Back
Itai Greenberg
CRO, Check Point Software Technologies

CPX 360 2020 Cyber Talk: Secure Your Everything - Itai Greenberg, VP Product Management

🎥 Oct 01, 2020 📺 Check Point Software ⏱ 31m 👁 1568 views
On their journey to digital transformation, organizations will realize business benefits but should not underestimate potential risks. With applications moving to the cloud, proliferation of IoT and endpoint devices, and growth in network traffic, attack vectors expand and expose organizations to the 6th generation of cyber attacks. Join this session to learn how we help security professionals to prevent cyber threats with innovative solutions for cloud, IoT, SD-WAN and endpoint devices with a consolidated security architecture. For more information on Check Point's latest products, visit our...
Watch on YouTube

About Itai Greenberg

Itai Greenberg, Chief Strategy Officer (CSO) and former Vice President of Product Management at Check Point Software, has been discussing the impact of generative AI on cybersecurity and the company's product strategy. In a June 2025 interview, Greenberg stated that attackers are using AI to create phishing emails and websites at scale with little effort. He described Check Point's approach to AI from three angles: the attacker, protecting AI systems, and using AI for prevention. He said Check Point offers products to control employee use of public large language models (LLMs) and to secure organizations' own GenAI applications. Greenberg also advocated for a "hybrid mesh" security architecture, arguing that customers need a platform that provides prevention and simplicity rather than multiple products and alerts. In earlier appearances, Greenberg discussed Check Point's Secure Service Edge (SSE) and Secure Access Service Edge (SASE) offerings, emphasizing a hybrid approach that performs inspection on the device or browser to reduce latency and privacy concerns. He commented that funneling all internet traffic to cloud providers for SSL decryption would be costly and create cross-border privacy issues. Greenberg also highlighted Check Point's partnership with Microsoft Azure, stating that Microsoft selected Check Point as the number one security vendor for Azure. He promoted Check Point's Security Log Analytics Service, which uses Azure Data Explorer to aggregate logs from Check Point enforcement points. Additionally, Greenberg warned that organizations should prepare for quantum computing attacks, noting that hackers are already collecting encrypted data for future decryption.

Source: AI-verified profile updated from Itai Greenberg's recent appearances. Browse all interviews →

Transcript (10 segments)
H
Host0:00
Our next speaker has 20 years of cybersecurity experience with companies like Intel, Microsoft, M86, and Check Point. He also played professional handball with the Israeli national team, so he knows all about goals. Ladies and gentlemen, please welcome Check Point's VP of Product Management, Itai Greenberg.
I
Itai Greenberg0:33
So I'm a big fan of the Olympic Games. I'm the guy that wakes up in the middle of the night to watch a judo fight and get really excited when an athlete breaks yet another world record, even if it's by only one millisecond. And so I want to take you to the year of 2008, to the year of the Olympic Games in Beijing, and I want to share with you a story about innovation. It's not innovation of software or security, but it is very, very cool innovation. So bear with me. Take a look at this building. This is the main arena in the Olympic Games. The name of this building is the Bird's Nest. It's the stadium in Beijing. Now there's so much innovation in this building, but I'm not going to talk about the building itself. I'm going to talk about the trees around the building. Let's take a look at one of those trees. Now you see this picture was taken when the Olympic Games started, and the tree is a nice tree. It's a big-sized tree. The thing is that I was in Beijing five months before the Olympic Games started and happened to see the trees when they got just planted. And you know what? It was much smaller. This was the tree five months before the Olympic Games started. So one can ask himself, how do you take a tree that is that small and make it grow so fast to be like this in five months? What innovation they used over there? So to learn about it, you'll have to stay until the end. But I will start to talk about innovations in Check Point. Now, different companies have different ways to innovate in cybersecurity, but the way we do it in Check Point, we have two very important principles. The first principle, we call it practical prevention. Now we talk about prevention all the time. We're here to prevent. We are not here to detect. We don't want to generate for you yet another alert. But to make it practical, it means that we cannot slow down your business. We cannot generate false