Go back

Tech Disruptors: Zscaler CEO Jay Chaudhry on Anthropic’s Mythos

40m 54s

Tech Disruptors: Zscaler CEO Jay Chaudhry on Anthropic’s Mythos

In this podcast, Jay Chaudhry, CEO of Zscaler, discusses the implications of Anthropic's Claude Mithos model for cybersecurity. He explains that while Mithos can rapidly discover vulnerabilities, the real issue for enterprises is the lack of time and resources to fix them all. Instead of trying to eliminate every vulnerability, Chaudhry advocates for a zero-trust architecture that hides applications behind Zscaler's exchange, preventing attackers from scanning or reaching them. He compares this to wearing shoes to protect against thorns rather than trying to remove all thorns from the world. Chaudhry addresses the growing threat of AI agents, which he views as digital workers that are always untrusted. Zscaler plans to extend its zero-trust exchange to handle agents, using identity from hyperscalers like Microsoft and Google for policy enforcement rather than competing to be an identity provider. He also notes that Zscaler uses GPUs for inference and small language model training, but avoids using AI agents to write critical security code. The company embraces AI for non-critical tasks like UI and analytics, seeing significant productivity gains. Finally, Chaudhry suggests that cybersecurity business models may evolve to charge based on work volume, such as traffic or tokens processed.

