnership offer Zscaler? Yeah, I mean, I think we're still uncovering all of the opportunities to be candid, right? These are models that weren't specifically developed initially to identify vulnerabilities, and yet they were doing so at machines speed and at scale that nobody anticipated. We were an early partner with Anthropic and Glasswing.
Starting point is 00:12:22 We're an early partner with OpenAI on Daybreak. And it really does give us an opportunity to understand these models. We get to apply those models internally and understand how it would affect us. And then we get to learn and be able to apply those learnings to our customers and prospects so that we can provide the best cybersecurity for them and their environments. And so being a participant has obviously been very important for us, and we have a great relationship with the frontier model companies. Okay, so this is obviously a very competitive space. You've got incumbents out there that are building integrated security platforms and just really going all in.
Starting point is 00:13:02 Zscaler is not the most acquisitive company in the world, but you recently made a fairly big acquisition in Red Canary. I wonder if you could just talk a little bit about why y'all did that and what you think the challenges and the opportunities there are. So one of the areas of opportunity that we've seen for a bit of time is the fact that we sit on an incredible amount of high-fidelity, rich, security-oriented data. We process a half a trillion transactions a day through the Zero Trust Exchange, orders of magnitude greater than even Google searches in a given day to kind of put a context to how much volume of traffic goes through our security cloud each and every day. And we believe we have a unique position to provide our customers with an understanding and a perspective and a context around that data that is unique to us as a vendor. The rationale behind Red Canary was they had a decade-plus experience doing detection and response. They had taken that experience and established dozens of agents that were being able to scale that experience across a wide population of data. And if we could pair that with our rich data set, that does provide a very unique set of information and insights to our customers. And that was the ultimate approach and philosophy.
Starting point is 00:14:28 Red Canary, after evaluating a variety of vendors in the space, surfaced as the right partner for us in being able to integrate their technology into what we will ultimately launch in the near term, which is our integrated SecOps solution. And the goal is to migrate legacy Red Canary customers into this new integrated solution, as well as offer it to existing customers. And we think it's a very differentiated opportunity to provide that insight. i want to go back to ai for just a second because i think one of the headlines that we're seeing a lot these days is companies starting to question the return on investment in regard to ai right token usage is eating up budgets left and right you're starting to question whether what's cheaper, the employee or the AI? And it used to be that that was the argument was AI is going to make it cheaper. But now the employees are starting to look like maybe that's not a bad
Starting point is 00:15:34 option after all. I wonder, do you feel like Zscaler, are you recognizing clear ROI on these AI investments today? Or is this more of an investment in the future that you are sort of have faith that it will pay off? So it's a little bit of both if we're being completely candid. I I mean, we're at early innings as an industry around AI. We have seen significant productivity using AI in areas like engineering and product development. We've seen significant benefits in customer support and, you know, some of the other areas that, you know, early successes have been realized by others as well. So those are real tangible benefits that, you know, that we have been seeing and taking advantage of. Our approach internally to AI is not human or AI. It's really human and AI, right? How do we best pair AI and agentic technology with our existing workforce to provide the best productivity and outcomes for customers? And that's the lens at which we look at AI use.
Starting point is 00:16:46 It certainly is exploding internally in terms of the various different teams that are using it. You know, we are very focused on how we balance between token usage and what those outcomes are, right? Certain models are much more expensive in terms of tokens than others. So we're trying to be very mindful in what models we use for what use cases and what outcomes. but there's no going back, if you will. I mean, as an industry, a Gentic is going to be as disruptive as, you know, any of the, you know, tech waves have been in the past, whether it was mobile, internet, et cetera. I mean, this is just the next frontier
Starting point is 00:17:27 of how businesses will need to compete. Yeah, I like that. AI plus the person, right? It does seem to work really well. Just speaking as an analyst here at The Fool, I mean, I use those tools every day. I mean, they are absolutely helpful. I mean, I still like to do my own writing, but it's like Search 2.0, right? I've always kind of viewed it as sort of this evolution of search and we're just have access to more information than ever before. And it can put things together so much more quickly. So, yeah, I like that. The AI plus the person. That's a good perspective there. Okay, so as CFO, right, cybersecurity budgets are one of the last things that are ever kind of downturn, right? I mean, this is just mission critical stuff. You can't go without it. But by the same token, I mean, we're seeing a macro environment where I think CFOs across the board are having to scrutinize every dollar that's going out the door. So I just wonder, how's this macro environment affecting your company's decision making over the past years? Is it something that's keeping you up at night?
Starting point is 00:18:28 Well, there's two dimensions or two ways in which I think about it. From a commercialization, Zscaler is an incredible value proposition to a large organization that has built its cybersecurity based on traditional network-based security, hardware, and the like. So if you look at the ROI of deploying Zscaler in a large network infrastructure, it is significant. You are deprecating a bunch of firewalls, VPNs, SD-WANs, MPLS devices, and you are replacing those with a service that provides you with your traffic and your inspection and your security. So those customers who have deployed Zscaler benefit from a significantly lower total cost of ownership under Zscaler. So, as I think about the opportunity in this environment, it's only becoming more evident that customers and prospects need to be looking outside the box, both figuratively, literally, in terms of how they approach cybersecurity. And those conversations are incredibly compelling when we sit down with customers and prospects and spell out what they can get rid of in their corporate network by deploying Zscalers. So it's a highly cost efficient way to provide, frankly, better service, right? If we think about, again, this idea that, you know, vulnerabilities are being identified faster and deeper than ever before, your best defense of that is being able to hide behind a service like ours. And we're uniquely positioned, the largest security cloud in the world. We operate a security cloud across 160 plus points of presence. So there's a there's a deep amount of expertise and scale that sits behind Zscaler. Internally, we also benefit from the fact that our entire business runs on Zscaler. So my cost of cybersecurity is going to naturally be less than a competitor or another vendor that is, you know, using traditional cybersecurity.
Starting point is 00:20:34 security. You know, the other tension point today is, as we talked about, it's AI and the cost of AI relative to your overall financial model. And those companies that are best able to manage that balance will be the most competitive companies in, you know, in the market today. Yeah, well, let me clearly, your customers like what you're giving them. I mean, I saw in this recent earnings call, I mean, your customers that are generating over $1 million in annual recurring revenue that grew 18% from a year ago to 748. So I just, I think that's really encouraging. We'll leave it there. He's the CFO of Zscaler. Mr. Kevin Rubin, thank you so much for joining us today. Thank you for having me. I appreciate it. As always, people on the program
Starting point is 00:21:20 may have interest in the stocks they talk about, and The Motley Fool may have formal recommendations for or against, so don't buy or sell stocks based solely on what you hear. All personal finance content follows Motley Fool editorial standards and is not approved by advertisers. Advertisements are sponsored content and provided for informational purposes only. To see our full advertising disclosure, please check out our show notes. For the Motley Fool Hidden Gems Investing Team Podcast, I'm Jason Moser. Thanks for listening. We'll see you next time.

There aren't comments yet for this episode. Click on any sentence in the transcript to leave a comment.