21.3M
policy violations prevented quarterly
50%
TCO reduction
200%
improvement in operational efficiency
Desafios
The traditional perimeter-based security model reached its limits with cloud-based work surging including high Microsoft 365 adoption
As remote work grew, inconsistent policies and visibility between on-premises and cloud environments created management difficulties
Multiple point solutions for DNS security, remote access, and endpoint protection fragmented policy management and added operational complexity
Jornadas de clientes
Established consistent internet security across all users, locations and devices, blocking malicious sites and ransomware before they reach users
Strengthened data protection by controlling sensitive data transfers and blocking file uploads to unauthorized generative AI services
Unified remote access on a zero trust framework, running internet security and private app access through a single agent
Resultados
Strengthens security posture by eliminating ransomware incidents and inspecting 100% of encrypted traffic, which accounts for 87% of total traffic
Improves operational efficiency by 200% by managing a broader security scope on a unified SaaS platform without adding headcount
Establishes a foundation for global expansion with consistent security policies across worldwide operations, including the new US smelter
Korea Zinc Snapshot
The world's leading non-ferrous metal smelter, operating the largest single smelting facility globally
Setor:
Manufacturing
Sede da empresa:
Seoul, South Korea
Size:
3,000+ employees, with operations in Korea, Australia, and the US
Estudo de Caso
Non-ferrous industry leader makes bold move from perimeter-based security model to zero trust
Korea Zinc is the global leader in non-ferrous metal smelting, operating the world's largest single smelting facility at its Onsan complex in Ulsan, South Korea and producing more than 8% of the world's zinc. Beyond zinc, lead, copper, gold, and silver, the company has expanded into rare metals like indium, antimony, and bismuth, and now employs its "Troika Drive" strategy, focused on secondary battery materials, renewable energy, and resource circulation. A new smelting facility currently under construction in Tennessee, US marks the next chapter of its global expansion.
Behind this growth, Korea Zinc's IT security environment was undergoing a fundamental shift. The 2020 rollout of Microsoft 365 (M365) moved the company's work environment from on-premises to the cloud at an accelerated pace. As email, collaboration, and authentication moved to the cloud, the traditional castle-and-moat model, built on the assumption that the internal network is safe, began to show its limits.
At the time, Korea Zinc relied on a DNS-based security solution to block malicious sites. The company was utilizing multiple point solutions in parallel, which fragmented policy management and added complexity. The existing approach lacked the visibility and policy flexibility needed for cloud environments. As such, the company needed dynamic, context-aware policies based on user location, device, and access environment.
Phase 1: Making the move to zero trust with Zscaler Internet Access (ZIA)
In 2021, Korea Zinc began evaluating zero trust security platforms. At the time, Zscaler was effectively the only enterprise-grade zero trust cloud security platform available in the Korean market. Zscaler stood out as the right choice: a Gartner Magic Quadrant leader for Security Service Edge (SSE), backed by a strong portfolio of global references and a unified platform approach — delivering a global-standard security solution ready to deploy without customization.
Korea Zinc started by deploying Zscaler Internet Access (ZIA) to rebuild its internet access security from the ground up. With ZIA, the company enforced consistent internet security policies for every user, regardless of location. Beyond blocking malicious and unauthorized sites, ZIA delivered real-time SSL/TLS decryption, a capability missing from the previous solution, allowing Korea Zinc to find and stop threats hidden in encrypted traffic.
To secure the M365 environment, the team leveraged the Tenant Control feature. This allowed access only to the company's authorized tenants and shut down bypass attempts through personal accounts or unauthorized tenants. In the first three months after deployment, the platform processed roughly 1 billion transactions, prevented 21.3 million policy violations, and blocked 1,842 threats hidden in encrypted traffic.
The most dramatic change came in ransomware defense. Before deployment, Korea Zinc dealt with four to five serious ransomware incidents a year, each severe enough to require a full PC reformat. After deploying ZIA and integrating it with CrowdStrike EDR for endpoint protection, those incidents disappeared.
Phase 2: Protecting national core technology with Zscaler Data Security
As cloud-based collaboration spread across the company, controlling data movement and protecting core assets became urgent. Korea Zinc holds two technologies designated by the Korean government as national core technologies: the Hematite Manufacturing Technology for Iron Recovery in Hydrometallurgy and the Manufacturing Technology for Lithium Secondary Battery Cathode Precursors. The company also helps stabilize the global supply chain for germanium, a critical mineral for aerospace and defense. Strong controls to prevent leakage of this technical information were essential.
To meet this need, Korea Zinc deployed Zscaler Data Security. The team now monitors web uploads and internet traffic in real time for unauthorized transfers of unique data identifiers, including personal identification numbers. With File Type Control, the company proactively blocks file uploads to unauthorized cloud storage, personal webmail, and external generative artificial intelligence (GenAI) services that have emerged as security risks.
