Guide | Next Steps in Cloud Security with Check Point and AWS
This guide explores how Check Point's solutions, in partnership with AWS, simplify cloud security in multi-cloud environments. By integrating security, compliance, and performance monitoring, businesses can manage complex cloud architectures effectively. Learn how Check Point helps ensure secure, scalable, and compliant cloud-native applications.

Custom content for Check Point by studioID
Taking the Next Steps in Cloud Security with Check Point CloudGuard and AWS
T HE C O MP L E XI T Y C ONUNDRUM:
The flow of data has never been more pervasive. Data now moves from the server farm to the cloud, and from the cloud to the edge. Employees have become “data centers,” as today’s increasingly remote and mobile workforce uses more cloud-native applications faster than ever before.
This should be great news for enterprises and employees alike – and overall, it is, increasing productivity and flexibility for countless organizations across industry sectors. Amazon Web Services (AWS), the industry leader in the cloud and cloud security, has seen this seminal shift firsthand. With it, however, many AWS customers have seen an increase in security complexity “times 100.”
The rapid increase in remote and hybrid workforces has expanded most companies’ attack surfaces. Malicious actors have gotten better, too, exploiting serverless architectures and targeting vulnerabilities within Kubernetes clusters to gain access to sensitive data or launch distributed denial-of-service (DDoS) attacks.
70% OF ALL WORKLOADS ARE MOVING TO THE CLOUD By 2023, 75% of security failures will result from inadequate management of identities , access and privileges, up from 50% in 2020.
2
According to the 2023 Thales Data Threat Report, a survey of 3,000 IT and security professionals across 18 countries, 47% said security threats are increasing in volume or severity, with 48% reporting an increase in ransomware attacks. More than a third (37%) have experienced a data breach in the past 12 months.
By far, those surveyed said their cloud assets were their biggest security concerns. Over a quarter (28%) said SaaS apps and cloud- based storage were the most at risk, followed by cloud-hosted applications (26%) and cloud infrastructure management (25%).
This should come as no surprise. The increases in cloud exploitation and security issues are directly due to the increase in workloads moving to the cloud – 75% of respondents in the Thales study said four-tenths of all data stored in the cloud is now classified as sensitive, compared to 49% of respondents in 2022.
Fortunately, there is a proven solution. Recognizing that customers and users must be confident in their systems, Check Point - an AWS Software Partner with Security Software and Networking Competencies—has addressed these complex cloud security issues by enhancing the security that AWS services deliver.
“COMPLEXITY IS THE WORST ENEMY OF SECURITY. AND OUR SYSTEMS ARE GETTING MORE COMPLEX ALL THE TIME.” BRUCE SCHNEIER Cryptographer and Computer Security Expert
3
We need cloud-native applications more than ever. But keeping network access and sensitive data flowing to the right hands – and out of the wrong ones – is an increasingly complex endeavor.
Too many disparate security solutions and integration challenges leave gaps in security protection and can create potential issues such as a lack of network visibility. This also can lead to a host of new challenges, including possible misconfigurations, a lack of up-to-date security knowledge and skills among workers, limited budgets and wasted cloud resources. There’s also a risk to a company’s reputation and bottom line, including recovery costs or impacting others along the supply chain.
THE “COMPLEXITY CONUNDRUM” IS A CRITICAL MOMENT FOR ENTERPRISES
Additional challenges include:
The nature of software development Companies use both AWS and third-party tools and APIs, yet app developers aren’t security experts. This makes automation crucial for ensuring that users have limited access.
Compliance Keeping up with changing compliance regulations and knowing which ones to use and how to apply them.
Alert fatigue Workers can become overwhelmed by numerous and often non-essential alerts or even false alarms, leading to potentially serious alerts being ignored. “Many organizations don’t even see all the problems that they have, yet the number of problems that they do see is just huge,” said Eyal Fingold, VP of Product Development for Check Point CloudGuard. “That’s a tough challenge for them and it’s also tough for them to understand who needs to fix the problems.”
The Complexity Conundrum is real and is being felt across multiple industries. But fortunately, there is a way out.
4
Managing the sheer numbers of data today is only sustainable with a new approach. Complex multi-cloud environments lead to a lack of visibility, control, customization and consistency.
We need to change the narrative from complex expansion to contextual consolidation – an end-to-end “code to cloud” platform that ensures everything is integrated and working together.
