Zscaler completed its acquisition of managed detection and response (MDR) provider Red Canary after announcing the agreement on May 27, 2025. The price was not disclosed. Although the original announcement anticipated an August 2025 closing, Zscaler listed Red Canary as acquired in its fiscal 2025 results. The transaction extends Zscaler from access control and cloud traffic inspection into managed detection, investigation, threat hunting and response.
What Zscaler announced—and what happened
Zscaler announced a definitive agreement to acquire privately held Red Canary on May 27, 2025. The parties did not disclose financial terms, and reporting at the time said the transaction was expected to close in August 2025, subject to customary conditions and regulatory approvals. Zscaler later confirmed completion in its fiscal 2025 results: this is now a completed acquisition, not a pending proposal.
In its fiscal 2026 third-quarter results, Zscaler said Red Canary contributed $127 million in annual recurring revenue (ARR). In the same quarter, Zscaler reported total ARR of $3.525 billion, up 25% year over year, or 21% excluding Red Canary’s contribution. The figures demonstrate that Zscaler acquired an operating MDR business with recurring revenue, not merely a set of detection tools; they do not independently prove that every announced integration benefit has been delivered.
Sources: SecurityWeek, Zscaler fiscal 2025 results and Zscaler fiscal 2026 third-quarter results.
Free tools Windows power users keep installed
One-click scans. No signup required.
#1 Best Overall
What Red Canary brought to Zscaler
Red Canary operated as an MDR and security-operations provider rather than simply a software vendor. Its reported service model combines continuous monitoring with technology and human analysts.
- 24/7 threat monitoring and alert triage.
- Detection engineering, investigation and threat hunting.
- Threat intelligence and automated remediation workflows.
- Human-led incident response when automation is insufficient.
- Coverage for endpoints, identities, cloud workloads, SaaS applications, networks and related environments.
- Connections to more than 200 technology and security products, according to announcement-era coverage.
Reporting described Red Canary as serving nearly 1,000 organizations and having raised more than $135 million before the acquisition. Those are historical, attributed figures rather than a current post-acquisition customer count. Sources: ETTelecom/Reuters, SecurityWeek and Dark Reading.
Why Red Canary was strategically attractive
Zscaler’s existing position
Zscaler’s Zero Trust Exchange delivers secure access, web and cloud security, data protection and related controls from a cloud platform. Announcement-era coverage cited approximately 500 billion transactions processed through Zscaler’s security cloud each day. That is transaction volume—not a count of alerts, attacks or unique threats.
The missing operational layer
Telemetry and prevention controls do not, by themselves, run a security operations center. MDR adds the operating steps many customers struggle to staff:
What’s actually slowing this PC down?
Pick the symptom - the matching free tool is one click away.
Rank #2
- Continuously monitor signals.
- Decide whether an alert represents a credible threat.
- Correlate activity across multiple data sources.
- Investigate and hunt for related attacker behavior.
- Coordinate or execute containment and remediation under agreed authority.
Zscaler’s thesis was that its security-cloud telemetry and Data Fabric for Security could provide context, while Red Canary supplied detection logic, threat intelligence, analysts and response workflows. Zscaler described the move as a natural expansion into MDR and threat intelligence. Source: SecurityWeek.
What the combined operating model is intended to do
The announced vision is an integrated, AI-assisted security-operations capability spanning network, endpoint, identity, SaaS and cloud signals. A representative workflow would look like this:
- Zscaler observes suspicious access or traffic in its cloud.
- Signals are correlated with endpoint, identity, cloud or SaaS telemetry.
- Automated systems prioritize and enrich the alert.
- Red Canary analysts investigate, threat-hunt and determine scope.
- The customer or an authorized workflow contains the activity and remediates affected assets.
- Case intelligence and analyst findings improve future detections.
“AI-powered” should be read as AI-assisted triage, correlation, investigation and recommendations combined with human monitoring. The available evidence does not establish unrestricted autonomous response or a lights-out SOC.
How the deal fits Zscaler’s acquisition path
Zscaler acquired Avalor for approximately $350 million in 2024. Avalor supplied risk-management and Data Fabric technology; Red Canary adds managed detection, threat intelligence, investigation and response. Together, the acquisitions give Zscaler a logical path from collecting and contextualizing security data to operationalizing it in a SOC workflow. That is a product-fit inference, not evidence that every planned integration milestone is complete. Source: SecurityWeek.
