
What is Zscaler?
Zscaler is a cloud-based security platform that protects users, devices and applications without routing traffic through a traditional data centre. Instead of sitting on your network as a physical box, Zscaler runs as a service in the cloud, inspecting traffic and enforcing security policy wherever your people and applications happen to be.
It's built for a world where work doesn't happen inside four walls anymore. Your people connect from home, from branch offices, from client sites. Your applications sit in public cloud, private cloud and software as a service (SaaS) platforms. Zscaler secures that traffic at the point of connection, rather than forcing it back through a central firewall first.
How does Zscaler work?
Zscaler operates through a global network of cloud-based security checkpoints. When a user tries to reach an application, whether that's an internal system or a public cloud service, their traffic is inspected at the nearest checkpoint rather than travelling back to a corporate data centre.
This inspection covers things like malware scanning, data loss prevention and access control, all applied consistently regardless of where the user is or what device they're on. Because the inspection happens close to the user, it also avoids the latency that comes with backhauling traffic across long distances.
Zscaler's platform splits broadly into two services: one that secures user access to the internet and SaaS applications, and another that secures access to private, internal applications. Together, they replace the need for users to connect through a traditional virtual private network (VPN) to reach company resources.
Zscaler and SASE
Zscaler is one of the best-known names in secure access service edge (SASE), the model that combines networking and security into a single, cloud-delivered service. SASE brings together capabilities like Zscaler's, alongside SD WAN, to apply consistent security policy across every connection, no matter where a user or application sits.
This matters because splitting networking and security into separate tools creates gaps. A SASE approach, with a platform like Zscaler handling the security layer, means policy travels with the user and the application, not with a fixed location.
Zscaler, zero trust and SD WAN
Zscaler is often described as a zero trust platform, because it verifies every user and device before granting access, rather than trusting anything by default just because it's already inside the network. It applies the same principle to every request: check identity, check device health, check context, then grant only the access that's needed.
Zscaler works alongside SD WAN rather than replacing it. SD WAN handles the intelligent routing of traffic across your sites and clouds. Zscaler handles the security inspection of that traffic once it's moving. Run together, they give you a network that's both efficient and consistently protected, wherever your traffic starts or ends.
Colt's network connects 900+ data centres across a 32,000+ km fibre network, giving Zscaler and other SASE and SD WAN deployments the low-latency, on-net reach they need to inspect and secure traffic without adding delay. Colt's Network as a Service platform makes it straightforward to scale that connectivity as your SASE deployment grows.
Why enterprises choose Zscaler
- No backhaul required. Traffic reaches its destination directly, rather than routing through a central data centre for inspection first
- Consistent policy everywhere. The same security controls apply whether a user connects from head office, home or a branch site
- Reduced attack surface. Applications aren't exposed directly to the internet, since Zscaler brokers every connection
- Simpler for IT teams. One cloud platform replaces a patchwork of on-premises firewalls and VPN concentrators
Frequently asked questions
What is Zscaler used for?
Zscaler is used to secure user access to the internet, SaaS applications and internal company systems, without routing traffic through a traditional on-premises firewall or VPN.
Is Zscaler a VPN?
No. A VPN grants broad access to a network once a user connects. Zscaler checks identity and context for each request and grants access only to the specific application needed, following zero trust principles.
How does Zscaler fit into SASE?
Zscaler provides the security layer of a SASE architecture. Combined with SD WAN for intelligent routing, it applies consistent security policy to every connection, regardless of user location.
Does Zscaler replace SD WAN?
No. SD WAN routes traffic efficiently across sites and clouds. Zscaler secures that traffic once it's moving. The two work together rather than one replacing the other.
Is Zscaler suitable for smaller enterprises?
Yes. Because Zscaler is cloud-delivered, it scales to organisations of any size without the up-front cost of on-premises security hardware.











