On August 1, 2025 — the opening days of its fiscal 2026 — Zscaler closed its acquisition of Red Canary, a deal announced at roughly $675 million and closer to $692 million in total consideration once the filings did the math. On paper it looks like an SSE vendor buying a managed detection and response shop. In practice it is something more ambitious: an inline-proxy company betting it can build an AI-driven, largely autonomous SOC and stop being priced like a single-category security vendor.
Nearly a year in, there is enough evidence to judge the bet. This brief covers what actually changed, whether Zscaler can credibly fight CrowdStrike, Palo Alto Networks, and Microsoft in security operations, what happens to Red Canary’s prized vendor neutrality — and what existing Red Canary MDR customers should renegotiate right now.
What changed
Red Canary now operates as a business unit inside Zscaler, keeping its brand but not its independence. Zscaler’s stated plan is to fuse three assets: Red Canary’s decade of MDR runbooks and its agentic AI investigation pipeline; the Zero Trust Exchange, which by the company’s own count inspects more than 500 billion transactions daily; and the Data Fabric for Security that came from the 2024 Avalor acquisition. The pitch is an agentic SOC — AI agents that triage, investigate, and increasingly respond to alerts with human analysts supervising rather than grinding through queues.
Zscaler also now sells MDR under its own name, something it never did before. CEO Jay Chaudhry has framed the move as complementing rather than competing with MDR providers, but the product page tells its own story. The takeaway: Zscaler is no longer just the vendor that secures your traffic — it wants to be the vendor that runs your detection and response.
Why it matters
Security operations is where the consolidation war is being decided. CrowdStrike, Palo Alto Networks, and Microsoft have all spent the last three years pulling SIEM, XDR, and SOAR into single platforms, because whoever owns the SOC workflow owns the renewal conversation for everything else. Zscaler had a strong SSE franchise and no SOC story. That was a strategic dead end — the buyers I talk to increasingly want their zero-trust vendor and their operations vendor to at least share a data plane.
Red Canary fixes the gap faster than Zscaler could have built it. The company was consistently rated among the strongest independent MDR providers, and its early, public work on agentic AI investigation was ahead of most of the market. What Zscaler bought is not just revenue — it is credibility with SOC teams, a population that historically viewed Zscaler as a networking purchase. Verdict: strategically sound, execution unproven.
Can an inline-proxy vendor credibly run your SOC?
Here is the honest problem. A SOC platform lives or dies on telemetry breadth, and Zscaler’s native telemetry is network-centric — web, SaaS, private app access, DNS. It sees traffic in extraordinary volume, but it does not natively own the endpoint, the identity tier, or the cloud workload the way its new rivals do. CrowdStrike starts from the endpoint, Microsoft from identity and productivity, Palo Alto from the firewall estate plus Cortex agents. Every one of them will argue their vantage point matters more than inline traffic.
Zscaler’s counter is that Red Canary was built to be telemetry-agnostic — it ingests CrowdStrike, Microsoft Defender, SentinelOne, and others, and correlates across them. Pair that with the Data Fabric and Zscaler does not need to own every sensor, just the analytical layer above them. It is the same architectural argument we examined in our Zscaler vs Palo Alto SASE comparison: Zscaler wins when it positions as the neutral fabric, and struggles when it tries to out-platform the platforms. The SOC market will test that thesis harder than SASE ever did.
The vendor-neutrality question
Red Canary’s entire brand was built on independence — it graded EDR telemetry honestly because it sold none of its own. That stance is now structurally compromised: the parent company competes, at least partially, with the vendors whose telemetry Red Canary ingests. The expanded Zscaler–CrowdStrike partnership announced around the deal is a genuine mitigant, and dropping CrowdStrike support would be commercial suicide given how much of Red Canary’s customer base runs Falcon. Expect support to continue.
But watch the roadmap, not the press releases. The predictable drift is that new agentic capabilities land first — and work best — when Zscaler telemetry and the Data Fabric are in the loop, while third-party integrations get maintenance-mode attention. Nothing malicious required; that is just how acquired platforms evolve. If you chose Red Canary specifically because it was Switzerland, that reason is expiring on a schedule nobody will announce.
