Truth in IT
    • Sign In
    • Register
        • Videos
        • Channels
        • Pages
        • Galleries
        • News
        • Events
        • All
Truth in IT Truth in IT
  • Data Management ▼
    • Converged Infrastructure
    • DevOps
    • Networking
    • Storage
    • Virtualization
  • Cybersecurity ▼
    • Application Security
    • Backup & Recovery
    • Data Security
    • Identity & Access Management (IAM)
    • Zero Trust
    • Compliance & GRC
    • Endpoint Security
  • Cloud ▼
    • Hybrid Cloud
    • Private Cloud
    • Public Cloud
  • Webinar Library
  • TiPs
  • DRAW

Zero Trust Cellular SIM for IoT and OT Device Security

Zscaler
04/06/2026
0 (0%)
Share
  • Comments
  • Download
  • Transcript
Report Like Favorite
  • Share/Embed
  • Email
Link
Embed

Transcript


about stuff. And when I say stuff, I'm talking about devices and no, I'm not talking about your Windows laptop, Mac OS, iPad, Chrome, Firefly, none of that stuff. We're talking like different type of devices and these are devices that maybe you're selling to your customers. Maybe it's a car of some nature that's kind of internet connected. Maybe you sell some cameras. Maybe it's a Chupacabra. Just kidding. It's your devices. Maybe you have like a internet connected car. Maybe you have an autonomous vehicle. Selling IP based cameras that are doing all kinds of cool reporting. Shipping containers. Maybe it's a gas station point of sale. You have your IIOT. You have your OT. Heck, you may even have an ambulance that's reporting back critical vital signs back to the ER where they're about to take a patient. So again, like this isn't like your run of the mill devices. This is something, a product or service that you're giving to your customers. Now with that said, these things are never one and done. They need to be touched every once in a while and so they're going to have to grab updates and maybe you're like my grandpa and you're like, oh, you know what, we have a perfect place to host these applications that need to come up and it's called the data center and that's cool. It doesn't really matter to me. We can kind of make all things work and so we'll call it applications A and B for these updates for these devices that need to kind of come back over here and communicate or a little bit, you know, maybe you're thinking we're going to do this stuff in the cloud and good news is I can support you there as well. So we have the cloud, your usual suspects, Azure, AWS, GCP, OCI, and it doesn't really matter and maybe those are similar applications or maybe there's completely different and we'll just call them application C and D. Now when we look at this, we have to figure out like these devices need to be able to connect back, right? Like how are they going to do it? So maybe one of them would be like, hey, we're going to send traffic right here. It's going to beacon back over to the public cloud going out to application C and you're going to do something to, you know, posture this username, password, maybe certificate. But the idea is you're starting to develop what I call an attack surface, right? So it's kind of a negative thing. So we'll say, hey, if it's reachable, it's breachable. And that's always a bad thing. Now, back at the data center, you could be publicly facing these these applications as well, or you'd be doing something like a VPN type of client. And again, lots of problems with it. It's in there waiting for what? Waiting for your devices to come back over there and phone back home. But the challenge with that is it's also open to the entire Internet. It's going to be a little bit messy. And so we look at that and say that's going to be a challenge. And the other part to VPN is that you are taking the biggest liability in your life, which is a device like third party device and putting it onto the network. And that's going to do the whole like lateral movement. It's not very zero trust us at all. So that's kind of a negative. And the next one that I look at is that in order for you to do this whole VPN connectivity, chances are you might have to install a client right here. So they have to worry about is the client up to date? Is it running correctly? Is it always on? So that'd be a challenge. And then also, when you think about that, you have clients to contend with and then you have complex networks as well. So you're going to think of patches, maintenance, upgrades, scale events, all those things in top of policy to kind of orchestrate this. And again, it's doing it from a device that is somewhere that generally is out of control, but it needs to be updated. And I look at this and say that there's got to be a better way. So using the power of post editing, I snap my fingers. I'm going to clean this light board and we're back. It's already looking better, if you ask me. So for those of you watching, you may have seen some stuff. You know, it's coming. I know it's coming. What we're going to do right