About this session
Jonathan Ha-Tran, a sales engineer at Zscaler, walks a general audience through the vital elements of a zero trust architecture, using the book The Seven Elements of a Highly Successful Zero Trust Architecture as a spine. He frames zero trust as assuming users, devices and networks are already compromised, then replacing the traditional VPN-to-network model with a proxy that brokers each connection. Using analogies of a switchboard operator instead of a phone book, and an escorted visitor instead of a free-roaming badge holder, he explains how the platform verifies identity and context, controls content and access, and enforces a per-session policy. He covers terminating and inspecting encrypted traffic, SSL inspection at scale, data loss prevention techniques such as exact data match and OCR, device posture, and browser isolation for unmanaged third-party devices. He argues the proxy model shrinks the external attack surface because only the platform's address is exposed. A long bilingual Q&A digs into integration with existing tools, agentless access, CVEs, reporting and performance.
Key takeaways
- Adopt a zero trust posture by assuming users, devices and networks are already compromised rather than trusting anything by network location.
- Replace VPN tunnels that expose your whole network with a proxy that terminates and brokers each connection, so only the proxy's address is internet-facing.
- Enable SSL inspection, because with most traffic encrypted, DLP and threat controls are blind without it.
- Give unmanaged third-party devices browser-isolated, agentless access instead of full VPN access to shrink the risk from contractors.
- Enforce policy per session using identity, device posture and context, and keep your existing IAM and EDR as integrations rather than replacing them.