How the field lines up
As of mid-2026, four credible platform paths exist for an AI-assisted SOC. The deeper feature-by-feature breakdown is in our AI SOC platforms comparison; the strategic shape is below.
| Zscaler + Red Canary | CrowdStrike | Palo Alto Networks | Microsoft | |
|---|---|---|---|---|
| SOC anchor | MDR service + agentic investigation, Data Fabric analytics | Falcon platform, Next-Gen SIEM, Falcon Complete MDR | Cortex XSIAM “machine-led SOC” + Unit 42 services | Sentinel + Defender XDR, Security Copilot agents |
| Native telemetry edge | Inline traffic at massive scale; endpoint via third parties | Endpoint and identity depth; strong first-party sensors | Firewall estate plus Cortex endpoint agents | Identity, email, productivity — the breach entry points |
| Agentic AI maturity | Strong — Red Canary shipped agentic triage early | Strong — Charlotte AI expanding across workflows | Strong pitch; automation depth varies by data onboarding | Broad agent catalog, uneven polish across it |
| Best fit | Zscaler SSE shops; teams wanting MDR outcomes, not tooling | Endpoint-first orgs consolidating onto Falcon | Large SOCs ready to replace the SIEM outright | E5-heavy estates optimizing license economics |
| Watch out for | Integration risk; neutrality drift; new to first-party SecOps | Premium pricing as module count grows | Migration effort; services-heavy deployments | Multi-cloud and non-Microsoft telemetry gaps |
The short version: Zscaler is the only one of the four entering the SOC from the service side rather than the tooling side. That is a real differentiator — many mid-enterprise teams want detection and response as an outcome, not another console — but it also means Zscaler’s SecOps revenue depends on people and AI agents performing, quarter after quarter, not just software shipping.
What to do about it
If you are an existing Red Canary MDR customer, act at renewal — not later. Three items belong in the negotiation. First, contractual protection for third-party telemetry: named support for your EDR of record (CrowdStrike, Defender, SentinelOne) for the full term, with service credits if parity slips. Second, pricing protection: acquired MDR services routinely get repackaged into platform bundles, and you want a cap on year-over-year increases before that happens. Third, data portability: confirm your detection history and tuned analytics can be exported if you leave.
If you are a Zscaler SSE customer without Red Canary, the calculus is friendlier — bundling SSE with MDR from one vendor will likely be priced aggressively while Zscaler buys market share, and the integration genuinely shortens time-to-value if your traffic already flows through the Zero Trust Exchange. Pilot it against an incumbent quote. And if you are mid-evaluation for an AI SOC platform generally, do not let this deal rush you: run Zscaler + Red Canary head-to-head with at least one endpoint-anchored platform and score them on investigation quality per analyst-hour, not feature checklists.
Frequently asked questions
Why did Zscaler acquire Red Canary?
Zscaler needed a security operations story to compete beyond SSE. Red Canary supplied a respected MDR business, ten years of detection runbooks, and early agentic AI investigation technology that Zscaler pairs with its Data Fabric for Security — accelerating a SOC roadmap that would have taken years to build internally.
Will Red Canary still support CrowdStrike and Microsoft Defender telemetry?
Yes, as of mid-2026 — Zscaler and CrowdStrike publicly expanded their partnership around the deal, and third-party EDR ingestion remains core to Red Canary’s offering. The open question is long-term roadmap parity, which is why customers should lock support commitments into renewal contracts.
What is an agentic SOC?
A security operations model where AI agents autonomously handle triage, enrichment, and investigation of alerts — escalating to human analysts for judgment calls and response authorization. The goal is cutting mean time to respond and analyst burnout, not eliminating the SOC team.
Does Zscaler compete with CrowdStrike now?
Partially. The companies remain integration partners and jointly serve many customers, but Zscaler’s MDR service now overlaps with CrowdStrike’s Falcon Complete, and both are chasing the same agentic SOC budget. Expect cooperation on telemetry and competition on services.
Enterprise Techie publishes vendor-honest analysis like this daily — get the brief by email, free.
