Truth in IT
    • Sign In
    • Register
        • Videos
        • Channels
        • Pages
        • Galleries
        • News
        • Events
        • All
Truth in IT Truth in IT
  • Data Management ▼
    • Converged Infrastructure
    • DevOps
    • Networking
    • Storage
    • Virtualization
  • Cybersecurity ▼
    • Application Security
    • Backup & Recovery
    • Data Security
    • Identity & Access Management (IAM)
    • Zero Trust
    • Compliance & GRC
    • Endpoint Security
  • Cloud ▼
    • Hybrid Cloud
    • Private Cloud
    • Public Cloud
  • Webinar Library
  • TiPs
  • DRAW

Cyber Risk Quantification with Zscaler Risk360

Zscaler
05/08/2026
0 (0%)
Share
  • Comments
  • Download
  • Transcript
Report Like Favorite
  • Share/Embed
  • Email
Link
Embed

Transcript


You might be asking yourself, what the heck is that? It is a cyber risk quantification engine or platform. Now before I jump into exactly the specifics on that, you might be thinking, well, Zsco you're a proxy, how can you possibly play in this game? Let me outline it for you. So let's have a little conversation about where your users, your applications all exist. So maybe you have some platform as a service, infrastructure as a service over here, a little S on there, and it's your usual suspects, the AWS of the world, GCP and Azure. It could be more than that, but we'll leave it right there. And you have applications that live over here, we'll call them applications one, two, and three, but also this is really where your enterprise data could exist. And that's kind of paramount when looking at RISC. Shifting gears, you also are adopting SaaS-based applications as well. And those are your usual suspects, great partners, M365 of the world, salesforce.com, and ServiceNow. But at the end of the day, again, this is where your enterprise data could exist. Where else should your data be? Well, that's kind of simple over here at the data center. Now whether you have one data center, two data centers, trying to get out of the data center game, not that big of a deal. And at the data center, you're going to have applications that live over here as well. Applications I don't know, X, Y, and Z, but critically here, this is where your data is. I mean, you have to think holistically when evaluating RISC, how do you kind of segment that? Where's one location in which your data probably shouldn't go? That's the obvious one. It'd be the internet. Maybe your employees are going out to AOL, checking their email. Maybe going out to nefarious websites like briandeach.com. And we have to think about where your user's at, where your workload's at, and that's kind of simple. You probably have some branch offices, warehouse, factories, clinics, all that good stuff. So we'll come over here and say we got a branch. But we also have users over here. Maybe you're doing some type of fancy segmentation. Maybe you have some OT networks, IoT as well, guest Wi-Fi. Then, of course, your users aren't always at the branch or a known location. They can be kind of working from anywhere. And that's at home, Starbucks, and abroad. And, of course, we can't forget about the last little piece of the puzzle, and that's the third parties that are coming in, partners, contractors that you might have in your environment. So we'll just come over here and say third party. And really what RISC 360 is about is trying to reduce the pressure on your teams, right? Better board reporting, streamlined compliance, and ultimately just reducing risk. And so Zscaler is the glue that kind of puts that all together. So we'll come over here, draw the Zscaler cloud. And we'll just refer to that as the Zero Trust Exchange, kind of keep a high level. And the narrative is simple. And the reason why we can help quantify risk is that all roads kind of point to Zscaler. For your users that are off the network, their traffic's coming through the Zscaler Zero Trust Exchange. Maybe you're doing some Zero Trust SD-WAN over here at your branch near factories. And, again, that traffic's coming over here. The underlying narrative when going out to the internet or SaaS is to allow the good, block the bad, and stop the stupid. And then for your internal applications, we don't do silly things like VPN, right? We do an inside-out connection here. We have our little connectors that reach outbound to the Zero Trust Exchange. Have that application adjacency to your enterprise applications and your data. Same thing over here. And, of course, we're not going to forget about the third parties that are in here. They, too, are going to go through the Zero Trust Exchange. So as we look at this, one thing becomes abundantly clear. If I'm kind of like that default gateway, I become a very strategic point of control. And then I also become a very strategic point of visibility. And the biggest reason there is that not only do I see all of your flows, your users, your contractors, your remote locations, and your data centers, but I also am doing the TLS inspection to give these more visibility. Now, if we think about the other risk players and how they do it, right? They just kind of have like a third-party thing, and they're just doing outside-in. They're scanning your perimeter. They're doing domain-based analysis. And the kind of the buck stops right there. And then you have to kind of integrate other products and other feeds in there to get a better view. And so Zscare looks at this a little bit different because we are sitting in line. When we do this, we're able to produce what we call an organization risk score. And it's based off these four pillars. One is your external attack surface. Two, the ability to evaluate compromise. So that's like looking at your policy. Are you doing SSL inspection? Are you scanning for botnets? Are you blocking malware? In addition to that, we're looking for lateral propagation, which means can your users talk to every single application? Or