Itai Greenberg0:00
Hi everyone, my name is Itai Greenberg and I'm the VP of Product Management for Check Point. In this session, I will share with you how Check Point customers use our innovations to secure their own data center. So let's start.
Now, we talked all day about how customers are moving into the clouds, very obvious, but this also comes with changes and requirements for how we actually need to secure the data center. As we move to the cloud, applications span over the data center and the cloud. So it's not only that if you still have data center applications, you'll have a lot of communication between cloud and your data center.
Second thing is that we all want to kind of mimic, have the same kind of experience in the cloud also in your data center. And the third, now especially with the COVID, we all want to access applications where they are, in the data center or in the cloud, it needs to feel the same.
And so securing the kind of hybrid data center with the cloud is a complex task for those reasons. One is since applications are all over, it's hard to control it, to make sure that you manage it all from one place. Second is the agility. Me as the developer, I don't want to wait kind of few days for the security guys to close the ticket. I don't want to deal with tickets, I want things to happen immediately.
The other problem is that I want to have a very simple, intuitive experience when I'm accessing my application, when I'm developing the application, and I don't want security to interfere with me in this process. And the last piece is I want security to be scalable, to be automatic. I don't want to deal with adding more gateways, removing gateways, shutting down or taking down my data center just for maintenance reasons. Those things cannot happen anymore.
We believe in Check Point that customers deserve to have a modern type of security for their hybrid data center, and that's exactly what Quantum is about. Quantum is the Check Point solution to secure the hybrid data center. So what do you get from Quantum? Three main key values. One, prevention first. We believe in prevention, we don't believe in generating yet another tickets for the customers to deal with. So we have a lot of AI and machine learning to help with this.
We're giving a lot of automations, APIs, but in this session I will talk about scalability, automation, and the last piece is consolidation. How do we reduce the overhead, the operational cost with better management products for security.
Let's start with AI and machine learning. Now, as we've seen during the day, and Maya did a great job to talk about different types of attacks that we see in the data center, how do you actually deal with them? I will mention some of the attacks that maybe Maya didn't cover. So everyone knows about Sunburst and the supply chain type of attack. I'm not going to talk much about this, but here are two other examples.
For example, DarkSide, which is an attack that started with hackers actually using ransomware techniques to target the critical control system. And it started with one and paved its way to another one and another one, and a huge impact on these customers. And yet another attack that was Conti, and again, that's an attack that stole 700 gigabytes of patient data from the data center.
So we see this type of sophisticated attacks happening on the data center, and our approach, Check Point's approach, is prevention. So for many years we are developing this zero-day prevention solution. I will talk about it, but we have two other products and solutions which we just launched to the market about 12 months ago, some of them are even newer.
And this is the workload and container security, which is very much relevant to the cloud, but also for containers that you have in your data center. And the other new solution that we have is the next-generation WAF. How do we secure applications with web and APIs? So let's start with the zero-day.
On the zero-day, we have over 60 types of security engines, most of them are running machine learning, artificial intelligence. And the idea here is that we are preventing the unknown. This is the most important thing. Over the last few years, NSS tested Check Point and other competitors, and they found that Check Point, when it comes to security, we do the best job. We really prevent the attack, and we're doing it with zero false positives.
And we're doing it not only by having those kind of engines running in the appliances themselves, in the gateways, but also a lot of capabilities that run in our ThreatCloud, the most powerful threat intelligence. Which all the Check Point products, all the gateways, all the endpoints, the mobiles, the cloud, everything is connected to ThreatCloud. So we have a network of 150,000 security elements that communicate with this ThreatCloud and consult about URLs, about files. We're doing it more than, close to 100 billion times a day.
