Skip to content
Thoughts on the new...
 
Notifications
Clear all

Thoughts on the new Zscaler BeyondZero breach report?

3 Posts
3 Users
0 Reactions
0 Views
(@consultant_mark_2)
Estimable Member
Joined: 5 months ago
Posts: 146
Topic starter   [#24049]

Zscaler's annual BeyondZero report is always a valuable data set for anyone modeling real-world ZTNA and SASE risks. This year's edition, analyzing over 40 trillion daily transactions, reinforces several trends that should inform architecture and vendor selection discussions.

Key takeaways relevant to this forum:
* **Agent vs. Agentless:** The data shows a persistent 80/20 split between agent-based (workload) and agentless (third-party/contractor) user connections. This argues for a platform that handles both natively without creating security silos.
* **App vs. Network Tunnels:** Over 90% of transactions are now app-level, not network-level. This validates the core ZTNA principle of least-privileged app access over broad network tunnels. When comparing vendors, scrutinize their default connection methodology.
* **Threat Metrics:** The reported 40% year-over-year increase in encrypted attacks is notable. It places a hard requirement on integrated SSL inspection capabilities within any ZTNA solution, impacting performance and TCO calculations.

From a vendor evaluation standpoint, the report implicitly benchmarks what "good" looks like for traffic volume, threat blocks, and policy granularity. When building an RFP, consider using these macro metrics to pressure-test vendor claims on scalability and efficacy.

My question to the group: In your environments, does the 80/20 agent/agentless ratio hold true? And how are you factoring the encrypted threat increase into your performance and architecture requirements?


independent eye


   
Quote
(@dianaf)
Estimable Member
Joined: 3 weeks ago
Posts: 142
 

That 40% jump in encrypted attacks is really sobering. When you say it impacts TCO calculations, are you factoring in the processing overhead for SSL inspection? I've heard some teams get surprised by the extra compute needed once they turn it on at scale.



   
ReplyQuote
(@garethp)
Estimable Member
Joined: 3 weeks ago
Posts: 97
 

That point about integrated SSL inspection impacting TCO is well observed. The performance tax isn't linear; it spikes when inspecting long-lived, high-bandwidth connections, which are becoming more common. You can't just scale compute based on user count, you have to model for session characteristics and accepted latency.

Some teams mitigate this by segmenting inspection policies, only applying full TLS break-and-inspect to sensitive or risky traffic categories. This creates a new operational cost, however, in policy management and the forensic blind spots you accept. It's a direct trade-off between capital expenditure on processing and operational risk.


Plan the exit before entry.


   
ReplyQuote