Cloud Native Application Protection Platforms (CNAPPs) represent the way forward. They are designed to address the unique challenges of securing cloud-native applications, providing comprehensive protection throughout the entire lifecycle.
A CNAPP incorporates multiple functions into one platform, including:
• Network segmentation
• Automation and ability to scale
• Visualization and vulnerability management
• Artifact scanning, cloud configuration, runtime protection
• Detection, reporting and remediation, ensuring you have the proper context to focus on the right areas
• Application and compliance monitoring
• Web application and API protection
• User access control and authentication and cloud infrastructure entitlement management
CNAPPs also align with the evolution of DevSecOps practices. By promoting collaboration and integrating security into the development process, CNAPPs foster a “culture of security” every step of the way.
CNAPP: A “SWISS ARMY KNIFE” FOR CLOUD SECURITY
5
As described by Gartner, CNAPPs generally follow a three-stage process:
GETTING FROM CODE TO THE CLOUD
01 02 03 Code/Build The earliest and, therefore, most critical phase of the application development cycle. Key aspects include:
• Promoting secure coding practices by giving developers access to best practices and secure coding libraries, reducing the risk of vulnerabilities right from the start
• Vulnerability and container image scanning to analyze the application code and any dependencies
Deploy Ensuring the security and integrity of the deployment process includes image and configuration validation; enforcing authentication policies so only authorized people can deploy or later modify applications; and compliance policy enforcement
Run This final stage focuses on continuous monitoring and protecting applications during execution. This often includes:
• Behavioral analysis and machine learning to detect and prevent threats in real time
• Runtime protection features such as intrusion prevention systems and web application firewalls
• Incident response and remediation such as alerts, reports and other security guidance mechanisms
6
There are thousands of security solutions to choose from, covering many different aspects of security. With CloudGuard, you not only get coverage in the main areas of Cloud Security Posture Management, Converged Network Systems, and Cloud Workload Prevention Platform (CWPP), but you also get unified management—and you can get it all on AWS Marketplace.
CloudGuard CNAPP is a “code to cloud” solution that can secure all of your cloud-native applications with a fully integrated solution, including:
• Network and cloud security, including intelligence and threat hunting, application security, and pipeline security that’s fully automated
• Cloud Security Posture Management (CSPM), with granular and intuitive visibility into all cloud assets, networks and security groups
• Web Application and API Protection (WAAP)
• Cloud Infrastructure Entitlement Management (CIEM) to visualize, detect, prioritize and remediate IAM risks
• CWPP for unified visibility, compliance, and threat protection
• Agentless Workload Posture (AWP) for deep workload visibility with no agents
• Effective Risk Management that focuses on the 1% of risks that matter to your business (and fixes them faster)
CLOUDGUARD: PROTECTING THE CLOUD IN CONTEXT
7
“Part of our DNA is also prevention,” he added. “It’s not just turning on the light and showing you where you have problems, but also take actions that help you do risk reduction and prevention, including reducing attack surfaces that you might have due to over-permissive roles.”
“THERE’S NO MAGIC IN CLOUD SECURITY. IT REQUIRES ONGOING WORK AND EFFORT, SO OUR FOCUS IS TO HELP OUR CUSTOMERS OPERATIONALIZE THEIR SECURITY. THE ENTIRE CYCLE OF REMEDIATING IS VERY IMPORTANT FOR US.” EYAL FINGOLD VP of Product Development for Check Point CloudGuard
8
As an AWS Software Partner with Networking and Security Software Competencies, Check Point can help remove security obstacles to create a safe and easy path for migration to the cloud.
The Check Point CloudGuard for AWS Security blueprint delivers advanced, multi-layered network security for the AWS Cloud environment and protects cloud assets. It also provides best practices for designing a secure cloud-based migration and deployment allowing for agility, scalability and efficiency. This blueprint promotes process automation using APIs and supports “Infrastructure as Code” practices.
CloudGuard CNAPP provides intelligent risk prioritization, agentless scanning, entitlement management, compliance and guidance and pipeline security capabilities – delivering more context, actionable security and more intelligent prevention.
CLOUDGUARD AND AWS
9
As an AWS Software Partner, Check Point seamlessly supports AWS security services. This results in more efficient and effective solutions, built to enhance native security.