Transcription

5544 Words, 31121 Characters

English
[MUSIC] Hello and welcome to the Bloomberg Tech Disruptors podcast. My name is Mandip and with me today is J. I'm from the Greenwich Audery, Chairman and CEO of Zscaler J. Welcome back to the podcast. And it hits an honor and pleasure. Yeah, great. You're a repeat guest and I think the last time we had you on was a few months back, maybe a year. So it's great to get your fresh perspective given the world of cybersecurity changes almost every week. The latest one being the Claude Mithos release, which obviously has been a very big deal for enterprises across the globe. Even the governments are looking closely at it. So we'd love to start off there and I have a lot of questions. So hopefully we can cover a lot of ground today. It's an important and timely topic. Yeah, so maybe look, I think with Mithos, one of the things that obviously the market reacted quite negatively in terms of what it means for the pure play, you know, security companies. And it feels like what people are trying to better understand is what are the vulnerabilities that this model showcase and obviously it's not available for folks like us to play around with. And first question is, have you been able to take a look at it in terms of, you know, what are the capabilities of this model and what is it that you have evaluated so far in terms of, you know, what this model brings to the table. On the APS, we have been actually testing it for several weeks. But the first question, the market reaction to Mithos is less for SaaS security companies. It's more for the broader customer base. The SaaS companies got impacted when Claude code for security got announced. Now Mithos model basically said, this model can identify security vulnerabilities very easily, very quickly. And it has found some of the vulnerabilities that have been sitting there in operating systems and the like for quite some time. So it essentially says we need to wake up and take care of those vulnerabilities or do something to protect ourselves from them. So is the model powerful? Absolutely. Now is the sky going to fall tomorrow? Not really. So here is here are some of the practical things. There's not a lack of vulnerabilities that enterprises know they need to fix. There's a long list of those. The challenge has been time and resource to fix them. Now Mithos is piling up a bigger list on top of that. Now real question is what's a practical solution to it? So as we look to the model, we understand some of the vulnerabilities. I think the number one thing enterprises can do is to make sure applications that are exposed to the internet, they are the highest risk applications. Any vulnerabilities, any serious vulnerabilities for those applications need to be looked at seriously and passed if possible. But the easiest thing you can do to protect yourself is hide those applications behind a service like the scalar, like zero to a sec change. How do bad guys attack you? Number one way to attack you is they find your attack surface. They scan from the internet, they find a range of applications. They may be firewalls, VPNs, this may be MCP servers. And this may be other applications out there. From then they can figure out what those applications are, what the versions are, what the vulnerabilities are, and that's how to exploit it. In the Z-skiller zero trust model, your applications are hidden behind Z-skiller. If they can't reach you, they can't reach you. So that's one of the things that our customers are working with us, previously, to make sure they make themselves safer. So, I mean, just out of curiosity, why do you think these operating systems or browser vulnerabilities were not uncovered by you or someone in the cybersecurity domain? Like, what was so special? I mean, are these extremely technical in terms of the part of the code that Mito's has been able to scan? Like, what's special about the vulnerabilities that they have uncovered? Look, first of all, software always has vulnerabilities. And you come from different angles, you run it through different scenarios, you discover them. Mito's being the highly trained model, has been able to discover a bunch of them, that humans haven't discovered. So, it's not surprising that some of these models will do better job in detecting them and better job in being able to exploit them, than human beings do. Now, that's not to say human beings can't do it. The problem is, there are a small number of very sharp human beings who can do it. Yeah, but at scale is lacking. We all have been reading about lack of cyber experts. There have been hundreds of thousands of jobs that have been unfilled in the cyber space. So, at scale to find these issues and fix them has been a hard problem. So, but where did they get the training data from? Because I thought all these LLMs are trained on open Internet data that they have scraped. And so, where is the open Internet data to train security LLMs? So, all these open source applications, Linux, FreeBSD, all these things are open source. They all get trained. It's not hard. Look at how big the open source community is. It's large. Yeah, okay. So, I guess that sort of explains the training data that they may have used. I probably doubt there is any synthetic data that they are using here to train the models, but clearly that part is not very well understood. And so, you guys are part of that project, glass wing that they have announced and what they're doing with that or not. That's correct. So, they had a few dozen companies. We have been part of it. They make one announcement. There are multiple coming after that. But we have been part of it for several weeks actually. And what does that project entail in terms of what are the kind of the key focus? So, essentially what Anthropic has told, Anthropic's view was, let's provide access to this model to a smaller group of companies who play a critical role in making sure their own offerings and services are secure and don't have serious vulnerability. And so, these companies are protecting the nation and all kind of customers of the. So, giving them early access. It's almost too similar to what Microsoft has done