# Check Point Exposure Management – FAQ

## Remediation

### 1. Does the remediation capability have to be all-or-nothing, or can a customer start small and grow?
Customers can start with a single use case and expand at their own pace. There is no requirement to connect the full security stack on day one. A common starting point is read-only visibility: the platform discovers assets, surfaces CVEs, and generates a prioritized remediation plan without pushing any changes to security controls.

From there, teams typically enable virtual patching on one firewall or endpoint tool before rolling it out more broadly. Each integration is incremental and API-based, so there is no agent to install and no large-scale change management required upfront.

### 2. What types of remediations are available?
Exposure Management supports three categories of remediation action:

- **Virtual patching:** Push IPS signatures, policy updates, and blocklists to network, endpoint, cloud, and OS controls. This neutralizes a vulnerability without requiring a software patch on the affected host.
- **Takedowns:** Disrupt external attacker infrastructure including phishing sites, impersonating social profiles, and malicious mobile apps at the source.
- **Remediation workflow triggers:** Automatically create and route tickets into existing ITSM, SOAR, SIEM, and collaboration tools (ServiceNow, Jira, Splunk, etc.) so the right team receives a validated, prioritized action rather than just an alert.

All three can run in parallel. For example, a phishing kit targeting the company brand can trigger a takedown request while simultaneously pushing an updated blocklist to the firewall and creating a ticket for the infrastructure team.

**504** Safe remediations/month avg.

**~3.1 days** Median MTTR: virtual patching (exploitable CVEs)

**12 hrs** Avg. Takedown MTTR

**99%** Phishing Takedown Success Rate

_MTTR figures derived from production alert data across resolved, automated remediations. Virtual patching median based on exploitable vulnerability and exposed port alert types. Takedown median based on phishing website alerts with automated takedown actions._

### 3. How does the platform verify that a remediation action will not break something in production?
Every remediation action goes through a validation step before enforcement. The platform includes built-in false positive detection and business rule analysis. It tests whether applying a specific control change would conflict with existing traffic patterns or approved business rules before recommending it.

For virtual patches specifically, the system first moves the relevant control to a **detect-only mode** for a configurable period (typically one week). During that window, it monitors whether any legitimate traffic would have been blocked. If nothing is broken, the system recommends promotion to **block mode**. This two-stage process ensures infrastructure teams can enforce security changes with confidence, without requiring a change freeze or manual testing cycle.

### 4. How are remediations pushed out to security controls?
All integrations are **API-only**: no agents are deployed on target systems. The platform connects bidirectionally to existing security controls via REST API, pulling context about assets, configurations, and current policy, then pushing validated remediation actions back to those same controls.

Supported control types include:

- Network: NGFW, WAF, SSE/SASE (Check Point, Palo Alto, Fortinet, and others)
- Endpoint: EPP, EDR, XDR (Crowdstrike, SentinelOne, and others)
- Cloud: CNAPP, cloud-native controls
- OS-level configurations
- 3rd-party ITSM, SOAR, SIEM, and collaboration tools

Teams that prefer not to have the platform push changes directly can instead have it generate a detailed remediation plan delivered into their existing ticketing workflow. This preserves existing approval processes while eliminating the manual triage work.

## Architecture & Deployment

### 5. Does this solution require agents to be installed?
**No.** Exposure Management uses an agentless, API-first architecture. There is nothing to install on endpoints, servers, or network devices. All integrations run via API connections to existing security controls and scanners.

This means deployment is significantly faster than agent-based solutions, typical API-based setup takes roughly 20 minutes per integration, and it avoids the agent sprawl, compatibility issues, and endpoint performance impact that can slow security program rollouts.

For organizations that already run solutions like Sophos, Crowdstrike, or Microsoft Defender, the platform reads telemetry directly from those tools via their existing APIs. No additional agent or sensor is required.

### 6. Can the platform discover assets and technologies that don’t have an integrated security tool connected? (CAASM / Cyber Asset Attack Surface Management)
Yes. The platform includes both **external attack surface management (EASM)** and internal asset discovery, together providing a Cyber Asset Attack Surface Management (CAASM) capability.

For external discovery, the platform can build a full picture of an organization’s internet-facing footprint using only the primary domain as a starting point. It automatically enumerates subdomains, IP ranges, exposed services, cloud assets, and associated technologies, including assets that were never registered with an internal security tool. This is how shadow IT, forgotten subdomains, and misconfigured cloud buckets surface.

