3 Months
to deploy zero trust access
50K
global users protected by zero trust
92%
faster security update management
Desafíos
Traditional network perimeter security architecture could not scale to support the company's modern cloud migration plan
Legacy firewalls and VPN appliances could not support least-privileged policy controls, exposing a wider attack surface
Traditional monitoring solutions only provided siloed performance insights, creating risk and degrading user experience
Experiencias de clientes
Delivered direct-to-internet connectivity as a strategic precursor to planned migration from data centers to the cloud
Replaced VPNs with zero trust network access, leveraging AI power to map application segments with speed and precision
Introduced AI-powered monitoring features, gaining end-to-end visibility from user to app for faster issue resolution
Resultados
Secures connectivity across 100 countries and 2,000 corporate locations, protecting 800+ critical IT systems in the cloud
Automates user-to-app mapping and segmentation to shrink the attack surface, blocking two million threats quarterly
Increases visibility into user activity and app performance across the cloud environment to better support global operations
KION GROUP AG Snapshot
World leader in industrial trucks and integrated supply chain solutions
Sector:
Manufacturing
Sede central:
Frankfurt/Main, Hessen, Germany
Size:
€11.3 B in annual revenue
Historia de Éxito de Clientes
Shifting the security mindset with zero trust
KION GROUP AG was formed in 2006, the outcome of consolidation between shipping solution leaders Linde Material Handling and STILL GmbH. Today, KION’s portfolio consists of well-known brands including Dematic, Baoli, Fenwick, and OM – enabling KION to offer its customers the full spectrum of supply chain solutions around the globe. The combined history of these brands represents more than 200 years of innovation in materials handling and shipping logistics.
Today, KION is recognized as a world leader in industrial trucks and integrated supply chain solutions, including intralogistics and warehouse automation. With more than 2,000 sales and service locations in 100 countries and 28 production plants across five continents, the company has a highly dispersed global footprint.
To bolster efficiency and ensure operational resilience, KION recently modernized IT infrastructure, migrating its diverse operating environments from data centers to the cloud. Because a traditional, network-based security architecture can’t support a dynamic, cloud infrastructure, adopting zero trust was also part of the company’s larger digital transformation.
“The traditional model of securing a network perimeter no longer reflects how our business actually operates,” said Steffen Sollorz, Director Network & Communication Platform with KION Group IT. “Zero trust was the only security model that could keep pace with our modern cloud infrastructure. This wasn’t just a security upgrade, this was a strategic shift in security mindset.”
A zero trust platform to support all phases of cloud maturation
To prepare for its eventual move from data centers to the cloud, KION had already deployed Zscaler Internet Access (ZIA) to secure outbound traffic in a consistent, cloud-delivered manner. Early adoption of this solution enabled the company to provide direct internet connectivity for a distributed workforce of 50,000 users, start streamlining its technology estate, and begin the separation from traditional data center infrastructure. This foundational step was an intentional precursor to the company’s planned cloud migration.
“Zscaler is a recognized market leader in cloud-delivered security with a broad portfolio of zero trust solutions,” shared Sollorz. “While we only deployed one solution initially, we appreciated that there was an opportunity to consolidate other key areas of our security architecture on the Zscaler platform as our cloud migration matured.”
“Zero trust was always part of our long-term security strategy,” added Helge Never, Senior Manager WAN & Security Operations with KION Group IT. “Choosing Zscaler to secure outbound traffic was the first important step on that journey.”
Once infrastructure migration to Microsoft Azure was complete, KION wanted to mature its zero trust approach and improve security around application access, with an emphasis on identity-based policies.
The company’s remaining network-centric security architecture, built around IPSec connectivity and VPN access, had become too complex to manage in a cloud environment. These legacy appliances did not support least-privileged access and posed an increasing security risk.
Because the ZIA solution was already deployed and working well, it was a natural and easy decision to expand zero trust architecture at KION using the Zscaler Zero Trust Exchange platform. Seamless integration with Microsoft & Google (the providers driving cloud transformation at KION) reinforced the decision to deepen engagement with Zscaler.
“Zscaler has already proven to be a strong partner with a reliable product,” explained Never. “We were confident that expanding our use of the Zscaler platform could help us move towards zero trust with greater efficiency and a stronger security posture.”
Replacing VPNs with identity-based access to better protect global supply chains
KION currently hosts 5,000 applications and operates more than 800 IT systems in the cloud. These private resources are like a digital nervous system for the company, running the critical processes that are essential for both daily operations and future resilience. In the high-stakes risk environment of logistics, compromise to any of these resources can lead to real-world supply chain disruption.
In the wake of cloud migration, the limitations of network-based access became more pronounced, and the company recognized that a legacy VPN solution was not aligned to its long-term zero trust strategy. The way traditional VPNs function to broker remote access via public IP addresses inherently creates a wider attack surface. Because VPNs do not support granular access control policies, the risk of lateral threat movement also increases.
