- Products
- Learn
- Local User Groups
- Partners
- More
Quantum Spark Management Unleashed!
Check Point Named Leader
2025 Gartner® Magic Quadrant™ for Hybrid Mesh Firewall
HTTPS Inspection
Help us to understand your needs better
CheckMates Go:
SharePoint CVEs and More!
Congratulations to our CheckMates Champions for 2022:
Q&A below.
We are the leading provider of cybersecurity solutions, protecting businesses, critical infrastructure, and governments from cyber-attacks by providing the best security solutions.
We have plans for new capabilities to help customers manage their policy. The focus will be on better visibility & understanding of what is happening in your policy plus suggestions to tidy it up and tighten rules by analyzing actual traffic patterns. We may also include suggestions for new rules, based on applications or users we see in the network.
It's not currently in our plans to provide a generic wizard to add/modify rules. It is very challenging to provide good recommendations in a complex rulebase that will not make it bloated with many rules. It's something we tried in the past ("rule assistant"), but we were not satisfied with the results to make it GA.
We are hard at work in adding more features and capabilities to Web SmartConsole, which is supported in Quantum Security Management from R81.
New features are actually written directly into Web SmartConsole and hosted in the full Windows SmartConsole. In 2023, we have more content planned such as a new Gateway editor.
Since Windows SmartConsole is a huge application with many features, this is a journey that will take time and we cannot yet give a definitive ETA. That said, we are open to feedback from the field on which features they want to see first.
In R82, we are planning to add support for IPv6-only support for the management traffic (policy installation, logs, monitoring, ...). The Management machines themselves may still use IPv4 for some things such as HA sync. Note that this is a plan and not yet a hard commitment.
The deliverable for Skyline is an OpenTelemetry Collector, which will send the data to any server capable of consuming OpenTelemetry data. We have tested our integration with Promethus and Grafana and provide some basic instructions for installing these servers. We also provide sample dashboards for Grafana in the Skyline SK.
OpenTelemetry itself provides a number of tools, APIs, and SDKs which make it possible to integrate with other solutions.
Yes.
We are addressing both performance and usability challenges during the coming year, some of which will land in the next major release (R82). We are also developing a "learning mode" which will help identify potential issues during deployment and provide recommendations.
We follow secure coding best practices and implement tools in our development pipeline to catch vulnerabilities before they are released. We react quickly to reported security vulnerabilities, both in Check Point developed code and open source code that we include as part of our products.
A love of math, computer science, and riddles. All of which are very complementary in Cyber Security. Was exposed to Cyber Security in the army.
We continue to work on moving SmartDashboard content into SmartConsole. We try to handle the features that are used by many customers, so some legacy features that aren't frequently used will not be migrated.
In R80.40 we moved much of the HTTPS Inspection configuration (such as the rulebase), and in R82 we plan to move much of the remaining HTTPS inspection functionality.
Check Point’s Nano-Agents is a technology that allows organizations to protect and prevent threats targeting a wide spectrum of platforms and systems. Nano Agents enforce security best-practices on the platform and context on which they are installed and run, for within IOT device firmware, on web servers, and more.
Here are several examples of how we leverage Nano agents today, to prevent threats:
We will continue expand our nano agents technologies – to protect more platforms and offer further security capabilities
Yes, we're planning to introduce the concept of a "Trust Profile". This will allow our customers to setup different trust requirements such as device, authentication level, geo location, posture and more. We also plan to allow trust mitigation and on-demand ask users for a step-up authentication. There is also an aspect of building such a policy that we plan to automate for our customers so this will not be a massive project.
3 key aspects: first, the ability to inspect SCADA protocols and provide IPS signatures for ICS. second, ruggedized appliance that can withstand the harsh environmental conditions and third, partnership with 3rd party vendors that specialize in ICS and OT.
We expect to release the solution during Q1 this year. More specifically, we're aiming at the first week of February during our CPX events.
If you consider the stats from our IoT Protect, the top ones will be VoIP phones, IP Cameras and printers (based on popularity).
I would start with understanding the ways to backup and the best practices around it. See:
https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&solut...
They will co-exist in many environments.
It's a very wide topic but I will say:
We see SASE continuing to evolve and gain popularity, as businesses aim to adopt cloud-based network security that is delivered as a service, to protect their roaming users, and to implement zero-trust network access. Another key driver is the adoption of SD-WAN and the move to direct internet breakout from branch offices.
Check Point's SASE solution is Harmony Connect, which provides a complete solution. We continue to rapidly expand end enhance the Harmony Connect service in multiple ways. Some examples of things we are working on: unified management of Harmony Connect gateways from Smart-1, advanced zero-trust policy enforcement, new scalable network-as-a-service back-bone and tight integration with the upcoming Quantum SD-WAN.
This is already addressed today by ThreatCloud, but... specifically for more flexible and granular response scenarios we do work on something exciting as part of the Horizon family called 'PlayBlocks'. we will further elaborate on it during CPX event. stay tuned!
NSaaS will be available on top of AWS in Q1. More specifically we aim to have it ready for CPX.
We're expanding the number of IoT/OT partners we will integrate with. The new technology is API based and allow other vendors to provide their OT intelligence as well as read data discovered by our gateways.
Yes
There is a significant roadmap for 2023 around Threat Prevention with a strong focus on zero day unknown threats and AI. This includes adding new capabilities to our DNS security offering, web security, file security and some very exiting and important new domains. Much of this will be covered as part of the upcoming CPX events - so I strongly recommend attending!
We added MDR and we have many more services - we look at make more clarity around all the wide services we have
Traditional WAF products are based on signatures, and given that it's their nature they can't many sophisticated attacks and zero-days. AppSec is AI Based - it has proven time after time that it's AI security engine can protect against zero days like log4shell / spring4shell / sqlite json bypasses...
