Back
Itai Greenberg
CRO, Check Point Software Technologies

#CPX360 2020 Vienna – Secure Your Everything- New Products Announcements – Itai Greenberg

🎥 Apr 02, 2020 📺 Check Point Software ⏱ 29m 👁 614 views
Now the breach that we are talking about is happened to a large financial organization on AWS and it exposed 100 million ...
Watch on YouTube

About Itai Greenberg

Itai Greenberg, Chief Strategy Officer (CSO) and former Vice President of Product Management at Check Point Software, has been discussing the impact of generative AI on cybersecurity and the company's product strategy. In a June 2025 interview, Greenberg stated that attackers are using AI to create phishing emails and websites at scale with little effort. He described Check Point's approach to AI from three angles: the attacker, protecting AI systems, and using AI for prevention. He said Check Point offers products to control employee use of public large language models (LLMs) and to secure organizations' own GenAI applications. Greenberg also advocated for a "hybrid mesh" security architecture, arguing that customers need a platform that provides prevention and simplicity rather than multiple products and alerts. In earlier appearances, Greenberg discussed Check Point's Secure Service Edge (SSE) and Secure Access Service Edge (SASE) offerings, emphasizing a hybrid approach that performs inspection on the device or browser to reduce latency and privacy concerns. He commented that funneling all internet traffic to cloud providers for SSL decryption would be costly and create cross-border privacy issues. Greenberg also highlighted Check Point's partnership with Microsoft Azure, stating that Microsoft selected Check Point as the number one security vendor for Azure. He promoted Check Point's Security Log Analytics Service, which uses Azure Data Explorer to aggregate logs from Check Point enforcement points. Additionally, Greenberg warned that organizations should prepare for quantum computing attacks, noting that hackers are already collecting encrypted data for future decryption.

Source: AI-verified profile updated from Itai Greenberg's recent appearances. Browse all interviews →

Transcript (9 segments)
I
Itai Greenberg0:00
So to learn about it, you'll have to stay until the end, but it will start to talk about innovations in Check Point. Now, different companies have different ways to innovate in cybersecurity, but the way we do it in Check Point, we have two very important principles. The first principle we call it practical prevention. Now, we talk about prevention all the time. We're here to prevent. We are not here to detect. We don't want to generate for you yet another alert. But to make it practical, it means that we cannot slow down your business. We cannot generate false positives. Everything needs to work fast. And the second principle is consolidation. So we are coming with this innovation for mobile, for cloud, for endpoint, and then we have the 24 years of innovation that we developed up until now. And we ask ourselves, I do it too, one plus one equals three. How do we combine these offerings together and to give more value to the customers? In this session today, I'm going to talk about 11 new innovations. There are many more in this event, but I focused on 11 of them and I grouped them in five categories. The first category is how do we secure the cloud. How do we secure your AWS, your Google Cloud? Then we'll talk about how do we connect your existing environment, your data centers, your branch offices, and connect them to the cloud in a secure way. Then I will talk about how do you connect the devices and connect them to the cloud in a secure way and to the internet. Then I will talk about the modern devices, the IoT, and I will summarize with how everything works together. Let's start with the cloud. How do we secure the cloud? The thing is that we started to secure the cloud five years ago and by now we have over 4,000 customers that use Check Point to secure the cloud. They use CloudGuard and we have them from all over the world, from all the different sectors. We have them from finance, from telco, we have them from retail, from utility companies. They use Check Point CloudGuard to secure the cloud. Now, if I want to simplify the story and to look at the cloud, I will divide it into two parts. The left part of the cloud is the infrastructure, is where we put the VMs, the virtual machines, maybe the containers. The right side is where we have all the services. We have hundreds of services that we need to secure. It can be storage, it can be load balancer, it can be web services, maybe database services. Now, with Check Point, we give you security for both. We give you security for the left side with CloudGuard. We give you the best advanced threat prevention for the left side and micro-segmentation. It's auto-scaling and everything on the left side. For all the services and inside the cloud, we have CloudGuard Online. CloudGuard Online is a leading solution to give you posture management, security posture management for all your cloud workloads and applications and services inside your cloud. Now, as we look at the cloud, we see that modern applications in the cloud are consisting of many, many small components, many small elements. It's not one big server that does everything. Now, it becomes very challenging to secure it because they are communicating with each other, they get traffic from outside, communicating outside. Maybe your application spans over two different clouds and the data center. How do you secure, how do you see, how do you understand what's happening over there? For that, we came up last year with CloudGuard Logic. Now, I love the name Logic. Logic, CloudGuard Logic. And the idea was that we took all the logs, all the activities that happen in the cloud, and we created for you the Google Map. You can now see what happens in your cloud. You can understand what actually the applications are connected to. And just like with Google Map where you can create layers one on top of the other, we developed machine learning and artificial intelligence on top of this tool to detect anomalies. And with the CloudGuard technology, we can also automatically remediate things that look suspicious. I have with me here Amir Kiboshonsky that I want to invite on stage to come and show you a demo about CloudGuard Logic.
