1,500

users secured with zero trust

188 M

transactions processed monthly

4 M

policy violations prevented quarterly

Défis

Traditional security architecture could not adequately protect a distributed cloud environment or secure hybrid users

Legacy firewalls and VPN appliances compromised outbound and inbound user connectivity, exposing a wider attack surface

Traditional experience monitoring solutions did not effectively mitigate user issues in an expanding digital environment 

Parcours client par étapes

Delivered secure direct-to-internet connectivity and expanded cloud sandbox features to protect users from any location

Reduced VPN use in favor of zero trust network access, enforcing least-privileged controls to shrink the attack surface

Introduced AI-powered monitoring features to better understand and positively steward the user experience in real time

Résultats

Secures outbound connectivity across Türkiye, enabling ~1,500 users to access the internet and SaaS apps from anywhere

Deploys least-privileged, zero trust access to secure private apps and data, blocking 700,000+ threats quarterly

Increases visibility into user experience across a distributed cloud environment, identifying and resolving issues faster

Enerjisa Üretim Snapshot

Largest private-sector power generation company in Türkiye

Industrie:

Energy, Oil, Gas, and Mining

Siège:

İstanbul, Türkiye

Taille:

36 power plants generating 4.25 GW

Onur Sari

Onur Sari

Network Architect, Enerjisa Üretim
Zero trust has been a game-changer ... With Zscaler, we’ve been able to eliminate the friction of legacy access methods with greater confidence that our user connections are governed by consistent policies.

Étude de cas client

Embracing zero trust security to operate safely in an expanding digital landscape

Enerjisa Üretim was founded in 1996 as a power supplier for Sabancı Holding (one of the largest Turkish conglomerates), providing electricity to the group’s industrial portfolio. Major reforms in Türkiye’s electricity sector in the 2000s saw the company expand its energy ecosystem, building and acquiring large generation assets across multiple technologies.

Today, Enerjisa Üretim is Türkiye’s market leader in private-sector electricity generation. 

With increasing focus on wind power, hydroelectric power, and solar power, 64% of the company’s current portfolio is dedicated to renewable energy and a lower carbon footprint.

As the energy sector becomes increasingly data-driven, Enerjisa Üretim has worked to modernize its operations through digitalization and embracing cloud technologies. A cloud-first approach allows the company to improve operational efficiency and system resilience. Because traditional legacy security architecture is not built to protect a distributed cloud environment, Enerjisa Üretim also made the leap to a zero trust security architecture as part of their digital transformation journey.

“As a critical player in the national energy infrastructure, compromised security doesn’t just result in IT disruption. It can have devastating real-world consequences,” said Onur Sari, Network Architect at Enerjisa Üretim. “A zero trust security model offers greater protection for our essential infrastructure and systems.” 

Zscaler preserves network identity while enforcing zero trust policies

Previously, Enerjisa Üretim relied on a legacy perimeter security architecture built around firewalls, VPNs, and various gateway-based threat prevention point products. This outdated security model became increasingly difficult to manage as the company’s users, applications, and infrastructure grew more distributed and digital. 

Enerjisa Üretim wanted a cloud native zero trust platform that could mitigate risk more effectively and better protect users, applications, and data across Türkiye. 

IT leaders at Enerjisa Üretim value independent industry analyst research when considering vendor partnerships. Zscaler is consistently recognized as a leading provider in the secure access and zero trust security market. After conducting a proof of concept with Zscaler, Enerjisa Üretim chose the Zscaler Zero Trust Exchange platform as the foundation for a new zero trust architecture.

“We wanted a scalable zero trust platform that could improve operational efficiency and eliminate risk,” shared Sari. “The Zero Trust Exchange really impressed us during the proof of concept.”

An important non-negotiable for Enerjisa Üretim was being able to use their own registered public IP addresses without compromising zero trust transformation. For enterprises operating in highly regulated industries that provide critical services, like energy generation, maintaining IP identity can be important for regulatory traceability and supporting already established external partner integrations.

Enerjisa Üretim would be able to deploy its Zero Trust Exchange platform as a Private Service Edge (PSE). A Zscaler PSE is a single-tenant, dedicated instance of the Zscaler service-edge software deployed exclusively for one customer in that customer’s own environment—meaning Enerjisa Üretim could maintain its specific network identity requirements and source IP while the Zscaler PSE connects to the Zscaler cloud to enforce zero trust policies enterprise-wide.

“Choosing Zscaler as our zero trust partner was an easy decision,” said Sari. “In fact, there really was no other choice once we started exploring the possibility for our own exclusive-use Zscaler service edge.”

Quote

With Zscaler, even if a user device becomes compromised, bad actors will not be able to move through the network ... threat is stopped at the endpoint.

Onur Sari, Network Architect, Enerjisa Üretim

Safeguarding end-user connectivity with Zscaler for Users

Enerjisa Üretim has prioritized a layered, multi-vendor zero trust security architecture. Rather than consolidating its technology stack with a single partner, the company intentionally maintains specialized solutions from multiple sources. 

