- Products
- Learn
- Local User Groups
- Partners
- More
The Great Exposure Reset
24 February 2026 @ 5pm CET / 11am EST
CheckMates Fest 2026
Watch Now!AI Security Masters
Hacking with AI: The Dark Side of Innovation
CheckMates Go:
CheckMates Fest
Here is the recording of our session
Failure will most of the time will show an error code. The error code meaning are listed here: https://support.checkpoint.com/results/sk/sk154435
After that I would recommend to check https://support.checkpoint.com/results/sk/sk179626
Post-Quantum encryption support exists in R82 and later releases of Security Gateway.
We already have a complete ZTNA solution, and have replaced Zsclaer and Netskope in many customers with Harmony SASE. We are working tireless to address feature gaps. We have unique architecture, which we believe this is the best architecture that delivers the best speed with our Zero Distance SASE (Hybrid Architecture), for customers that are looking for speed and ease of use. Check Point SASE is the winner.
For many years, machine learning - data driven - security is used in the ThreatCloud services backend. Here we use over 60 ML and AI engines empowering zero day threat prevention: https://www.checkpoint.com/solutions/threat-prevention/
We're working to simplify the VPN interoperability with many vendors. We already have simplified implementation for leading cloud providers.
Check Point Engage events will replace CPX in 2026. More details here: https://community.checkpoint.com/t5/General-Topics/CPX-2026/m-p/265494
The Exposure management product does exactly this, it identifies the vulnerabilities and misconfiguration over your technologies, fuse this with unique intelligence and implement remediation to close the gaps within hours
In a nutshell, we believe organizations should embrace AI otherwise they will be left behind. We, at Check Point, believe we need to enable secure use of AI. This is why we're now talking about a new AI security pillar.
Our Sandblast has two features: Threat Extraction that removes all active components of the file to deliver it fast. This is accompanied by our sandboxing solution, Threat Emulation that opens and verifies the original files in a safe environment.
We prevent the access in the first place, so that the user will never land on the phishing page.
The R82 release does not support the TE2000XN model. Support for the TE250XN model is planned for the R82 Jumbo Hotfix Accumulator. This SK article will be updated accordingly: https://support.checkpoint.com/results/sk/sk173494
We use AI in the Management in multiple places:
Also stay tuned for more announcements on this in 2026!
We have many gates and guardrails on our development lifecycle. Some are general and some tailored for AI. But the most important security measure we use for protecting against AI prompt injection is using Lakera!
It has a very important role! Senior R&D and Product Managers look at CheckMates to get a feel for potential problems that exist in the field. In addition, we look at posts related to our products to see what people like or dislike. CheckMates is also a great place for us to share info about new features and hear from you what you'd like us to further improve or enhance.
Yes, we are actively closing the gaps. A big one that was just closed is the support for UPPAK. Which is now available for ElasticXL and Maestro.
Stay tuned for exciting announcements about this in 2026!
Playblocks in the Infinity Portal already allows you to activate various playbooks. You can use the out-of-the-box ones, or create your own (even using AI and natural language). We are definitely looking at even more advanced capabilities by leveraging AI reasoning and agentic capabilities to be even smarter with automating responses for security or operational events.
We're investing a lot in Web SmartConsole. We keep releasing new features every month and will continue to do so in 2026. We hope that by the end of this year, many customers can get by without having to install the Desktop application. There will remain a ""long tail"" of features that are less common and will take longer to cover.
We are constantly monitoring the activity of IPS and AV in the field. Customers sharing telemetry data (you can opt in or opt-out) and use this data to improve signatures. You can see that signatures are getting updated over time. Check the videos here https://community.checkpoint.com/t5/Check-Point-for-Beginners/Videos-Configuring-Access-Control-and-...
In some deployments, use of VPNs (Site-to-Site) is not suitable. You may want to explore Harmony SASE as connectivity backbone and then using Wireguard to connect to your on-premises office.
As long as the appliance is under support and can install R82.20, you can get the new simplicity features. The features do not depend on the latest models. Obviously some features that are compute intensive may work better / faster on the new models.
It depends on your deployment, but we offer security components that run in the cloud (CloudGuard Network Security, i.e. virtual firewalls, CloudGuard WAF, which integrates with web stacks, and CNAPP-type functionality via our partnership with Wiz).
We are working on customization for our general reporting infrastructure in the Infinity Portal. It will be first rolled out in Infinity Events, and later other applications (such as WAF) will be able to add the new capabilities as well.
We have updatable objects and other object types - check out this video on CheckMates https://community.checkpoint.com/t5/Security-Gateways/Hands-on-Access-and-Application-Control/m-p/25...