at a smaller scale. Microsoft has been finding lots of security vulnerabilities in windows operating systems and other applications. Because there are new vulnerability comes. But the last several years, we have been part of the program. And the Microsoft will give us access to those days or a week or two ahead of time. So, these things can be passed or taken care of. And then it gets made available abroad. MeTos is being a far more impactful program. So, they did it in a smart and responsible way. And so, these scalers physically also announce a partnership with OpenAI. And that's separate from project glassving, right? Similar but separate. You would expect that OpenAI also is competing in the same market and space. So, they want to make sure they can play in the cybersecurity space and they have important partnerships. So, what is driving all these frontier LLM companies to focus on cybersecurity all of a sudden? I thought their focus was more on search and you know, agent take functionality like suddenly cybersecurity seems to have been front and center for frontier labs. Yes. But if you start, how Claude started, right? Claude came, Gemini was there. These things are leaf frogging. About three months ago, we used to say, OpenAI chat, GPU is wonderful. Then Gemini 3.0 came around. Much powerful. Then Claude came around. Then Claude called for Cobra, got announced and you saw some big hit on some of these companies out there. Claude called for Lockheed around. Claude for Design came around. I think the reason you're getting more interest in cyber is because cyber says you can't get it. could get in trouble. You could have cloud code for cobalt or design. It's not going to happen overnight. In cyber, the big concern of enterprises and governments is that if these vulnerabilities get discovered by bad guys, and the same AI can help to exploit them, it's a dangerous thing. So it's natural that everyone is worried about cyber, and that's why you're getting all the attention and coverage. So what is the worst attack that you have come across where it feels like a couple come to my mind, where the Mexican government was recently hacked, and they had some sort of a breach where LLMs were used as a tool. So help us frame what are the capabilities of these coding agents to initiate sophisticated attacks? Because I thought for a while, we were really concerned about the state-sponsored attacks, and they were very sophisticated, but I feel the LLMs take that sophistication to a new level now. Absolutely. I mean, they are like one with top, top notch, wide call, a wide call hackers, right? So think of it. These agents know how to code. You can tell them to code. And you can also tell them how do you exploit a given vulnerabilities? So it can essentially put the whole code together to exploit vulnerabilities. It's very natural. The expert who knows how to write code also knows how to write code to exploit the code. It's that simple. That's why the big risk is. So it's a race. So these powerful technologies, they are helping companies like us to provide better security, better software, and better tools for our customers. But again, they're also being abused by bad guys. Our goal is to stay ahead. So there are many things that play into it. For example, if you just focus on who can eliminate all vulnerabilities faster, they'll never happen. Software will always have one. It is not enough time and resources to get it off it. They have better protections. I learned very early on in my childhood. It said, if you want to protect yourselves from all the thorns in the world, and this tone came in coming from Indian village background, OK? You will never be able to get it out the world of all the thorns. But if you put shoes on your feet, you can go around. That's the one who cares. Similarly, I believe that all the vulnerabilities are softwill, never be taken care of. But if you do better protection, you're doing a better job. For example, I talked about zero-trust architecture, puts applications behind its exchange. So hackers can't even scan them and discover them. So while you do want to focus on taking on some of the vulnerabilities, you'll never have enough time. Our recommendation is, number one step you should do is hide your applications. Number two step you do is prioritize the vulnerabilities and the one that are at the highest risk focused on fixing it. Number three, there are things like this. If a bad actor happens, it comes in. They want to get on your network, try to find your servers, use something like decoy technology. Because if they get in, they could fall for a honey pot and get caught and you can take care of them. After all, defense is a multi-layer strategy. And that's what we advocate to our customers. So all this, I mean, your think about softwill always have vulnerabilities, definitely resonates. The problem right now, I guess the confusion that people have is a lot of the new stuff is being written for agents. It's not really for human users or software. So in a world where the agents are doing work on your behalf and it's productive work, how do you protect the agents of users? Right. So look, today a user is the weakest link from cyber point of view. Tomorrow AI agents will be the weakest link. Imagine agent, only on corporate network getting hacked or hijacked. Therefore, more dangerous. Because these guys act in milliseconds. And the number keeps on growing. And they need no sleep, no coffee break, no vacation or weekends. So they are more dangerous. This is how we look at it. The biggest risk is an infracted user machine or agent on your corporate network. Once they're on the network, they move left, they move right, they find mission critical applications, they take them down or they encrypt them. That's the biggest risk in the zero-trust architecture. A user is always untrusted. AI agents will always be untrusted because AI agents is fundamentally a digital worker. It's almost like a user. The way Z-skiller pioneer zero-trust was, a user comes to our exchange, our switchboard. We check who you are, what you're allowed to access. Then we connect them to a particular application and that application