Hi, I'm Tom Field, senior vice president of editorial with information security media group. I'm talking today about network transformation. My privilege to be speaking with Paul Reyes, he's a CISO with Bistra Energy in Texas, and also speaking with Dan Shelton, head of transformation strategy with Zscaler. Paul, Dan, thank you so much for taking time to speak with me today.
Thank you. Thank you, Tom. So Paul, you have been through this network transformation, so I want to ask you up front, what did network security look like for you before transformation? What it looked like for us, it was we were mainly on premise for our company back then, and we started to just move our stuff out to the cloud, started doing a lot of mobile first pieces, and so we really controlled everything with our walls, we controlled everything with passing through our data centers, and the biggest challenge we started to see is that there was a lot of stuff I couldn't see anymore, right?
People were connecting directly to SAS, people were connecting to the cloud, and it was very difficult to be able to give our business a view into our posture because there was a lot of things I was blind to. Dan, I'm going to guess that sounds pretty familiar based on your own experience and what you see in your role now. Yeah, and Tom, that's definitely talking with our customers at Zscaler, because for me, my role at Zscaler is helping them to find what their transformation journeys can look like because I was a previous customer at Zscaler, I was in a similar situation that Paul is describing, and I'll tell you that visibility into the traffic flows, it's absolutely critical to be able to quantify that and have actionable data to talk about with your business. When you're making decisions on risk and on what people should be allowed to access, how we are leveraging these new tools, you don't have that visibility, it's really hard to make a decision on what you need to do and why.
Well, I don't want to undersell the massive impact of something like transformation. It's a big deal. What did you learn while your organization was going through the process? I think the biggest thing is that user experience matters considerably.
The adoption of it for us, at least for our company, we had a whole bunch of folks that were driving in our company as a productivity is the most important thing, right? How can they deliver what they need for the business as fast and as easy as possible? And security was a really secondary thought for us. And so as we started to roll it out, I was really thinking security was number one and we needed to lock things down and it never was successful with just that kind of amen day.
So we learned a lot is that we had to do organizational change management. We had to make sure our ducts were in order. We had to make sure that we seamlessly rolled it out in the areas where it was least amount of friction. Dan, would you say these are common challenges that organizations face?
Absolutely. So it is that constant balance between the user experience and security. And one of the things that companies are able to leverage when you take that capability that Paul referenced in having it on-prem and you move it to a cloud platform where your first hop out to the internet is your security capability and the cloud and your last hop back in is also that security capability. So policies are of course there and what that it allows you to do is actually have the balance of both, right?
So you can have improved user experience and you can have an enhanced security posture. I mean, a big part of the challenges that we see customers trying to address is really that balance between the two. Paul, could you dive in more in terms of what your kind of high productivity versus high security mentality was and kind of the approach that you used to get there? Yeah, you know, we really looked at our users as personos.
We had to, you know, break them up into folks and how they worked because when we first started to roll it out, we noticed that, hey, we have 50 plus plants and mines out in the various parts of the United States. We have several retail organizations throughout the country. And so the challenge that we had was each one of these branch offices did things differently. They had different Wi-Fi's.
They had different connectivities out to the internet, some new DSLs, some use T1s. And so in those models, we had to really standardize first because when we started to change things, things were breaking left and right because we didn't all have the same architecture. So we standardize our Wi-Fi environments. We standardize our different links so that they were common across the board, allowing us to be able to do policy-based changes, enabling that infrastructure to kind of adapt and be standardized.
When we did that, then we were able to take an easy step and move to the next level. That the challenge that we also had is that users, some users would just use common tools like ostracify, box, and on-prem applications. But then there were special users that actually connected to their systems like a plant control system. And when they connected to it, they connected via an IP address.
So they were special power users that used their systems in unique ways that we didn't contemplate. And so when we turned on ZPA and various other tools to kind of move them to our traffic, things broke. And so we had to slow those down, put people into personas. And in those that were high impact, we put at a later stage.
And the other ones that were easy, we turned them on and went forward. Perfect. Thanks, Paul. So what I hear there is you kind of took a slower approach to make sure the user experience wasn't impacted and that your business could stay productive.
And so then you didn't break that balance of high productivity versus high security. Correct. Excellent. Well, follow up on that.
