October DealsAmazon USOctober deal check: compare before you payAmazon US: current deals, useful picks and tech finds.Check DealsClean PCRecommendedOne scan can reveal what keeps slowing WindowsLook for cleanup and repair opportunities.Run ScanOctober DealsAmazon USDeal season is back - check today's better picksAmazon US: current deals, useful picks and tech finds.See Picks×
Skip to content
The Finance Base
The Money Desk · Blog
Re:

Zscaler’s Red Canary Acquisition: Why the Zero-Trust Vendor Bought an MDR Operation

Zscaler completed its acquisition of Red Canary, combining Zero Trust Exchange telemetry with managed detection, threat hunting, investigation and response. The deal’s $127 million ARR contribution shows it was an operating MDR business, while integration, neutrality and service-quality questions remain.
From TheFinanceBase Team6 min to read

What’s actually slowing this PC down?

Pick the symptom - the matching free tool is one click away.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Zscaler completed its acquisition of managed detection and response (MDR) provider Red Canary after announcing the agreement on May 27, 2025. The price was not disclosed. Although the original announcement anticipated an August 2025 closing, Zscaler listed Red Canary as acquired in its fiscal 2025 results. The transaction extends Zscaler from access control and cloud traffic inspection into managed detection, investigation, threat hunting and response.

What Zscaler announced—and what happened

Zscaler announced a definitive agreement to acquire privately held Red Canary on May 27, 2025. The parties did not disclose financial terms, and reporting at the time said the transaction was expected to close in August 2025, subject to customary conditions and regulatory approvals. Zscaler later confirmed completion in its fiscal 2025 results: this is now a completed acquisition, not a pending proposal.

In its fiscal 2026 third-quarter results, Zscaler said Red Canary contributed $127 million in annual recurring revenue (ARR). In the same quarter, Zscaler reported total ARR of $3.525 billion, up 25% year over year, or 21% excluding Red Canary’s contribution. The figures demonstrate that Zscaler acquired an operating MDR business with recurring revenue, not merely a set of detection tools; they do not independently prove that every announced integration benefit has been delivered.

Sources: SecurityWeek, Zscaler fiscal 2025 results and Zscaler fiscal 2026 third-quarter results.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

What Red Canary brought to Zscaler

Red Canary operated as an MDR and security-operations provider rather than simply a software vendor. Its reported service model combines continuous monitoring with technology and human analysts.

  • 24/7 threat monitoring and alert triage.
  • Detection engineering, investigation and threat hunting.
  • Threat intelligence and automated remediation workflows.
  • Human-led incident response when automation is insufficient.
  • Coverage for endpoints, identities, cloud workloads, SaaS applications, networks and related environments.
  • Connections to more than 200 technology and security products, according to announcement-era coverage.

Reporting described Red Canary as serving nearly 1,000 organizations and having raised more than $135 million before the acquisition. Those are historical, attributed figures rather than a current post-acquisition customer count. Sources: ETTelecom/Reuters, SecurityWeek and Dark Reading.

Why Red Canary was strategically attractive

Zscaler’s existing position

Zscaler’s Zero Trust Exchange delivers secure access, web and cloud security, data protection and related controls from a cloud platform. Announcement-era coverage cited approximately 500 billion transactions processed through Zscaler’s security cloud each day. That is transaction volume—not a count of alerts, attacks or unique threats.

The missing operational layer

Telemetry and prevention controls do not, by themselves, run a security operations center. MDR adds the operating steps many customers struggle to staff:

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
  1. Continuously monitor signals.
  2. Decide whether an alert represents a credible threat.
  3. Correlate activity across multiple data sources.
  4. Investigate and hunt for related attacker behavior.
  5. Coordinate or execute containment and remediation under agreed authority.

Zscaler’s thesis was that its security-cloud telemetry and Data Fabric for Security could provide context, while Red Canary supplied detection logic, threat intelligence, analysts and response workflows. Zscaler described the move as a natural expansion into MDR and threat intelligence. Source: SecurityWeek.

What the combined operating model is intended to do

The announced vision is an integrated, AI-assisted security-operations capability spanning network, endpoint, identity, SaaS and cloud signals. A representative workflow would look like this:

  1. Zscaler observes suspicious access or traffic in its cloud.
  2. Signals are correlated with endpoint, identity, cloud or SaaS telemetry.
  3. Automated systems prioritize and enrich the alert.
  4. Red Canary analysts investigate, threat-hunt and determine scope.
  5. The customer or an authorized workflow contains the activity and remediates affected assets.
  6. Case intelligence and analyst findings improve future detections.

“AI-powered” should be read as AI-assisted triage, correlation, investigation and recommendations combined with human monitoring. The available evidence does not establish unrestricted autonomous response or a lights-out SOC.

How the deal fits Zscaler’s acquisition path

Zscaler acquired Avalor for approximately $350 million in 2024. Avalor supplied risk-management and Data Fabric technology; Red Canary adds managed detection, threat intelligence, investigation and response. Together, the acquisitions give Zscaler a logical path from collecting and contextualizing security data to operationalizing it in a SOC workflow. That is a product-fit inference, not evidence that every planned integration milestone is complete. Source: SecurityWeek.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

What customers may gain—and what they should not assume

Potential advantages

  • Fewer handoffs between a zero-trust provider and a separate MDR supplier.
  • Better correlation of network, cloud, identity, endpoint and SaaS signals.
  • Faster triage and more investigative context.
  • Access to continuous monitoring, analysts and threat-hunting expertise.
  • More automated containment and remediation options.