only a never on the network. Agents will be no different. Agents could be generally they start from the end user machine. That's OK. They come to our exchange. We check identity. The policy connection gets made. It's very similar that what's different is the identity of the agent gets a little bit tricky and harder than users because they come and go. Identity will become more dynamic. But the policy engine is not very different. Just like users are said are supposed to have this group of users can only access this group of application. Agents are the same thing. If your agents have only access to certain things and they're not on your network, you're in far better shape. That's what zero trust becomes. Bring to agent security. We call it zero trust for AI agents. Yeah. And in that example, I feel like the Palo Alto's acquisition of cyber art for identity. It sounds like strategically that seems to be the right bet because identity is going to become a lot more important in that framework that you just described where there are so many agents who are coming in and they need to be validated for identities. Is that something you're missing in your portfolio? So your statement, I partially agree. Identity is important, will be important. But who should be the right provider of identity? Is the big question. You know when workloads came around 6, 7 years ago, there are a few dozen companies that said, we're going to create identity workloads because identity is important. Those companies have come and gone because hyper scalers did not want to embrace the identity offered by these small companies. And they built their own identity. They start to build tags and labels to identify workloads. And that's is being used as identity for workload to workload zero trust communication. Tons of these customer are doing that. Similarly, hyper scalers want to create identity when they create agents. Microsoft has already done so in Entra ID and it's already integrated with ZSKID. Google wants to create identity for this agent, AWS, Salesforce, all of them guys. So I think for a company to say, I want to be the identity provider. Is a long shot. I think what's going to happen is, identity will come with agents that are created by these development platforms. And ZSKID wants to be the broker of the identity. We take the identity from the developer and we use it for policy. And then we make the right connection. That is the right approach. I want to be the Switzerland. Rather than compete for creating identity. I want to work with hyper scalers to take their identity and use it for policy enforcement. Yeah. And anything else that would be more relevant from a cyber portfolio perspective given, you will probably have a multiplier effect when it comes to the number of agents that are working on behalf of a user. So I can clearly see that multiplier effect of agents. And it sounds like there isn't a standard protocol yet when it comes to this agent behavior but would be curious to hear your thoughts on those two things. Yeah. So first of all, we do expect a number of agents to grow significantly. That means a risk growth significantly. but there's some in the traffic goes significantly. We see it as a big opportunity. opportunity for Z-scaler. We pioneered zero-trust exchange for users, and agents saw similar to users, a lot more bigger volume and moving fast. We are in the best position to extend our exchange from users to agents. That's point number one, point number two. There are a few things that are different. Identity is different, and we'll work with all leading companies to take their identity and use it as a part of the policy engine. Please, there are some of the other protocols that are needed. For example, MCP protocol, A to A protocol. We are integrating with them. So having MCP gateways as a part of exchange or A to A gateway is an actual thing which acts as a translation to be able to talk to different parties and apply policy. It is about policy to say, these agents can access only these applications. Is the fundamental thing we need for better security and better use of AI agents? >> So as a company that owns a lot of data centers, and are you guys investing in GPU infrastructure or doing things around reinforcement learning or anything that these frontier labs are doing? So first of all, we have a co-location where our systems are setting to process and policy enforcement. Adding GPU capacity to them is a natural thing. The way we've always done is we are able to do lots of traffic in our own data centers, and also we use hyperscalers for some of the things that make sense. So combinational our own and hyperscalers, yes, when it comes to inference, we do need use them. I think when it comes to training, generally gets kind of viewed that, training is extremely expensive. I think it's misunderstanding. If you want to train something on the world's data, then it's very expensive. A lot of stuff we do in the cyberspace, doesn't have as much data. So those small language models are not that expensive to train, and they work pretty well. So we are using GPU as needed where they're needed. I thought cyber generated the most telemetry data out of any other sector. So it does, very true. In fact, we do over 500 billion transactions logs a day. But that number dwarfs, as compared to when you need to train, cloud or chat GPT on the whole world's data. - Wow, wow. Okay. (laughing) And so when it comes to your own R&D spend, like how has that changed over the past 12 months, given all the developments that we have seen around the frontier labs focused on cybersecurity? So ability to write code, generate code with these tools such as cloud code or Google code assist or cursor of the world is quite promising. We are able to build some of the applications or refactor some of the old code, probably in weeks that would have taken months. So it is big need to show some pretty impressive results better quality code in a shoulder amount of time. So that's very useful. We are embracing it big time. But having said that, we are careful, for example, when it comes to the code I have for inline inspection with SSL and all that stuff to take some