Solution Brief | Cloud Security with Check Point & Wiz

Solution Brief | Cloud Security with Check Point & Wiz

Learn how Check Point and Wiz unite risk visibility with threat prevention, eliminating false positives and accelerating secure cloud remediation.

Solution Brief | Cloud Security with Check Point & Wiz

© 2025 Check Point Software Technologies Ltd. All rights reserved.

From Time to Remediation to Time to Prevention

Today, cloud security separates CNAPP-based high-fidelity risk visibility from network

enforcement controls provided by cloud and virtual firewalls. This forces teams to

investigate and remediate findings, only to discover they are protected by firewall NAT

and access rulesets. In other cases, teams scramble to patch vulnerabilities at the

workload/app levels before attackers find and exploit them, even when firewall rules

and threat prevention engines could resolve these issues, at least temporarily.

Pairing Wiz’s unmatched visibility and prioritization with Check Point’s threat

prevention and cloud-agnostic rules closes the CNAPP-Firewall and risk-detection and

risk-prevention gaps, with a tight loop: Wiz pinpoints if cloud assets are public exposed

and have vulnerabilities with the context of Check Point firewalls and rules; while

Check Point determines how to implement its advanced threat prevention to make

vulnerable exposed assets impervious to exploitation, buying engineers the time they

need to remediate issues responsibly without putting business continuity at risk.

Prevention Context

isk

Check Point & Wiz: Unifying Visibility, Prioritization, and Prevention in Cloud Environments

© 2025 Check Point Software Technologies Ltd. All rights reserved.

CHECK POINT & WIZ SOLUTION BRIEF

THE PROBLEM 1

The Problem Due to legacy domain and expertise separation, cloud risk detection tools, such as Wiz, operate

independently of virtual firewalls like CloudGuard Network Security, lacking the visibility into

Virtual Gateways’ place within the cloud topology and their access rulesets. This fragmentation

also works in the opposite direction: Network firewalls are unaware of findings from CNAPP

solutions and do not respond to posture issues. For instance, firewalls cannot automatically

switch their IPS on if a CVE is present on a given asset.

he result? A fragmented security ecosystem with limited visibility and long investigation and

remediation cycles, and worse still, lengthy and complicated remediation processes that could

otherwise be resolved in systems with threat prevention-based virtual patching, such as IPS

systems blocking CVE exploitation and ML-powered malware detectors that could rectify

improper file MIME type validation in web applications.

• False urgency & missed risk: Posture platforms raise alarms whenever a vulnerability is

found; however, without visibility into firewall access and NAT rules, they cannot validate if a

true network path exists that exposes this vulnerability. The result: many alerts represent

theoretical exposure, leading teams to chase “false urgencies,” while assets that are truly

reachable and exposed slip down the queue.

• Manual correlation tax: Closely related to the point above, to separate real threats from

background noise, engineers must cross-reference Wiz-style findings with firewall

rulebases, gateway placements, and routing tables, and figure out which rules and security

controls will mitigate exposure. This hand-stitching is slow, error-prone, and drains scarce

expert time.

• Siloes and slow mitigation loops: Different teams, such as SOC analysts, network

engineers, IT, DevOps, and developers, see only part of the picture through their own tools

and dashboards. Without a unified view, priorities diverge, workflows are duplicated, and

issues that can be fixed in seconds are delayed to extended periods of time. For instance,

when legitimate exposure of a workload with a CVE is confirmed, patching that CVE can take

engineers days or even weeks, while a firewall’s IPS prevention might be able to virtually

patch that CVE in seconds.

• Compliance friction: Auditors and regulators increasingly expect evidence not just that

vulnerabilities are patched, but that they were never exploitable in the first place, or that a

virtual patch mitigated the risk in the interim. Proving this across multiple disconnected

systems adds significant overhead.

© 2025 Check Point Software Technologies Ltd. All rights reserved.