Important limitations

  • An integrated strategy does not guarantee one SKU, console, contract or lower total cost.
  • Customers may still need endpoint, identity, cloud, SIEM and third-party integrations.
  • MDR results depend on telemetry coverage, analyst processes, response authority and customer cooperation.
  • Existing Red Canary customers should verify packaging, contracts, data handling, integration support, service levels and roadmap commitments directly with Zscaler.

Competitive and market implications

The acquisition reflects cybersecurity consolidation: platform vendors are adding managed services and response expertise instead of selling only preventive controls. Zscaler becomes a more credible competitor to platforms that combine telemetry, detection and response.

Independent MDR providers retain a different proposition: vendor neutrality, specialized expertise, regional coverage or support for heterogeneous stacks. Buyers therefore face a trade-off between a closely integrated platform and an MDR that is structurally separate from their security vendors. The deal does not, on the available evidence, establish Zscaler as the market-share leader or prove that platform consolidation is superior for every organization.

Buying priority Likely direction
Existing Zscaler deployment and consolidation Zscaler with Red Canary capabilities
Endpoint-first detection and response CrowdStrike or SentinelOne
Microsoft 365, Entra ID and Azure alignment Microsoft Defender/XDR with managed services
Broad network, cloud and incident-response portfolio Palo Alto Networks Cortex and Unit 42
MDR-first relationship Arctic Wolf
SMB or MSP-oriented simplicity Huntress, subject to current scope and pricing verification

These are categories, not interchangeable products. Public pricing and equivalent service levels were not disclosed in the available sources. Zscaler directs buyers to its official site and reseller partners for evaluation.

Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

Risks and diligence questions

Integration and neutrality

The value depends on connecting Zscaler telemetry, Red Canary analytics, third-party endpoint data, identity signals and response workflows. Poor integration could leave an acquired MDR service beside the Zscaler platform rather than inside it. Customers may also ask whether Red Canary’s recommendations remain neutral toward products that compete with Zscaler.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
Rank #4
Mastering Microsoft Endpoint Manager: Deploy and manage Windows 10, Windows 11, and Windows 365 on both physical and cloud PCs
  • Mastering Microsoft Endpoint Manager: Deploy and manage Windows 10, Windows 11, and Windows 365 on both physical and cloud PCs
  • ABIS BOOK
  • Packt Publishing

Service quality and response authority

MDR is a people-and-process service. Buyers should clarify analyst coverage, escalation quality, false-positive handling and the limits of automation. In particular, ask who may isolate an endpoint, disable an account or block traffic; what approvals are required; how mistaken actions are reversed; and what happens outside business hours.

Concentration and AI risk

One supplier for access, telemetry, detection and response can simplify operations but increases dependency on its availability, pricing, roadmap and incident handling. AI may accelerate triage and recommendations, but buyers should not assume it understands every incident or safely executes every action without human oversight.

Customer checklist

  1. Confirm current Red Canary product names and Zscaler packaging.
  2. Review supported data sources, connectors and third-party integrations.
  3. Check data retention, processing locations and residency options.
  4. Ask about analyst coverage by region and time zone.
  5. Obtain escalation, response and incident-notification service levels.
  6. Document approval requirements for automated remediation.
  7. Understand onboarding time and required sensors or connectors.
  8. Clarify whether pricing is based on users, endpoints, assets, data, events or a custom subscription.
  9. Review contract treatment for existing Red Canary customers.
  10. Confirm portability of detections, playbooks, case data and threat intelligence if you leave.

What remains unknown

  • The purchase price and detailed transaction economics.
  • Retention and staffing plans for Red Canary personnel.
  • Exact product packaging, migration requirements and post-acquisition service-level changes.
  • Regional data-handling details and independently measured security outcomes.

The Bottom Line

Zscaler’s Red Canary acquisition gives the zero-trust vendor a credible route into managed detection and response: Zscaler contributes cloud telemetry and security controls, while Red Canary contributes analysts, detection, hunting and response operations. Its practical value will depend on integration depth, neutrality, service quality, customer control over remediation and support for mixed technology environments—not on the acquisition announcement alone.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

More post from the Money Desk

  1. The Money DeskBlogTheFinanceBase07 MAR 2625 minWhat Is a 457 Plan?
  2. The Money DeskBlogTheFinanceBase07 MAR 2621 minTime Value of Money: What It Is and How It Works
  3. The Money DeskBlogTheFinanceBase07 MAR 2627 minAre You Living in One of These Top 10 Most Expensive Cities to Retire?
Recommended PC Tool
Recommended PC Tool
Crashes, No Sound, or Screen Glitches?Free driver scan
Windows Errors? Fix Them Before They SpreadFree repair scan

Two free Windows tools

One Free Minute Could Fix That PC

Before you go - each of these free tools takes about a minute and tackles what quietly slows a Windows PC down.

Special offer. View Outbyte info, uninstall instructions, EULA, and Privacy Policy.