How does your infrastructure footprint look today? We're probably a little over 90% of our applications and systems are in the cloud now. The only ones that remain are special plants and mine sites, things that are running in control systems, historians that are sitting closer to the plant or our nuclear site, for instance, that has direct locations on the plant. But the rest are pretty much, like I said, 90 plus systems are in the cloud.
And so there's a mission between native cloud apps and legacy apps, but they're all in native AWS or Azure cloud for us. What's next for you in this transformation? Tightening up our pipelines. We're really, when we think about Zero Trust, a lot of times folks will turn on some of these functions and features.
What we're looking to do is that there is no other way to connect to any application that we have, whether it's a SaaS or an on-prem application or when I say on-prem, it could be, you know, in Azure or AWS for us. But no other way to connect to it other than going through our Tscaler model. And so that way, every traffic including cloud services that are you heading for our company will go through these systems and we have increased our visibility. And so that has been, like I said, with Dan a trickle effect, we're starting to turn those on and see how it feels.
And then with a, actually in today's pandemic issue, that actually turned up the heap a lot because we pushed a whole lot of people off to their homes. And with that, we turned on all these features so that they get back to their office and applications. And so that wind for us allows us to be able to have license to go to the next application that we go through. Hey, Paul, with that move to putting more of the access through Zscaler internet access or Zscaler prime access and really having, again, the ability to have granular policies per user, per app, and the ability to do it without actually connecting the user to the network, has that reduced the complexity around your firewall infrastructure that you put into in your legacy data centers and your plant systems in your Azure AWS environments?
Because now you know all the traffic is only coming from Zscaler and you're able to really lock down those environments and say, hey, look, just don't allow anything in unless it's coming over this control channel from Zscaler. Have you guys seen that happen in terms of your access, listeners, firewalls, devices, things like that and overall management? Yeah, we definitely had that as a targeted benefit for us. And the complexity of that has definitely been reduced.
What I will tell you, though, is we've actually, we're already pushing our SD-WAN throughout our various plants and mines already. And so the cost benefit of reducing that footprint was already contemplated. But at the end of the day, I think your point is the complexity of that was reduced, definitely. The one thing that we are doing just for saving grace is leaving some of those firewalls in our architecture, and that we're not using them, simply in case something never happens, we can turn them on and still protect our perimeter for that in case something happens with Zscaler.
And so because we're running critical infrastructure for the country, we wanted to make sure we have a back-out plan as well. And that would go same thing for CPA. We are peeling people off of our current VPN solution. We're not getting rid of it.
We're just letting it stay there stagnant so that if anything does happen, we can then have an alternative view. But it's been going great. What about when we talk about reducing complexity, what about the kind of shift in what your team is doing from a security resource perspective? That's a good point.
A lot of times, we're just looking at logs. Now we're trying to figure out how do we produce metrics and data analytics from the various sources now, because the sources are changing, the views are changing. And so we're learning more around how do we leverage the DLP function, and how do we do more threat hunting type of activities rather than log monitoring? Perfect.
That's something that I see on the customer side a lot with our current customers, as well as when I was a customer. It's having that actionable data and then being able to go back to your business with meaningful metrics and say, this is how IT is helping. And it really helps get a seat at the table with the business as being that kind of digital business enabler as opposed to the black box where the business throws a ton of money and they don't see a lot of value, because they look at, hey, somebody's spending 20% of their time patching and managing and underlying infrastructure capability. That's not a real value of the business.
Yeah, of course, you need it, but they don't recognize that and they kind of take it for granted. Yeah, absolutely. And I think the biggest challenge for most of my analysts is not really understanding the value of reporting what's not happening. And I think that's, I go the long way for most CISOs to consider is that the ability to go show what the users are not feeling and not seeing is a very valuable piece to say, this is why we're spending money.
We had an over 19 pandemic occur and here is the uptake that we see that has occurred and you felt nothing. We have the visibility to do that now. And so trying to get our teams to be able to, hey, pose that picture up, show our business what we're stopping with this investment that we've done, and then to be able to show the value of that. And that's why we're not in the news.
So that's a really good push for us to be able to show the threat hunting and the threat analytics that we're providing now. Yeah, that's a great lens and a great frame of reference. I'm like, these are all the things that are not happening. And this is, I mean, for me, the company that I previously led, we deployed DIA, we deployed ZPA.