positives. Everything needs to work fast. And the second principle is consolidation. So we are coming with this innovation for mobile, for cloud, for endpoint, and then we have the 24 years of innovation that we developed up until now. And we ask ourselves, if I do it to one, plus one equals three? How do we collect, combine offerings together and to give more value to the customers? In this session today, I'm going to talk about 11 new innovations. There are many more in this event, but I focused on 11 of them, and I group them in five categories. The first category is how do we secure the cloud. How do we secure your Azure, your AWS, your Google Cloud? Then I will talk about how do we take your existing environments, your data centers, your branch offices, and connect them to the cloud in a secure way. Then I will talk, okay, how do you attack the devices and connect them to the cloud in a secure way and to the internet? Then I will talk about the modern devices, the IoT, and I will summarize with how everything works together. Let's start with the cloud. How do we secure the cloud? The thing is that we started to secure the cloud five years ago, and by now we have over 4,000 customers that use Check Point to secure the cloud. They use CloudGuard, and we have them from all over the world, from all the different sectors. We have them from finance, from telco, we have them from retail, from utility companies. They use Check Point CloudGuard to secure the cloud. Now, if I want to simplify the story and to look at the cloud, I will divide it into two parts. The left part of the cloud is the IaaS, is the infrastructure, is where we put the VMs, is the virtual machines, maybe the containers. The right side is where we have all the services. We have hundreds of services that we need to secure. It can be storage, it can be load balancer, it can be web services, maybe database services. Now, in Check Point, we give you security for both. We give you security for the left side with CloudGuard IaaS. We give you the best advanced threat prevention for the left side and micro-segmentation. It's auto-scaling and everything on the left side. For all the services and inside the cloud, we have the CloudGuard Posture. The CloudGuard Posture is a leading solution to give you posture management, security posture management for all your cloud workloads and application and services inside your cloud. Now, as we look at the cloud, we see that modern applications in the cloud are consisting of many, many small components, many small elements. It's not one big server that does everything. Now, it becomes very challenging to secure it because they are communicating with each other, they get traffic from outside, communicating outside. Maybe your application is spanned over two different clouds in the data center. How do you secure, how do you see, how do you understand what's happening over there? For that, we came up last year with CloudGuard Logic. Now, I love the name Logic. Log, I see, Logic. CloudGuard Logic. And the idea was that we took all the logs, all the activities that happens in the cloud, and we created for you the Google Map. You can now see what happens in your cloud. You can understand what actually the applications are connected to. And just like with Google Map where you can create layers one on top of the other, we developed machine learning and artificial intelligence on top of this tool to detect anomalies. And with the CloudBots technology, we can also automatically remediate things that look suspicious. I have with me here Ami Kadosh that I want to invite on stage to come and show you a demo about CloudGuard Logic.
A
Ami Kadosh6:56
I'm here. Ami, thank you for joining us. By the way, Ami wanted to be a medical doctor, and I'm so happy that you become a cybersecurity doctor. Thank you. So what's the demo about? So we are going to show, to talk about a recent cloud breach that happened to a large financial organization, and we will show how Logic protects you against it. Okay. So before we start the demo, I want to show you how Logic looks like. So it's an example of the flow visualization. So this is how the different entities in your cloud talk to each other. Now, the breach that we are talking about happened to a large financial organization on AWS, and it exposed 100 million accounts. Here you can see what the attacker did in order to gain access to this data. Basically, she took tokens, the AWS tokens, used it in her environment in order to gain access for the entire S3 bucket of the organization. And if we come back to Logic and look at the flow visualization, now we can clearly see that we have a communication with a malicious entity. If we go to the alert screen, we see two related alerts. One alert related to the use of Tor, and the other one is related to the abuse of the access tokens. We're interesting. Thank you very much. Any time.