here is talk a little bit about the Zero Trust Exchange, the Zscare Cloud. And before you fast forward or even click off, just know that there's a little bit more going on here than meets the eye, but we'll back into it. So some of the fundamental architecture that you're already familiar with is around the ability to reduce your attack surface. So that's the first thing that we kind of focus in on. Very squeaky today. So by first and foremost, by reducing the attack surface, what I want to do is I don't want to have to deploy VPNs and I want to take every single application that you guys have and hide it back behind the Zero Trust Exchange. There is no inbound access to it. It's just an any any deny. It's completely dark. You can't hack what you can't see. And for those of you watching, maybe you're like, oh, how does that work? With Zscare VM, it is kind of has the ability to talk internally to the applications, but instead of allowing traffic in, it does like this whole like inside out connectivity to the Zero Trust Exchange. Simple as that. Same thing over here in the cloud. It doesn't really matter which cloud you're working on. It's that very same fundamental architecture. Now, you might be looking at this and saying, oh, yeah, we know how to do this. You're going to convince us to install a client or an SDK. And the answer is actually, no, I'm not going to do that at all. Whatsoever. So instead, what I'm going to do is I'm going to position something a little bit different. And these devices, they're Internet connected, right? And the way that they're usually connected is with like Internet service of some nature. And what we have here is the Zscare cellular SIM. Now, this is available in two flavors, either physical SIM or an eSIM, but either case, you're good to go. And what's kind of neat about that is this is going to be my feeble attempt at drawing like a cellular network. So we're going to come over here. It looks like this, I think, a little thing beaconing out. And it doesn't matter where you're at in the world. The way that the SIM card works is, again, there's no client and there's no SDK. Just plug it in. And 100 percent of that traffic originating from this device is going outbound to the Internet. Now, it doesn't really matter what that device is in the world. This is going to be a service that works anywhere where it's, you know, U.S., APAC, RMEA and vice versa, right? It's taking this traffic across that any mobile network in the first stop is going to be the zero trust exchange. And this gives us the ability when the traffic arrives here to do true zero trust policy. That means you can get, you know, complete control and visibility. Into your traffic and what's going on. So when we look at this, we're just going to basically meet in the middle as we've always done. But we're doing this without a client that allows these devices to communicate back to these applications without putting the device on the network, reducing your attack surface and all that good stuff. Now, I'm sure somebody here. Is saying, oh, we're going to qualify outbound. We like our expensive networks and complexity because we, for whatever reason, we need to actually come up. We actually have the ability to come back over here and talk to this device. Well, guess what? I'm about to hit you with the Steve Jobs moment. There's one more thing. So let's take that employee, that user. They're over here. They're at home. Starbucks, abroad, in the office, it doesn't matter. They have Zscare Client Connector on their laptop and that traffic always comes in right here. And I know you're thinking, oh, Brian, are we going to take the traffic and bring it over here and do something weird and push an update? Absolutely not. So not only do I allow this to communicate directly here and talk to these applications, I can take a sanctioned user that's past posture. I can actually allow them to come back this direction to the device. So if you think about it, maybe as you're doing some advanced troubleshooting, you'll be able to pull logs and telemetry off of there on a whim, or even maybe you need to push an update because it's an OT device in a segmented network, you're going to be completely covered. So when we look at Zscare Cellular, it gives us the ability, right, reduce the attack surface. You can't have that lateral movement. There's no client, no SDK, zero trust policy that gives you the ability to do complete control and visibility. And ultimately, what we're doing is we're driving down risk entirely. Time to values be much quicker. And last but not least, you're going to be saving me a ton of money because you're not having to deal with patches, maintenance, upgrades and scale events. You're just going to set a policy and forget about it. And with that said, that's my time. Thanks for watching. Do me a huge favor. Reach out to your local sales team. We'd love to talk to you more about Zscare Cellular. Have a good day.

