Komatsu Australia is moving to protect its corporate network using zero trust network architecture to tackle rapidly emerging cyber security threats posed by frontier AI models.
At the end of this month the mining equipment company will enter a pilot phase using Zscaler’s cloud-based security, zero trust exchange, to broker access to its applications, moving away from investment in building its own network protection infrastructure.
The initial pilot will involve up to 100 users with a view to extending it just over 4000 users across its network footprint in Australia, New Zealand, New Caledonia and Papua New Guinea.
Komatsu Australia cyber security manager Henry Wright told iTnews that the change meant that the company would treat every device connecting into its network, whether in the hands of a remote worker or one on premises, with the same level of trust.
The move is partly driven by concerns about internal security threats such as employees transitioning to rivals, however Wright said it was primarily in response to recent developments in AI.
Specifically, Wright said he was referring to the increasingly frequent reports of the likes of Anthropic and OpenAI losing control of agents that then autonomously carry out successful cyber-attacks on other companies.
“The concern that we have right now … is things like [Claude] Mythos where they are going to scan your environment at machine speed to find a way in. If we're not working towards minimising that attack surface, we're opening ourselves up for a serious world of pain.
“That's why we started now. We think that as these advancements progress and as threat actors start utilising these tools to their advantage doing things at machine speed it’s going to be scary, so we're planning for that and that's why we want to separate our network completely,” Wright said.
Zscaler's zero trust network access (ZTNA) methodology is based on the concept of placing a switchboard between end users, an organisation's applications and the wider internet.
Applications called client connectors that sit on devices and lightweight virtual machines that run in data centres reach each other through points of presence on Zscaler's global Zero Trust Exchange cloud platform to have security controls applied.
Depending on what services are turned on, the zero trust exchange then controls what applications or internet locations users can access.
Zscaler internet access (ZIA) replaces traditional firewalls acting as secure gateways to control outbound public internet access requests.
Zscaler's ZPA service sets access policies for inbound requests for applications which are, theoretically, then made invisible to the wider internet behind ZTE, hiding the attack surface from threats.
Komatsu had been using ZIA for remote workers since the pandemic and is now expanding to ZPA.
Even with the attack surface reduced, Wright said his main concern with AI is not that it would uncover critical vulnerabilities, but rather that it will find smaller ones and chain them together to create novel attack paths.
“I just think that we don't know what we don't know and that's the fear I have,” he said.
The investments have also moved the heavy equipment manufacturer away from a capex model toward an opex model for security.
As iTnews has previously reported, it’s an approach adopted by the likes of Toll Group was well.
“If we were looking at the alternative – where we did the traditional, let's build a firewall, let's build a web application firewall, let's … build out a closed network with infrastructure and everything else – we would be spending a lot of time trying to upgrade that change at a cost to the business because those things are not cheap,” Wright said.

Open House Sydney
SAP NOW AI Tour ANZ
Open House Melbourne
NiCE World APAC 2026
Forrester's AI Forum Sydney