A
Amir Kiboshonsky4:41
I'm here. Thank you for joining us, by the way. Amir wanted to be a medical doctor and I'm so happy that you became a cybersecurity doctor. Thank you. So what's the demo about? So we are going to show, to talk about a recent cloud breach that happened to a large financial organization and we will show how Logic protects you against it. Okay, so before we start the demo, I want to show you how Logic looks like. So it's an example of the flow visualization. So this is how the different entities in your cloud talk to each other. Now, the breach that we are talking about happened to a large financial organization on AWS and it exposed 100 million accounts. Here you can see what the attacker did in order to gain access to this data. Basically, she took tokens, the AWS tokens, used it in her environment in order to gain access for the entire S3 bucket of the organization. And if we come back to Logic and look at the flow visualization, now we can clearly see that we have a communication with a malicious entity. If we go to the alert screen, we see two related alerts. One alert related to the use of Tor and the other one is related to the abuse of the access tokens. We're interesting. Thank you very much. Any time.
I
Itai Greenberg6:30
So with CloudGuard Logic, we can really prevent a very known breach that happened in 2019. Now, the thing is that I talked before about all the small components that application is consisting of. Now, obviously, we are starting with virtual machines and Linux that you have in the cloud and we have plenty of them. But we have new things. We have containers, Kubernetes, we have Docker, we have serverless like Lambda. How do we secure all those small components that you have all over the clouds? For that, we have the Nano Agent technology that Gil talked about before. With the Nano Agent technology, we can secure your workloads inside your cloud. Now, I'm happy to introduce two new products that take advantage of this Nano Agent technology. The first one is CloudGuard WAP and the second one is CloudGuard Workload. Let's understand what the two products actually do. Now, you know Check Point will give you access control, zero trust, we give you threat prevention. But what you see here, we are taking it to the next level. We're doing runtime protection. We are doing hardening vulnerabilities. We are doing web and API security, not like the old WAF that you need to configure and doing things manually. It's all based on machine learning. We're doing code analysis, dynamic and static code analysis inside your code. So we are taking it much deeper and we are giving it all fully integrated into your CI/CD. So your DevOps people can move much faster with this technology. I have with me here TJ. TJ, please join me on stage to show you a demo about workloads.
T
TJ8:24
Hi TJ. Thank you very much. I need it. So by the way, TJ is the founder and the CEO of Protego, which we acquired, and is a workaholic. What I know that you get sick just thinking about sleeping. Hey, sleeping, hate sleeping. So what's the demo about? Yes, we're gonna show our new solution for workload protection, the way it works and what it is supposed to do. Okay, so let's start with why do we need a new type of protection. We are used to this world where we had a data center, a monolithic application, and it used to have a perimeter and we expected the attacker to come through that perimeter. So what did you do? We put a Web Application Firewall in that perimeter and we hope that it will stop the attacks. Now, let's look at the same application in a modern application architecture environment. Instead of one monolithic application, you have hundreds of microservices, service functions, containers interconnected with one another. Each and every one of them has potentially hundreds of different entry points and the attacker can take advantage of them. It doesn't take a genius to understand that your perimeter is dead and your new perimeter is the workload itself, whether it's a service, function, or a container. And that's exactly where the concept of workload protection comes in. In our solution for workload protection with CloudGuard Workload, what we do with CloudGuard Workload, we put protection where it matters, on the workload itself. In the example we're showing here in the demo, serverless protection. So we have a service function that can go anywhere, it can be anywhere. We put what we call function self-protection. It's protection that attaches itself to the function itself. It lives with the function, it goes wherever the function goes. It automatically builds protection profiles for the function even before it runs, so it knows what the function is supposed to do. And then when the function actually runs, this function self-protection will inspect everything that comes into the function independent of the input. It will also stop behavior-type attacks. If the function is trying to do something it's not supposed to do according to its automatically built profile, we will stop it. So protection that lives with the workload, goes with the workload, known attacks, unknown attacks, always there, doesn't matter how the workload got there. So that's workload protection coming soon. Actually, there, man, this was fast. Thank you very much.
