Back to ZS Profile
    deep_dive
    draft
    2025-12-29

    Investment Idea: Zscaler (ZS)

    Golden Door Research

    Investment Thesis: Zscaler (ZS)

    Recommendation: BUY Target Price: $250.00 (Current: ~$200.00) Upside: ~25%

    1. Executive Summary

    Zscaler (NASDAQ: ZS) is the architect of the "Zero Trust" revolution. In the old world, security meant building a moat (firewall) around the castle (data center). Once you were inside the moat, you were trusted. In the new world of cloud and remote work, there is no castle. Users are everywhere, and apps are everywhere.

    Zscaler's thesis is simple: Don't trust the network. Connect the user directly to the app, not the network. This architecture, known as the "Zero Trust Exchange," is fundamentally different from the legacy firewall approach used by competitors like Palo Alto Networks.

    Why Now?

    • The Hook: The VPN Replacement Cycle. Legacy VPNs are slow, insecure, and hated by users. Zscaler Private Access (ZPA) is the modern alternative. As high-profile hacks (like the Colonial Pipeline) expose VPN vulnerabilities, CIOs are ripping them out and replacing them with Zscaler.
    • The Edge: Architecture. Zscaler was born in the cloud. They process 300 billion transactions per day across 150 data centers. You cannot "retro-fit" a hardware firewall to do this. This architectural advantage makes them faster and more scalable than competitors who are trying to pivot from hardware to cloud.
    • The Catalyst: AI Security. Employees are pasting sensitive corporate data into ChatGPT. Zscaler sits in the middle of the traffic, so it can see and block this data exfiltration. Their new "AI Data Protection" product is a must-have for any CISO worried about AI leaks.

    2. Industry Context: The Death of the Firewall

    For 30 years, the firewall was the king of security. But firewalls are hardware appliances. They are expensive, hard to manage, and don't work well when users are working from Starbucks.

    • The Hub-and-Spoke Problem: In the old model, if a user in London wanted to access Salesforce, their traffic had to be backhauled to a data center in New York (where the firewall was) and then out to the internet. This adds latency.
    • The Direct-to-Cloud Model: Zscaler inspects the traffic locally in London and sends it directly to Salesforce. It is faster and cheaper.

    The Competition: Platform vs. Best-of-Breed

    • Palo Alto Networks (PANW): The "Platform" play. They argue that you should buy everything (Firewall, Cloud Security, Endpoint) from one vendor.
    • Zscaler (ZS): The "Best-of-Breed" play. They argue that network security is too important to bundle. They partner with CrowdStrike (Endpoint) and Okta (Identity) to form a "best-of-breed" triad.

    3. The Business Model: The Switchboard in the Sky

    Zscaler operates a massive proxy cloud. They sit between the user and the internet.

    Products & Segments

    1. Zscaler Internet Access (ZIA)

    • The Secure Gateway: This replaces the traditional web gateway. It protects users from bad websites, malware, and phishing.
    • Growth: This is the mature product, but it is still growing 20%+ as companies shut down their on-premise gateways.

    2. Zscaler Private Access (ZPA)

    • The VPN Killer: This allows users to access internal apps (like an HR system) without ever being on the corporate network. The app is "invisible" to the internet.
    • Adoption: Growing faster than ZIA. It is the default choice for Zero Trust Network Access (ZTNA).

    3. Zscaler Digital Experience (ZDX)

    • The Performance Monitor: Since Zscaler sees all the traffic, they can tell you why Zoom is lagging. Is it the Wi-Fi? The ISP? The laptop? This helps IT teams troubleshoot remote work issues.

    The Moat (Competitive Advantage)

    • The Network Effect: Zscaler processes 300 billion transactions a day. Every time they detect a new threat for Customer A, they instantly block it for Customer B (and the other 7,000 customers). This "cloud immunity" gets stronger as they get bigger.
    • Inline Inspection: Inspecting encrypted traffic (SSL) is computationally expensive. Hardware firewalls choke on it. Zscaler's cloud architecture allows them to inspect SSL at scale without slowing down the user.

    4. Financial Analysis

    Zscaler is a "Rule of 60" company, balancing high growth with high free cash flow.

    Financial Snapshot (FY2025 Est)

    MetricValueYoY Growth
    Revenue~$2.66B+23%
    Billings~$3.2B+23%
    Gross Margin80%Software-like
    FCF Margin25%Strong
    Net Retention>115%Sticky

    Key Performance Indicators

    1. Billings Growth: This is the leading indicator. If billings slow down, revenue will slow down next year. Watch this closely.
    2. Upsell (ZPA/ZDX): Are existing ZIA customers buying ZPA and ZDX? The "platform" sell is critical for maintaining high retention rates.
    3. Sales Efficiency: Zscaler has historically spent a lot on sales and marketing (60%+ of revenue). Investors want to see this leverage down as they scale.

    The Profitability Pivot

    Like many SaaS companies, Zscaler has pivoted from "growth at all costs" to "profitable growth." They have slowed hiring and focused on FCF. The fact that they can still grow 23% while generating 25% FCF margins proves the business model works.


    5. Valuation & Scenarios

    Zscaler is expensive. It always has been. It trades at a premium because it is the pure-play leader in a secular growth market.

    • Current Price: ~$200.00
    • Forward P/E (FY25): ~70x
    • EV/Sales: ~13x

    Scenario Analysis

    Base Case: "The Zero Trust Standard" ($250 Target)

    • Assumptions: Revenue grows 23%. FCF margins expand to 28%. Multiple holds at 14x sales / 60x earnings.
    • Outcome: ~25% upside.
    • Driver: Continued replacement of legacy VPNs and firewalls.

    Bull Case: "The AI Tailwind" ($300 Target)

    • Assumptions: AI Data Protection drives a new upgrade cycle. Revenue growth re-accelerates to 28%. Margins hit 30%. Multiple expands to 16x sales.
    • Outcome: ~50% upside.
    • Driver: Zscaler becomes the "AI Firewall" for the enterprise.

    Bear Case: "The Platform Squeeze" ($150 Target)

    • Assumptions: Palo Alto Networks successfully bundles SASE for free/cheap to kill Zscaler. Growth slows to 15%. Margins contract due to price war.
    • Outcome: ~25% downside.
    • Driver: Consolidation favors the platform giants (PANW, MSFT).

    6. Risks

    1. Competition (PANW): Palo Alto Networks is aggressive. They are offering "free" implementation and massive discounts to win deals. Zscaler has to maintain pricing discipline.
    2. Competition (MSFT): Microsoft has a product called "Entra Private Access." It is not as good as Zscaler, but it is "good enough" for many shops and is included in the E5 license.
    3. Sales Execution: Zscaler had some sales leadership turnover in 2024. Any disruption in the sales org can lead to a missed quarter.

    7. Conclusion

    Zscaler is the "cleanest" story in cybersecurity. It doesn't have a legacy hardware business to protect (like PANW or Cisco). It is 100% cloud, 100% subscription, and 100% Zero Trust.

    While the valuation is rich, the opportunity is massive. We are in the early innings of the network transformation. As long as Zscaler maintains its technological lead, it will continue to compound. We rate ZS a BUY.


    Disclaimer: This report is for informational purposes only and does not constitute financial advice. Golden Door Research has no business relationship with any company mentioned.