Zero Trust for Users Masterclass: The Playbook for M&A Day-1 Secure Access
dsd
Overview
The image is a screenshot from a presentation titled "Zero Trust for Users Masterclass: The Playbook for M&A Day-1 Secure Access," presented by Zscaler (featuring speaker Corey Burks).
It outlines "The Zscaler M&A Playbook," a step-by-step timeline strategy for integrating systems, applications, and security controls during a Mergers & Acquisitions (M&A) process to achieve secure access by Day 1.
Timeline Breakdown
Pre-planning Phase (Yellow)
Focus: Governance, due diligence, and foundational setup.
Key Tasks: IT due diligence, obtaining legal approval, establishing points of contact, and assessing legal and compliance implications.
30 Days Prior to Close (Light Blue)
Focus: Asset identification and placement planning.
Key Tasks: Identifying critical applications ("crown jewels") and planning placement locations for Zscaler App Connectors.
21 Days Prior to Close (Medium Blue)
Focus: Automated infrastructure deployment.
Key Tasks: Deploying App Connectors using Terraform within the target environment (noted here as the Red Canary environment).
15 Days Prior to Close (Dark Blue)
Focus: Validation and testing.
Key Tasks: Testing Zscaler Internet Access (ZIA) and Zscaler Private Access (ZPA) configurations in an isolated test environment to verify functionality without risking production.
7 Days Prior to Close (Magenta)
Focus: Identity and access control policy mapping.
Key Tasks: Defining Role-Based Access Control (RBAC) policies across all new ZPA traffic flows to enforce least-privilege principles.
Day-1 and Beyond (Green)
Focus: Execution and operationalization.
Key Tasks: Go Live — Enabling secure zero-trust user access on Day 1 without needing complex network convergence, VPN bridging, or routing overhauls.








.png)
