Solution Brief | Cloud Security with Check Point & Wiz
Learn how Check Point and Wiz unite risk visibility with threat prevention, eliminating false positives and accelerating secure cloud remediation.

© 2025 Check Point Software Technologies Ltd. All rights reserved.
From Time to Remediation to Time to Prevention
Today, cloud security separates CNAPP-based high-fidelity risk visibility from network
enforcement controls provided by cloud and virtual firewalls. This forces teams to
investigate and remediate findings, only to discover they are protected by firewall NAT
and access rulesets. In other cases, teams scramble to patch vulnerabilities at the
workload/app levels before attackers find and exploit them, even when firewall rules
and threat prevention engines could resolve these issues, at least temporarily.
Pairing Wiz’s unmatched visibility and prioritization with Check Point’s threat
prevention and cloud-agnostic rules closes the CNAPP-Firewall and risk-detection and
risk-prevention gaps, with a tight loop: Wiz pinpoints if cloud assets are public exposed
and have vulnerabilities with the context of Check Point firewalls and rules; while
Check Point determines how to implement its advanced threat prevention to make
vulnerable exposed assets impervious to exploitation, buying engineers the time they
need to remediate issues responsibly without putting business continuity at risk.
Prevention Context
isk
Check Point & Wiz: Unifying Visibility, Prioritization, and Prevention in Cloud Environments
© 2025 Check Point Software Technologies Ltd. All rights reserved.
CHECK POINT & WIZ SOLUTION BRIEF
THE PROBLEM 1
The Problem Due to legacy domain and expertise separation, cloud risk detection tools, such as Wiz, operate
independently of virtual firewalls like CloudGuard Network Security, lacking the visibility into
Virtual Gateways’ place within the cloud topology and their access rulesets. This fragmentation
also works in the opposite direction: Network firewalls are unaware of findings from CNAPP
solutions and do not respond to posture issues. For instance, firewalls cannot automatically
switch their IPS on if a CVE is present on a given asset.
he result? A fragmented security ecosystem with limited visibility and long investigation and
remediation cycles, and worse still, lengthy and complicated remediation processes that could
otherwise be resolved in systems with threat prevention-based virtual patching, such as IPS
systems blocking CVE exploitation and ML-powered malware detectors that could rectify
improper file MIME type validation in web applications.
• False urgency & missed risk: Posture platforms raise alarms whenever a vulnerability is
found; however, without visibility into firewall access and NAT rules, they cannot validate if a
true network path exists that exposes this vulnerability. The result: many alerts represent
theoretical exposure, leading teams to chase “false urgencies,” while assets that are truly
reachable and exposed slip down the queue.
• Manual correlation tax: Closely related to the point above, to separate real threats from
background noise, engineers must cross-reference Wiz-style findings with firewall
rulebases, gateway placements, and routing tables, and figure out which rules and security
controls will mitigate exposure. This hand-stitching is slow, error-prone, and drains scarce
expert time.
• Siloes and slow mitigation loops: Different teams, such as SOC analysts, network
engineers, IT, DevOps, and developers, see only part of the picture through their own tools
and dashboards. Without a unified view, priorities diverge, workflows are duplicated, and
issues that can be fixed in seconds are delayed to extended periods of time. For instance,
when legitimate exposure of a workload with a CVE is confirmed, patching that CVE can take
engineers days or even weeks, while a firewall’s IPS prevention might be able to virtually
patch that CVE in seconds.
• Compliance friction: Auditors and regulators increasingly expect evidence not just that
vulnerabilities are patched, but that they were never exploitable in the first place, or that a
virtual patch mitigated the risk in the interim. Proving this across multiple disconnected
systems adds significant overhead.
© 2025 Check Point Software Technologies Ltd. All rights reserved.
