Big earnings, yet a plunge! Zscaler misjudged? AI security zero trust hits a super turning point

Big earnings, yet a plunge! Zscaler misjudged? AI security zero trust hits a super turning point

Article Summary: Zscaler’s earnings were strong, yet the stock still plunged. Is the real AI security breakout here, and will zero trust become the next 2x winner? If you follow AI cybersecurity, you’ll notice something odd about Zscaler: revenue rose 25%, ARR rose 25%, and operating margin hit a record high, yet the market still sold the stock off. This isn’t just normal earnings volatility—Wall Street is weighing a bigger question: in the AI era, is cybersecurity truly a must-have, or just hype?

Zscaler’s earnings were strong, yet the stock plunged. Is the AI security real breakout here, and could zero trust become the next doubling dark horse?

If you follow AI cybersecurity, you’ll notice something odd about Zscaler: the results were clearly strong, revenue grew 25%, ARR grew 25%, operating margin hit a record high, yet the market still knocked the stock down.

This is not a normal earnings swing. Wall Street is really judging a bigger question: in the AI era, is cybersecurity truly a must-have, or just another over-packaged software story.

If you only look at the stock price, you’d think something went wrong at Zscaler. But if you look deeper, you’ll find the real issue may not be Zscaler at all, but that the entire enterprise security rulebook is being rewritten by AI.

In the past, companies defended against hackers by defending against people. Now they have to defend against AI that can automatically write code, find vulnerabilities, fake identities, and even enter systems and execute tasks.

Even more worrying, companies will not just have employee accounts in the future, but AI Agent accounts. They will access customer data, call internal systems, read databases, send emails, and even trigger workflows.

So who decides what these AI Agents can and cannot see? Who stops them from overstepping permissions? Who prevents employees from dumping confidential data into external models? And who protects the last gate when AI helps hackers scan vulnerabilities at machine speed?

That is the real reason this Zscaler video is worth watching.

By the end, you should understand at least three things.
First, why Zscaler’s strong earnings still led to a stock drop, and what the market is really worried about.
Second, why zero trust, AI Red Teaming, and Agentic SecOps may become the hardest new themes in AI software stocks.
Third, whether Zscaler is a slowing software stock or a core AI security player unfairly sold off by short-term sentiment.

If you still think AI security is just a small branch of cybersecurity, you may be missing one of the most dangerous and most profitable hidden lines in the next AI software move. Because the stronger AI gets, the less companies want to run naked. And whoever can protect the gateway into enterprise systems may become the true security toll booth of the next stage. Before the video starts, please like and subscribe, and let’s get into today’s key points.

Let’s start with the earnings themselves.

Zscaler’s Q3 report looked very impressive on the surface.
Revenue rose 25% year over year.
ARR rose 25% year over year.
Non-GAAP operating margin reached 23%, a record high.

What does that mean? It means Zscaler is not the kind of software company that only burns cash and tells stories. It has entered a more mature stage: revenue is still growing, margins are improving, customer demand has not disappeared, and the zero trust theme is still intact.

But the U.S. stock market is never a gentle teacher. It will not reward you just because you scored 90 points. If the market expected 95, or even 98 next time, then 90 can still get punished.

That is the cruelty of high-valuation growth stocks. The problem may not be the present, but that the future is not exciting enough.

The reason Zscaler got hit is not that the business collapsed, but that the market has doubts about the future. Q4 guidance was not dazzling enough, sales team adjustments made investors worry about execution, and software stocks as a group are in a very sensitive phase. As soon as future growth shows even a little uncertainty, money runs first and asks questions later.

That is today’s software market. You cannot just be good; you have to be better. You cannot just grow; you must prove growth can continue. You cannot just say AI will create opportunity; you must prove AI will turn into orders, revenue, profit, and free cash flow.

So this drop in Zscaler is really the market asking one question: when does your AI security story become real money?

But from another angle, this kind of divergence is interesting. If a company’s earnings are already bad and the stock falls, there is not much to discuss. But if the operating data is still solid, the long-term thesis is strengthening, and the stock still gets hit by short-term expectations, then you get a market disagreement. And real investing opportunities often hide in disagreement.

Next we need to see whether Zscaler’s long-term thesis has changed. The answer is not only no, it may actually be more important now.

Why? Because AI is reshaping cybersecurity.

In the past, enterprise security was more like defending a city. The inside was the city, the outside was beyond the walls. Firewalls were walls, VPNs were gates. As long as you defended the boundary, you felt safe.

But that world is gone. Cloud apps, SaaS systems, remote work, APIs, third-party plugins, and external model calls have punched holes in the old walls. Enterprise data no longer sits only on company servers, employees no longer sit only in the office, and apps no longer run only on internal networks. The boundary has disappeared.

