Toll Group Snapshot
End-to-end supply chain provider connecting businesses across Asia-Pacific and beyond.
Industrie:Transportation Services
Siège:Melbourne and Singapore
Taille:14,000+ employees across 300+ sites

250 sites
transitioning to zero trust
20%
projected annual savings
1 weekend
to stand up 22 locations
Défis
The outdated, complex perimeter-based network consisted of SD-WAN, firewalls, and VPNs connecting six data centers and was unable to support over 70% cloud adoption and expansion plans
Upfront capital investments in legacy hardware with support, maintenance, and fluctuating refresh costs created IT budgeting uncertainty
Frontline and in-office users struggled with poor performance when accessing mission-critical resources over VPN and MPLS
Parcours client par étapes
Replaced VPN with zero trust, allowing users to quickly and securely access the internet and vital cloud apps without backhauling to data centers
Transitioned branches from SD-WAN to zero trust, reducing setup complexity and costs
Deployed digital experience monitoring (DEM), moving to a proactive model for improving employee productivity
Résultats
Fortifies security posture and prevents data loss with inline TLS/SSL traffic monitoring, advanced threat protection, and inline DLP for all traffic
Accelerates site setup from months to just one weekend
Achieves annual CapEx cost savings while reducing complexity with a simple, predictable OpEx financial model
Global logistics company modernizes its aging perimeter-based network and security infrastructure with zero trust
Toll Group has been in business for more than 130 years, providing businesses in Asia Pacific with technology-driven shipping, transport, and supply chain solutions. The company has an extensive global footprint: more than 300 sites and 2 million square feet of warehouse space spanning 30 countries. Every project it undertakes is unique, ranging from transporting perishables, manufactured goods, temperature sensitive products to complex projects. Toll Group is committed to going the extra mile for its diverse global customer base, with the goal of ensuring seamless, tailored, and efficient service.
The company is investing heavily in growing its Asia Pacific presence with new infrastructure projects and joint ventures to enhance cross-border e-commerce for multiple sectors, from retail and healthcare to technology and government.
Toll Group shifted 77% of app workloads to Azure and AWS, but its outdated data centers and SD-WAN struggled to keep pace. Hairpinning cloud-bound traffic to data centers resulted in performance bottlenecks, impaired workforce productivity, and higher costs due to MPLS. When Toll Group’s data center network equipment reached end of life, the timing was perfect for Head of Technology David Linton to launch a cloud-first modernization initiative based on zero trust. His goal is to reduce the company’s data center footprint and retire on-premises security appliances by adopting the Zscaler Zero Trust Exchange platform to securely link its global locations.
“We had a very old legacy network that we had to uplift. Zscaler’s platform approach made sense and ticked a lot of boxes for us. As we transition to a cloud-first organization, zero trust is fully in line with our vision of enabling users to connect to cloud resources directly while phasing out legacy technologies,” said Linton.
Zero trust SASE paves the way for secure, high-performance connectivity to the internet and apps
The first stage of Toll Group’s zero trust secure access service edge (SASE) transformation was deploying Zscaler Internet Access (ZIA) and Zscaler Private Access (ZPA). The objective was to enable its mobile workforce to safely access the internet, SaaS, and private apps from anywhere and on any IT/OT device, including handhelds, scanners, and print servers. Employees work at distributed field sites, in transit via truck, ship, and even helicopter, or work from home, making secure remote connectivity a vital necessity. With identity-based, least-privileged zero trust access, users only have access to the resources they need. ZIA and ZPA reduce risk by working together to enforce consistent, unified access policies company-wide.
ZIA hides Toll Group’s apps and infrastructure from the internet, shrinking the attack surface. With integrated 100% SSL/TLS inline traffic inspection, it discovers and blocks hidden malware while preventing data loss. Linton and his team are currently focused activating advanced security controls, including:
- Zscaler Zero Trust Firewall to inspect and protect web and non-web traffic across all protocols, eliminating the need for costly, high-maintenance physical firewalls
- Zscaler Cloud Sandbox to isolate, analyze, and neutralize ransomware and zero-day threats
- Zscaler Secure Web Gateway to safeguard the organization from potentially malicious web content while curbing data exfiltration
By implementing ZPA, Toll Group has eliminated vulnerable, high-latency VPNs that backhauled traffic to legacy data centers. Private apps are no longer exposed to the public internet. ZPA shrinks the attack surface while preventing lateral movement of threats by connecting users directly to authorized private apps, never the corporate network. Users enjoy a superior user experience, with secure, frictionless connectivity to apps, regardless of where they work.
So far, Linton has rolled out ZPA to 2,500 users and ZIA to 2,000 users and plans to deploy both technologies to the rest of the workforce in the coming months.
Faster issue resolution creates a superior digital experience and helps users keep pace with business demands
Timeliness is critical to global logistics. Any connectivity friction or application lag directly impacts field productivity and supply chain SLAs. To minimize downtime, Linton is deploying AI-powered Zscaler Digital Experience (ZDX), which is seamlessly integrated into the unified Zscaler SASE platform. ZDX, a digital experience monitoring (DEM) tool, helps maintain business continuity by enabling faster resolution of network outages or connectivity slowdowns. By providing real-time, end-to-end visibility, ZDX makes IT more efficient by reducing time spent on troubleshooting and accelerating time to resolution. This ensures a productive, disruption-free digital experience for employees wherever they work.
