This session is for members.

Subscribe or log in to watch every GoSec session.

Subscribe Log in

This recording is not available yet.

Reducing operational cost and complexity through zero trust

Download resources

About this session

Claudio Francavilla, a sales engineer at Zscaler with a background in IT and cyber M&A due diligence at KPMG, argues that traditional perimeter architectures, firewalls, VPN mesh, MPLS, and point solutions for sandboxing and VDI, sprawl as organizations grow, driving up infrastructure spend, management overhead, security risk, carbon footprint and lost productivity. Drawing on Zscaler client data, he notes over half of M&A integrations miss their deal thesis, often from unplanned technology costs and inherited technical debt. He walks through the NIST zero trust framework: continuously verified identities and device posture feed a cloud policy engine that brokers access to SaaS, public cloud and legacy data-center applications, replacing exposed VPN endpoints with inside-out app connectors deployable without re-architecting the network. He ties this to measurable savings, in his examples up to 90 percent less spend on appliances and roughly 70 percent more freed-up staff time, plus faster breach remediation and smoother M&A integration. A Q&A covers using SSL and packet inspection at the policy engine to apply data-loss-prevention rules to ChatGPT and other AI-tool traffic instead of a blanket block.

With all the economic uncertainty and changes that have taken place in the past few years, including the widespread adoption of remote work, organizations are actively looking for ways to cut costs and increase agility as they look for cloud-based solutions to replace their traditional security architecture. Migrating to zero trust security accomplishes these goals in numerous ways.

Key takeaways

  • Total the real cost of an architecture as effort (management time, troubleshooting, remediation) plus capital spend, not just license renewals, since effort is usually the bigger and more overlooked driver.
  • Before an acquisition, define the integration thesis and budget for overlapping IPs, mismatched networking and inherited technical debt; over half of integrations in this dataset missed their deal goals.
  • Retire exposed VPN endpoints in favor of inside-out application connectors so a compromised gateway can't hand an attacker a path to internal systems.
  • Route AI-tool traffic (ChatGPT and similar) through SSL and packet inspection with DLP policies instead of an outright block, so legitimate use stays open while sensitive data stays filtered.
  • Consolidate policy into a single control plane to cut the number of management consoles and rule sets an administrator has to keep in sync across sites.

Speakers

Claudio Francavilla
Claudio Francavilla
Sales Engineer · Zscaler
Claudio, currently serving as a Sales Engineer at Zscaler, is a seasoned professional adept at architecting robust security solutions tailored to elevate organizational defenses. With a distinguished tenure as a Senior Manager in KPMG's… Read moreRead less

Claudio, currently serving as a Sales Engineer at Zscaler, is a seasoned professional adept at architecting robust security solutions tailored to elevate organizational defenses. With a distinguished tenure as a Senior Manager in KPMG's Cybersecurity practice, Claudio possesses a wealth of experience in orchestrating comprehensive cyber and IT due diligence initiatives. His keen eye for identifying pivotal risks and optimizing security architectures underscores his commitment to safeguarding enterprises in an ever-evolving threat landscape.

Resources

Tags

More from GoSec 2024

Also from Claudio Francavilla

On the same topic

This site is registered on wpml.org as a development site. Switch to a production site key to remove this banner.