CHECK POINT & WIZ SOLUTION BRIEF

THE SOLUTION 2

The Solution

1. etect with Wiz

Wiz continuously scans cloud environments, workloads, and identities to identify misconfigs,

vulnerabilities, and toxic combinations. Now, thanks to the strategic partnership between Wiz

and Check Point, Wiz has visibility not only into the presence of CloudGuard Network Security

gateways’ place in the cloud’s network topology, but also gateways’ access and NAT rulesets,

enabling Wiz to discern if a linked set of findings rise to the level of a critical toxic combination,

and if it does, allows engineers to determine, on the spot, whether a simple tweak of

CloudGuard’s NAT and Access rules can resolve the issue. Conversely, if Wiz determines that

CloudGuard provides sufficient security, it will de-risk the alert, allowing engineers to focus on

truly critical issues.

This means that Wiz’s new awareness of and visibility into CloudGuard saves investigation time,

shortens time to remediation, and reduces alert fatigue.

2. ecide with nfinity and/or cloud engineers

Once Wiz flags an issue, Infinity CTEM ingests it in real time. It then analyzes the customer’s

network topology, traffic flows, and CloudGuard policy, and evaluates whether CloudGuard’s

existing prevention capabilities can mitigate the threat. For example, if CloudGuard’s IPS can

block an exploit, Infinity CTEM can recommend switching CloudGuard’s IPS from 'Detect' to

'Prevent' within the confines of CTEM’s user interface. Importantly, Infinity CTEM performs

impact analysis and false-positive checks before recommending or applying any policy changes,

ensuring that security enforcement does not disrupt business continuity.

3. Prevent with loud uard

Acting as the enforcement and threat prevention plane, beyond access control and

segmentation, CloudGuard’s unmatched threat prevention engines can virtually patch almost

any issue discovered by Wiz, allowing DevOps and infrastructure teams to implement

permanent patches at the configuration, workload, or code level. Importantly, prevention is

applied consistently across cloud providers and hybrid networks, leveraging CloudGuard’s

cloud-native integrations and identity and app-aware policy model.

ssue

To ic Combination severity threshold

ssue s details e g , CVE CTEM CloudGuardC C T

Cloud uard conte t

C T

etermine W risk mitigation

© 2025 Check Point Software Technologies Ltd. All rights reserved.

CHECK POINT & WIZ SOLUTION BRIEF

THE SOLUTION STACK 3

The Solution Stack Wiz provides complete, agentless visibility into cloud infrastructure, applications, code, and

identity. It correlates misconfigurations, vulnerabilities, excessive permissions, and data

exposure, and identifies toxic combinations of vulnerabilities that could materialize into attacks,

protecting clouds from code to runtime.

Crucially for this joint solution, Wiz can also detect the presence of CloudGuard Network

Security’s cloud NGFW in front of vulnerable workloads, along with its NAT and access rulesets,

allowing Wiz to de-risk findings and for engineers to reassess risk based on exposure.

heck Point loud uard etwork ecurity enforces adaptive, enterprise-grade security

controls around, in, and between cloud environments and workloads. It combines L3, L4, and L7

protections, IPS, application control, and cloud-native policies based on object types and tags to

block both known and unknown threats in real-time with unmatched effectiveness.

As part of its advanced threat prevention engines, CloudGuard Network Security is particularly

adept at acting as a virtual patching engine for workloads and preventing attackers from

exploiting vulnerable web applications.

heck Point nfinity hreat xposure anagement connects Wiz’s contextual risk intelligence

with CloudGuard’s enforcement capabilities. It automatically validates whether existing security

policies protect critical vulnerabilities, identifies gaps, and orchestrates remediation.

For this joint cloud security solution, Infinity Threat Exposure Management enables security

practitioners and cloud engineers to remediate risks identified by Wiz by changing CloudGuard

NGFW configurations with a click and without risking business continuity, shortening

remediation cycles to seconds.

Worldwide Headquarters

5 Shlomo Kaplan Street, Tel Aviv 6789159, Israel | Tel: +972-3-753-4599

U.S. Headquarters

100 Oracle Parkway, Suite 800, edwood City, CA 94065 | Tel: 1-800-429-4391

www.checkpoint.com

© 2025 Check Point Software Technologies Ltd. All rights reserved.


Item Type: pdf