The way we work has drastically fundamentally shifted over the past few years. We no longer operate within the safe, predictable confines of a corporate office network. Work now happens anywhere and everywhere, often on unmanaged personal devices, across sprawling third-party partner supply chains, and under the constant threat of AI-driven cyberattacks that move much faster than traditional security teams can defend against. To be very honest, legacy SASE architectures are simply not cut out for this. Most of them were built in a post-pandemic rush, relying on a glorified firewall and VPN model that essentially exposes corporate applications directly to the public internet, invites dangerous lateral threat movement, and turns configuration management into an absolute administrative nightmare.

Recognising that network perimeters no longer exist, Zscaler has announced a significant expansion of its Zero Trust SASE solution. Built on a single, cloud-native architecture, this major overhaul introduces an autonomous AI management framework while actively expanding zero-trust protections to unmanaged endpoints, business-to-business supply chain partners, and multi-cloud environments. Under the hood, Zscaler is leveraging its position as the operator of the world’s largest inline security cloud, which now secures a staggering 750 billion daily transactions. This massive footprint acts as the ultimate real-time training ground for its AI engine, translating directly into highly optimised threat detection capabilities for the modern enterprise.
Automating SASE Management with the ZAgent Framework
One of the biggest pain points for enterprise security teams isn’t just defending against external bad actors; it’s surviving the daily friction of managing bloated, fragmented tools. Zscaler is addressing this directly by imbuing its platform with agentic AI operations to simplify complex administrative workflows. At the heart of this push is the new ZAgent Framework, an AI orchestration layer that automatically manages and validates security configurations, detects configuration drift, and speeds up system troubleshooting. Instead of manually digging through layered settings menus, IT administrators can interact with ZAgent using simple, familiar natural language prompts right within the Zscaler Experience Center.
Operating directly under this new framework is the updated Zscaler Digital Experience (ZDX) Agent. In daily practice, user experience issues like a flaky local Wi-Fi connection or an ISP bottleneck frequently get misdiagnosed as critical application failures. The ZDX agent steps in as an autonomous diagnostic tool to pinpoint the exact root cause of an end-user’s connectivity drop in seconds, remediating local hardware or network choke points before they spiral into a helpdesk ticket escalation.
Replacing VDI and Securing the B2B Supply Chain
For most organizations, trying to safely connect external vendors and Bring Your Own Device (BYOD) workers without compromising internal data is a delicate teetering act. Zscaler is aggressively targeting this challenge by delivering browser-based solutions designed to completely replace expensive, resource-heavy Virtual Desktop Infrastructure (VDI) setups. The company’s new Zero Trust Enterprise Browser and cross-browser extension natively embed SASE capabilities right into a full Chromium-based environment. This configuration delivers localised data controls and Browser Detection & Response directly on unmanaged endpoints, serving as a unified on-ramp to corporate data without requiring invasive endpoint management profiles.

Supply chain security is getting a massive upgrade as well. The new Zscaler B2B exchange enables policy-controlled, bi-directional application access for corporate customers and their verified partners. This completely replaces high-risk partner connectivity methods like site-to-site VPNs and complex MPLS networks, granting precise application access without ever exposing the underlying network or forcing administrators to manage messy firewall rule sets. Furthermore, Zscaler is introducing an Endpoint Sandbox to guard against offline entry points. While cloud sandboxing handles digital file transfers, this endpoint capability isolates and neutralises malicious files introduced directly to hardware from physical sources like flash drives.
Consistent Security Across Multi-Cloud Workloads
As application architecture fragments across multiple public clouds, managing disparate infrastructure security platforms often creates operational silos. Zscaler is bringing much-needed consistency to this environment by extending its uniform SASE protections to the Google Cloud Platform (GCP), matching its existing AWS integration. The Zero Trust Gateway for GCP brings policy-driven security across workload-to-workload and workload-to-internet traffic patterns, successfully tearing down cloud-specific silos. To make cloud-native deployments even more nimble, Zscaler has rolled out automated Microsegmentation for Kubernetes. Operating directly inside environments like the Google Kubernetes Engine (GKE), this feature halts lateral threat movement between containers and Virtual Machines (VMs) with zero code changes, stripping out the operational friction that usually plagues microsegmentation strategies.
