Solution Brief | Check Point & Upwind for Next-Gen Cloud Security, Q1 2026
Check Point and Upwind connect runtime cloud risk detection with validated exposure analysis and automated threat prevention. Combines Cloud Firewall, Threat Exposure Management, and runtime insights to reduce exposure, accelerate remediation, and strengthen cloud cyber security operations.

© 2025 Check Point Software Technologies Ltd. All rights reserved.
DATASHEE T
Real-Time Intelligence Meets Automated Threat Prevention
Traditional CNAPP workflows often stall at “theoretical risk”. They surface long lists of
vulnerabilities and misconfigurations based on an outside-in view of the cloud posture,
leaving security teams to answer the hard questions manually: “is this asset actually
reachable, which controls sit in the path, and are they enforced or merely monitored?”
The manual correlation of CNAPP alert ⇒ reachability ⇒ firewall policy/NAT path ⇒ IPS
posture, costs precious time while exploitation windows stay open.
The Check Point + Upwind integration closes that gap with a validated, closed-loop
path from discovery to mitigation.
• Upwind finds risk in runtime context (“inside-out”) – identifying vulnerable or risky
workloads based on what’s actually running and communicating.
• Check Point Threat Exposure Management validates exposure and control gaps –
correlating Upwind findings with the relevant enforcement points and the active
protection posture.
• Check Point Cloud Firewall prevents threats, and Threat Exposure Management
orchestrates the required change at the enforcement point to reduce exposure
immediately while teams patch on their own timeline.
This is more than alert forwarding. It turns runtime insight into actionable, validated
remediation at the network enforcement layer – reducing noise, shortening mean time
to mitigation, and ensuring that when a risk is real, prevention is real too.
Check Point & Upwind From Runtime Risk to Validated Exposure and Automated Prevention
© 2025 Check Point Software Technologies Ltd. All rights reserved.
CHECK POINT & UPWIND SOLUTION BRIEF
THE PROBLEM 1
The Problem Cloud security teams are forced to operate across disconnected control planes. CNAPP tools
excel at identifying risk signals (vulnerabilities, misconfigurations, suspicious behavior). Still,
they often stop short of answering the operational question that matters most: “Is this risk truly
exposed, and is there an enforcement control in the path that’s actually blocking it?” Meanwhile,
cloud firewalls are powerful enforcement points, but they typically lack the runtime context
needed to prioritize and tune protections at the speed of cloud-native change.
Without a bridge to connect runtime reality with network policy, organizations face:
• The “Reachability Gap” (noise vs. true exposure): Outside-in scanners flag vulnerabilities at
scale, but they cannot reliably confirm whether an attacker can reach the vulnerable
component through real routing, access policy, and NAT. Upwind improves fidelity by
detecting risk in runtime context (“inside-out”). However, without a mediation layer, teams
still need to determine whether the Check Point Cloud Firewall is actually in the
enforcement path and whether protections are set to block rather than detect.
• Manual correlation tax: Security engineers are forced to “hand-stitch” the story across
tools: Upwind findings, cloud topology, firewall policies, NAT, routing, and IPS posture. That
workflow is slow, brittle, and dependent on scarce experts, exactly the opposite of what’s
needed when cloud workloads are ephemeral, and attacks move fast.
• Slow mitigation loops during patch windows: Even when a risk is well understood,
production patching takes time: release cycles, validation, rollback planning, and change
windows. During this period, the organization needs immediate compensating controls. Too
often, the firewall remains in a monitoring stance (e.g., IPS set to Detect) or isn’t tuned to
the relevant exposure, leaving a preventable window open.
• Runtime drift and “shadow exposure” between scans: Cloud environments change
continuously: new containers, redeployments, configuration drift, hotfixes, and unexpected
service exposures. Periodic scanning misses what happens between snapshots. Without
runtime awareness (process execution, L7/API activity, real traffic patterns), teams can’t
keep enforcement aligned with reality, so exposures reappear silently and remain
unmitigated until the next scan or incident.
© 2025 Check Point Software Technologies Ltd. All rights reserved.
CHECK POINT & UPWIND SOLUTION BRIEF
THE SOLUTION 2
The Solution
1. Detect with Upwind: Runtime-first “inside-out” intelligence
Upwind provides runtime visibility from inside cloud workloads using eBPF-powered sensors
(with complementary coverage options when sensors aren’t feasible). Instead of treating every
discovered vulnerability as equally urgent, Upwind focuses on runtime evidence, what’s actually
running, communicating, and behaving abnormally, so security teams can prioritize the risks
that matter now, not the risks that merely exist on paper.
