Solution Brief | Cloud Security with Check Point & Wiz | Check Point Software
Solution Brief | Cloud Security with Check Point & Wiz
From Time to Remediation to Time to Prevention
Today, cloud security separates CNAPP-based high-fidelity risk visibility from network enforcement controls provided by cloud and virtual firewalls. This forces teams to investigate and remediate findings, only to discover they are protected by firewall NAT and access rulesets. In other cases, teams scramble to patch vulnerabilities at the workload/app levels before attackers find and exploit them, even when firewall rules and threat prevention engines could resolve these issues, at least temporarily. Pairing Wiz’s unmatched visibility and prioritization with Check Point’s threat prevention and cloud-agnostic rules closes the CNAPP-Firewall and risk-detection and risk-prevention gaps, with a tight loop: Wiz pinpoints if cloud assets are public exposed and have vulnerabilities with the context of Check Point firewalls and rules; while Check Point determines how to implement its advanced threat prevention to make vulnerable exposed assets impervious to exploitation, buying engineers the time they need to remediate issues responsibly without putting business continuity at risk.
The Problem
Due to legacy domain and expertise separation, cloud risk detection tools, such as Wiz, operate independently of virtual firewalls like CloudGuard Network Security, lacking the visibility into Virtual Gateways’ place within the cloud topology and their access rulesets. This fragmentation also works in the opposite direction: Network firewalls are unaware of findings from CNAPP solutions and do not respond to posture issues. For instance, firewalls cannot automatically switch their IPS on if a CVE is present on a given asset. The result? A fragmented security ecosystem with limited visibility and long investigation and remediation cycles, and worse still, lengthy and complicated remediation processes that could otherwise be resolved in systems with threat prevention-based virtual patching, such as IPS systems blocking CVE exploitation and ML-powered malware detectors that could rectify improper file MIME type validation in web applications.
False urgency & missed risk: Posture platforms raise alarms whenever a vulnerability is found; however, without visibility into firewall access and NAT rules, they cannot validate if a true network path exists that exposes this vulnerability. The result: many alerts represent theoretical exposure, leading teams to chase “false urgencies,” while assets that are truly reachable and exposed slip down the queue.
Manual correlation tax: Closely related to the point above, to separate real threats from background noise, engineers must cross-reference Wiz-style findings with firewall rulebases, gateway placements, and routing tables, and figure out which rules and security controls will mitigate exposure. This hand-stitching is slow, error-prone, and drains scarce expert time.
Siloes and slow mitigation loops: Different teams, such as SOC analysts, network engineers, IT, DevOps, and developers, see only part of the picture through their own tools and dashboards. Without a unified view, priorities diverge, workflows are duplicated, and issues that can be fixed in seconds are delayed to extended periods of time. For instance, when legitimate exposure of a workload with a CVE is confirmed, patching that CVE can take engineers days or even weeks, while a firewall’s IPS prevention might be able to virtually patch that CVE in seconds.
Compliance friction: Auditors and regulators increasingly expect evidence not just that vulnerabilities are patched, but that they were never exploitable in the first place, or that a virtual patch mitigated the risk in the interim. Proving this across multiple disconnected systems adds significant overhead.
The Solution
Detect with Wiz
Wiz continuously scans cloud environments, workloads, and identities to identify misconfigs, vulnerabilities, and toxic combinations. Now, thanks to the strategic partnership between Wiz and Check Point, Wiz has visibility not only into the presence of CloudGuard Network Security gateways’ place in the cloud’s network topology, but also gateways’ access and NAT rulesets, enabling Wiz to discern if a linked set of findings rise to the level of a critical toxic combination, and if it does, allows engineers to determine, on the spot, whether a simple tweak of CloudGuard’s NAT and Access rules can resolve the issue. Conversely, if Wiz determines that CloudGuard provides sufficient security, it will de-risk the alert, allowing engineers to focus on truly critical issues. This means that Wiz’s new awareness of and visibility into CloudGuard saves investigation time, shortens time to remediation, and reduces alert fatigue.Decide with Infinity and/or cloud engineers
Once Wiz flags an issue, Infinity CTEM ingests it in real time. It then analyzes the customer’s network topology, traffic flows, and CloudGuard policy, and evaluates whether CloudGuard’s existing prevention capabilities can mitigate the threat. For example, if CloudGuard’s IPS can block an exploit, Infinity CTEM can recommend switching CloudGuard’s IPS from 'Detect' to 'Prevent' within the confines of CTEM’s user interface. Importantly, Infinity CTEM performs impact analysis and false-positive checks before recommending or applying any policy changes, ensuring that security enforcement does not disrupt business continuity.Prevent with CloudGuard
Acting as the enforcement and threat prevention plane, beyond access control and segmentation, CloudGuard’s unmatched threat prevention engines can virtually patch almost any issue discovered by Wiz, allowing DevOps and infrastructure teams to implement permanent patches at the configuration, workload, or code level. Importantly, prevention is applied consistently across cloud providers and hybrid networks, leveraging CloudGuard’s cloud-native integrations and identity and app-aware policy model.
The Solution Stack
Wiz provides complete, agentless visibility into cloud infrastructure, applications, code, and identity. It correlates misconfigurations, vulnerabilities, excessive permissions, and data exposure, and identifies toxic combinations of vulnerabilities that could materialize into attacks, protecting clouds from code to runtime. Crucially for this joint solution, Wiz can also detect the presence of CloudGuard Network Security’s cloud NGFW in front of vulnerable workloads, along with its NAT and access rulesets, allowing Wiz to de-risk findings and for engineers to reassess risk based on exposure. Check Point CloudGuard Network Security enforces adaptive, enterprise-grade security controls around, in, and between cloud environments and workloads. It combines L3, L4, and L7 protections, IPS, application control, and cloud-native policies based on object types and tags to block both known and unknown threats in real-time with unmatched effectiveness. As part of its advanced threat prevention engines, CloudGuard Network Security is particularly adept at acting as a virtual patching engine for workloads and preventing attackers from exploiting vulnerable web applications. Check Point Infinity Threat Exposure Management connects Wiz’s contextual risk intelligence with CloudGuard’s enforcement capabilities. It automatically validates whether existing security policies protect critical vulnerabilities, identifies gaps, and orchestrates remediation. For this joint cloud security solution, Infinity Threat Exposure Management enables security practitioners and cloud engineers to remediate risks identified by Wiz by changing CloudGuard NGFW configurations with a click and without risking business continuity, shortening remediation cycles to seconds.