KION replaced VPNs with Zscaler Private Access (ZPA). The company’s private applications and systems, hosted primarily on Microsoft Azure, are now hidden behind the Zero Trust Exchange and no longer accessible via the internet. Behind the Zscaler platform, these resources become invisible to unauthorized users and bad actors.
ZPA enables identity- and context-based policies that map users only to the resources they are entitled to access. This user-to-app segmentation prevents lateral threat movement by connecting users directly to only the private applications they are authorized to use, eliminating the risks associated with the whole-network access that VPNs enable.
Since ZIA was adopted enterprise-wide before the company’s cloud migration, KION was able to expand its Zscaler platform rapidly, deploying ZPA to enable zero trust network access (ZTNA) for its 50,000 internal and external users in just three months.
“Retiring legacy VPNs in favor of ZTNA eliminates the risk of lateral threat movement across our most sensitive systems,” said Luca Bathon, Zero Trust Solutions Engineer with KION Group IT. “With ZPA, we’ve taken a big step forward on our path to true zero trust architecture.”
Zscaler Autonomous User-to-App segmentation blends precision and speed to support seamless least-privileged access
With ZPA, KION fully shifted its security mindset from network-centric to application-centric, enabling true least-privileged access through granular application segmentation. Even with that crucial new foundation unlocked, defining the right segments at a global enterprise scale, with thousands of applications and tens of thousands of end-users, can quickly become complex.
Manually mapping user-to-application segments often creates unsustainable administrative overhead with introduce bottlenecks and frequent break-fix cycles. On the other hand, wildcard access risks recreating the flat network problem and reverting to a VPN mindset in a ZTNA paradigm.
To avoid the extremes of policy bloat and policy laziness, KION added Zscaler Autonomous User-to-App Segmentation to its ZPA deployment. This AI-powered solution uses machine learning to analyze transaction data and recommend precise, granular user access parameters, automating and accelerating the process of application segmentation.
Autonomous Segmentation groups applications by actual usage patterns and continuously adapts policies as environments change. With one-click policy deployment and continuous policy refinement, KION Group IT can deliver precise zero trust policies faster, with greater confidence and less administrative burden.
“Autonomous User-to-App segmentation on the Zscaler platform blends the precision of meticulous segmentation with wildcard speed,” explained Bathon. “Understanding our unique transaction patterns helped us replace guesswork with data-driven insights to ensure seamless least-privileged access across the enterprise.”
Translating Zscaler insights into better support for business-critical resources
To complement its evolving zero trust architecture, KION also deployed Zscaler Digital Experience (ZDX). Unlike traditional monitoring tools that deliver only fragmented visibility into either user activity or application performance, ZDX provides end-to-end visibility across the entire digital experience — from the user's device, through the network, to the application.
With ZDX, KION's front-line technical support teams can quickly pinpoint where a performance issue is occurring — whether it originates on the device, across the last-mile ISP, Zero Trust Exchange, or at the application itself. This clarity allows Level 1 support to diagnose and resolve common user issues faster, without the back-and-forth escalations that previously slowed response times.
“ZDX has been a really beneficial tool for the IT team, especially for bolstering our first level of support for user issues,” shared Never.
ZDX also gives KION near real-time visibility into device, network, and application performance on a single-pane-of-glass dashboard. That consolidated view has been especially valuable as KION operates thousands of applications and 800+ IT systems across a globally distributed footprint, where performance bottlenecks were previously difficult to detect, let alone resolve.
The insights gained through ZDX have allowed KION to establish better KPIs around traffic patterns, directly supporting the company's broader goal of protecting business-critical resources across its global supply chain.
"Before Zscaler, we did not have a global traffic view," said Bathon. "Zscaler gives us greater transparency to identify and resolve network performance bottlenecks, so we are using it more effectively to support critical business resources."
Leveraging the Zscaler platform to close security gaps and strengthen security posture
The depth and breadth of visibility that KION gained through the Zscaler platform has enabled the company to transcend from fragmented insights and reactive monitoring to data-driven governance.
The team led by Sollorz, Never, and Bathon were able to identify pockets of shadow IT and problematic misconfigurations. Unsupported legacy systems and unsanctioned SaaS applications had slipped through the cracks of a traditional security architecture, and these discoveries empowered further architecture cleanup at KION. The IT team decommissioned insecure legacy appliances and removed unsupported applications. Streamlining the company portfolio forcing application, security & user standartization.
“Zscaler helped us identify issues we weren’t able to discover in the past,” explained Sollorz.
“The visibility and insights gained on the Zscaler platform allowed us to identify hidden security gaps,” added Never. “With Zscaler, we turned over every stone and cleared out the debris.”
KION has leveraged a modern, zero trust architecture built on the Zscaler platform to eliminate problematic legacy systems and shrink the attack surface—effectively closing those security gaps and strengthening security posture.