For internal assets, visibility is built from the API integrations connected to the platform. Assets that fall entirely outside any integrated control are flagged as coverage gaps, so security teams have a clear map of where blind spots exist.

In a typical organization, EASM scans regularly surface assets that IT was unaware of, cloud storage buckets, development environments, or acquired company infrastructure that was never fully onboarded into the security program.

### 7. How does the platform calculate risk scores, and can it factor in proprietary scoring models from existing tools (e.g., CVSS, vendor-specific scores)?
The platform does not replace existing scoring models, it enriches and contextualizes them. CVSS scores and vendor-specific risk ratings from connected scanners are ingested as inputs, then correlated with additional signals to produce a **true exposure score** that reflects actual risk rather than theoretical severity.

The enrichment layer adds:

- **Exploitability:** Is there an active exploit in the wild? Is this CVE being used in campaigns targeting your industry right now?
- **Reachability:** Is the vulnerable asset reachable from the internet, or is it isolated behind compensating controls?
- **Existing coverage:** Does the organization already have a virtual patch, IPS signature, or firewall rule that effectively mitigates the risk?
- **Asset criticality:** What is the business importance of the affected system?
- **Active threat actor targeting:** Is a known threat group actively scanning for or exploiting this vulnerability against companies like yours?

The result is that a CVSSv3 score of 9.8 on a server with no external exposure and an active IPS signature may rank lower priority than a CVSSv3 score of 6.5 on a publicly exposed asset being actively targeted. This approach directly reduces the volume of “critical” findings teams are asked to chase, focusing effort on vulnerabilities where remediation will actually reduce risk.

**13,333** Exposures identified/year per org

**1,200** Business days of labor saved annually

## Threat Intelligence

### 8. What threat intelligence does the platform include, and how is it different from what customers already have?
The platform fuses Check Point’s 32-year intelligence network with its Exposure Management intelligence capabilities. This includes dark web and deep web monitoring, leaked credential detection, brand impersonation signals, supply chain intelligence, and active campaign tracking. All of it maps directly to the customer’s environment.

The key differentiator is **operational connection**. Most threat intelligence solutions surface information in a separate portal that security teams then manually correlate to their assets. Here, intelligence is directly tied to the customer’s specific assets, technologies, and threat actor targeting profile. If a known threat group is actively weaponizing a CVE against entertainment companies, that context elevates the relevant exposures automatically. No analyst needs to make the connection manually.

**55M** Intel items collected/month

**93%** True positive alert rate

**700M+** New intel items in 2025

### 9. We already have an ITDR solution for identity threat detection. Does this overlap with that?
There is some overlap in data sources, the platform does monitor for leaked credentials and dark web exposure of employee identities, but the focus is different. ITDR tools are primarily **detection-oriented**: they identify when an identity is being actively abused inside the environment. Exposure Management is **prevention-oriented**: it identifies leaked or exposed credentials before they are used, and combines that signal with infrastructure vulnerability data to understand the full potential attack path.

For organizations with a mature ITDR capability, the two are complementary. Credential exposure intelligence from Exposure Management can feed into ITDR tooling as early warning signals. And if an ITDR tool detects active credential misuse, Exposure Management can help identify the infrastructure vulnerabilities an attacker would be most likely to pivot to next.

## Agentic AI & Emerging Threats

### 10. How does the platform address threats from agentic AI, both attackers using AI agents and internal AI agents that customers are building?
The platform addresses the agentic threat from two directions.

**Attacker-side:** The platform deploys its own fleet of AI agents, modeled on how agentic attackers operate, to continuously probe the customer’s external attack surface. These agents combine dark web intelligence, leaked credential data, and vulnerability data to discover attack paths that traditional scanners, which run at fixed intervals and follow known patterns, would not find. Unlike penetration testing, this is continuous and non-disruptive.

**Customer-built agents:** As organizations deploy their own AI agents (on cloud infrastructure, internal servers, or SaaS platforms), those agents introduce new attack surface. The platform can identify whether the infrastructure those agents run on has exploitable vulnerabilities, for example, a web server serving an internal AI agent that has an unpatched CVE could allow an external attacker to access the agent’s underlying systems and data. This is distinct from AI governance or prompt-injection monitoring tools, which inspect the agent’s input/output; this approach identifies whether the host infrastructure itself is exploitable.

In practice, for one enterprise customer, the agentic assessment exposed the full system prompt and internal SharePoint links accessible to their production AI agent, all through an infrastructure vulnerability on the server it ran on, not through the agent’s interface itself.
