White Paper | Check Point SASE: Multilayer Secure Access Architecture | Check Point Software
White Paper | Check Point SASE: Multilayer Secure Access Architecture
Check Point SASE: Multilayer Secure Access Architecture Practical Use Cases Illustrating How to Protect the Modern Enterprise
MULTILAYER SECURE ACCESS ARCHITECTURE
Executive Summary
The modern enterprise runs in the browser. Employees draft documents, access SaaS applications, collaborate in real time, and move between tasks entirely through web-based tools. While this shift has improved productivity and organizational agility, it has also created new security blind spots that traditional network-centric models cannot address. Most work now takes place outside the traditional perimeter – across home networks, coffee shops, partner environments, and unmanaged contractor devices. The browser itself has become a high-value target, capable of executing code from multiple sources simultaneously. Malicious downloads, embedded scripts, and compromised documents are common entry points for attackers.
Simultaneously, corporate data flows have become more fluid and difficult to control. Users regularly move sensitive information through SaaS interfaces, personal devices, clipboard actions, file uploads, downloads, form fills, and increasingly into generative AI tools – all of which fall outside the visibility of legacy DLP and firewall solutions. These challenges are top of mind for the security teams tasked with protecting modern distributed workforces. While not exhaustive, the use cases below illustrate the core patterns organizations must address: securing browser-based workflows, controlling data movement, and enabling safe access across both managed and unmanaged devices. Check Point SASE’s multilayer secure access architecture brings these elements together. Rather than relying solely on network inspection or device agents, the architecture applies controls at multiple points – in the browser, on the device, and across a global cloud security fabric – to deliver consistent protection regardless of where or how users work.
The New Enterprise Reality
Employees today use the browser as their primary interface with the business. Work that once depended on dedicated applications is now performed inside cloud and SaaS platforms like Google Docs, Salesforce, Monday, Office 365, WebEx, and Adobe Creative Cloud. This browser-first environment supports flexible, collaborative workflows across distributed teams. A user can draft content, manage a CRM pipeline, join a meeting, upload files, and collaborate on presentations – all without leaving the browser. Remote work amplifies this model, with the browser acting as the bridge between users and corporate resources from any location.
But the browser’s openness introduces substantial risk. Its ability to load and execute content from many sources – ad networks, third-party scripts, embedded documents, and dynamic code – creates fertile ground for sophisticated attacks. Threat actors exploit temporary downloads, malicious JavaScript, and file-based payloads, many of which bypass traditional perimeter defenses. Meanwhile, unmanaged devices are now part of daily operations. Contractors, freelancers, and BYOD users routinely access corporate applications without the protections found on managed corporate laptops. Organizations often lack visibility into the security posture of these devices, increasing the chances of data leakage or compromise. These changes have stretched legacy security models beyond their limits. Network appliances cannot see inside the browser. VPNs provide overly broad access. Traditional DLP cannot govern in-browser actions like copy/paste, file uploads, cloud-to-cloud interactions, or form submissions. Enterprises need a new approach – one that addresses real-world workflows rather than legacy network boundaries.
Fluid Data Movement
Fragmented Security Controls Data may move from a SaaS app to a local download, into a clipboard, into a personal device, or into an AI tool. Traditional DLP struggles to inspect or control these flows. Network security, endpoint security, identity systems, and cloud access tools often operate in isolation. Without coordination, gaps emerge between layers.
The Gaps Security Teams Must Address
Despite their investments in network inspection, identity security, and endpoint tools, organizations still face four persistent gaps:
- Blind Spots Inside the Browser
Most security tools struggle to see or govern the actions users take inside the browser – where sensitive data is copied, pasted, uploaded, downloaded, or moved between applications. - Unmanaged and Semi-Managed Devices
Contractors, third parties, and BYOD users frequently access corporate resources using devices without corporate controls. Agent deployment is often impossible or impractical.
Use Case #1: Securing Corporate Employees Across SaaS & Cloud
Corporate employees rely heavily on SaaS applications and web-based tools to complete daily work. Even with managed devices, most of their activity still takes place inside the browser, where traditional network or endpoint security has limited visibility. Remote and hybrid work amplify this with users connecting over networks outside the organization’s control.
Challenges
- Most workflows now occur in SaaS or web applications accessed through the browser
- Need consistent protection and performance across distributed locations
- On-device threats such as ransomware, keyloggers, or zero-day exploits
- Limited visibility into browser-level actions even on managed devices
- Growing risks from AI-augmented SaaS features and browser-embedded GenAI tools
Solution Approach
Combine device-level prevention, browser-level governance, and cloud-delivered inspection to protect all user activity across SaaS, web, and internal applications.
Capabilities Supporting This Use Case
- Device Agent: Prevents ransomware, keyloggers, and zero-day threats at the endpoint
- Global Cloud PoPs: Ensure fast, secure connectivity to SaaS and corporate applications
- Browser Controls: Enforce safe search settings, rate search results, and monitor sensitive actions within SaaS sessions
- ThreatCloud AI: Blocks malicious downloads, websites, and embedded scripts in real time
- GenAI Data Controls: Prevent inadvertent sharing of corporate data into AI-driven fields or prompts
Outcome
Corporate employees gain fast, reliable access to cloud applications with comprehensive protection across device, browser, and network layers – without impacting productivity.