TL;DR

  • Zscaler Cellular is a physical SIM or eSIM that routes all device traffic through the Zero Trust Exchange without requiring any client software or SDK installation on the device itself.
  • The solution addresses security challenges for non-traditional connected devices like autonomous vehicles, IoT sensors, OT equipment, and point-of-sale terminals that need periodic updates but cannot run traditional security agents.
  • Applications remain completely hidden from the internet with no inbound access—only outbound connections to the Zero Trust Exchange—eliminating attack surface and preventing lateral movement.
  • Authorized users can establish secure reverse connections to devices for troubleshooting and updates while maintaining full zero trust policy enforcement and visibility across global mobile networks.

The Challenge of Securing Non-Traditional Connected Devices

Organizations increasingly deploy internet-connected devices that fall outside traditional endpoint management—autonomous vehicles, IP cameras, shipping containers, point-of-sale terminals, IIoT sensors, OT equipment, and even ambulances transmitting patient vitals. These devices require periodic updates and connectivity back to applications hosted in data centers or public clouds like Azure, AWS, GCP, and OCI. Traditional approaches create significant security challenges: publicly exposing applications creates attack surface where anything reachable becomes breachable, while VPN-based solutions require client installation on devices that may not support agents, place untrusted third-party devices directly onto corporate networks enabling lateral movement, and introduce operational complexity around client maintenance, patching, and network infrastructure management.

Zscaler Cellular Architecture and Zero Trust Implementation

Zscaler Cellular introduces a fundamentally different approach by embedding security directly into a physical SIM or eSIM card. When installed in any cellular-connected device, 100% of traffic routes through the Zscaler Zero Trust Exchange before reaching any destination—eliminating the need for client software or SDKs entirely. Applications in data centers and clouds connect to the Zero Trust Exchange via outbound-only connections using Zscaler VM, making them completely dark to the internet with no inbound access permitted. The solution works globally across any mobile network in the US, APAC, and EMEA regions. Beyond device-to-application connectivity, authorized users running Zscaler Client Connector can establish reverse connections to managed devices for troubleshooting, log retrieval, or pushing updates to OT devices in segmented networks—all while maintaining zero trust policy enforcement with complete control and visibility over traffic flows.

Chapters

0:00 - Introduction to Non-Traditional Devices
1:08 - Device Connectivity Requirements
2:04 - Traditional Approach Problems
4:04 - Zero Trust Exchange Architecture
5:43 - Zscaler Cellular SIM Solution
7:27 - Bidirectional Device Access
8:28 - Summary and Benefits

Key Quotes

2:26 "So it's kind of a negative thing. So we'll say, hey, if it's reachable, it's breachable."
3:05 "And the other part to VPN is that you are taking the biggest liability in your life, which is a device like third party device and putting it onto the network."
5:00 "It's completely dark. You can't hack what you can't see."
6:26 "Just plug it in. And 100 percent of that traffic originating from this device is going outbound to the Internet."

Categories:
  • » Webinar Library » Zscaler
  • » Cybersecurity » Network Security
  • » Cybersecurity » Zero Trust
  • » Data Protection
Channels:
News:
Events:
Tags:
  • Zero Trust
  • OT
  • IoT Security
  • Network Security
  • Technical Deep Dive
  • Demo
  • Zero Trust Security
  • Cellular SIM Security
  • IoT Device Protection
  • OT Security
  • Attack Surface Reduction
  • Agentless Security
  • Mobile Network Security
  • Device Connectivity
Show more Show less

Browse videos

  • Related
  • Featured
  • By date
  • Most viewed
  • Top rated
  •  

              Video's comments: Zero Trust Cellular SIM for IoT and OT Device Security

              XStreaminars (watch here)

              • Jul
                28

                Illumio + Netskope: Zero Trust in the Age of AI Autonomy

                07/28/202601:00 PM ET
                • Jul
                  29

                  Ask Your Cloud Anything: Unlocking Governance Silos in your Environments

                  07/29/202601:00 PM ET
                  More events

                  Industry Events (watch there)