Once AI Agents arrive, the problem becomes even more complex. An AI Agent is not a normal tool. It may automatically log into systems, call customer data, generate reports, modify code, send emails, create tickets, and trigger workflows. Sounds great, right? But from a security angle, it is scary. Because an AI Agent that can execute tasks is basically a digital employee that never sleeps. It needs permissions, data access, app access, and connections to different systems. If permission management is sloppy, if data boundaries are unclear, if the model is thrown off by prompt injection, or if hackers exploit the AI Agent, it can quickly turn from an efficiency tool into an internal security hole.

That is why zero trust becomes a must-have again in the AI era.

The core logic of zero trust is simple: trust no one by default, no device, no app, no connection. Every access must be verified, every data flow checked, and every user, device, application, and AI Agent must run under least privilege. That sounds cumbersome, but this is exactly where large enterprises are willing to spend. Because what companies fear most is not inconvenience, but losing control.

In the past hackers had to find a door. Now AI can help hackers scan every window in the building. In the past companies worried employee accounts might be stolen. Now they also worry AI Agents might be manipulated into overstepping permissions. In the past data leaks may have come from employee mistakes. Now leaks may come from an automated agent sending information out in milliseconds. So if your company is still using old VPN and traditional firewall thinking, it is like using a wooden door to block a tank in the AI era.

That is where Zscaler’s value lies. Its job is not just to sell a security product, but to integrate enterprise access control, application connectivity, data protection, zero trust architecture, and AI security capabilities.

That is also why its collaborations with OpenAI and Anthropic are so worth watching.

The point of Zscaler’s partnership with OpenAI is not simply “we also plugged into AI.” It is about using advanced model capabilities in secure development workflows, vulnerability detection, AI Red Teaming, and Agentic SecOps. In plain language, it means letting AI help security teams find code vulnerabilities faster, identify risks faster, test system weaknesses faster, and handle security incidents faster. This matters because the security industry may enter a new stage: not human vs. human, but human plus AI vs. human plus AI.

Cybersecurity used to look like two chess players. Now it may become two sides each playing with supercomputers. Attackers can use AI to find vulnerabilities, write malware, forge emails, fake identities, and quickly test attack paths. If defenders still rely on manual checks, manual patching, and manual response, they will increasingly struggle. So security companies must also use AI.

Zscaler’s involvement in Anthropic’s Project Glasswing has a similar meaning. If models like Claude can find software vulnerabilities faster and better understand code risks, that is good for defenders. But on the other hand, it also means vulnerability discovery will get faster and faster. Security problems in software may be amplified by AI. In the past a vulnerability might take days or weeks for a researcher to uncover. In the future AI may greatly accelerate discovery. For companies, that is both an opportunity and a fear. The opportunity is fixing problems faster; the fear is attackers exploiting them faster too.

So the long-term demand for AI security is not marketing hype. It is pushed by technical change itself. The stronger AI gets, the stronger attacks get. The stronger attacks get, the less companies can cut defense budgets. That is the hardest part of Zscaler’s long-term thesis.

So where is Zscaler’s opportunity? I think it can be broken into four layers.

The first layer is replacing traditional VPNs and firewalls. This was Zscaler’s original core thesis. As enterprise cloud adoption deepens, employees become more distributed, and apps multiply, traditional perimeter security gets harder and harder. The zero trust architecture replacing the old architecture is still ongoing.

The second layer is protecting enterprise use of generative AI. Employees may use ChatGPT, Claude, Copilot, and various internal AI tools. What are companies most afraid of? They are afraid employees will paste in customer lists, financial data, source code, or trade secrets and have them absorbed by external models. So companies need to know who is using AI, which AI they used, what data they sent, and whether there is leakage risk. That is the demand for AI access security and data protection.

The third layer is protecting AI Agents. This is a much bigger future story. Once AI Agents are not just chatting but begin accessing systems, calling APIs, reading data, and executing workflows, companies must assign them identity, permissions, boundaries, and audit trails. Whoever can help manage AI Agent behavior may win the next security budget.

The fourth layer is AI Red Teaming and automated security operations. Companies must not only defend against external attacks, but also proactively test whether their AI systems are vulnerable: can the model be prompt-injected, can the AI Agent overstep permissions, can internal data be called incorrectly, are there hidden flaws in application code, and can the security team use AI to fix problems faster? If Zscaler can combine these capabilities, it will no longer just be a traditional cybersecurity company; it could become the gateway into enterprise AI security. That is where the upside really is.

In the future, companies will not ask whether they should use AI. That question is already settled. The real question will be: how do I use AI safely? Whoever can answer that may win the next budget cycle.

But at this point, we also need to be clear about the risks.

Zscaler is not risk-free, and the market’s selloff this time was not completely unreasonable.

The first risk is short-term guidance. High-valuation software stocks fear downward revisions to growth expectations the most. Once the market thinks future revenue growth may step down, the stock can get hit hard.