critical decision, we aren't having an agent write that code. Okay. But there are lots of areas where they can write code for us in some of the UI UX, very reporting analytics, security operations, they do very well. I was talking to CEO of very large bank because he's got a customer in APJ. He had a similar view. He said, we love to use AI for many areas. For example, he said for customer support, we are using a lot of it. But when it comes to my core banking applications that's used for transferring hundreds of millions of dollars every day, we are very cute who touches that code. Yeah. Yeah. No, that makes a ton of sense. And I guess in terms of the business model shift, one thing we've been hearing from companies is like they're getting charged on tokens. So if it's a token that is helping a company drive a productive output, then you're paying a higher price for that token compared to something that's more pilot or still being trialled. So in the world of cybersecurity, how would this whole notion of measuring output by tokens and the quality of tokens, how would that feed through the business model? Fundamentally, the underlying principle is, can you charge by the amount of work you're doing? Mm-hmm. And amount of work could be measured by the amount of traffic flow, the number of requests, and number of tokens. And it's a little bit tricky. Same request, one request could use lots of top tokens as a small number of tokens. That's where the world is trying to figure out. CIOs are trying to figure out what will my cost be if I use this application? While vendors probably all want token based on it. And as application can more sophisticated, probably for the same request, they'll use more tokens out there. The CIOs and CIOs are worried about my budget by spend they want predictability. Yeah. So practically speaking, this thing will settle somewhere in between, the token will be a factor of it. Number of requests will be a factor of it. But it couldn't be just purely token based because it just breaks the predictable budget model for CIOs and CIOs. Yeah, especially I thought that was one of the reasons why we moved from a licensed to a subscription model to give everyone predictability. And now we've just, I guess, changed that completely with this tokenization. That is correct. This is still being talked about. It'll be a little bit back and forth between customers and providers. And I think it'll settle somewhere which is good for both parties. Okay, so changing gears, I want to touch on this notion of, more fragmentation in the cloud world because of NeoClouds now, if you know, providing a lot of GPU compute. One of your partners has been quite explicit with their alliances when it comes to, you know, partnering with NeoClouds. How are you thinking about NeoClouds as obviously entities that are providing inference compute? And training compute and how big could that opportunity be? See, personally, I naturally see as the market moves, NeoArea comes in, new companies create, these new cloud folks are coming out to, but hyperscalers are also able to add the same kind of capabilities out to you. No, it's a matter of price performance comes in. It's not that NeoClouds can give you better price performance. Hyperscaler can give you price performance too. It's a matter of demand and supply and how much market cloud you have. And also in many cases, you need traditional compute and the GPU's compute as well at the same time. So I personally believe that hyperscalers will play a pretty meaningful role as we go forward in the world of AI and the world of providing you the GPU's you need. And in the world of NeoCloud, there'll be lots of new cloud companies that are coming, they'll come on the scene. A small number of them will survive. Most of them will disappear. That's all. Everything works. Right? The Darwinism survival of the Fertest is normal part of business. So how are you thinking about your CapEx and infrastructure spend going forward in light of how we are witnessing this super AI super cycle play out and really the CapEx numbers from the hyperscalers don't seem to be taking a breather and everyone seems to be continuing to spend on CapEx for AI. - That's very true. It's one of fairly tough questions. We're all trying to figure it out. Where does it go? What does happen? On a hyperscaling, spending too much. Yeah, also then. related topic then, when the hardware's bought by say, hyperskillers, he's a five or six year period to spread the cost over. Now, some of these GPUs are coming at a much faster pace. Now, will that the life cycle reduce from six years to three years? And the driver for that may not be just a GPU compute. It's a power power is becoming a constraining factors. So some of these hyperskillers may have to move the new models, new chip models to really have better utilization because of power constraints. So our strategy is a combination of the two. We are using the capacity coming from hyperskillers or will use neoclades as needed and some of our own. And as we learn from it, we will expand it as needed. Got it. Okay. I always like to end with a lightning round so that we can cover a few more topics with you. So, yeah, we'll try and cover a few more topics we haven't touched on in this last five minutes. What is the future of SOC given, my toes and all the things that we have discussed so far in this episode? SoC, the security operations is probably the biggest thing that get disrupted the AI. It's an ideal application. AI agents are able to do it. In fact, a company be acquired called Red Canary has been using AI agents to do the work off security analysts to make it more productive. They'll get this impacted and companies like Zee Schiller has that has tons of telemetry and tens of logs are pretty well positioned to disrupt some of the companies that have been in this space. So it's an area of big investments for Zee Schiller. So security has always been a fragmented market. Do you think that could change with what we are witnessing now with the frontier lab capabilities around cybersecurity? The answer is yes and no. The reason security is fragmented is security needs a lot more constant