So we talked about how we actually prevent the zero-day. Now the other two products that I mentioned before, the first one is the Kubernetes. You use Kubernetes in your AWS, in Azure, when you Google, great. But you also use Kubernetes in your own private data center. Why not secure it all across with a single unified solution? Having the ability to, for example, have a posture management for your Kubernetes environment, having the ability to scan open-source vulnerabilities inside Kubernetes, and to deploy a security, a nano-engine security inside your Kubernetes to prevent attacks happening in runtime.
And the last piece is that with this solution, you can actually get security not only for the Kubernetes itself but for the infrastructure of the Kubernetes, which is a complementary solution for your container security.
When it comes to web and API, well, now we are developing everything on top of RESTful APIs, and that's the new type of application. Even if it's hosted in your data center, you want to secure those applications with a next-generation WAF. Don't think about the old WAF where you had to deal with a lot of tuning and configuration, that's the old way. Now you get from Check Point a solution that you can put in your data center as a reverse proxy on NGINX or the virtual machine that runs on Linux, for example. Or you can put it again also in AWS or Azure.
But the idea here again, unified solutions to prevent OWASP attacks, to protect your APIs, to prevent bots, if your application is infected, from communicating with the command and control, and to have threat prevention inside this solution. So everything here doesn't require any configuration, it's all based on machine learning. You put it in your environment, after 12 hours, 24 hours, we learn the patterns of the behavior of the application, and we are ready to secure it.
So we talked about how we actually prevent the attack, but what if you have still an infected application inside your environment? Maybe a supply chain attack, for example. You need to contain, you need to isolate this attack. What do you do? Well, in Check Point, we are giving you a very good solution for micro-segmentation, for zero trust.
The first solution would be the Policy Layers. With Check Point Policy Layers, which by the way, it's quite unique, you won't find a concept like this in other vendors. You don't need to deal with kind of a policy that has hundreds and thousands of rules that are all kind of complex to manage. You can have a dedicated sub-policy or policy layers, as we call it, associated with your segmented environment in a very business logic way. It gives you much tighter security and it gives you the agility to manage a policy per segmented environment.
The second solution that I want to talk about regarding zero trust and segmentation would be the level of integrations that we have with SDN vendors, in NSX, VMware, in Cisco ACI, or even with OpenStack. What we do with them is not only that we automate the supply chain, the service chaining, how the traffic is actually flowing from those virtual machines into our environment or from their containers into our gateway solution, but also the way we manage the policy.
The policy based on SDN is very dynamic. We learn about those changes that take place in NSX, in ACI, and we don't require the administrator to actually manage those changes via tickets. We dynamically learn about them and automatically update the gateways about any change that happens in this environment.
So we talked about how we actually secure your data center. Let's talk about how we reduce the operational cost, how we make your life as an administrator much more efficient, how do you enable innovation in your environment. So the thing is that you're dealing today with too many requests. You have thousands of requests a year which generates rule changes, policy changes, creating new rules. How can you actually deal with those so many changes?
And also when we see the traffic between your cloud and your data center, we see that the amount of traffic between your cloud and the data center is growing dramatically, right? And so what we're offering here is first of all the solutions to deal with the amount of traffic. As the application that you're taking from your data center moving to the cloud, you would see a lot of traffic between your data center and the cloud. Maestro is the solution for you.
Why Maestro is so good? One, because it gives you a way to scale in minutes. And with a traditional solution, you have kind of a cluster solution, an active-passive. The passive gateway does nothing. You buy a solution and still it sits idle waiting for a failover. With Maestro, it's all active-active. So you can get to a solution where you start with three gateways, the year after you need more performance, more security performance, don't throw away those gateways like with the old way, with the cluster way, just add another one and another one, up to 52 gateways that can work together to service your needs.
Obviously not everyone needs to get to the 52, maybe four, five, six, seven gateways enough for you over the years. But the agility here, the scalability here is a huge benefit, and you do it all without any downtime to your data center. When you need to add more capacity, just plug in another gateway. And this is the most cost-effective solution in the market when you think about a gateway solution. Let me explain why.