is it kind of narrowed down to just the applications they need to be able to talk to? And last but not least, what kind of data protection are you doing? Now, we're going to take this scoring. We're going to evaluate it over time. So looking at this risk score trend, you can see exactly where you're at for the last six months, last couple of months. Obviously, you want this score to be trending down. And what's nice about this is you can compare yourself against the industry peer average score as well. And if you're like me, you're probably hyper-competitive, and you want to make sure that you're below that curve and you're looking better. However, even though Zscaler does a ton of stuff in line, we also do things out of band. And let's kind of denote that here as a dotted line, which means I can come over here into both SaaS, Platform-as-a-Service, Private Cloud, Infrastructure-as-a-Service, and do API-based scans here as well and get us increased visibility. Now, we're going to take this information. We're going to pull data from external decoys. We're doing our external scans. We're looking at top-level domains. We're looking at subdomains. We're taking the IP addresses of the host. We're doing a reverse DNS on that. We're looking at your ASNs. We're looking for CVEs and evaluating TLS versioning as well. Now, the way that we evaluate this is we're looking at factors. There are about 100 granular factors that map to these four stages. Everything that we do, it's a factor-based model. Each factor has its own data pipeline, heuristic, and weighted score, all backed by real data. This is your data, not some fake stuff that's out there. Since we are in line and inspecting all things, not only do we see the threats, we block them, we can look at the internal segmentation and find out who has access to what. Leveraging out-of-band SSPM, we can see stuff like fail logins, bulk uploads, bulk downloads, into your SaaS-based applications like M365, Salesforce.com. We have the ability to weed out the anonymous behavior, score it, and assign risk. Now, once we have assigned risk, we have the ability to map this to a financial risk. We look at these things, and we tie it over here. One of my favorite things about this platform is I'm not trying to boil the ocean. As you can see, if your financial exposure is $10.35 million, it would probably be great to get rid of all of that. With our platform, we're looking at this particular scenario. We can reduce that by $4.1 million. Right now, I'm picking on some stuff like VPN usage, posture profiles, DLP, and risky cloud applications. Now we have the ability to showcase what we're finding and give you some reporting, whether it's an SCC disclosure, cybersecurity maturity assessment, attack surface reports. These are things you can hand off to your team so that way they can take action on it. Most importantly, we have CISO board-level slides ready to take to the board and have great conversations. What does that really mean? You can track stuff over time, and you can present this to the board saying, Hey, our risk score is a 27. We want to get that down to a one. 100 would be terrible. Our average against our peers is a 51, so we're doing pretty well. Then it goes into the scoring. What's nice about this is it shows it trending over time. As you're having those meetings with the board, it makes it easier to present this. You're not mucking around in our UI trying to find this information. Again, this is real data. This is your data, not some fabricated stuff. Now we're going to take this because that's great, but our score has gone down. What does that really mean? We take that information, and we put this into our top findings. If our score is a 27, and we're trying to get it down as low as possible, what are the top things we should put our time, focus, and energy into? Right here would be an external attack surface. We have a VPN. Maybe it's time to retire that VPN. Compromise, lateral propagation, and data loss. Let's find those risky applications. Let's minimize that. Again, that's one thing to look at, but let's prioritize it a little bit more. Now we're going to take this, the four stages that we look at, the top five factors, and the financial exposure. If you do this, if you get rid of that external attack surface, that VPN there, you should be able to prevent a lot of that lateral propagation. If you can drive down that risk, you drive down that financial exposure as well. Ultimately, what you're left with is the strategic point of visibility that helps you quantify that cyber risk that's out there, figure out where in this equation you need to focus your time and effort, and more importantly, the cost savings that are associated with it. With all that said, that's my time. That is Risk 360. My name is Brian Peach. Do me a favor, subscribe if you haven't already, like this video, and leave a comment. Thank you for your time.

TL;DR

  • Risk360 leverages Zscaler's inline position as a security proxy to provide comprehensive cyber risk quantification across all user traffic, cloud environments, and data centers through both inline inspection and API-based scanning.
  • The platform evaluates organizational risk using 100+ granular factors across four pillars (external attack surface, compromise evaluation, lateral propagation, data protection) and translates technical findings into quantified financial exposure metrics.
  • Risk360 delivers board-ready reporting that tracks risk scores over time, benchmarks against industry peers, and prioritizes remediation actions by their potential to reduce financial risk, enabling data-driven security investment decisions.
  • Unlike traditional risk platforms that rely on external perimeter scanning, Risk360 combines inline TLS inspection with out-of-band cloud API scanning to analyze actual traffic patterns and security posture rather than inferring risk from external observations.

