About Itai Greenberg
Itai Greenberg, Chief Strategy Officer (CSO) and former Vice President of Product Management at Check Point Software, has been discussing the impact of generative AI on cybersecurity and the company's product strategy. In a June 2025 interview, Greenberg stated that attackers are using AI to create phishing emails and websites at scale with little effort. He described Check Point's approach to AI from three angles: the attacker, protecting AI systems, and using AI for prevention. He said Check Point offers products to control employee use of public large language models (LLMs) and to secure organizations' own GenAI applications. Greenberg also advocated for a "hybrid mesh" security architecture, arguing that customers need a platform that provides prevention and simplicity rather than multiple products and alerts.
In earlier appearances, Greenberg discussed Check Point's Secure Service Edge (SSE) and Secure Access Service Edge (SASE) offerings, emphasizing a hybrid approach that performs inspection on the device or browser to reduce latency and privacy concerns. He commented that funneling all internet traffic to cloud providers for SSL decryption would be costly and create cross-border privacy issues. Greenberg also highlighted Check Point's partnership with Microsoft Azure, stating that Microsoft selected Check Point as the number one security vendor for Azure. He promoted Check Point's Security Log Analytics Service, which uses Azure Data Explorer to aggregate logs from Check Point enforcement points. Additionally, Greenberg warned that organizations should prepare for quantum computing attacks, noting that hackers are already collecting encrypted data for future decryption.
Source: AI-verified profile updated from Itai Greenberg's recent appearances.
Browse all interviews →
Transcript (35 segments)
J
John Brighamin0:14
Hi, I'm John Brighamin. I'm with CBTS as a consulting CSO, and I'm here today to talk with Check Point and Itai Greenberg.
J
John Brighamin0:30
Here at RSA, one of the hot topics still continues to be zero trust, and SASE has come up on occasion. So what would you say is Check Point's SASE product offering, or how does it fit into the market, or what do you see the future for SASE?
I
Itai Greenberg0:46
Yeah, I think it's a very important topic. We've seen that over the last, I would say, three or four years, what happened is that we moved more and more applications into the cloud. People started to work from home, and instead of redirecting all the traffic from the employees into the data center and from there either to go to the internet or to go to applications that used to be in the data center but now in the cloud, we want to send the traffic directly to the applications. Because we are not in the office anymore, we used to secure these kind of connectivities with a solution that was designed inside your on-prem environment. Some of them, we all felt safer because we had our big firewalls in the data center, everybody was in the office, everybody accessed it that way. But now that we're working from home, we've got a different challenge.
J
John Brighamin1:43
It's a different challenge indeed. We used to use like a proxy or maybe things on the device. At Check Point, we secure a lot of customers on the internet connectivity, but things have changed, right?
I
Itai Greenberg1:55
Now what happened is that customers and the industry started to look at this concept of SSE and SD-WAN, two different technologies that kind of merged together into what we call SASE. So the secure service edge, you know, people don't understand it, but if you think about it, the goal of zero trust is to protect the data. So we want to protect the data and who's accessing it, so we have to protect the edge device that's accessing the data. And there are three main use cases at the end of the day. The first one, I want to secure users when they access the internet, so it's the internet security. I want to allow users to access corporate applications whether they are on-prem or in the cloud. And I want to connect the branch offices to those applications as well and to the internet.
J
John Brighamin2:45
So sometimes you are in the, sometimes it's hard for you to secure something inside your branch office because it's not a user, it's not a device, maybe IoT.
I
Itai Greenberg2:52
Yeah, so IoT is a whole separate topic. But that's good. So then come the technology that says let's redirect all the traffic into these SASE things in the cloud in order to do the security. We'll open all the SSL and then we will redirect the traffic to either the internet or the cloud or the data center.
J
John Brighamin3:17
So to get into that SSL connection, you've got to be functioning as a proxy essentially. You have to function as the proxy or as the man-in-the-middle solution that knows how to open the SSL.
I
Itai Greenberg3:28
A positive man-in-the-middle, not the bad guy. You need to have the certificate authorities and certificates that will allow you to do that. But then think about it, there are one billion employees around the world. Do you think that we should take all the employees' traffic wherever they are, when they want to access, let's talk about the use case of the internet, when they want to access the internet, we'll take all their traffic, we shuffle it into one point which we call SASE, we will open the SSL for everyone and do the security. And usually those SASE solutions are running on AWS and Azure and Google Cloud. So all the traffic of the internet of the world will go to a few, like AWS and Azure, and will open it. It's insane.