In this example, I will compare Check Point Quantum, so this is a 6U configuration security solution, to our competitors, which again, it's a 6U solution but it's active-active with two gateways. You can see that the same configuration with Check Point Maestro, you get four times more performance, 120 gig of performance versus 30. But with Maestro, if you need, you can go all the way up to 1500 gigabit of traffic, and you can go and play with whatever type of gateway that you want to put in the Maestro. It's the regular Check Point gateways but stacking together.
Now, Maestro is a huge success for Check Point. We have over 450 customers that already made the decisions to go on Maestro to secure their data center with the Maestro hyperscale technology.
Now, as you move to the cloud, you would like to have security for the cloud, right? So CloudGuard is the Check Point solution for cloud. I'm not going to talk much about CloudGuard today, we have a different event for this. But CloudGuard will give you a lot of technologies to secure your cloud. The beauty of having CloudGuard to secure the cloud and Quantum to secure the data center is the ability to manage both your hybrid cloud environment from one location, from a central policy.
And we have today over 4,000 customers that already use Check Point to secure their clouds, the AWS and Azures, and most of those customers use Check Point, by the way, also to secure their on-prem data center. Okay, so it's customers that use it on both sides.
Now let's talk a little bit about consolidation and the efficiency here. I talked before, and here I'm repeating myself, about the number of tickets, the number of changes that you need to deal with. Then the question for you guys, how do you reduce the overhead of those tickets? So here I'm going to show you different types of technology that all exist in our gateway solution, in our management solution, to reduce your operational cost.
The first one is the ability to manage a policy in a very dynamic way. We bring all the information, all the intelligence from the user identity, whether it's Okta, Ping, Azure AD, we bring it and we identify the application itself, whether here it's an example, whether it's Atlassian or Jira or ServiceNow. We also bring all the information from the cloud, so we bring the objects into our policy from NSX, from ACI, from Azure, from AWS, from Google, from Alicloud. And eventually end up with a policy that is very, very dynamic. Changes that take place in those environments will automatically get updated on the gateway since we get notification from those environments about those changes constantly.
Another very important solution for the data center is the ability to empower multiple administrators to make changes at the same time. You'll have automation, and automation doesn't care about policies that get locked. The automation needs to work all the time, so automation can be considered as yet another administrator, and you have multiple automations, right? The idea here is that we never lock the entire policy with our solution. We only lock one rule that the administrator is working on, and we are managing it in a session. So you can immediately revert the changes that you need for a specific session, allowing other administrators to make changes at the same time, simultaneously.
And we are giving you the ability to see which administrator made what changes at what time. So a very intuitive way to manage policy by multiple administrators.
The last piece here is the fact that you can now manage your policy, and we have many examples of how we reduce operations. I'm just choosing three of them here. But here is, let's assume that you need to troubleshoot a rule in your policy. You don't want to go and work with another tool to see the logs and the traffic, and another screen to see the rules that serve the policy. Here, within the same screen, you can look at the rules and you can see the traffic associated with this rule.
Now, you would put our solution in your data center and you need to integrate with a lot of systems inside your environment, with a SIEM solution, whether it's Splunk or QRadar, whether it's Orchestrator, whether it's SDN solution. We have a lot of plugins that we developed over the years, and more and more plugins that we are developing with IoT, as I mentioned here, all the SDN partners, to streamline, to automate the policy, the deployments, the integration into your overall ecosystem environment in your own data center.
So guys, to summarize, if you see, we have over 60 percent of the Global 2000 customers choose Check Point or trust Check Point to secure the data center. Many of them, by the way, also use Check Point to secure their cloud. They trust because we give them the prevention, we give them the ability to isolate the attack with zero trust, with segmentation, we give them the automation they need via APIs, we have dynamic policy, we give them the ability to scale the performance as they need to connect the remote users into the cloud, and to do it all with a unified policy. So guys, thank you very much for being with me today, and enjoy the rest of the show. Thank you very much.