Risk360 Platform Overview and Architecture

Brian Dietsch introduces Risk360, Zscaler's cyber risk quantification platform that leverages the company's unique position as an inline security proxy. The presentation establishes how Zscaler's Zero Trust Exchange serves as a strategic control and visibility point across all user traffic, including remote workers, branch offices, third-party contractors, and connections to SaaS applications, cloud infrastructure, and data centers. Unlike traditional risk platforms that rely solely on external perimeter scanning, Risk360 combines inline traffic inspection with TLS decryption and API-based scanning of cloud environments to provide comprehensive visibility into organizational risk. This architectural advantage allows Zscaler to analyze actual traffic flows and security posture rather than inferring risk from external observations alone.

Risk Scoring Methodology and Financial Quantification

The platform generates an organizational risk score based on four core pillars: external attack surface, ability to evaluate compromise, lateral propagation potential, and data protection effectiveness. Risk360 evaluates approximately 100 granular factors across these pillars, each with its own data pipeline, heuristic analysis, and weighted scoring based on real customer data rather than theoretical models. The system tracks risk scores over time and benchmarks them against industry peer averages, enabling competitive comparison and trend analysis. Critically, Risk360 translates technical risk factors into financial exposure metrics, demonstrating how specific security improvements can reduce quantified financial risk. The platform identifies prioritized remediation opportunities that deliver measurable risk reduction without attempting to address every possible vulnerability simultaneously.

Board-Level Reporting and Strategic Decision Support

Risk360 provides executive-ready reporting capabilities designed specifically for board presentations and compliance requirements. The platform generates SEC disclosure reports, cybersecurity maturity assessments, and attack surface analyses that security leaders can present without navigating complex technical interfaces. Board-level slides track risk scores over time, compare organizational performance against peer benchmarks, and highlight top findings with associated financial exposure. The system prioritizes remediation recommendations by showing which security improvements deliver the greatest risk reduction and cost savings, enabling CISOs to make data-driven investment decisions and demonstrate security program effectiveness to executive stakeholders through quantified business impact rather than technical metrics alone.

Chapters

0:00 - Introduction to Risk360
0:23 - Enterprise Architecture and Data Locations
3:21 - Zscaler's Strategic Visibility Position
5:44 - Risk Scoring Methodology
7:32 - Factor-Based Risk Model
8:26 - Financial Risk Quantification
9:03 - Board-Level Reporting Capabilities
10:01 - Prioritized Remediation Recommendations

Key Quotes

4:18 "The underlying narrative when going out to the internet or SaaS is to allow the good, block the bad, and stop the stupid."
4:53 "If I'm kind of like that default gateway, I become a very strategic point of control. And then I also become a very strategic point of visibility."
7:42 "There are about 100 granular factors that map to these four stages. Everything that we do, it's a factor-based model. Each factor has its own data pipeline, heuristic, and weighted score, all backed by real data. This is your data, not some fake stuff that's out there."
8:38 "One of my favorite things about this platform is I'm not trying to boil the ocean. As you can see, if your financial exposure is $10.35 million, it would probably be great to get rid of all of that. With our platform, we're looking at this particular scenario. We can reduce that by $4.1 million."
10:47 "Ultimately, what you're left with is the strategic point of visibility that helps you quantify that cyber risk that's out there, figure out where in this equation you need to focus your time and effort, and more importantly, the cost savings that are associated with it."

Categories:
  • » Webinar Library » Zscaler
  • » Cybersecurity » Zero Trust
  • » Cybersecurity » Cloud Security
  • » Data Protection
Channels:
News:
Events:
Tags:
  • Cloud Security
  • Zero Trust
  • Compliance & Governance
  • Technical Deep Dive
  • Demo
  • Cyber Risk Quantification
  • Zero Trust Architecture
  • Security Posture Management
  • Financial Risk Assessment
  • Board-Level Security Reporting
  • Attack Surface Management
  • TLS Inspection
Show more Show less