I
Itai Greenberg8:44
So as you can see with CloudGuard Logic, we can really prevent a very known breach that happened in 2019. Now the thing is that I talked before about all the small components that application is consisting of. Now obviously we are starting with virtual machines and Linux that you have in the cloud, and we have plenty of them. But we have new things. We have containers, Kubernetes, we have Docker, we have serverless like Lambda. How do we secure all those small components that you have all over the clouds? For that, we have the knowledge and technology that Gil talked about before with the nano-agent technology. We can secure your workloads inside your workloads inside your cloud. Now I'm happy to introduce two new products. They take advantage of these nano-agent technology. The first one is CloudGuard WAF, and the second one is CloudGuard Workload. Let's understand what the two products actually do. Now, you know Check Point will give you access control, zero trust, we give you threat prevention. But what you see here, we are taking it to the next level. We're doing runtime protection. We are doing hardening vulnerabilities. We are doing web and API security, not like the old WAFs that you need to configure and doing things manually. It's all based on machine learning. We're doing code analysis, dynamic and static code analysis inside your code. So we are taking it much deeper, and we are giving it all with your DevSecOps fully integrated into your CI/CD. So your DevOps people can move much faster with this technology. I have with me here TJ. TJ, please join me on stage to show you a demo about workloads.
T
TJ10:38
Hi TJ. Thank you very much. I need it. So by the way, TJ is the founder and the CEO of Protego, which we acquired, and is a workaholic. What I know that you get sick just thinking about sleeping. Hey, sleeping, hate sleeping. So what's the demo about? Yes, we're going to show our new solution for workload protection, the way it works, and why this is supposed to do. Okay, let's take a look. So let's start with why do we need a new type of protection. We are used to this world where we had a data center, a monolithic application, and it used to have a perimeter, and we expected the attacker to come through that perimeter. So what did you do? We put a web application firewall on that perimeter, and we hope that it will stop the attacks. Now let's look at the same application in a modern application architecture environment. Instead of one monolithic application, you have hundreds of microservices, service functions, containers interconnected with one another. Each and every one of them has potentially hundreds of different entry points, and the attacker can take advantage of them. It doesn't take a genius to understand that your perimeter is dead, and your new perimeter is the workload itself, whether it's a service function or a container. And that's exactly where the concept of workload protection comes in. In our solution for workload protection with CloudGuard Workload, what we do with CloudGuard Workload, we put protection where it matters, on the workload itself. In the example we're showing here in the demo, serverless protection. So we have a service function that can go anywhere, it can be anywhere. We put what we call function self-protection. It's protection that attaches itself to the function itself. It lives with the function, it goes wherever the function goes. It automatically builds protection profiles for the function even before it runs, so it knows what the function is supposed to do. And then when the function actually runs, this function self-protection will inspect everything that comes into the function, independent of the input. It will also stop behavior-type attacks. So if the function is trying to do something it's not supposed to do according to its automatically built profile, we will stop it. So protection that lives with the workload, goes with the workload, known attacks, unknown attacks, always there, doesn't matter how the workload got there. So that's workload protection coming soon. Actually, there, man, this was fast. Thank you very much.