As GenAI use has surged across industries, raising data leakage concerns, Korea Zinc has taken a proactive stance, blocking low-relevance external AI services and arbitrary cloud platforms. At the same time, the team reviews monthly Zscaler analytics reports to track employee AI usage and keep data visibility comprehensive.
In the past, data flow management was confined to the firewall-protected internal network. Now, Korea Zinc applies consistent data protection governance in the cloud, wherever users work. Just as important, running ZIA and data protection on a single platform gave the company both policy consistency and operational efficiency.
Phase 3: Completing the zero trust framework with ZPA
To work around the speed and security limits of traditional SSL-VPN, Korea Zinc initially deployed a separate remote access solution. But running it alongside ZIA, with a different agent and management console, created two structural problems: a fragmented user experience for employees and dispersed operational resources for the security team. Users had to switch agents depending on their access environment, and administrators had limited ability to enforce precise access control based on device posture.
To solve this, Korea Zinc rolled out Zscaler Private Access (ZPA) across the enterprise in June 2026. Employees now use one agent, Zscaler Client Connector, to secure both internet access and private application access. The change is expected to sharply reduce end-user inquiries about agent conflicts and configuration errors, leading to better user experience and will also ease the security team's day-to-day load.
Zscaler's global Point of Presence (PoP) architecture (more than 160+ data centers globally) also delivers high-quality connectivity and a stable user experience for traveling employees and staff at global sites, without slowing them down. As a SaaS platform, it gives Korea Zinc a ready-made foundation for global expansion: when the new Tennessee smelter and other overseas operations come online, the company can apply the same zero trust policies as their headquarters, with no additional physical security infrastructure required.
Looking ahead: Evolving security for the AI era
Building on ZIA, ZPA, and Zscaler Data Security, Korea Zinc is shaping a next-generation security roadmap.
In the short term, the company plans to deploy Zscaler Zero Trust Firewall to strengthen DNS security and extend control to network-level application traffic. The goal is to move beyond web- and application-centric access control and gain granular visibility and tight control across the broader network infrastructure including non-web protocols.
Korea Zinc is also taking a proactive stance towards AI security. As GenAI adoption accelerates and MCP (Model Context Protocol) environments emerge to connect AI models with core enterprise systems, controlling data flows to and from AI services has become a defining challenge for the next wave of security. Korea Zinc is actively evaluating a PoC of Zscaler AI Security, with particular interest in capabilities that show which users connect to which AI services, and what data they share.
The company also plans to deploy the Zscaler platform across its new US smelter project, where network infrastructure design is currently underway. By applying the same cloud-based zero trust architecture as headquarters, Korea Zinc will strengthen its global security posture from day one.
Zero trust delivers gains in operational efficiency and global readiness
Since deploying Zscaler, Korea Zinc has seen measurable gains across operational efficiency, employee experience, and global compliance, well beyond simply blocking threats.
On the operational side, the unified SaaS-based management framework has reduced total cost of ownership (TCO) for security by more than 50%. In the past, security administrators spent significant time monitoring hardware status and handling firmware upgrades or equipment replacements as capacity limits hit. Now, the team focuses on what matters most: setting and optimizing security policy in the cloud. Deployment time for new security solutions has dropped by more than 80%. What once took more than a month from procurement to rollout can now go live in days through policy configuration alone.
Threat response has also strengthened through deeper integration. With the Zscaler platform at the center, Korea Zinc has connected CrowdStrike EDR, Microsoft Defender for Cloud Apps (MDCA), and Microsoft Sentinel into a unified security operations framework. Endpoint threats detected by CrowdStrike flow to Zscaler in real time to block network entry, while Zscaler's refined security logs flow to Microsoft Sentinel for unified analysis. The team can now monitor external intrusion attempts and internal data exfiltration in a single view.
Compliance, an essential gateway for global business, has also taken a major step forward. The ability to consistently block unauthorized sites and inspect encrypted traffic, regardless of user location, has created a favorable environment for industry security certifications such as TISAX. Zscaler became the first SaaS company to achieve CMMC Level 2 certification under US Department of Defense standards, enabling Korea Zinc to be well-positioned for regulatory compliance in future technology collaborations across the global defense supply chain.
Korea Zinc's zero trust journey is not a simple swap of security solutions. It is the work of embedding into corporate culture an operational model and governance framework that continuously verifies and controls users, devices, applications, and, most importantly, the company's data. As AI-driven work environments accelerate and global expansion continues, Korea Zinc plans to advance its security framework alongside the Zscaler Zero Trust Exchange platform.