J
John Brighamin4:17
It's insane because of different reasons. The cost will be enormous. The privacy is a bit of an issue because you need to open SSL wherever you are, and sometimes you travel around the world. So where do you put the, open the traffic? And there's privacy laws. I mean, the European Union might have a different stance on whether or not you should be allowed to observe that traffic versus the United States versus Israel versus wherever.
I
Itai Greenberg4:43
Very much. And you still want to live in the world, you want to travel. It will impact the user experience because of latency. Because if I'm redirecting all traffic to one place, I'm opening the SSL, it's a latency issue. It will also, in many cases, will not be able to give you the level of security that you need because you are missing the context of what is happening on the device. And so we're all moving into, let's move all the traffic to the cloud, do this magic, open it over there. And when I looked at this, I said, wait a second, it doesn't make sense. We need to look at it a bit different. We want to have this kind of SASE in the cloud, we want to be able to open traffic in the clouds to do the security, but I don't think we should do it for 100% of the internet traffic.
J
John Brighamin5:30
So make a determination.
I
Itai Greenberg5:32
Yeah, I think it's the wrong approach. I think the right approach would be let's leverage what we have on the device. We have CPU on the device, we have context on the device. So we at Check Point, we believe that we can do a mix of doing things in the device and things in the clouds together. So I will try to do as much as I can security inside your browser. I don't need to open the SSL. I can still give you the URL filtering, the application control, the IPS, the file security for whatever you do inside the browser. But for those rare cases where I have a doubt, maybe this file is not something that I'm able to do within the browser, maybe it's a connection that didn't come from the browser, it comes from some other application inside my device, maybe it's a script that looks very suspicious. So for those rare cases, I still want to consult with something that sits in the clouds that has higher context, has more compute power, and can do things that I'm not able to do in the browser. By joining or combining the ability to do things within your device, within your browser in this case, and to do things in the cloud, I believe we can gain a much better solution of this what I call the next generation of SASE. We can avoid the privacy issues if you don't have to break apart the SSL. You don't have to deal with the problem of, for example, latency.
J
John Brighamin7:06
Yes, because you're getting to it before it even starts the transmission process. Like that, you do the security as soon as you get the content to your browser, you inspect it, and immediately it goes to the internet. It doesn't, you don't redirect it to a POP in some cloud, remote cloud, to open the SSL and everything.
I
Itai Greenberg7:25
When you order a pizza, think about it. If I would order pizza and I'm sitting in, let's say, Berlin, but my POP, my cloud solution is in Munich, I will get the pizzas in Munich, not the pizzas in Berlin. But I search for pizza in Berlin. And this is still in German, which is good. But what if I traveled maybe to France and my cloud is in Berlin? I will get it in German, but I want to get a French pizza, not a German pizza. So it's in many, many things related to the user experience will be solved if I'll be able to do the things in the browser, not only in the cloud.
J
John Brighamin8:08
So what does it require on the browser side? Are we saying you're going to install an application, or is it an extension to the browser, or what's the...
I
Itai Greenberg8:17
Exactly. So we believe that you need to have something, an extension to the browser that is able to provide you the level of security that you need for the internet security, not for the remote access that you go to your corporate application, but you go to internet.
J
John Brighamin8:32
I mean, it'll be a hybrid environment where you'll have some of your applications, perhaps legacy applications, are still inside the corporate network. So you will use your VPN, so you're not getting rid of that.
I
Itai Greenberg8:45
Sorry, or maybe not. So we will talk soon about the use case of remote access to your corporate application, but I'm putting it for a second on the side. I'm focusing on the internet. Which, by the way, thinking about it, 90% of your traffic that goes outside your computer, mobile or laptop, goes to the internet, doesn't go to a corporate application. This is the big part of the traffic. Would you pick what I be today for SASE vendors to inspect it? That's a lot. I can reduce it by tenfold if I use the compute power of the employee device and if I don't pay for the traffic to the cloud provider.
J
John Brighamin9:28
Yes, then you save money.
I
Itai Greenberg9:30
Tons of money. So better experience, no privacy issues, way less cost. And I'll give you an example of better security even. In the cloud, when the user puts in username and password, it's already encrypted. I don't know how to understand if it's good or bad. In the browser, I see the user is putting username and password. I can tell him, wait, stop, you cannot use your corporate passwords in Facebook to access your private Gmail. So I can even interact better and do better security for the end user within the context of the browser.
J
John Brighamin10:08
Yeah, you've pushed the control to the end user on the end device. I mean, so it's definitely securing that service edge and securing the user and securing what I would like to say is, you know, the most important corporate asset, the data. Because you could probably even stop them from putting in, uploading a file from their personal device to Dropbox or Google if the office solution for cloud storage is OneDrive. So you could probably interrogate whether or not, I mean, like I said, you can do URL filtering, I would imagine, within the browser.