“Our cybersecurity strategy is to use different vendors for different types of security functions,” explained Sari. “A best-of-breed approach lets us apply the most suitable technologies to each part of our environment.”

With the Zscaler platform—specifically the Zscaler for Users deployment—Enerjisa Üretim will focus on the end-user side of its environment. Tailored with user access in mind, Zscaler for Users is designed to secure user connections to the internet and corporate resources (both external and internal) regardless of a user’s location. This configuration will reinforce user-centric zero trust security across the company’s operations to protect nearly 1,500 Enerjisa Üretim employees. 

A phased deployment of the Zscaler for Users configuration has allowed Enerjisa Üretim to secure both outbound and inbound connectivity for end-users, shrink the attack surface, and strengthen overall security posture.

Phase 1: Zscaler secures fast, reliable outbound traffic for users across Türkiye

The Enerjisa Üretim workforce is dispersed across Türkiye. Engineers, plant operators, and field technicians support 36 power plants situated across the country, while corporate staff work from the Istanbul headquarters, several operations centers, and unlimited remote locations. Reliable and secure internet access for these employees is critical for daily operations in an environment like this.

Enerjisa Üretim deployed Zscaler Internet Access (ZIA) as its secure web gateway (SWG) to broker direct access to the internet and SaaS applications for users from any location. The Zscaler PSE configuration delivers traffic inspection and policy enforcement from a service edge exclusive to Enerjisa Üretim, eliminating the need to backhaul internet traffic.

ZIA includes functionality for zero trust firewall, URL filtering, and advanced threat protection. Most importantly, Zscaler enables 100% SSL/TLS traffic inspection at scale, ensuring that threats hidden in encrypted traffic can be identified and blocked without degrading connectivity performance. With these important security measures built-in to the Zscaler platform, Enerjisa Üretim can ensure zero trust policies are consistently enforced for all outbound traffic while strategically reducing the point products it chooses to manage.

The company expanded threat protection capabilities even further by adding Zscaler Cloud Sandbox to identify threats that signature-based systems cannot detect. Cloud Sandbox is a cloud-delivered advanced threat protection capability that uses AI/ML analysis and behavioral inspection to analyze unknown files, detecting malware and ransomware before they reach endpoints. 

“Every internet connection is inspected against our established security policies, no matter where the user connects from,” said Sari. “With Zscaler, we can provide fast, reliable user-to-internet connectivity without compromising security posture.”

Quote

The numbers say everything. Zscaler significantly strengthens our security edge.

Onur Sari, Network Architect, Enerjisa Üretim

Phase 2: Replacing VPNs with identity-based access control to protect critical resources

Enerjisa Üretim manages a wide range of sensitive operational and corporate data, including power plant monitoring systems, engineering platforms, operational analytics, and internal business applications. Protecting access to these systems is essential for maintaining reliable energy production and safeguarding critical energy infrastructure.

The company’s legacy VPN appliance was difficult to manage and slow to connect. Traditional VPNs expand the attack surface and provide broad network access once a user is connected, which enables threats to move laterally across the network. Additionally, VPNs do not support least-privileged access control policies, which can put applications and data at risk. 

Enerjisa Üretim deployed Zscaler Private Access (ZPA) as a zero trust alternative to its VPN solution. The company’s private applications and data, hosted on its own data center and anchored by Microsoft Azure, reside behind the Zero Trust Exchange, making them invisible to threats and unauthorized users. 

ZPA creates identity- and context-based policies that connect users only to the applications they are entitled to access. This user-to-app segmentation prevents lateral threat movement by connecting users directly to only the private applications they are authorized to use, eliminating the risks associated with broad, network-level access that VPNs enable. Having Zscaler Application Connectors deployed alongside ZPA means that users can access the private Azure environment from any location without the need for additional connections, like IPSec or ExpressRoute.

“With Zscaler, we can easily establish and enforce identity-based access control policies,” shared Sari. “On the Zscaler platform we can connect individual users or groups to our private applications quickly and without putting the internal network at risk.”

Phase 3: Enhanced experience monitoring increases visibility and expedites issue resolution

As Enerjisa Üretim continues to expand its digital infrastructure, the operating environment becomes even more distributed. Centralized telemetry is essential for effectively troubleshooting performance issues.

Traditional experience monitoring solutions aren’t designed for a cloud-first environment, only providing limited visibility around user activity and application performance. Inadequate experience monitoring solutions make it harder for companies to identify operational blind spots that create risk or degrade the user experience.

To complement its zero trust architecture and better manage the end user experience, Enerjisa Üretim is currently piloting Zscaler Digital Experience (ZDX), which eliminates visibility gaps through a single endpoint agent natively built into the Zero Trust Exchange.