Check Point has over 50 integrations with AWS security services to help your organization do more on AWS. For example, CloudGuard CNAPP enhances AWS security through integrations with AWS Security Hub, Amazon Macie, Amazon GuardDuty, AWS VPC flow logs, AWS CloudTrail, AWS Gateway Load Balancer, AWS Lambda, and many more security services.
CLOUDGUARD AND AWS INTEROPERABILITY
Some of CloudGuard’s features and associated AWS integrations include:
Data security posture management (DSPM) CloudGuard’s new DSPM feature protects sensitive data by identifying which workloads contain the sensitive data, assessing their security posture and updating cloud environment risks accordingly to help administrators stay focused on the highest priority issues.
The integration with Amazon Macie allows security teams to quickly pinpoint any Amazon Simple Storage Service (Amazon S3) buckets that contain sensitive data and will highlight them clearly in the CloudGuard dashboard. This visibility helps to accurately gauge any assets containing sensitive data in real time, so that teams can immediately take necessary action through the Risk Management dashboard.
Intelligence, visualization, and threat hunting As part of CloudGuard CNAPP, CloudGuard Intelligence delivers threat hunting and visualization capabilities native to AWS. CloudGuard Intelligence interoperates with AWS CloudTrail, enriches its logs with context, transforming them into readable security logic, and enables security teams to take cloud security to the next level. With CloudGuard Intelligence, businesses can see every data flow and audit trail in today’s elastic AWS environments, and make sense of cloud data and activities to expedite investigation processes.
10
Features include:
• Security for all IaaS and PaaS cloud assets: gain full visibility and security posture awareness for ephemeral assets such as AWS Lambda, NAT Gateways, AWS Gateway Load Balancer, and more.
• Bullseye threat prevention: detect cloud anomalies to remediate at once and quarantine threats utilizing Check Point’s ThreatCloud AI, a large threat intelligence feed.
• Context-rich visualization: Make sense of cloud big data with informative visualization, intuitive querying, intrusion alerts, and notifications on policy violations.
In addition, CloudGuard integrates with AWS Security Hub, an AWS service on which security teams can centrally see and manage security alerts from AWS resources and automate compliance checks. The integration of AWS Security Hub with CloudGuard CNAPP allows findings to be sent to the hub, where they can be seen and managed.
Intrusion detection and response (IDR) IDR capabilities within CNAPPs provide cloud-native threat security forensics through machine learning visualization, giving real-time context of security issues and anomalies across your multi-cloud environment. With CloudGuard, this includes:
• Catching unattended security issues immediately with real-time intrusion detection and policy violation alerts based on user-defined criteria.
• Comprehensive investigation of security Issues with cloud network security analytics, streaming the world’s largest security intelligence database, ThreatCloud AI.
• Preventing unauthorized access attempts continuously with CloudBots and advanced encryption.
11
CloudGuard Workload Protection Approaches like Workload Protection are essential for managing evolving cloud and hybrid cloud environments – Workload Protection is flexible and “lightweight,” eliminating the need to install and manage security agents on individual workloads. This reduces complexity and allows for greater resource optimization. And unlike more traditional, agent-based security solutions, Workload Protection reduces attack surfaces by eliminating the need for agents that could be exploited or misconfigured.
By utilizing integrations with AWS Lambda and AWS Fargate, CloudGuard Workload Protection provides unified visibility, compliance and threat prevention from development through runtime, across applications, APIs, virtual machines and microservices.
Some common use cases include:
• Image assurance: secure container image scanning of open-source packaging, 3rd party dependencies and source code
• Admission control: easily set security policies and guardrails for cluster operations. Enforce least privileged access rights and govern cluster operations with admissions controller
• Web and API protection: protect web applications and APIs, with fully automated, low administration WAF
• Runtime protection: real-time threat detection and prevention to protect known and unknown attacks with baselining and behavioral signatures
• Container self-protection: secure the entire container lifecycle with continuous image scanning through CI/CD and runtime
• Serverless protection: reach zero-trust least-privilege-access through machine learning
• Web apps & API security: fully automated security powered by contextual AI
12
Securing the pipeline Engineers make hundreds of micro-decisions faster than anyone can regulate or authorize, potentially introducing mistakes, risks and misconfigurations. And existing tools are not designed for developers – they lack accuracy, are fragmented, and take too long to deploy.