Use Case #2: Securing Unmanaged Devices (Contractors & BYOD)
Contractors and employees using their own devices access corporate applications from environments that the organization does not control. These unmanaged devices introduce similar types of risks: no endpoint agent, no visibility into system posture, and no reliable way to enforce data-handling policies.
Challenges
- Need for precise, application-specific access for contractors or temporary workers
- No ability to deploy or trust endpoint agents on personal or contractor devices
- Data exposure through copy/paste, uploads and downloads
- Risk of compromised or risky devices connecting to corporate applications
Solution Approach
Create an isolated, controlled browser workspace or deliver access through cloud-delivered controls on any device, without an agent. This ensures unmanaged devices can safely reach approved applications without exposing the broader environment.
Capabilities Supporting This Use Case
Organizations gain visibility and control over sensitive data across all browser-based workflows, preventing accidental or intentional leakage into SaaS, AI tools, or unmanaged environments.
- Browser DLP: Governs file transfers, clipboard actions, and data handling inside SaaS applications
- Secure Enterprise Browser: Adds restrictive workspace controls, including screenshot blocking and print protections
- Clipboard & Form Fill Protection: Identifies sensitive information before it leaves the browser
- GenAI Governance: Prevents users from pasting or submitting confidential data into generative AI services or AI-augmented SaaS interfaces
- ThreatCloud AI: Analyzes web content and file activity to prevent malicious or unsafe actions
Use Case #3: Data Protection & Governance in the Browser
Modern workflows involve constant data movement through the browser, such as copying, pasting, uploading, downloading, filling forms, and interacting with cloud applications. Traditional DLP tools cannot see or control many of these in-browser actions, leaving gaps in data governance across SaaS environments.
Challenges
- Sensitive data movement through uploads, downloads, clipboard activity, and form entries
- Cloud-to-cloud transfers that bypass traditional DLP
- Browser-based interactions invisible to network-only or endpoint-only controls
- User-initiated data exposure through GenAI tools or AI-powered SaaS features
- Need for consistent policy enforcement across managed and unmanaged devices
Solution Approach
Apply data loss prevention policies directly in the browser – where sensitive actions occur – and reinforce them with cloud inspection and device-level controls.
Capabilities Supporting This Use Case
Users gain secure, role-appropriate access to internal systems without exposing the broader environment, while data and in-app actions remain governed at the browser level.
- GenAI Data Controls: Governance over sensitive data being copied or pasted into generative AI tools
- Agentless ZTNA: Secure, browser-based access for unmanaged devices when agents can’t be deployed
- Per-Application Zero Trust Access: Granular, identity-aware access to internal apps without exposing the broader network
- Browser-Level Visibility & Control: Monitoring and governance of copy/paste, uploads, downloads, and form actions inside internal applications
- Secure Enterprise Browser: Hardened workspace for regulated or high-risk roles requiring stronger protections
Use Case #4: Zero Trust Access to Internal Applications
Internal applications are critical to business operations, yet traditional access controls often fall short. Legacy VPNs provide overly broad connectivity, increasing the chance of lateral movement, while identity-only controls lack sufficient context for secure access.
Challenges
- Legacy VPNs expose more of the network than necessary
- BYOD and contractor devices cannot install agents
- Need per-app segmentation and role-based control
- Browser-based actions inside internal apps remain unmonitored
- Possibility of internal data being copied into external GenAI tools
Solution Approach
Deliver per-application Zero Trust access for managed and unmanaged devices while governing in-browser actions to prevent data leakage or unauthorized behavior.
Pulling the Use Cases Together – A Unified Architecture
Across these scenarios, several patterns emerge:
- Browser-level protection is essential, as this is where most user activity occurs.
- On-device capabilities strengthen security for managed endpoints.
- Cloud-delivered inspection ensures global consistency, performance, and policy enforcement.
- Identity- and context-based controls drive effective Zero Trust.
This unified model applies security policies consistently – including controls that prevent sensitive information from flowing into external AI systems – regardless of device, network, or application. Unified Operations Through the Check Point Portal The Check Point Portal centralizes visibility and control across all protection layers, allowing administrators to monitor browser activity, device posture, and cloud traffic from a single interface. This makes scaling – to new users, locations, or applications – effortless thanks to the cloud-delivered model.
Why Check Point
- Deep protection inside the browser through both an extension and Enterprise Secure Browser
- Full threat prevention powered by ThreatCloud AI
- Flexible secure access options for managed, unmanaged, and BYOD devices
- Global PoPs for optimized connectivity and low latency
- Unified policy management across all access and data protection layers
Work happens in the browser, on every type of device and across a wide mix of apps and cloud services. Protecting this reality means using security that fits how people actually work today, not relying on outdated, network-centric assumptions.