Key Benefits:
• High-fidelity runtime findings (workload behavior + real traffic context)
• Noise reduction through runtime context (prioritization of actionable risks)
• Coverage that aligns with modern runtime realities (containers, ephemeral workloads, and
AI-era applications)
2. Decide with Check Point Threat Exposure Management: Validation and orchestration
While Upwind provides the runtime signal, Check Point Threat Exposure Management provides
the missing decision layer: whether the risk is actually exposed and whether the appropriate
enforcement control is in place and enabled.
Threat Exposure Management ingests Upwind findings and correlates them with its visibility
into the organization’s enforcement posture, especially the policies and protections enforced by
the Check Point Cloud Firewall.
© 2025 Check Point Software Technologies Ltd. All rights reserved.
CHECK POINT & UPWIND SOLUTION BRIEF
THE SOLUTION 3
• Exposure validation: correlate the Upwind finding to the relevant cloud enforcement points
and determine whether a real network exposure path exists (e.g., via routing and published
access paths) and whether the applicable protections are active.
• Control-gap detection: identify when enforcement exists but is not in a blocking posture (for
example, a relevant IPS protection set to Detect instead of Prevent).
• Safe remediation logic: ensure the proposed action is targeted and aligned with policy
intent, reducing risk without creating unnecessary disruption.
3. Prevent with Check Point Cloud Firewall: Enforce protection immediately
When Threat Exposure Management validates that a runtime risk is truly exposed and identifies
an actionable control gap, it triggers network-layer prevention via the Check Point Cloud
Firewall, which offers unmatched, industry-leading threat-prevention capabilities.
This is where the integration turns insight into immediate risk reduction:
• Virtual patching/compensating controls: the Cloud Firewall can shift from observation to
blocking (e.g., IPS from Detect to Prevent or enabling the relevant protections) to reduce
exposure immediately.
• Buy time for proper patching: developers can remediate the root cause on schedule, while
the enforcement layer reduces the likelihood of successful exploitation in the meantime.
© 2025 Check Point Software Technologies Ltd. All rights reserved.
CHECK POINT & UPWIND SOLUTION BRIEF
THE SOLUTION STACK 4
The Solution Stack Upwind: Inside-out CNAPP built for runtime reality
Upwind provides an inside-out, runtime-first
CNAPP designed for cloud-native speed and
change. Using eBPF-powered runtime sensors,
Upwind builds a real-time understanding of what’s
actually happening in cloud workloads, process
execution, system activity, and live traffic behavior,
so security teams can prioritize what matters
based on runtime evidence rather than theoretical
exposure. This turns “vulnerability inventory” into actionable runtime risk, helping teams focus
on the small subset of issues that are truly active, reachable, or trending toward exploitation.
Check Point Cloud Firewall: The enforcement & threat prevention plane
Check Point Cloud Firewall delivers enterprise-
grade network security and threat prevention for
public and private cloud environments and serves
as the primary enforcement plane in this joint
solution. It’s where validated risk becomes
immediate protection: inspecting and controlling
traffic flows and applying preventive measures
when needed. Once Threat Exposure Management
determines that a risk is real and exposed, the Cloud Firewall is the control point that can shift
from monitoring to blocking and reduce exploitability while teams patch.
Check Point Threat Exposure Management: The orchestration bridge
Check Point Threat Exposure Management is the
connective tissue of the integration, making the
workflow closed-loop rather than “alert
forwarding.” It takes Upwind’s runtime findings and
correlates them with the enforcement posture,
which controls are in place, how they are
configured, and whether they are actually
preventing exploitation.
© 2025 Check Point Software Technologies Ltd. All rights reserved.
CHECK POINT & UPWIND SOLUTION BRIEF
CONCLUSION 5
Conclusion This latest strategic cooperation and integration between Upwind and Check Point introduces a
new paradigm in cloud security, seamlessly merging cloud workload risk with network-level
threat prevention in the context of any and all security controls across the entire estate – from
on-prem to cloud.
With Check Point and Upwind, you can eliminate 95% of redundant alerts, allowing you to focus
on risks that are grounded in workload reality. Once an issue is found, vulnerable workloads are
protected with 100% effectiveness, while mapping other runtime findings to the relevant
enforcement points, with remediation and virtual patching just one click away.
Contact us today to get:
Less alerts Exploit Block Rate 3 ° Visibility -Click Safe Remediation
Worldwide Headquarters
5 Shlomo Kaplan Street, Tel Aviv 6789159, Israel | Tel: +972-3-753-4599
U.S. Headquarters
100 Oracle Parkway, Suite 800, Redwood City, CA 94065 | Tel: 1-800-429-4391
www.checkpoint.com
© 2025 Check Point Software Technologies Ltd. All rights reserved.