innovations that big companies generally don't do. So new companies come around with better innovations. And but our CISOs don't want 50 point products. They want a smaller number of platforms that work well together. So you'll see consolidation, but there's no such thing as consolidation to one God security platform that does everything. You'll have a handful of platform provider security. They'll become pretty dominant. And that's what Zee Schiller is position to do so. But there'll be lots of new companies coming. Most of them get acquired and they'll become for the platform story. Are you concerned about the slow down in employee growth for a lot of standard prices, including tech companies as a result of the productivity benefits that we may see from LLMs. So yeah, the market is trying to figure out how much growth will happen, how much growth won't happen. And I generally see the trend where the hiring growth is slowing down. Okay. And to some degree and the CEOs and trying to figure out how much of automation can be done with the AI. The impact is happening. The question that's still being debated is how much impact that point number one point number two, Zee skillers revenue or ARR is linked to multiple factors, not just the number of users. Many times investors think that if your subscription model is linked to users, then your growth may get limited. Zee Schiller charges some of these products on a subscription basis by number of users. That's one piece. But when we do cloud workloads, it's not users and the number of cloud workloads is growing. We are doing zero trust for IoT, O T devices. Those numbers are going through the roof. And that's important. And when we do data security, some of it is linked to users. A lot of us linked to how much data are we able to classify and secure. And lastly, as AI agents come on the scene as the big need to come, our subscription will be linked to number of agents plus the amount of traffic and requests and tokens alike. So I think we are pretty well covered since our subscription is linked to a whole number of variables, not just users. Great. And last couple of questions. So obviously the Middle East situation is very unfortunate. And just curious if you had to make any adjustments to your business because of that. And if you were impacted as a company. So the Middle East is bringing a couple of sound fronts, a couple of things are for fun. Number one. Countries are wanting more of sovereign clouds under their control because they want to make sure critical infrastructure is under their control. That's part number one. Part number two, we're also seeing from any conflict just like we saw the conflict of Ukraine, you see the Middle East, a lot of hacking activity starts picking up. And it's basically raising awareness in the mind of CEOs to make sure they are more focused on understanding the risk and embracing zero to architecture. So we are actually pursuing both of those opportunities to help our customers. Actually, it took me to the last question that I had was around sovereign investments. So do you think in this area of, you know, we talked about CapEx from hyperscalers, how big of an opportunity will it be in terms of sovereign clouds? And would that be a bigger opportunity for someone like you, a pure place, cybersecurity vendor given, you know, the sovereign clouds will want to build their own infrastructure and protect it themselves? Sovereign cloud is a natural thing where countries want to control everything that has to do with the critical infrastructure. If all your applications are running in some cloud, whether it's Germany or UK or France or India, they want the full control operational sovereignty. So sovereign cloud comes in a few flavors. Data sovereignty is not hard. And these from Zeesk and upon we built our cloud for data sovereignty from day one, operational sovereignty with all operations of the cloud will be done in a given country is the next big thing countries are asking for. And we have been working on it for quite some time. First, we had to set up the sovereign literally the sovereign cloud for US government that's sitting under their control and used and run by and by entities that are sovereign outside the control of a broad public cloud. Some of the leading European countries are very actively pursuing it. And we're working with them. We think it's a good opportunity, but you won't see sovereign cloud being done in every country. It did the overhead and expertise to do it. Not there. We're going to start seeing sovereign cloud starting with some of the large countries in in the Western world or in a PGA countries like India, Japan, Australia, UK, Germany and France are actively pursuing sovereign clouds. And we see is that a good opportunity to help our customers and those countries. Actually, I'm going to ask you this question, which I asked you though in the last episode, which you recorded with us as well, any misconceptions about Z scalar that you want to clear on this podcast. Many customers are confused about zero trust. They think that they can spend firewalls in the cloud and VPN on the cloud and they do zero trust. Unfortunately, firewall vendors are trying to perpetuate that understanding because they don't want to get disrupted. Just like you can't convert a traditional internal combustion in your car to an electric car by bolting on an engine, you can't really build zero trust on top of firewalls and VPNs. And it's not that those companies can't build zero trust, but they're worried about building zero trust because zero trust would disrupt the need for all these firewalls of VPN. The business gets impacted. So he's got a doesn't have to worry about disrupting the legacy technologies. So our customers, Z scalar customers understand zero trust very well. That's over 45% of the fortune-fired companies. And we want to secure the remaining 55% with zero trust as well. Great. Jay, it's been an absolute pleasure having you back on the podcast. You've been very generous. for your time. Thank you again and I want to wish you the very best for the rest of the year. - And Deep, thank you so much. It's always a pleasure to talk to you.

