Should I use Zscaler?
Leading cloud enterprise security provider for zero trust - zscaler.com
Depends. Buy if you're a large organization with security staff replacing VPNs, appliances, and legacy perimeter tools. Small teams without dedicated IT should pick a lighter, cheaper SSE tool.
Confidence
Medium. Based on 40+ public sources; snippets were truncated, so exact ratings and prices were not always visible.
Ratings
- Value for money
- Ease of use
- Feature depth
- Support quality
- Security posture
Pricing
Quote-based, annual
Zscaler Internet Access (ZIA)
ModelQuote-based
Monthly feesNot disclosed
HardwareNot disclosed
Zscaler Private Access (ZPA)Quote-based, annual
Best for
- →Large distributed enterprises
- →Zero-trust / VPN-replacement projects
- →Regulated sectors like government
- →Orgs consolidating many point security tools
Not for
- ×Small teams needing simple web filtering
- ×Startups with no dedicated security admin
- ×Buyers wanting published, transparent pricing
- ×Anyone unwilling to manage a heavy client agent
Gotchas - check before you buy
high
Quote-based only; buyers report 2025 price hikes — negotiate multi-year terms hard
high
Deep platform lock-in: leaving means re-architecting all traffic policies and agents
medium
Validate post-sales support SLAs in the contract before signing
medium
Client Connector agent has shipped CVEs; keep endpoint patching disciplined
Pros and cons
Pros
- +Broad 28-solution portfolio on one cloud security platform
- +Strong ratings on G2 and Gartner Peer Insights
- +ZPA praised for streamlining government access vs legacy VPN
- +Cloud-native with no appliances to maintain
- +Proven at scale with named public-sector and enterprise customers
Cons
- −Recurring sysadmin complaints about day-to-day experience
- −Opaque quote-based pricing with 2025 increases
- −Client Connector agent flaws enabled remote attacks (2026)
- −2025 supply-chain breach via Salesloft Drift exposed Salesforce data
- −Post-sales support quality openly questioned by prospective buyers
Sources & method
Analyzed 9/26/2026 - 14 sources - Active advisory program, but 2026 Client Connector CVEs and a 2025 Salesloft Drift supply-chain breach are on record.
official x2review x8security x2news x2
- Client Connector DoS (CVE-2026-59565), Denial-of-service flaw in the Zscaler Client Connector endpoint agent.
- Multiple Client Connector remote flaws, Improper input validation issues enabling remote attacks; patched via advisories.
- 2025 Salesloft Drift supply-chain breach, Token-based attack via Salesloft Drift exposed Zscaler Salesforce customer data.
Comments
One queue. No nested comments. Give a display name first. Limit: 200 words per comment and 7 comments per day. You can edit or delete yours.
No comments yet.