“With Zscaler, we have the data and insights to strategically define and consistently enforce security policies on a global scale,” said Sollorz. “The improvement in our security edge is notable.”
In a recent quarter, Zscaler processed more than 15 billion transactions and around 1,700 TB of traffic for KION, preventing nearly 219 million policy violations and blocking more than two million security threats.
Zscaler removes the friction from security management and enhances end user experience
In addition to strengthening security posture, another key driver for zero trust adoption at KION was the aim to simplify security management and improve user experience.
With the company’s legacy architecture, the IT team was maintaining no fewer than 17 different VPN gateways to control private access. These hardware-dependent silos carried a significant maintenance debt, requiring frequent manual patching cycles that could take up to 24 hours for each update, often across weekends. The high likelihood for misconfiguration was always a risk.
Embracing zero trust architecture on the Zscaler platform has created a cascading phenomenon of cost savings for KION. The siloed gateways are gone, which optimizes infrastructure costs. Zscaler also eliminates technology debt for the company by securing the backend environment automatically. The IT team uses the Zscaler Beta Cloud to validate updates with a predefined test group before globally pushing verified updates to end-user devices using the Zscaler Client Connector. What used to be a 24-hour process is now accomplished nearly 92% faster on the Zscaler platform, taking only around 2 hours, and the chance of global misconfigurations is eliminated with the buffer of a beta tenant.
“Having the Zscaler platform as our central control plane eases the complexity of operating safely in a cloud environment,” shared Never. “Zscaler removes a lot of the friction from security management.”
It’s not just the IT team experiencing less friction on the Zscaler platform. When the company was reliant on legacy solutions for private access, users had to actively connect to the network by manually enabling a VPN and providing passwords. Time spent on this VPN ritual is time that could have been invested in mission-critical work—even a few minutes is a drag on efficiency, especially when compounded by the tens of thousands of KION end users across the globe.
Now, users no longer need to initiate network connections. On the Zscaler platform, with the Client Connector running on endpoint devices, access to private resources is brokered automatically. Bathon estimates that end-users can connect 15-20% faster with Zscaler. Optimizing on the applications availability and multi cloud & multi regional setup.
“Whether working in the office or remotely, connectivity is as simple as ‘open browser and go’,” said Sollorz. “The Zscaler platform has simplified life for our users and boosted organizational agility.”
Securing critical external partner access with greater efficiency
This boost in agility at KION has also improved how third-party partner access is managed. On the Zscaler platform, there is no need to integrate networks or default back to VPNs for connecting external contacts. Onboarding external users is as simple as adding the Client Connector to user devices, creating user profiles that define which applications are allowed, and granting the new users access to the ZPA solution. Because Zscaler operates the world’s largest inline security cloud (160+ edge locations), the Zero Trust Exchange can support expanding volumes of traffic and users from any location. This seamless access is easily scalable, so the KION IT team can make adjustments quickly, when needed.
When an established external partner with 80-100 users was recently compromised, the IT team were able to immediately remove all users from that partner organization from the Zscaler platform simultaneously, cutting their access to private resources within seconds at the click of a button. Once the partner issue had resolved and was no longer a threat, those users were re-onboarded to the Zscaler platform within a day. The attack surface remained stable and shielded throughout.
With the company’s previous legacy solutions, removing access would have required manual intervention per individual user, and re-onboarding would have taken at least 30 minutes, again done manually per user. The risk of lateral threat movement would have been unavoidable in this scenario.
Sollorz believes this example makes a strong case for how the Zscaler platform could help KION expedite future expansion efforts if the company adds new brands to the portfolio.
“The scalability of the Zscaler platform allows us to onboard users flexibly, quickly, and securely, and I can certainly imagine how this would extrapolate to future M&A activity,” explained Sollorz. “Zscaler could help us better support those efforts.”
Future-proofing operations in partnership with Zscaler
As KION continues to mature its zero trust security architecture, the company wants to explore how Zscaler can help expand zero trust automation using AI technology.
Connecting the company’s Agentic AI to the Zscaler OneAPI framework with the Zscaler Integrations Model Context Protocol (MCP) Server could help KION translate stored corporate intelligence into autonomous security orchestration. This approach would ensure that as new AI workflows emerge, security posture scales accurately.
“Automating security processes based on API calls could save time, minimize error, and, ultimately, mitigate business risk better,” shared Never. “That’s a big plus in my book, so this would be an interesting next step on our zero trust journey.”
In partnership with Zscaler, zero trust at KION is about more than just secure access now—the comprehensive, AI-powered Zscaler platform unifies global security management and provides data-driven intelligence that can help future-proof operations for the logistics leader.
“I’m always careful when using the word ‘partnership’ because, at the end of the day, most companies are really just providers and we are the customer,” concluded Sollorz. “But with Zscaler, I truly see this as a partnership and we are excited to continue on our path to holistic zero trust.”
Soluciones