“Shift-Left Security” for pipeline protection – or securing applications earlier in the development process – empowers developers to fix vulnerabilities, misconfigurations and exposed secrets proactively before code deployment. It allows you to identify and remediate supply chain risks across your pipeline tools, including Git, Jenkins, and more, as well as extend workload protection throughout the CI/CD pipeline to remediate issues before production.
CloudGuard Spectral – Developer-First Security CloudGuard Spectral is a developer-centric code security platform that seamlessly monitors, classifies, and protects codes, assets, and infrastructure. With CloudGuard Spectral, organizations can prevent the potential exposure of API keys, tokens, and credentials, as well as remediate security misconfigurations. CloudGuard Spectral interoperates with AWS CodeBuild, making the security processes more efficient.
Relevant features and use cases include:
• Code scanning: automatically scan code from pre-commit to production, and secure code repositories
• Secrets detection: mitigate secret leads caused by bad credentials, misconfiguration or oversight
• IAC Security: scan code, configuration, binaries, or other material in your infrastructure
• Software Composition Analysis (SCA): an automated process that identifies open-source software in a codebase. This analysis is performed to evaluate security, license compliance and code quality
13
Agentless Workload Posture (AWP) CloudGuard CNAPP’s agentless workload posture (AWP) functionality provides security teams with visibility into the security posture of their AWS-based workloads. The AWP capability automates scanning for common cloud security risks, such as vulnerabilities (CVEs) and hardcoded secrets, providing in-depth security visibility. Information can be obtained natively within CloudGuard CANPP or through integration with Amazon Inspector.
Cloud Detection and Response A constant barrage of unprioritized alerts can get overwhelming for SecOps fast. What’s most needed isn’t just early real-time intrusion detection and enhanced response capabilities, but also real-time intelligence related to the context of threats and anomalies across your multi-cloud environment.
CloudGuard offers comprehensive “threat hunting” with cloud network security analytics, streaming the world’s largest security intelligence database, ThreatCloud AI. Our CloudGuard Intelligence solution enriches cloud logs with context, transforming them into readable security logic and enabling security teams to take cloud security to the next level. Businesses can see every data flow and audit trail, helping to make sense of cloud data and activities to expedite investigation processes. Information and alerts from several AWS services, including AWS CloudTrail, AWS CloudWatch, AWS Control Tower, and AWS Security Hub, can both ingest and be ingested by CloudGuard.
14
“WE CANNOT SOLVE OUR PROBLEMS WITH THE SAME LEVEL OF THINKING THAT CREATED THEM.” ALBERT EINSTEIN
The Complexity Conundrum won’t be solved overnight. Success requires not only using the right tools, but having the right mindset and patience. “Even if you take a million problems and say, ‘okay, I’m just going to solve the critical ones,’ you still have a lot of critical problems,” Fingold said.
“That’s the key challenge – to focus on where to reduce the attack surfaces that will have the greatest impact.”
Not all solutions are equal. But no matter where you are in the process, if you choose a vendor that can accommodate every area, make sure that they can scale into the solutions you need. See whether it’s a true CNAPP solution or just a bunch of disparate products strung together to look like a cohesive whole.
“At the end of the day, it’s about the operationalization of cloud security that the organization is doing internally,” Fingold said. “How are they making it part of their methodology, their ticketing systems and automation? On top of all this, it’s about having that ‘Shift Left’ mentality, where you are doing tests not only during production or QA, but on all of the code itself. The faster and better you can do it, the more secure your organization will be in the long run.”
15
Check Point Software Technologies Ltd. (www.checkpoint.com) is a leading provider of cyber security solutions to corporate enterprises and governments globally. Check Point Infinity’s portfolio of solutions protects enterprises and public organizations from 5th generation cyber-attacks with an industry leading catch rate of malware, ransomware, and other threats. Infinity comprises four core pillars delivering uncompromised security and Generation V threat prevention across enterprise environments: Check Point Harmony, for remote users; Check Point CloudGuard, to automatically secure clouds; and Check Point Quantum, to protect network perimeters and datacenters, all controlled by the industry’s most comprehensive, intuitive unified security management; Check Point Horizon, a prevention-first security operations suite. Check Point protects over 100,000 organizations of all sizes.
LEARN MORE