Podcast Summary

Key Points:

  1. Anthropic's Claude Mithos model can identify software vulnerabilities quickly and at scale, but the main challenge for enterprises is not discovering vulnerabilities—it's having the time and resources to fix them.
  2. Zscaler's zero-trust approach hides applications behind a secure exchange, preventing attackers from scanning or reaching them, which is a practical defense even when vulnerabilities exist.
  3. AI agents are becoming a new weak link in cybersecurity; they must be treated as untrusted digital workers, with identity and policy enforcement similar to human users but requiring dynamic identity management.
  4. Zscaler does not aim to be an identity provider; instead, it brokers identity from hyperscalers (e.g., Microsoft, Google) for policy enforcement, acting as a neutral "Switzerland."
  5. The company uses GPUs for inference and small language model training (which is less expensive than training on world-scale data) and embraces AI coding tools for non-critical code, but avoids using AI agents for core security functions like SSL inspection.
  6. Business models may shift toward charging based on work volume (traffic, requests, tokens), reflecting the amount of processing or protection provided.

Summary:

In this podcast, Jay Chaudhry, CEO of Zscaler, discusses the implications of Anthropic's Claude Mithos model for cybersecurity. He explains that while Mithos can rapidly discover vulnerabilities, the real issue for enterprises is the lack of time and resources to fix them all. Instead of trying to eliminate every vulnerability, Chaudhry advocates for a zero-trust architecture that hides applications behind Zscaler's exchange, preventing attackers from scanning or reaching them. He compares this to wearing shoes to protect against thorns rather than trying to remove all thorns from the world.

Chaudhry addresses the growing threat of AI agents, which he views as digital workers that are always untrusted. Zscaler plans to extend its zero-trust exchange to handle agents, using identity from hyperscalers like Microsoft and Google for policy enforcement rather than competing to be an identity provider. He also notes that Zscaler uses GPUs for inference and small language model training, but avoids using AI agents to write critical security code. The company embraces AI for non-critical tasks like UI and analytics, seeing significant productivity gains. Finally, Chaudhry suggests that cybersecurity business models may evolve to charge based on work volume, such as traffic or tokens processed.

FAQs

Mithos can identify security vulnerabilities quickly, adding to the existing list enterprises struggle to fix due to time and resource constraints.

Zscaler hides applications behind its exchange, preventing hackers from scanning or reaching them, even if vulnerabilities exist.

Mithos, as a highly trained AI, can detect and exploit vulnerabilities at scale, while only a small number of skilled humans can do so manually.

Project Glasswing gives select companies early access to Anthropic's Mithos model to secure their services, and Zscaler has been part of it for weeks.

AI agents act in milliseconds, need no rest, and can be hijacked, making them a more dangerous weakest link than human users.

Zscaler treats agents like untrusted users, using its zero-trust exchange to check identity and policy before connecting them only to authorized applications.

Chat with AI

Loading...

Pro features

Go deeper with this episode

Unlock creator-grade tools that turn any transcript into show notes and subtitle files.