The second risk is sales team restructuring. Cybersecurity software growth depends heavily on sales execution, big-account expansion, cross-sell, and renewals. If the sales organization is disrupted, the market becomes very sensitive.

The third risk is intense competition. Zscaler is not fighting alone. Palo Alto Networks, CrowdStrike, Okta, Cloudflare, Microsoft, and Wiz are all competing for enterprise security budgets. Everyone is talking about AI security, and everyone wants to be a platform. Customer budgets are limited, and only those who can prove real results will win more spending.

The fourth risk is that the AI security story still needs revenue conversion. AI Red Teaming, Agentic SecOps, and AI Access Security all sound impressive, but the market ultimately wants to know: are customers paying, are contracts getting bigger, are renewals improving, and is revenue showing up? If it is only a hot concept with no real conversion in the numbers, valuation expansion is hard to sustain.

The fifth risk is valuation and rates. Software stocks are very sensitive to interest rates and risk appetite. No matter how good the company is, if the valuation is too rich and the market backdrop shifts, multiples will compress.

So Zscaler does have a story, but the story is so big that the market is asking: when does it turn into money? That is my core view: Zscaler is not a stock to buy blindly, but it is definitely a core name worth keeping on your AI security watchlist.

How does it compare with other AI security names? Let’s break it down simply.

Zscaler’s keywords: zero trust, SASE, cloud access, data security, AI access control.
CrowdStrike’s keywords: endpoint security, threat detection, cloud security, AI security operations.
Okta’s keywords: identity management, AI Agent identity, access permissions.
Palo Alto Networks’ keywords: platform security, firewalls, cloud security, security operations.
Cloudflare’s keywords: network edge, application security, Zero Trust, developer and edge networking.

So you cannot lump all security stocks together. AI security will benefit the whole sector, but each company will capture a different budget. If companies worry about AI Agent overreach, Okta’s logic is more direct; if they worry about endpoint threats and detection, CrowdStrike is more direct; if they worry about cloud access, data flow, VPN replacement, and zero trust, Zscaler is more direct; if they want a broader platform security stack, Palo Alto has the advantage. That is why cybersecurity stocks will keep diverging. Not all security stocks are the same, and what really matters is where each one sits in the enterprise AI security stack.

What should ordinary investors watch next? I think Zscaler has several key indicators.

First, can ARR growth stay at a relatively high level? That shows whether long-term contracts and subscription demand remain strong.
Second, can the number of large customers and million-dollar customers keep growing? The most valuable security software comes from large accounts, especially multinational enterprises and major institutions.
Third, can non-GAAP operating margin and free cash flow keep improving? That would show the company is moving from burning cash for growth toward a more mature business model.
Fourth, can the new products like AI Security, AI Red Teaming, and Agentic SecOps start contributing clear revenue? That determines whether the AI story stays in press releases.
Fifth, can the sales execution issues be fixed? If the sales team disruption continues, the stock may remain under pressure in the short term.
Sixth, can next fiscal year guidance win back market confidence? Growth stocks are ultimately about the future, not the past.

The real opportunity is not how much the stock fell, and not how good the earnings headline looks. The real opportunity is: if the market hit it because of short-term guidance but medium- and long-term AI security demand keeps rising, then that divergence may become an investment opportunity.

So back to the original question: is Zscaler this time a risk signal or an opportunity window? My answer is both. In the short term, it clearly exposed issues around growth expectations, sales execution, and high market expectations. In the long run, it stands at the intersection of zero trust and AI security, and that position is very important.

In the AI era, security is not a supporting role; it is the passport. If companies want to use AI, they must solve access control, data protection, identity management, model security, vulnerability detection, and zero trust architecture. If those issues cannot be solved, companies will not dare put AI into core systems. So AI security is not optional; it is part of the infrastructure that makes AI possible.

That is the biggest takeaway from Zscaler’s earnings. The market may punish its guidance in the short term, but the long-term AI security theme has not disappeared. In fact, the more AI spreads, the more this theme deserves attention. If AI Agents enter enterprises at scale in the future, the biggest beneficiaries will not only be model companies or GPU companies. Security companies may become one of the hardest links in the next round of AI budgets.

To sum up, the focus of this Zscaler report is not just strong earnings or a stock drop, but that it has brought one of the most underestimated lines in AI software stocks into the spotlight. Zscaler’s opportunity is that zero trust is upgrading from a cloud security architecture into the enterprise access-control base layer of the AI era. Zscaler’s risk is that short-term guidance, sales execution, competition, and valuation swings still need to be re-evaluated by the market. So it is not a blind buy, but a core AI security name worth tracking continuously.

Detail Page Advertisement

Share Article

Next Korea FSS fines over 600 billion won: HSCEI ELS