The ability to control granular actions in applications like Salesforce, creating record.
SD-WAN allows saving MPLS costs as you can achieve application specific traffic steering. Quantum SD-WAN does not make any compromise on security so customers stay protected while saving costs.
Right now our strategy is to include every feature developed in web, also in the Desktop SmartConsole application. The way we do this is we host web frames within the app, so we don't need to develop it twice.
It's possible that, as adoption will increase for Web SmartConsole, we may revisit this strategy and start to develop some features for web only. It's likely that those won't include things you cannot live without. Maybe some UX goodies that are easier in web.
Using the show logs API, you could build something like this relatively easily.
We are working to add ability to select dedicated DNS record name per user and device. This should answer your need, we expect it to be released in the second half of 2026.
R82.10 Release
In R82, we provide a mechanism called Dynamic Layer, which allows you to install a specific policy to a specific gateway using a REST API. More details here: https://community.checkpoint.com/t5/Security-Gateways/Dynamic-Layer-in-R82-Direct-Gateway-API-Policy...
We have GenAI protect for exactly this protection.
https://sc1.checkpoint.com/documents/Infinity_Portal/WebAdminGuides/EN/SaaS-Admin-Guide/Content/Topi...
Once you onboard to Infinity Services, the on-premises management opens an outbound encrypted tunnel to our cloud. We don't need any incoming connectivity from the cloud to your management, so it can be behind NAT or Firewall.
Regarding the data that is transferred to the cloud, each product should have documentation that states what is transferred.
For example, AI Copilot will send the prompt that you typed, and will also transfer the outputs of various APIs it will run to fulfill your request. So if it needs to search logs to answer your question, it will run a log query and the results of that query will be sent to the cloud for the AI to process. But it does not send all your logs, only the first batch of logs that answer the query.
Policy Insights will send your policy rules and ""hitcount telemetry"" which is a compression of the different accepted networking paths. It will not send full log data or sensitive information.
We have introduced a lot of improvents in R82 - have you seen this video ? https://community.checkpoint.com/t5/Security-Gateways/Hands-on-HTTPS-Inspection-Oct-25/m-p/259207/hi...
We have a few development tasks for this year aimed at reducing the delay of log ingestion in Smart-1 Cloud. We acknowledge the customer feedback that they want to see the logs much faster.
It's not something that is on our short term roadmap, but we are not completely against it for the future.
In 2026, we are going to continue and accelerate the development of our SASE platform, with focus on AI and Data Security, Scalable Cloud Backbone and Digital Experince Monitoring. Additionally, we recently added support for branch interenet security as well as sercure enterprise browser for BYOD
Yes, we do plan to certify these for open servers.
It is in our plans to offer Hybrid Mesh Traffic Steering, which will cover this use case.
The market is adopting Exposure Management and evolving from finding and prioritizing risk to safely reducing it. This requires combining threat intelligence, contextual exposure analysis, and validated remediation into a single, continuous operational flow so that exposure dwell time is reduced without disrupting the business.
Sad I could not make it and be among all those good looking dudes : - )
Anywho, ALWAYS HONORED to even be mentioned...appreciated 🙌
Told ya...
Well deserved, Andy
One of your Sales people emailed me literally right after the presentation with my name on the list for platinum mvp...sucks I could not attend, o well...next year!
Thanks to all.
You are all doing a great job in the community.
Im sure I said this many times, but I keep saying it cause its so true...no matter how small or big you think your contribution is, it ALWAYS counts.
I wanted to ask this question, but since I could not attend, here it comes...any idea if PBR will eventually be supported with ISP redundancy? I have people ask me about it constantly...I really hope for good news soon : - )
@the_rock Ask in a separate post 🙂
Done 🙂
Leaderboard
Epsum factorial non deposit quid pro quo hic escorol.
| User | Count |
|---|---|
| 26 | |
| 22 | |
| 10 | |
| 9 | |
| 8 | |
| 8 | |
| 7 | |
| 7 | |
| 6 | |
| 5 |
Thu 19 Feb 2026 @ 03:00 PM (EST)
Americas Deep Dive: Check Point Management API Best PracticesTue 24 Feb 2026 @ 11:00 AM (EST)
Under The Hood: CloudGuard Network Security for Azure Virtual WANThu 19 Feb 2026 @ 03:00 PM (EST)
Americas Deep Dive: Check Point Management API Best PracticesTue 24 Feb 2026 @ 11:00 AM (EST)
Under The Hood: CloudGuard Network Security for Azure Virtual WANAbout CheckMates
Learn Check Point
Advanced Learning
YOU DESERVE THE BEST SECURITY