I
Itai Greenberg12:57
If you want to learn more about what we do with workloads, I'm inviting you to the tech tables and we show a real demo, and we have additional sessions about it. So let me drink some water. Even better, I will talk about summarizing what we have in the cloud space. So as you can see, we are giving you a full suite of products. We are giving you ability to secure everything in the cloud with the IaaS, with Dome9, we are giving you it with Logic, and now also with WAF and with workloads. So we talked about how we secure the cloud, but what about how do we connect your environment to the cloud in a secure way? You have your data center, you have your branch offices, they need to be connected as well. So when you think about connecting those environments to the cloud, three things are important. The first thing obviously is security. You need to make it scalable, and you want to make it fast. You don't want to spend time. You have many branch offices, you want to connect fast and to get them secure. So for that, we have on the left side, on the branch offices, we have CloudGuard Connect. And for the data center, we have a very, very unique offering here. We call it Maestro. And I want to start with Maestro and how we secure the data center. Now, if I ask you, you know, like you're taking your applications right now and you're moving them into the cloud, but you're not going to get rid of your data center. You're going to have a data center for many, many years to run. And more and more traffic will flow from your cloud, from the data center to the cloud. And then I will ask you, how much more traffic do you need between the data center and the cloud next year, the year after? You probably don't know. It's hard to know. With Maestro, it's not a problem because you put Maestro, you put whatever appliances that you bought from Check Point to secure your data center, and when you need more capacity, it only takes you two minutes to add yet another gateway to add it to Maestro and service the needs. You can protect your investment. You don't need to replace your appliances that you bought a year or two years ago. You just increase the capacity as needed. This is the hyperscale technology that is very unique, and it allows you to connect your data center to the cloud. Okay, but what about the branch offices? Now, for the branch offices, we are giving you the ability to do it in two ways. The first thing is with a cloud service we call it CloudGuard Connect. You can take all your branch office traffic, you can use whatever is the SD-WAN vendor that you want, and you've seen outside all of them sponsoring these events, with tight integration with them. And it was important for us to make sure that you can easily and very fast use whatever is the SD-WAN vendor that you want to connect all your branch offices to the cloud in a secure way, and it takes only a few minutes to do it. Then you can come and say, but what if I want to secure my branch office in the branch locally? For that, we have the CloudGuard Edge. CloudGuard Edge is a UCP. It's a very small gateway of Check Point that you can put inside your SD-WAN. For example, with VeloCloud, we are offering you the ability to put Check Point inside the VeloCloud SD-WAN, but there are others as well, and secure your branch office. And I have with me Aviv to come and show you how it actually works.
A
Aviv16:38
Hi Aviv, thanks for joining. So by the way, Aviv is like Gil and Dorit, which are the most veteran people in the company. Aviv is the third one with how many years? Nearly 24 years in the company. Unbelievable stuff. What's the demo about? So we thought you talked about CloudGuard Connect, and it's very easy and simple to set it up. But we wanted to take it much, much further. So what we've done, we've created an integration with leading SD-WAN vendors to make it very simple and intuitive to set it up. And what I'm going to show you is just how simple it is. So let's start. And we worked with the leading vendors, and we worked with API to create everything automatically for you to have that single experience of a single product to manage and to configure. And let's start and how it looks. We start with a very empty setup, nothing is defined. And now we're going to move to the Silver Peak Orchestrator, which is one of our SD-WAN vendors. All we have to do is drag that Check Point icon to the preferred policy order, and actually that's it. Nothing else you need to do. From this point, all your cloud, all your sites, all your data center is protected automatically and now and in the future. And you can see all the sites created automatically. And we are taking this to market in a very great way. We are going to expand our ecosystem to include all the leading SD-WAN vendors in this industry. And that's it. Thank you.