I
Itai Greenberg10:45
If you want to learn more about what we do with workloads, I'm inviting you to the tech tables and we show a real demo and we have additional sessions about it. So, drink some water. Even better, I will talk about summarizing what we have in the cloud space. So as you can see, we are giving you a full suite of products. We are giving you ability to secure everything in the cloud with Dome9, we are giving it with Logic, and now also with WAP and with workloads. So we talked about how we secure the cloud, but what about how do we connect your environment to the cloud in a secure way? You have your data center, you have your branch offices, they need to be connected as well. So when you think about connecting those environments to the cloud, three things are important. The first thing obviously is security, you need to make it scalable, and you want to make it fast. You don't want to spend time. We have many branch offices, you want to connect fast and to get them secure. So for that, we have on the left side, on the branch offices, we have CloudGuard Connect. And for the data center, we have a very, very unique offering here. We call it Maestro. And I want to start with Maestro and how we secure the data center. Now, if I'll ask you, you know, like you're taking your applications right now and you're moving them into the cloud, but you're not going to get rid of your data center. You're going to have a data center for many, many years to run. And more and more traffic will flow from your data center to the cloud. And then I would ask you, how much more traffic do you need between the data center and the cloud next year, the year after? You probably don't know. It's hard to know. With Maestro, it's not a problem. Because you put Maestro, you put whatever appliances that you bought from Check Point to secure your data center, and we need more capacity, it only takes two minutes to add yet another gateway to add it to Maestro and service the needs. You can protect your investment. You don't need to replace your appliances that you bought a year or two years ago. You just increase the capacity as needed. This is the hyperscale technology that is very unique and it allows you to connect your data center to the cloud. Okay, but what about the branch offices? Now, for the branch offices, we're giving you the ability to do it in two ways. The first thing is with a cloud service, we call it CloudGuard Connect. You can take all your branch office traffic, you can use whatever is the SD-WAN vendor that you want, and you've seen outside all of them sponsoring these events, with tight integration with them. And it was important for us to make sure that you can easily and very fast use whatever is the SD-WAN vendor that you want to connect all your branch offices to the cloud in a secure way. And it takes only a few minutes to do it. Then you can say, but what if I want to secure my branch office locally? For that, we have the CloudGuard Edge. CloudGuard Edge is a UCP, it's a very small gateway of Check Point that you can put inside your SD-WAN. For example, with VeloCloud, we are offering you the ability to put Check Point inside the VeloCloud, that's the one, but there are others as well, and secure your branch office. And I have with me Aviv to come and show you a demo how it actually works.
A
Aviv14:24
Hi Aviv, thanks for joining. So by the way, Aviv, besides Gil and Dorit, which are the most veteran people in the company, Aviv is the third one with how many years? 20, nearly 24 months in the company, unbelievable. Aviv, what's the demo about? So we talked about CloudGuard Connect and it's very easy and simple to set it up, but we wanted to take it much, much further. So what we've done, we've created an integration with leading SD-WAN vendors to make it very simple and intuitive to set it up. And what I'm going to show you is just how simple it is. So let's start. And we worked with the leading vendors and we worked with API to create everything automatically for you to have that single experience of a single product to manage and to configure. And let's start and how it looks. We start with a very empty setup, nothing is defined. And now we're going to move to the Silver Peak Orchestrator, which is one of our SD-WAN vendors. All we have to do is drag that Check Point icon to the preferred policy order, and actually that's it. Nothing else you need to do. From this point, all your sites, all your data center is protected automatically and now and in the future. And you can see all the sites created automatically. And we are taking this to market in a very great way. We are going to expand our ecosystem to include all the leading SD-WAN vendors in this industry. And that's it. Thank you.