By analyzing 500B+ daily transactions, ZDX offers a unified end-to-end view of the user-to-app journey, correlating device health and Wi-Fi data with last-mile and intermediate ISP telemetry—making it easier to monitor the company’s complete technology environment. With AI-powered root cause analysis, ZDX helps identify and resolve user issues more efficiently and without the effort of manual investigation. Challenges like last mile ISP latency or device health signals are easier to find, and ZDX will suggest effective remediation steps—remotely clearing caches, restarting Windows services, or rerouting traffic around ISP outages.

Using ZDX, Enerjisa Üretim can benefit from near real-time visibility into application, device, and network performance. Built-in Zscaler reports presented on a single-pane-of-glass dashboard will offer a greater depth of insight into user behavior, risk factors, and security posture. This enables a more proactive approach to stewarding the end user experience.

“With our workforce connecting from dispersed locations and accessing critical applications, it’s more important than ever for us to increase visibility around their user experience,” explained Sari. “Zscaler can help us understand application performance across our operating environment and respond faster when issues arise.”

Quote

We already see strong benefits from the core Zscaler platform, and look forward to exploring additional Zscaler solutions.

Onur Sari, Network Architect, Enerjisa Üretim

Next Up: Exploring Zscaler solutions to bolster threat protection and control data exposure

Achieving holistic zero trust is a dynamic process, not a one-time upgrade, and Enerjisa Üretim is already considering which additional Zscaler solutions to deploy in the future. While the company’s cybersecurity vision doesn’t shy away from multiple vendors, the IT team also recognizes that there are opportunities to strategically consolidate even more essential security processes on the comprehensive Zscaler platform.

Adding Zscaler Zero Trust Firewall will improve firewall controls for the company. While ZIA (already deployed) focuses on secure web gateway and application-layer security for outbound traffic, Zero Trust Firewall can extend protections to the network layer to secure all traffic, not just web traffic. The cloud-delivered Zero Trust Firewall centralizes user- and application-aware policy enforcement in a distributed cloud environment, securing web and non-web traffic for all users, apps, and locations.

Zscaler Unified DLP can help Enerjisa Üretim protect sensitive data and prevent data leakage. Zscaler DLP enforces consistent policies for data in-motion and at-rest across web, GenAI, SaaS, email, and private applications. Zscaler DLP also increases visibility into data exposure, identifying sensitive information wherever it travels.

Zscaler Zero Trust Browser could offer further protection against web-based threats by creating a secure barrier between user devices and web content. By controlling actions like copy-paste, printing, and file downloads, Zero Trust Browser protects against data leakage on both managed and unmanaged devices. Users can have a near-native browsing experience while Enerjisa Üretim maintains zero trust security protocols.

These additional solutions would expand the company’s zero trust architecture beyond secure access to provide layered protections that bolster threat prevention, control data exposure, and isolate risky web content. 

“Zero trust transformation is an ongoing journey for us,” said Sari. “We already see strong benefits from the core Zscaler platform, and look forward to exploring additional Zscaler solutions.”

Zscaler shrinks the attack surface and strengthens security posture

The most important drivers behind zero trust deployment at Enerjisa Üretim were shrinking the attack surface and strengthening security posture.

“Our primary mission as a cybersecurity team is to manage the attack surface,” explained Sari. 

His team identifies end-user devices as the company’s largest security risk, estimating that at least 60% of the attack surface at Enerjisa Üretim is situated at the client level. Because endpoints represent a majority of the potential attack surface, enforcing security controls at the end-user level through the Zscaler platform has dramatically reduced the company’s exposure to cyber threats. 

Sari also shared that issues with lateral threat movement have been eliminated as a result of Zscaler deployment. 

“Sometimes the biggest threats can come from within,” said Sari. “With Zscaler, even if a user device becomes compromised, bad actors will not be able to move through the network. The threat is stopped at the endpoint and never gains traction.”

In terms of the company’s security posture, it is measurably stronger on the Zscaler platform. In a recent quarter, Zscaler processed more than 566 million transactions and nearly 63 TB of traffic for Enerjisa Üretim, preventing four million policy violations and blocking more than 700,000 security threats. More than 7,000 of these blocked threats were hidden in encrypted traffic that the company’s previous security architecture would have been unable to inspect.

“The numbers say everything,” confirmed Sari. “Zscaler significantly strengthens our security edge.”

Zscaler partnership plays a central role in continuing digital evolution

By adopting a zero trust approach to user connectivity, Enerjisa Üretim has strengthened security for a distributed workforce and reduced the risk of threats that can start with endpoint devices. Protecting its users ultimately protects the critical generation assets that support energy production across Türkiye. The company continues to evolve its modern security architecture, and the Zscaler platform plays a central role in that evolution.

“Zscaler has helped us modernize how we manage secure user connectivity and private access,” concluded Sari. “Zero trust has been a game-changer, and the Zscaler platform is the foundation for our zero trust transformation. With Zscaler, we’ve been able to eliminate the friction of legacy access methods with greater confidence that our user connections are governed by consistent policies.”