                  • Aug
                    06

                    Mitigating Risks of Sensitive Data Exposure in AI Platforms

                    08/06/202604:00 AM ET
                    • Aug
                      06

                      Same Tactics, Enhanced Velocity: The Impact of AI Agents on Identity Attacks

                      08/06/202602:00 PM ET
                      • Aug
                        07

                        Discover DLP Memories: The Evolving Triage Agent That Learns Each Shift

                        08/07/202611:00 AM ET
                        More events

                        Upcoming Webinar Calendar

                        • 07/28/2026
                          01:00 PM
                          07/28/2026
                          Illumio + Netskope: Zero Trust in the Age of AI Autonomy
                          https://www.truthinit.com/index.php/channel/2031/illumio-netskope-zero-trust-in-the-age-of-ai-autonomy/
                        • 07/29/2026
                          04:00 AM
                          07/29/2026
                          Real-Time Strategies for Safeguarding Against Prompt Injections
                          https://www.truthinit.com/index.php/channel/1968/real-time-strategies-for-safeguarding-against-prompt-injections/
                        • 07/29/2026
                          01:00 PM
                          07/29/2026
                          Ask Your Cloud Anything: Unlocking Governance Silos in your Environments
                          https://www.truthinit.com/index.php/channel/2048/ask-your-cloud-anything-unlocking-governance-silos-in-your-environments/
                        • 08/06/2026
                          04:00 AM
                          08/06/2026
                          Mitigating Risks of Sensitive Data Exposure in AI Platforms
                          https://www.truthinit.com/index.php/channel/2058/mitigating-risks-of-sensitive-data-exposure-in-ai-platforms/
                        • 08/06/2026
                          02:00 PM
                          08/06/2026
                          Same Tactics, Enhanced Velocity: The Impact of AI Agents on Identity Attacks
                          https://www.truthinit.com/index.php/channel/2064/same-tactics-enhanced-velocity-the-impact-of-ai-agents-on-identity-attacks/
                        • 08/07/2026
                          11:00 AM
                          08/07/2026
                          Discover DLP Memories: The Evolving Triage Agent That Learns Each Shift
                          https://www.truthinit.com/index.php/channel/2062/discover-dlp-memories-the-evolving-triage-agent-that-learns-each-shift/
                        • 08/07/2026
                          11:30 AM
                          08/07/2026
                          Refreshing Beverage Ideas Paired with Essential Cybersecurity Insights
                          https://www.truthinit.com/index.php/channel/2063/refreshing-beverage-ideas-paired-with-essential-cybersecurity-insights/
                        • 08/13/2026
                          12:00 PM
                          08/13/2026
                          Harnessing AI for Secure Innovation in the Enterprise with Netskope & Omada
                          https://www.truthinit.com/index.php/channel/2065/harnessing-ai-for-secure-innovation-in-the-enterprise-with-netskope-omada/
                        • 08/19/2026
                          12:00 PM
                          08/19/2026
                          Becoming Agent Ready: Insights and Strategies with Cyera
                          https://www.truthinit.com/index.php/channel/2036/becoming-agent-ready-insights-and-strategies-with-cyera/
                        • 09/02/2026
                          12:00 PM
                          09/02/2026
                          Unified Data Security in Action: Uncover, Analyze, and Resolve Threats
                          https://www.truthinit.com/index.php/channel/2045/unified-data-security-in-action-uncover-analyze-and-resolve-threats/
                        • 09/30/2026
                          04:00 AM
                          09/30/2026
                          AI Command Center: Optimizing Visibility and Control in Your Operations
                          https://www.truthinit.com/index.php/channel/2024/ai-command-center-optimizing-visibility-and-control-in-your-operations/
                        Truth in IT
                        • Sponsor
                        • About Us
                        • Terms of Service
                        • Privacy Policy
                        • Contact Us
                        • Preference Management
                        Desktop version
                        Standard version