I
Itai Greenberg18:18
Thank you very much. Again, if you want to see more about our CloudGuard Connect and CloudGuard Edge, you are welcome to the tech tables and to the sessions. And as you can see here, if I'm summarizing this part, you see that we are connecting and protecting your data center and your branch offices with security, with hyperscale technology, and it's very, very fast. So we talked about securing the cloud, connecting to the cloud, but what about the devices, the mobile devices and the endpoint? Let's talk about that. They also need to connect to the cloud and today internet. Right now, more and more vendors today come to your customers and tell you, we give you a cloud service for that. Send us all the traffic, and we will secure the traffic that goes to the internet from a cloud service. What they don't tell you is that 80% of the traffic is SSL-based, and they don't open the SSL. They only give you URL filtering, and they don't really protect you from fifth-generation and sixth-generation cyber attacks. So obviously, a cloud service is not the best way to do that. What do we do in Check Point? We are giving you security on the devices themselves. So we did it for years now with our SandBlast Mobile. We secure Android and iOS. We are doing it now. We're securing Windows and Mac and Linux. This is a new thing that we are doing now with Linux as well. So we're securing your endpoint devices with SandBlast Agent. But we have something new today. We are doing it also within the browsers. We have SandBlast Web, and this is our ability to secure all the communication that comes in and out from your browsers. Now let's zoom in and understand what's the important feature or capabilities in this new product. So you want to secure the traffic that goes to the internet because we live on the browser. It's a small nano-agent that lives inside your browser. We see all the traffic in clear. So not only that we give you what everyone else is doing with preventing bad URLs, we can protect against zero-days because we see what the actual user is trying to do. We can protect you from zero-phishing. But the cool thing here also is that because it's not a cloud service, you don't need to pay the cost and the overhead of a cloud service, and you don't have the latency. And if you have employees that are traveling the world, you don't have to deal with privacy issues. So definitely, that's a much better way in our opinion to secure web communication. Now, I'm talking about devices. Let's talk about the new generation of the devices, the IoT. Now, IoT becomes the weakest link, and the reason for that is because no one actually patches them. You don't know about them. Someone comes to your organization and connects a smart camera, put it wherever you want, and it's part of your network. And those devices are not protected. And you know what? I'll tell you two stories about it. One story is about a few months ago. I have been in New York, and I met one of our customers. They have security cameras in the buildings, and they told me, you know, we had the controller that control all those security cameras got affected, so we had to replace it. The controller of those cameras came from the manufacturer with known vulnerabilities. So we were built in. The moment we connected it to the network, we started to have machines infected in our networks. And then we've seen it also with the smart meters. Companies that have smart meters, the hackers got into the smart meters and from there into the data center. Or with the UTM machine, they got into the UTM machine and from there into the data center. So we've seen different types of IoT devices that becomes the weakest link. Now we need to secure them, and for that, we have the Check Point IoT Security. Now, what do we do with the Check Point IoT Security? We focus on these three verticals. We focus on smart office and smart building. We focus on medical devices, the MRI machine, the infusion pump, and industrial IoT devices, OT devices. So it starts by you don't have to use Check Point at all. All you need to do is give us the framework. It's an online service. You give us the framework, and we generate for you an assessment, a risk assessment, telling you, you know, this device that you are using has weak password or no passwords and credentials. There are known vulnerabilities, and you know, it also tried to communicate with a domain with a URL that looks suspicious. Then, if you choose to use Check Point to secure your IoT, you can use this service, the risk assessment service, automatically to scan all your devices and give you information about all your devices automatically. And we are doing it by discovering all your devices. By the way, again, in this CPX, you'll see all the IoT vendors, discovery vendors that are partnering with us to give the service for you. Now, once you do that, we are also giving you the ability to micro-segment your environment. And if you are also a company that have a lot of IoT devices from the same type, I talked before about smart meters, or if you are an event of the developer IoT devices, we are giving you the ability to put a nano-agent on your IoT. Whatever framework that you use, put a Check Point nano-agent on your IoT and offer your customers this IoT secured with Check Point inside. So I talked about all the different security capabilities that we have, but I want to explain how everything works together. Right, this is what Gil talked about, the Infinity architecture. We secure everything, and it's with an architecture that works and secures everything together. We talked about the 60 security engines that we are offering. We talked about the fact that we secure 50 types of assets. But how