Do these 3 things before closing this tab:
1Clear out junk files and repair common Windows errors2Scan for outdated or missing drivers - takes under a minute3Repair Windows errors before they cause bigger problemsRank #3
What customers may gain—and what they should not assume
Potential advantages
- Fewer handoffs between a zero-trust provider and a separate MDR supplier.
- Better correlation of network, cloud, identity, endpoint and SaaS signals.
- Faster triage and more investigative context.
- Access to continuous monitoring, analysts and threat-hunting expertise.
- More automated containment and remediation options.
Important limitations
- An integrated strategy does not guarantee one SKU, console, contract or lower total cost.
- Customers may still need endpoint, identity, cloud, SIEM and third-party integrations.
- MDR results depend on telemetry coverage, analyst processes, response authority and customer cooperation.
- Existing Red Canary customers should verify packaging, contracts, data handling, integration support, service levels and roadmap commitments directly with Zscaler.
Competitive and market implications
The acquisition reflects cybersecurity consolidation: platform vendors are adding managed services and response expertise instead of selling only preventive controls. Zscaler becomes a more credible competitor to platforms that combine telemetry, detection and response.
Independent MDR providers retain a different proposition: vendor neutrality, specialized expertise, regional coverage or support for heterogeneous stacks. Buyers therefore face a trade-off between a closely integrated platform and an MDR that is structurally separate from their security vendors. The deal does not, on the available evidence, establish Zscaler as the market-share leader or prove that platform consolidation is superior for every organization.
| Buying priority | Likely direction |
|---|---|
| Existing Zscaler deployment and consolidation | Zscaler with Red Canary capabilities |
| Endpoint-first detection and response | CrowdStrike or SentinelOne |
| Microsoft 365, Entra ID and Azure alignment | Microsoft Defender/XDR with managed services |
| Broad network, cloud and incident-response portfolio | Palo Alto Networks Cortex and Unit 42 |
| MDR-first relationship | Arctic Wolf |
| SMB or MSP-oriented simplicity | Huntress, subject to current scope and pricing verification |
These are categories, not interchangeable products. Public pricing and equivalent service levels were not disclosed in the available sources. Zscaler directs buyers to its official site and reseller partners for evaluation.
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Risks and diligence questions
Integration and neutrality
The value depends on connecting Zscaler telemetry, Red Canary analytics, third-party endpoint data, identity signals and response workflows. Poor integration could leave an acquired MDR service beside the Zscaler platform rather than inside it. Customers may also ask whether Red Canary’s recommendations remain neutral toward products that compete with Zscaler.
Quick wins for a faster PC:
Fix the driver behind crashes, sound loss and screen glitchesFind Drivers →Clear out junk files and repair common Windows errorsFree Scan →Rank #4
- Mastering Microsoft Endpoint Manager: Deploy and manage Windows 10, Windows 11, and Windows 365 on both physical and cloud PCs
- ABIS BOOK
- Packt Publishing
Service quality and response authority
MDR is a people-and-process service. Buyers should clarify analyst coverage, escalation quality, false-positive handling and the limits of automation. In particular, ask who may isolate an endpoint, disable an account or block traffic; what approvals are required; how mistaken actions are reversed; and what happens outside business hours.
Concentration and AI risk
One supplier for access, telemetry, detection and response can simplify operations but increases dependency on its availability, pricing, roadmap and incident handling. AI may accelerate triage and recommendations, but buyers should not assume it understands every incident or safely executes every action without human oversight.
Customer checklist
- Confirm current Red Canary product names and Zscaler packaging.
- Review supported data sources, connectors and third-party integrations.
- Check data retention, processing locations and residency options.
- Ask about analyst coverage by region and time zone.
- Obtain escalation, response and incident-notification service levels.
- Document approval requirements for automated remediation.
- Understand onboarding time and required sensors or connectors.
- Clarify whether pricing is based on users, endpoints, assets, data, events or a custom subscription.
- Review contract treatment for existing Red Canary customers.
- Confirm portability of detections, playbooks, case data and threat intelligence if you leave.
What remains unknown
- The purchase price and detailed transaction economics.
- Retention and staffing plans for Red Canary personnel.
- Exact product packaging, migration requirements and post-acquisition service-level changes.
- Regional data-handling details and independently measured security outcomes.
The Bottom Line
Zscaler’s Red Canary acquisition gives the zero-trust vendor a credible route into managed detection and response: Zscaler contributes cloud telemetry and security controls, while Red Canary contributes analysts, detection, hunting and response operations. Its practical value will depend on integration depth, neutrality, service quality, customer control over remediation and support for mixed technology environments—not on the acquisition announcement alone.
Quick Recap
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.