CHECK POINT & WIZ SOLUTION BRIEF
THE SOLUTION 2
The Solution
1. etect with Wiz
Wiz continuously scans cloud environments, workloads, and identities to identify misconfigs,
vulnerabilities, and toxic combinations. Now, thanks to the strategic partnership between Wiz
and Check Point, Wiz has visibility not only into the presence of CloudGuard Network Security
gateways’ place in the cloud’s network topology, but also gateways’ access and NAT rulesets,
enabling Wiz to discern if a linked set of findings rise to the level of a critical toxic combination,
and if it does, allows engineers to determine, on the spot, whether a simple tweak of
CloudGuard’s NAT and Access rules can resolve the issue. Conversely, if Wiz determines that
CloudGuard provides sufficient security, it will de-risk the alert, allowing engineers to focus on
truly critical issues.
This means that Wiz’s new awareness of and visibility into CloudGuard saves investigation time,
shortens time to remediation, and reduces alert fatigue.
2. ecide with nfinity and/or cloud engineers
Once Wiz flags an issue, Infinity CTEM ingests it in real time. It then analyzes the customer’s
network topology, traffic flows, and CloudGuard policy, and evaluates whether CloudGuard’s
existing prevention capabilities can mitigate the threat. For example, if CloudGuard’s IPS can
block an exploit, Infinity CTEM can recommend switching CloudGuard’s IPS from 'Detect' to
'Prevent' within the confines of CTEM’s user interface. Importantly, Infinity CTEM performs
impact analysis and false-positive checks before recommending or applying any policy changes,
ensuring that security enforcement does not disrupt business continuity.
3. Prevent with loud uard
Acting as the enforcement and threat prevention plane, beyond access control and
segmentation, CloudGuard’s unmatched threat prevention engines can virtually patch almost
any issue discovered by Wiz, allowing DevOps and infrastructure teams to implement
permanent patches at the configuration, workload, or code level. Importantly, prevention is
applied consistently across cloud providers and hybrid networks, leveraging CloudGuard’s
cloud-native integrations and identity and app-aware policy model.
ssue
To ic Combination severity threshold
ssue s details e g , CVE CTEM CloudGuardC C T
Cloud uard conte t
C T
etermine W risk mitigation
© 2025 Check Point Software Technologies Ltd. All rights reserved.
CHECK POINT & WIZ SOLUTION BRIEF
THE SOLUTION STACK 3
The Solution Stack Wiz provides complete, agentless visibility into cloud infrastructure, applications, code, and
identity. It correlates misconfigurations, vulnerabilities, excessive permissions, and data
exposure, and identifies toxic combinations of vulnerabilities that could materialize into attacks,
protecting clouds from code to runtime.
Crucially for this joint solution, Wiz can also detect the presence of CloudGuard Network
Security’s cloud NGFW in front of vulnerable workloads, along with its NAT and access rulesets,
allowing Wiz to de-risk findings and for engineers to reassess risk based on exposure.
heck Point loud uard etwork ecurity enforces adaptive, enterprise-grade security
controls around, in, and between cloud environments and workloads. It combines L3, L4, and L7
protections, IPS, application control, and cloud-native policies based on object types and tags to
block both known and unknown threats in real-time with unmatched effectiveness.
As part of its advanced threat prevention engines, CloudGuard Network Security is particularly
adept at acting as a virtual patching engine for workloads and preventing attackers from
exploiting vulnerable web applications.
heck Point nfinity hreat xposure anagement connects Wiz’s contextual risk intelligence
with CloudGuard’s enforcement capabilities. It automatically validates whether existing security
policies protect critical vulnerabilities, identifies gaps, and orchestrates remediation.
For this joint cloud security solution, Infinity Threat Exposure Management enables security
practitioners and cloud engineers to remediate risks identified by Wiz by changing CloudGuard
NGFW configurations with a click and without risking business continuity, shortening
remediation cycles to seconds.
Worldwide Headquarters
5 Shlomo Kaplan Street, Tel Aviv 6789159, Israel | Tel: +972-3-753-4599
U.S. Headquarters
100 Oracle Parkway, Suite 800, edwood City, CA 94065 | Tel: 1-800-429-4391
www.checkpoint.com
© 2025 Check Point Software Technologies Ltd. All rights reserved.