Browse videos

  • Related
  • Featured
  • By date
  • Most viewed
  • Top rated
  •  

              Video's comments: Cyber Risk Quantification with Zscaler Risk360

              Upcoming Webinar Calendar

              • 06/23/2026
                01:00 PM
                06/23/2026
                The AI-Powered VMware Alternative
                https://www.truthinit.com/index.php/channel/2009/the-ai-powered-vmware-alternative/
              • 06/24/2026
                11:00 AM
                06/24/2026
                Accelerating Through AI: A Dynamic Webinar Series
                https://www.truthinit.com/index.php/channel/2012/accelerating-through-ai-a-dynamic-webinar-series/
              • 06/25/2026
                01:00 PM
                06/25/2026
                Generative AI Security: Preventing AI from Becoming a Data Breach Multiplier
                https://www.truthinit.com/index.php/channel/1998/generative-ai-security-preventing-ai-from-becoming-a-data-breach-multiplier/
              • 06/30/2026
                01:00 PM
                06/30/2026
                Mastering Active Directory Certificate Services for Long-Term Success
                https://www.truthinit.com/index.php/channel/2018/mastering-active-directory-certificate-services-for-long-term-success/
              • 07/01/2026
                04:00 AM
                07/01/2026
                Integrating Security in AI: Automated Red Teaming Strategies for Private Models
                https://www.truthinit.com/index.php/channel/1969/integrating-security-in-ai-automated-red-teaming-strategies-for-private-models/
              • 07/01/2026
                04:00 AM
                07/01/2026
                Schutz von KI in Anwendungen, Agenten und APIs.
                https://www.truthinit.com/index.php/channel/2008/schutz-von-ki-in-anwendungen-agenten-und-apis/
              • 07/01/2026
                01:00 PM
                07/01/2026
                Preventing Your AI from Turning Against You: Essential Strategies
                https://www.truthinit.com/index.php/channel/2021/preventing-your-ai-from-turning-against-you-essential-strategies/
              • 07/02/2026
                10:00 AM
                07/02/2026
                When the cloud goes dark: Resilience lessons from hybrid threats
                https://www.truthinit.com/index.php/channel/2011/resilience-insights-from-hybrid-threats-when-the-cloud-faces-challenges/
              • 07/07/2026
                01:00 PM
                07/07/2026
                A Comprehensive Demonstration of DLP Solutions and Strategies
                https://www.truthinit.com/index.php/channel/2030/a-comprehensive-demonstration-of-dlp-solutions-and-strategies/
              • 07/09/2026
                01:00 PM
                07/09/2026
                The HUMAN Experience: Empowering Trust Through Action and Engagement
                https://www.truthinit.com/index.php/channel/2026/the-human-experience-empowering-trust-through-action-and-engagement/
              • 07/14/2026
                01:00 PM
                07/14/2026
                Crafting a Championship-Quality Security Team for Unmatched Defense
                https://www.truthinit.com/index.php/channel/2025/crafting-a-championship-quality-security-team-for-unmatched-defense/
              • 07/21/2026
                04:00 AM
                07/21/2026
                Strategies for Managing AI Governance and Securing App-to-LLM API Traffic
                https://www.truthinit.com/index.php/channel/1967/strategies-for-managing-ai-governance-and-securing-app-to-llm-api-traffic/
              • 07/21/2026
                01:00 PM
                07/21/2026
                HUMAN Dialogue: Insights from Attackers Revealed at the FIFA World Cup
                https://www.truthinit.com/index.php/channel/2029/human-dialogue-insights-from-attackers-revealed-at-the-fifa-world-cup/
              • 07/22/2026
                06:30 AM
                07/22/2026
                Understanding the Dynamics of Data Privacy and Protection Regulations
                https://www.truthinit.com/index.php/channel/2000/understanding-the-dynamics-of-data-privacy-and-protection-regulations/
              • 07/28/2026
                01:00 PM
                07/28/2026
                Illumio + Netskope: Zero Trust in the Age of AI Autonomy
                https://www.truthinit.com/index.php/channel/2031/illumio-netskope-zero-trust-in-the-age-of-ai-autonomy/
              • 07/29/2026
                04:00 AM
                07/29/2026
                Real-Time Strategies for Safeguarding Against Prompt Injections
                https://www.truthinit.com/index.php/channel/1968/real-time-strategies-for-safeguarding-against-prompt-injections/
              • 09/30/2026
                04:00 AM
                09/30/2026
                AI Command Center: Optimizing Visibility and Control in Your Operations
                https://www.truthinit.com/index.php/channel/2024/ai-command-center-optimizing-visibility-and-control-in-your-operations/

              Upcoming Events

              • Jun
                23

                The AI-Powered VMware Alternative

                06/23/202601:00 PM ET
                • Jun
                  24

                  Accelerating Through AI: A Dynamic Webinar Series

                  06/24/202611:00 AM ET
                  • Jun
                    25

                    Generative AI Security: Preventing AI from Becoming a Data Breach Multiplier

                    06/25/202601:00 PM ET
                    • Jun
                      30

                      Mastering Active Directory Certificate Services for Long-Term Success

                      06/30/202601:00 PM ET
                      • Jul
                        01

                        Schutz von KI in Anwendungen, Agenten und APIs.

                        07/01/202604:00 AM ET
                        More events
                        Truth in IT
                        • Sponsor
                        • About Us
                        • Terms of Service
                        • Privacy Policy
                        • Contact Us
                        • Preference Management
                        Desktop version
                        Standard version