I
Itai Greenberg10:43
Within the browser. Yeah, so you just stop it before it even gets there. I do your filtering things inside the browser. I can control to which application you are allowed to access within the browser. I can do DLP within the browser. I can do even file security, malware security. Now, when I'm saying in the browser, I can still consult with the cloud. My browser can say I need this specific connection, traffic, script, files to consult with the cloud. But then it doesn't mean that 100% of the traffic I shovel or I redirect into a cloud security solution.
J
John Brighamin11:15
Right. So they have totally different approaches. If I have 10 tabs open in my internet browser, only one of those 10 tabs might be of interest for corporate purposes. So I could have one that has Facebook open and you might just let that traffic go.
I
Itai Greenberg11:30
You can still inspect it, but beforehand. So it doesn't matter how many tabs somebody has opened. Not exactly. It's not about the number of the tabs, where the traffic that goes to the corporate. I'm talking about still, let's assume that all tabs, it's only internet traffic. Some of the, or one tab, all this internet traffic. So you go to, let's say, to cnn.com, and within cnn.com everything looks good, but there is one file that you are downloading that might look suspicious. So for all the time that you are traveling and surfing inside cnn.com, it's okay. I will do the security within the browser. But here you are downloading a file and says, okay, this file I've never seen before, it looks suspicious. I will send only this file to consult with the cloud and get the verdict. So regardless of where it was, whether it was coming from cnn, it can come from cnn, it can come from your private Gmail account, wherever it comes, I will, for things that look suspicious, for one percent, maybe two percent of the traffic, I will consult with a more powerful cloud service that will give me a better verdict. For the rest, I can do a way better security within the browser. So the combination of what I do inside the browser or the device and the combination of what I do in the cloud, when they work together, in order to get the best of both worlds.
J
John Brighamin12:48
I get the best of both worlds.
I
Itai Greenberg12:50
Exactly. So I think this is, I'm looking at a lot of customers, a lot of vendors that are saying let's move everything from what we did on the device or what we did inside our proxy, sending all traffic to the cloud. I talk to many of those customers that say they are frustrated from the latency, from cost, from the performance, from the privacy issues. So my belief is that this might be a way better approach, and this is where Check Point is going in the direction of combining the two worlds together.
J
John Brighamin13:22
So do you see that with that solution, if it's going to be an extension of the browser, and I'm assuming that's, I mean, you're not going to replace, you know, Chrome with your own Check Point Chrome version, you're just going to add an extension to it, right?
I
Itai Greenberg13:37
This is a good topic that you bring. I love it that you brought it up. Just thinking, so some startups out there came up with the idea, let's replace the Chrome, let's put our own version of browser. I looked at this and I'm constantly evaluating technology and I thought it's an interesting idea. But I think that most customers around the world will not be able to replace their own browsers. I think it will be way too complex. I think that the end user experience will not be as good as if you use the regular Chrome that you get from Google or iOS or whatever that you like to use. And you know what, when security competes with user experience, user experience always wins.
J
John Brighamin14:21
That is correct.
I
Itai Greenberg14:24
So you need to think about how I provide security that embraces whatever the user wants to do. He wants to use his corporate, his private mobile device for whatever it is, finally to give him the right security over there. He wants to use his own browser that is familiar with, that has given the experience that he likes. I need to do the job over there. And there's also applications that are written sometimes for specific web browsers, so that can be an issue. Anyone wants plugins. You need to give the user the freedom to do what he wants to do. He only wants to block the things that are malicious, not their productivity things. So our belief is a plugin. I need to embrace what the user is doing and put the plugin inside the browsers, multiple browsers. Some of them are like Chromium, Chrome, Firefox, all of them we need to have a plugin. Some of them are plugins for your mobile device, some of them for your laptop. But yes, for the different, and understanding that some of the traffic that goes to the internet doesn't go to the internet from your browser. In those cases when the traffic doesn't go from the browser, I may have to go and redirect the traffic for cloud security to do the job. Because I cannot do it within the context of the browser, the traffic will be already encrypted. So I need someone to decrypt the traffic, look at the traffic, and inspect it. But the beauty of what I can do within the browser is that the traffic is not encrypted.
J
John Brighamin15:54
Yeah, I mean, like you said, if you can get to that entry point before the data gets encrypted, you can do the inspection without invading someone's privacy. That's the point. Well, this has been great. I appreciate your time. I hope you have a good rest of the conference, and I look forward to seeing the Harmony unified environment.
I
Itai Greenberg16:11
Sounds great. Thank you very much, and all the best. Enjoy the rest of the show.
J
John Brighamin16:14
Thank you. Take care.