I
Itai Greenberg16:04
Thank you very much, Aviv. Again, if you want to see more about our CloudGuard Connect and CloudGuard Edge, you are welcome to the tech tables and to the sessions. And as you can see here, if I'm summarizing this part, you see that we are connecting and protecting your data center and your branch offices with security, with hyperscale technology, and it's very, very fast. So we talked about securing the cloud, connecting to the cloud, but what about the devices, the mobile devices and the endpoint? Let's talk about that. They also need to connect to the cloud and to the internet. Right now, more and more vendors today come to you customers and tell you, we give you a cloud service for that, send us all the traffic and we will secure the traffic that goes to the internet from a cloud service. What they don't tell you is that 80% of the traffic is SSL-based and they don't open the SSL. They only give you URL filtering and they don't really protect you from fifth generation and sixth generation cyber attacks. So obviously, a cloud service is not the best way to do that. What do we do in Check Point? We are giving you security directly on the devices themselves. So we did it for years now with our SandBlast Mobile. We secure Android and iOS. We're doing it now, we're securing Windows and Mac and Linux. This is a new thing that we're doing now with Linux as well. So we're securing your endpoint devices with SandBlast Agent. But we have something new today. We are doing it also within the browsers. We have SandBlast Web and this is our ability to secure all the communication that comes in and out from your browsers. Now, let's zoom in and understand what's the important feature or capabilities in this new product. So you want to secure the traffic that goes to the internet because we live on the browser. It's a small nano agent that clips inside your browser. We see all the traffic in clear. So not only that we give you what everyone else is doing with preventing bad URLs, we can protect against zero-days because we see what the user is actually trying to do. We can protect you from zero-phishing. But the cool thing here also is that because it's not a cloud service, you don't need to pay the cost and the overhead of a cloud service and you don't have the latency. And if you have employees that are traveling the world, you don't have to deal with privacy issues. So definitely, that's a much better way in our opinion to secure web communication. Now, I'm talking about devices, let's talk about the new generation of the devices, the IoT. Now, IoT becomes the weakest link. And the reason for that is because no one actually patches them. You don't know about them. Someone comes to your organization and connects a smart camera, put it wherever you want, and it's part of your network. And those devices are not protected. And you know what, I'll tell you two stories about it. One story is about a few months ago, I have been in New York and I met one of our customers. They have security cameras in the building and they told me, you know, we had the controller that controls all those security cameras and got affected, so we had to replace it. The controller of those cameras came from the manufacturer with malware built in. The moment we connected it to the network, we started to have machines infected in our network. And then we've seen it also with smart meters. Companies that have smart meters, the hackers got into the smart meters and from there into the data center. Or with the UTM machine, they got into the UTM machine and from there into the data center. So we've seen different types of IoT devices that become the weakest link. Now we need to secure them. And for that, we have the Check Point IoT Security. Now, what do we do with the Check Point IoT Security? We focus on these three verticals. We focus on smart office and smart building, we focus on medical devices, the MRI machine, the infusion pump, and industrial IoT devices, OT devices. So it starts by, you don't have to use Check Point at all. All you need to do is give us the firmware. It's an online service. You give us the firmware and we generate for you an assessment, a firmware risk assessment, telling you, you know, this device that you are using has weak passwords, known passwords, and default credentials. There are known vulnerabilities. And you know, it also tried to communicate with a domain with a URL that looks suspicious. Then if you choose to use Check Point to secure IoT, you can use this service, the risk assessment service, automatically to scan all your devices and give you information about all your devices automatically. And we are doing it with discovering all your devices. By the way, again, in this CPX, you'll see all the IoT vendors, discovery vendors that are partnering with us to give this service for you. Now, once you do that, we are also giving you the ability to micro-segment your environment. And if you are also a company that have a lot of IoT devices from the same type, I talked before about smart meters, or if you are a vendor that develops IoT devices, we are giving you the ability to put a nano agent on your IoT, whatever framework that you use, put a Check Point Nano Agent on your IoT and sell to your customers this IoT secured with Check Point inside. So I talked about all the different security capabilities that we have, but I want to explain how everything works together. Right, this is what Gil talked about, the Infinity architecture. We secure everything and it's with an architecture that works and secures everything together. We talked about the six security engines that we are offering. We talked about the fact that we secure five types of assets. But