Moreover - AppSec can be deployed within modern platforms as it uses the nano-agent I/S - can be Kubernetes/Docker/Embedded Linux Agent and soon as a service as part of Check Point NSaaS.
Where all other vendors had to develop signatures, Appsec was preemptive to all of the above due to its superior technology.
Yes, we already improved the performance in R81.20 with HyperFlow and we plan to continue improving during 2023. We put a focus on improving our TLS inspection -- we plan for this to be software only so ALL of our customers can enjoy the benefits.
We plan to add the ability to add gateways and clusters through web smart console. In parallel, we're simplifying the way to connect gateways to Smart-1 Cloud via Zero Touch.
Harmony Email is cloud-based. We are now working to attach some of its features and functionality to our Quantum Security Gateway MTA.
What is Check Point's goals and features plans for providing security on cloud platforms?
We secure our customers in the cloud today in a viraiaty of ways (network / appsec, posture, intelligence, containers, serverless, dev 2 cloud and more. We think that too many customers are using detection more than prevention in teh cloud and we aspire to make it easy enough to place full security and prevention thru all the vectors of entry to cloud.
Yes, clustering is supported for active/standbay, active/active and Maestro hyper scale. All methods are valid and have their advantages so it is hard to comment specifically. I am sure your local Check Point SE would be happy to discuss the deployment most suitable for your requirements.
Check out the next-next-gen of AI and Threat Prevention session.
Some of our big customer replaced traditional solutions with appsec.
AppSec can do two things in relates to whitelisting:
On our roadmap - is to build the schema based on the traffic we see.
On top of the dedicated IOT security features, IOT device traffic undergoes inspection by our various threat prevention blades including IPS, Anti-Bot and others. For example IPS will be able to block attacks targeting vulnerabilities in IOT devices and anti-bot will be able to prevent C&C traffic using our advanced AI detection engines and with ThreatCloud.
Im upset now I could not attend, amazing stuff by the way and that jingle at the end, very impressive ; - )
I saw my photo in one of the slides, I think that was in China somewhere, gigantic floating restaurant...gotta love those : - )
CHEERS TO EVEN BETTER 2023!
Andy
"Not to be confused with Dwayne, The Rock, Johnson" said @Menuchak 🙂
We did post the Shwed Zeppelin tracks here: https://community.checkpoint.com/t5/General-Topics/Shwed-Zeppelin-songs-Part-of-CheckMates-Fest-2023...
Well, NO OFFENSE @PhoneBoy, if I was famous as Mr Dwayne Johnson, I would NOT be doing what Im doing LOL
Yeah man - you should have been there. It was a fun event though.
O well, customers come first, so it happened there was somewhat urgent issue at the same time...glad you guys had fun, video was great!
Was really great to celebrate 2022 with you all and looking forward to 2023! 🙂
Congratulations again to the community and all the category winners, you really do make this what it is.
Always a pleasure reading your helpful posts brother. By the way, I love Yagan square in Perth, my favorite place there. Not sure if it changed since I been there almost 10 years ago, but its so nice.
Cheers,
Andy
They're always trying to transform something there, it's not quite fed square in Melbourne, hey but it's ours.
Well, its same for Times sq in NY city, its most famour city sq in the world, but I will take your city square over it any day : - )
Excelete muchas gracias, feliz 2023
Thank you all. This platform has been incredibly helpful over the past 12-24 months.
Congratulations to our CheckMates Champions for 2022:
Q&A below.
We are the leading provider of cybersecurity solutions, protecting businesses, critical infrastructure, and governments from cyber-attacks by providing the best security solutions.
Leaderboard
Epsum factorial non deposit quid pro quo hic escorol.
User | Count |
---|---|
9 | |
7 | |
6 | |
6 | |
5 | |
5 | |
5 | |
5 | |
5 | |
5 |
Fri 12 Sep 2025 @ 10:00 AM (CEST)
CheckMates Live Netherlands - Sessie 38: Harmony Email & CollaborationTue 16 Sep 2025 @ 02:00 PM (EDT)
Securing Applications with Check Point and AWS: A Unified WAF-as-a-Service Approach - AmericasWed 17 Sep 2025 @ 04:00 PM (AEST)
Securing Applications with Check Point and AWS: A Unified WAF-as-a-Service Approach - APACWed 17 Sep 2025 @ 03:00 PM (CEST)
Securing Applications with Check Point and AWS: A Unified WAF-as-a-Service Approach - EMEAThu 18 Sep 2025 @ 03:00 PM (CEST)
Bridge the Unmanaged Device Gap with Enterprise Browser - EMEAFri 12 Sep 2025 @ 10:00 AM (CEST)
CheckMates Live Netherlands - Sessie 38: Harmony Email & CollaborationTue 16 Sep 2025 @ 02:00 PM (EDT)
Securing Applications with Check Point and AWS: A Unified WAF-as-a-Service Approach - AmericasWed 17 Sep 2025 @ 04:00 PM (AEST)
Securing Applications with Check Point and AWS: A Unified WAF-as-a-Service Approach - APACWed 17 Sep 2025 @ 03:00 PM (CEST)
Securing Applications with Check Point and AWS: A Unified WAF-as-a-Service Approach - EMEAThu 18 Sep 2025 @ 03:00 PM (CEST)
Bridge the Unmanaged Device Gap with Enterprise Browser - EMEAThu 18 Sep 2025 @ 02:00 PM (EDT)
Bridge the Unmanaged Device Gap with Enterprise Browser - AmericasAbout CheckMates
Learn Check Point
Advanced Learning
YOU DESERVE THE BEST SECURITY