And one of the things that that company is recognizing now is 100% mobile workforce. And they did it. They moved from 2000 mobile workforce employees to 8,000 overnight, and there was no impact at all. And so there's the I was reporting that to the business and to the board of look, look, we completely shifted our business model.
And it was because of the fact that our users could do their job from anywhere and still be productive. And of course, never circumventing security. Absolutely. If you don't mind, I'd like to cover one more topic.
Oh, please. Yeah. So I think some of the things that if I had to advise anybody going through this type of journey, one of the things I wish I did beforehand was identifying where your locations are that have a local traffic pattern. We have a lot of plants and mines.
They don't have big bandwidth pipes. And so when we drove things all through Z scaler and tried to print from somebody's desk to the printer right next door and it went out to the internet and came back and then printed, it became a very user impacting challenge, right? And so understanding where those existed and knowing those up front to be able to address, hey, we need to address this as a local travel path and then work with the scaler around a service edge mentality would be something we should have done ahead of time. After the fact now, we're working through that really well.
But I think that's something to consider is if you happen to have a scenario like that, that your bandwidth wouldn't be able to, you know, eliminate a user friction point and that's one thing you need to consider. The second piece is, when you make a change as big as this, everything becomes a Z scaler challenge. You know, somebody could have a terrible machine and all of a sudden you deploy a Z scaler, whether it's ZPA or CIA and all of a sudden it's your fault, why they're slow, right? And so we were struggling on being able to show a user experience on that.
And we wish we probably had that function and feature up front before you start doing that journey. So if you're doing this journey, highly considered using the user experience module on there for your internet traffic and to Z scaler, I will probably tell you, hey, a product to show user experience with ZPA would also be just as important. And I know that today that is not covered. And so that would be an area of a gap that I would love to see having a user experience view within a ZPA traffic pattern.
And that would help out tremendously when somebody says, well, it's must be Z scaler, you know, because I turned this on and I want to switch my old VPN and works great and be able to paint that picture would be really good. But I think of those two things, we go a long way for people to journey. Paul, thank you for the feedback. And that is something that we are absolutely building and testing with customers now so that that's important.
But it is true, it's actionable data and you have to know those traffic flows, right? So again, that's valuable lesson learned for anybody that's considering this same path, which many organizations are because they're being forced to by their businesses. Thank you. So Dan, you've been in Paul's seat, obviously, in your past experience, given that and where you are now, what do you draw from what Paul has told us today?
And where does Z scaler fit in helping organizations such as this make this transformation we've talked about? Well, it's really around the seamless transfer or the seamless kind of move to a digital business. And the approach to leverage or consume services as opposed to building them. And so from an IT perspective, when you look at what Paul talked about where they had a bunch of on-prem security appliances, they had a network that was very focused on that legacy hub and spoke model where the data center was the center of gravity for the organization.
And you know, now your users are off the network. You're after like Paul said, I think he said 80% of their apps are in the cloud. And of course, they still have legacy apps that need to connect to. But it's the enabler to just go to your business and say, look, it doesn't matter where your apps sit or which apps that you want to use.
It doesn't matter where the users are going to sit anymore. We could still provide access to them, still do it in a secure way. And it's really starting to follow some models that partners put together like their secure access service edge piece where you just need a very small device at these locations because you're going to consume these capabilities in other places, i.e. the cloud.
So not just for security, but even for applications, like SaaS applications, you think about Office 365 and the trend that started. More and more of that legacy infrastructure that sits inside of a data center is now being moved out. And that architecture that Paul's talking about implementing, it really enables that piece where you just use the internet as your network, the cloud as your data center, and that just then draws on so much from a business process perspective that you can enable your business. And again, it's digital business transformation, you hear that buzzword a lot.
And we're in the forefront of helping customers enable that for their business. Paul, I appreciate your honesty and your advice. Thank you so much for sharing your story, Dan. Appreciate your perspective as well.
Thank you. All right. Again, the topics have been networked transformation. We've heard from Paul Reyes to siss up with Mr.
Energy, and Dan Shelton, head of transformation strategy with Zscaler. For information security media group, I'm Tom Field. Thank you very much.