do we do it all together? How do we manage this operation? Today, you have to buy a Check Point management server and to do it yourself, right? You have to upgrade it, to maintain it, to replace the appliances, the security management appliance. What if we will give it to you as a cloud service? You can go and just log into a cloud portal and get everything. For that, two entries today: the Check Point Management as a Service. You go to the Check Point Infinity portal, and you can manage your endpoint, your mobile, you can manage your cloud, Dome9, you can manage your appliances. Everything is with the web GUI. You don't need to worry about the maintenance of the management solution. We'll care and do it for you. Now, on top of that, everything is scalable. Obviously, the management is scalable, but we also wanted to give you scalability on the enforcement point, on the appliances. And we are shipping now today five new appliances that are all powered with Maestro, all tightly connected and work with Maestro. And because security, we take it very seriously, and we believe that we need to protect against fifth-generation of cyber attacks, they are all coming in the first year with the best and the full security from Check Point with our SandBlast package. Now, this is the last innovation that I'm going to talk about today, and I think this is the coolest one in my opinion. We have in Check Point ThreatCloud, right? This is the solution, the intelligent solution that gets to investigate four billion IOCs every day. This is the solution that prevents 25 million unknowns every day. But up until now, we used ThreatCloud only to help our products to give you the security. What if I'm giving you the ability to access ThreatCloud as much as you want and to query ThreatCloud? For that, we're introducing today Check Point Infinity SOC. You can now Google search ThreatCloud. Give us the domain, the URL, the file. We will tell you everything we know about it and how to mitigate it. We will give you a full solution, a full report about what we know there. And in the Infinity SOC, you'll find many more capabilities. For example, you will find that we give you a tool that finds hidden attacks, exposed infected machines inside your network that you don't know about them, and give you a very detailed explanation how to mitigate, how to remediate it. So I want to invite on stage for the last time of the day, I want to invite Eitan.
E
Eitan27:31
So Eitan, what are we going to see here? So we're going to show a quick demo that illustrates really some of the power of Infinity SOC and show how we can provide insights that accelerate and focus security operations. So let's get it rolling. Sure. Okay, hi everyone. So this is a demo from a customer, about 10,000 users, a small 24/7 security operation. They had absolutely no idea they'd been already breached, but within 24 hours of onboarding the customer, Infinity SOC identified 12 infections on the network and helped them find the root cause and prevent future attacks. So here it is in action. Our AI engines have identified, you can see here, the 12 infected hosts, classified them. There were six malware families in there, and for each alert, you can see there's a lot of analytics both from the customer network and from ThreatCloud. And using this data, the customer actually ran an investigation and confirmed to us these were all spot-on detections, no false positives. So after cleaning the infections, they wanted to understand how the system, and for this, they used Infinity SOC to search ThreatCloud and searching for some of the indicators, and you'll see this in a moment in the video. And the customer gets a wealth of information. So here you can see the search of the indicators, and we provide a lot of information both from global spread, the email subjects, related IOCs, very detailed reports, and much, much more. And using this information, the customer was able to very quickly identify the root cause of the attack was an email. And as a result, the customer has now moved not only to use Infinity SOC, they're actually implementing Check Point SandBlast to address some of the gaps in their security. Well, thank you very much, Eitan. Thank you. Thank you, everyone.
I
Itai Greenberg29:52
So to summarize everything, you remember at the beginning I told you my innovation story from Beijing, right? And I promised to explain what happened there. So here it is. So we have the tree on the left side, this is the big tree. We have the small tree on the right side, and I asked you, how do you, what innovations they used in Beijing to make it grow so fast in five months? So this is what they did. They injected fertilizers into the trunk of the tree, into the veins of the tree, and make it grow so fast. I was amazed when I've seen it. And by the way, I've seen the people actually planting those trees, and I talked to the supervisor, and we become kind of friends. And after a while, he asked me, so tell me, Itai, how many Israelis are there? And this is the local Chinese guy. And I told him, we're eight million. And he says, no, not here, in China altogether. And I say, no, no, we're only eight million people. Anyway, so talking about innovation, I showed, I shared with you today 11 new innovations that we are introducing in these CPX events. And these innovations help you to prevent fifth and sixth generation of cyber attacks. And we gave you on the chairs when you came in a brochure listing 18 new innovations that we are introducing here in this CPX event. You are welcome to go and learn more about them in the track sessions. You are welcome to go and visit us in the tech tables to see a real demo of how they work. Thank you very much, and enjoy CPX.