how do we do it all together? How do we manage this operation? Today, you have to buy from Check Point a management server and to do it yourself, right? You have to upgrade it, to maintain it, to replace the appliances, the security management appliance. What if we will give it to you as a cloud service? You can go and just log into a cloud portal and get everything. For that, we introduce today the Check Point Management as a Service. You go to the Check Point Infinity portal and you can manage your endpoint, your mobile, you can manage your cloud, you can manage your appliances. Everything is with the web GUI. You don't need to worry about the maintenance of the management solution. We care and do it for you. Now, on top of that, everything is scalable. Obviously, the management is scalable, but we also wanted to give you scalability on the enforcement point, on the appliances. And we are shipping now today five new appliances that are all powered with Maestro, all tightly connected and work with Maestro. And because security, we take it very seriously and we believe that we need to protect against fifth generation of cyber attacks, they are all coming in the first year with the best and the full security from Check Point with our SandBlast package. Now, this is the last innovation that I'm going to talk about today and I think this is the coolest one in my opinion. We have in Check Point ThreatCloud, right? This is the solution, the intelligent solution that gets to investigate four billion IOCs every day. This is the engine that prevents 25 million unknowns every day. But up until now, we used ThreatCloud only to help our products to give you the security. What if I'm giving you the ability to access ThreatCloud as much as you want and to query through ThreatCloud? For that, we're introducing the Check Point Infinity SOC. You can now Google search ThreatCloud. Give us the domain, the URL, the file. We will tell you everything we know about it and how to mitigate it. We will give you a full solution, full report about what we know there. And in the Infinity SOC, you'll find many more capabilities. For example, you will find that we give you a tool that finds hidden, attacked, exposed, infected machines inside your network that you don't know about them and give you a very detailed explanation how to mitigate, how to remediate it. So I want to invite on stage for the last time of the day, I want to invite Eitan.
E
Eitan25:17
Hey Eitan. So everyone, what are we going to see here? So we're gonna show a quick demo that illustrates really some of the power of Infinity SOC and show how we can provide insights that accelerate and focus security operations. So let's get it rolling. Sure. Okay, hi everyone. So this is a demo from a customer, about 10,000 users, a small 24/7 security operation. They had absolutely no idea they'd been already breached, but within 24 hours of onboarding the customer, Infinity SOC identified the 12 infections on the network and helped them find the root cause and prevent future attacks. So here it is in action. Our AI engines have identified, you can see here, the 12 infected hosts, classified them. There were six malware families in there. And for each alert, you can see there's a lot of analytics both from the customer network and from ThreatCloud. And using this data, the customer actually ran an investigation and confirmed to us these were all spot-on detections, true positives. So after cleaning the infections, they wanted to understand how the system, and for this, they used Infinity SOC to search ThreatCloud. And searching for some of the indicators, and you'll see the Cinnamon in a moment in the video, and the customer gets a wealth of information. So here you can see the search of the indicators and we provide a lot of information both from global spread, the email subjects, the detonation reports, and much, much more. And using this information, the customer was able to very quickly identify the root cause of the attack was an email. And as a result, the customer has now moved not only to use Infinity SOC, they're actually implementing Check Point SandBlast to address some of the gaps in their security. Oh, thank you very much, Eitan. Thank you.
I
Itai Greenberg27:33
Thank you everyone. So to summarize everything, you remember at the beginning I told you my innovation story from Beijing, right? And I promised to explain what happened there. So here it is. So we have the tree on the left side, this is the big tree. We have the small tree on the right side. And I asked you how do you, what innovations they used in Beijing to make it grow so fast in five months. So this is what they did. They injected fertilizers into the trunk of the tree, into the veins of the tree, and make it grow so fast. I was amazed when I've seen it. And by the way, I've seen the people actually turning there and planting those trees. And I talked to the supervisor and we became kind of friends. And after a while he asked me, so tell me, how many Israelis are there? And this is the local Chinese guy. And I told him, we're eight million. And he says, no, not here, in China altogether. And I say, no, no, we're only eight million people anyway. So talking about innovation, I shared with you today 11 innovations that we are introducing in this CPX event. And these innovations help you to prevent fifth and sixth generation of cyber attacks. And we gave you on the chairs when you came in the brochure listing 18 new innovations that we are introducing here in this CPX event. You are welcome to go and learn more about them in the track sessions. You are welcome to go and visit us in the tech tables to see a real demo of how they work. Thank you very much and enjoy CPX.