“The service desk more clearly understands the experience users are having. They can precisely pinpoint connectivity issues and triage tickets faster,” said Linton. “One of the intangible benefits of ZDX is our ability to be more proactive, fixing issues before users even notice anything.”
Accelerating new site setup: From eight weeks with SD-WAN to one weekend with Zero Trust Branch
With the core components of a secure zero trust access and DEM in place, Linton took the first steps toward converting distributed sites to Zscaler Zero Trust Branch. Traditionally, branch traffic was backhauled via expensive MPLS to data centers for inspection by firewall appliances and other solutions in the security stack. But this outdated SD-WAN model introduced excessive risk, complexity, and latency.
“Our SD-WAN network was ready for a lifecycle management refresh. In Zscaler, we found a smarter way to do things. Rather than going through our data center, our branches connect to Zscaler and then straight out to the cloud,” said Linton.
The transformation was spurred on to meet the stringent IT, data security, compliance and third-party risk requirements of its customers, particularly in environments handling sensitive operational and defence-related information. After weighing the pros and cons of SD-WAN versus Zero Trust Branch, Linton determined that SD-WAN was unable to meet the rigorous timelines and proved to be more costly.
Before Zscaler, Toll Group relied on a managed service provider (MSP) to acquire prescribed SD-WAN hardware and set up new sites—a one-size-fits-all approach that often caused procurement and technical delays and typically took up to eight weeks.
“With Zero Trust Branch, we were able to go live with 22 new sites in just one weekend. All this was accomplished with zero high-severity incidents and significant cost savings while speeding time to market with an agile, scalable solution. Toll Group has never done anything like that before,” related Linton.
With the new DTL sites in place and its two data centers in Australia phased out, Toll Group looks forward to leveraging Zero Trust Branch to enable its remaining 200-plus sites in Asia Pacific and EMEA and eliminate four more global data centers.
How zero trust transforms the financial model
Zero Trust Branch has completely changed how the Toll Group budgets for infrastructure and security. Under the traditional architecture, the company invested heavily in capital-intensive network and security stacks, maintenance, and support contracts. Using a typical capital expenditure (CapEx) model, the company depreciated and amortized these costs over a period of time. Additionally, because equipment reaches end of life at some point and needs to be replaced, spending was uneven. For these reasons, it was hard to forecast month-to-month budgets.
With the operating expenditure (OpEx) model that Zscaler provides with Zero Trust Branch, Toll Group knows exactly what their costs are over the entire life of their contract. If one of their Zscaler devices goes down, Zscaler replaces it free of charge under the terms of the lease. Patches are pushed out automatically and can be released by Linton’s team at their discretion.
“The simplified zero trust SASE architecture cuts costs by reducing hardware dependencies. We’ve forecasted annual savings of 20%. We no longer have to navigate CapEx as we've done in the past. Apart from streamlining the budgeting process and providing cost benefits, Zscaler’s OpEx model makes conversations with business units easier. Now I can tell them something they like hearing: ‘You have project depreciation amortization, but you have no upfront infrastructure costs,’” explained Linton. “At each of our zero trust-enabled sites, we’ve done away with complex lifecycle refresh management for firewalls, routers, and other equipment.”
Everything works better, faster, and more efficiently with zero trust
Along with cost savings, there are other positive business outcomes resulting from the switch to Zscaler’s unified zero trust platform.
The cutover to Zscaler for the 22 DTL sites provides Toll Group with a repeatable blueprint that the company can extend to its other sites. Through disciplined planning, a standard Zero Trust Branch configuration template, and cross-functional team alignment, the company can accelerate its global transformation, standing up sites in just one weekend without disrupting business operations.
Zscaler has also strengthened security across users and IT/OT with company-wide zero trust enforcement; advanced threat protection and data loss prevention at scale; and app and device segmentation to shrink the attack surface and prevent lateral movement.
Linton pointed out that these advantages and efficiencies have been enthusiastically embraced by both general users who enjoy seamless access and IT for its simplicity and wide range of capabilities.
On the horizon: Ensuring business continuity and governing AI agents
In the near term, Linton and his team are actively rolling out Zero Trust Branch to all locations, methodically phasing out legacy data centers. When the job is done, they aim to thoroughly assess the remaining infrastructure to fully modernize on the cloud-native zero trust architecture.
Moving forward, Linton is interested in exploring Zscaler Business Continuity Cloud for ZPA to sustain uninterrupted access to mission-critical apps in the event of unexpected cloud or internet outages. Zero trust policy enforcement will continue during disruptions to prevent attackers from exploiting potential vulnerabilities and will ensure resilient operations.
Linton is especially looking forward to learning more about Zscaler’s latest innovations around AI security that provide visibility into and govern AI agents without compromising agility. He explained that Toll Group manages two types of agents: productivity agents tied to the identities of individual employees and enterprise agents that have their own distinct identities. One of his top priorities is securing them and mapping their data usage across the environment.
“Agent sprawl is something that’s bound to happen at organizations, and we definitely don't want that at Toll Group. We believe that Zscaler will provide the insights for us to understand that a lot better and then put in the right compensating controls. Investing in the tools to provide insights, observability, and control from a single platform is something I’m really excited about,” said Linton.



