Zscaler CEO Highlights AI Security Surge, Zero-Trust Momentum at Citi Conference

Zscaler (NASDAQ:ZS) CEO and Founder Jay Chaudhry said the company entered fiscal 2027 with an expanded product portfolio, improving sales momentum and growing customer interest in AI security and zero-trust architecture.

Speaking at Citi’s TMT Conference with Fatima Boolani, Chaudhry said Zscaler’s platform now spans zero trust for users, branches, devices, workloads and agents. He said the company also expanded its AI-security lineup from one product a year ago, GenAI Security, to six integrated products.

“We have better portfolio platform than anyone out there,” Chaudhry said, adding that the pace of product development by Zscaler’s internal AI-security startup exceeded his expectations.

Sales transformation and customer metrics

Chaudhry said the company’s sales transformation, initiated roughly 2.5 years ago after Mike Rich joined the organization, has shifted the go-to-market process toward enterprise-account focus. He pointed to improvement in net-new annual recurring revenue growth as evidence of progress.

  • Net-new ARR growth was limited in fiscal 2024, according to Chaudhry.
  • Growth reached 7% in fiscal 2025.
  • It rose to 10% in the first half of fiscal 2026 and 17% in the fourth quarter.

Chaudhry also cited a net promoter score in the 80-to-85 range and said customer satisfaction has supported upselling. Zscaler had about 785 customers with more than $1 million in ARR, he said, while the number of customers using its Zero Trust Everywhere offerings increased from 300 a year earlier to 950.

The company completed a record number of $1 million deals in the fourth quarter, created record pipeline during the period and reported its highest sales productivity in about four years, Chaudhry said.

AI security demand is building, but deal sizes remain small

Chaudhry said concerns around “frontier models” have altered conversations with chief information security officers, chief information officers and corporate boards. He said large enterprises have formed cyber task forces following what he called “Mythos,” with the goal of assessing risks and reporting to boards more frequently.

According to Chaudhry, AI models can discover internet-exposed assets and potential vulnerabilities at a much greater rate than prior tools. He said Zscaler is working with customers to reduce their exposed attack surfaces by placing applications behind zero-trust controls.

He also said organizations are seeking ways to deploy AI agents safely, including controlling which agents can communicate with other agents. Zscaler’s approach is based on extending its zero-trust architecture from user-to-application connections to branches, devices, cloud workloads and agents.

Security-for-AI bookings exceeded $100 million over the 12 months disclosed after the third quarter, Chaudhry said. In the fourth quarter, bookings in the category rose 50% sequentially. Still, he said many customers are initially making smaller purchases as they evaluate products before committing to multimillion-dollar deployments.

Chaudhry added that 70% of AI-security deals closed in the fourth quarter also included data-security products. He said AI-related concerns are also accelerating some zero-trust deployments, as customers seek to reduce the potential “blast radius” from a breach.

Agentic SecOps and Red Canary integration

Zscaler launched Agentic SecOps at the conference, a product initiative supported by the company’s Red Canary acquisition. Chaudhry said Red Canary contributed managed-security operations expertise, playbooks and agents that Zscaler incorporated into its new SecOps offering.

He said the acquisition was intended to accelerate development of an agentic SecOps solution rather than make Zscaler solely a managed detection and response provider. Customers will be able to purchase the product and may also choose managed services, he said.

Red Canary has been a revenue headwind rather than a tailwind so far because standalone MDR businesses have traditionally experienced higher churn, particularly among smaller customers, Chaudhry said. Zscaler plans to move Red Canary customers from the existing offering to its new solution and has factored uncertainty around that transition into expectations.

Chaudhry said Zscaler believes its advantage in agentic SecOps is its ability to use first-party inline and endpoint telemetry, identify threats quickly and enforce policy without first moving data to a separate data lake.

Flexible purchasing and fiscal 2027 priorities

Zscaler also introduced Z Flex, a flexible purchasing structure intended to reduce procurement friction. Chaudhry said the arrangement allows customers to swap modules, purchase additional products through a rate card and use rollout ramps for broader deployments. Customers using Z Flex generated upsell that was 30% higher than customers not using the program during its first year, he said.

Looking toward fiscal 2027, Chaudhry identified AI security and Zero Trust Everywhere as the areas most likely to provide upside. He also said he is watching adoption of the company’s Agentic Exchange, which is currently in limited availability with customers. The exchange is designed to manage policy enforcement and communications among agents from multiple platforms and providers.

About Zscaler (NASDAQ:ZS)

Zscaler, Inc is a cloud-native cybersecurity company that provides security services designed to help organizations connect users, devices, applications and workloads securely over the internet. Its platform is built around a zero-trust security model, which verifies access based on identity, context and policy rather than relying primarily on a traditional corporate network perimeter.

The company’s offerings include Zscaler Internet Access, which secures access to internet and software-as-a-service applications, and Zscaler Private Access, which provides secure, policy-based access to private applications without requiring conventional virtual private networks.