Solution Brief | Cloud Security with Check Point & Wiz | Check Point Software

Solution Brief | Cloud Security with Check Point & Wiz

From Time to Remediation to Time to Prevention

Today, cloud security separates CNAPP-based high-fidelity risk visibility from network enforcement controls provided by cloud and virtual firewalls. This forces teams to investigate and remediate findings, only to discover they are protected by firewall NAT and access rulesets. In other cases, teams scramble to patch vulnerabilities at the workload/app levels before attackers find and exploit them, even when firewall rules and threat prevention engines could resolve these issues, at least temporarily. Pairing Wiz’s unmatched visibility and prioritization with Check Point’s threat prevention and cloud-agnostic rules closes the CNAPP-Firewall and risk-detection and risk-prevention gaps, with a tight loop: Wiz pinpoints if cloud assets are public exposed and have vulnerabilities with the context of Check Point firewalls and rules; while Check Point determines how to implement its advanced threat prevention to make vulnerable exposed assets impervious to exploitation, buying engineers the time they need to remediate issues responsibly without putting business continuity at risk.

The Problem

Due to legacy domain and expertise separation, cloud risk detection tools, such as Wiz, operate independently of virtual firewalls like CloudGuard Network Security, lacking the visibility into Virtual Gateways’ place within the cloud topology and their access rulesets. This fragmentation also works in the opposite direction: Network firewalls are unaware of findings from CNAPP solutions and do not respond to posture issues. For instance, firewalls cannot automatically switch their IPS on if a CVE is present on a given asset. The result? A fragmented security ecosystem with limited visibility and long investigation and remediation cycles, and worse still, lengthy and complicated remediation processes that could otherwise be resolved in systems with threat prevention-based virtual patching, such as IPS systems blocking CVE exploitation and ML-powered malware detectors that could rectify improper file MIME type validation in web applications.

The Solution

  1. Detect with Wiz
    Wiz continuously scans cloud environments, workloads, and identities to identify misconfigs, vulnerabilities, and toxic combinations. Now, thanks to the strategic partnership between Wiz and Check Point, Wiz has visibility not only into the presence of CloudGuard Network Security gateways’ place in the cloud’s network topology, but also gateways’ access and NAT rulesets, enabling Wiz to discern if a linked set of findings rise to the level of a critical toxic combination, and if it does, allows engineers to determine, on the spot, whether a simple tweak of CloudGuard’s NAT and Access rules can resolve the issue. Conversely, if Wiz determines that CloudGuard provides sufficient security, it will de-risk the alert, allowing engineers to focus on truly critical issues. This means that Wiz’s new awareness of and visibility into CloudGuard saves investigation time, shortens time to remediation, and reduces alert fatigue.

  2. Decide with Infinity and/or cloud engineers
    Once Wiz flags an issue, Infinity CTEM ingests it in real time. It then analyzes the customer’s network topology, traffic flows, and CloudGuard policy, and evaluates whether CloudGuard’s existing prevention capabilities can mitigate the threat. For example, if CloudGuard’s IPS can block an exploit, Infinity CTEM can recommend switching CloudGuard’s IPS from 'Detect' to 'Prevent' within the confines of CTEM’s user interface. Importantly, Infinity CTEM performs impact analysis and false-positive checks before recommending or applying any policy changes, ensuring that security enforcement does not disrupt business continuity.

  3. Prevent with CloudGuard
    Acting as the enforcement and threat prevention plane, beyond access control and segmentation, CloudGuard’s unmatched threat prevention engines can virtually patch almost any issue discovered by Wiz, allowing DevOps and infrastructure teams to implement permanent patches at the configuration, workload, or code level. Importantly, prevention is applied consistently across cloud providers and hybrid networks, leveraging CloudGuard’s cloud-native integrations and identity and app-aware policy model.

The Solution Stack

Wiz provides complete, agentless visibility into cloud infrastructure, applications, code, and identity. It correlates misconfigurations, vulnerabilities, excessive permissions, and data exposure, and identifies toxic combinations of vulnerabilities that could materialize into attacks, protecting clouds from code to runtime. Crucially for this joint solution, Wiz can also detect the presence of CloudGuard Network Security’s cloud NGFW in front of vulnerable workloads, along with its NAT and access rulesets, allowing Wiz to de-risk findings and for engineers to reassess risk based on exposure. Check Point CloudGuard Network Security enforces adaptive, enterprise-grade security controls around, in, and between cloud environments and workloads. It combines L3, L4, and L7 protections, IPS, application control, and cloud-native policies based on object types and tags to block both known and unknown threats in real-time with unmatched effectiveness. As part of its advanced threat prevention engines, CloudGuard Network Security is particularly adept at acting as a virtual patching engine for workloads and preventing attackers from exploiting vulnerable web applications. Check Point Infinity Threat Exposure Management connects Wiz’s contextual risk intelligence with CloudGuard’s enforcement capabilities. It automatically validates whether existing security policies protect critical vulnerabilities, identifies gaps, and orchestrates remediation. For this joint cloud security solution, Infinity Threat Exposure Management enables security practitioners and cloud engineers to remediate risks identified by Wiz by changing CloudGuard NGFW configurations with a click and without risking business continuity, shortening remediation cycles to seconds.