White Paper | Check Point & Illumio: Hybrid Mesh Security in the Age of AI

White Paper | Check Point & Illumio: Hybrid Mesh Security in the Age of AI

See how Check Point and Illumio stop attacks sooner, contain lateral movement faster, and respond with clearer context across cloud and on-prem environments.

White Paper | Check Point & Illumio: Hybrid Mesh Security in the Age of AI

ILLUMIO & CHECK POINT

Securing Hybrid Cloud and On-Prem Environments

In the Age of AI-Assisted Attacks

1

© 2026 Check Point Software Technologies Ltd. All rights reserved.

ILLUMIO & CHECK POINT

EXECUTIVE SUMMARY

Executive summary Prevent what you can, contain what gets through, and respond with confidence when it matters most.

Modern applications no longer live in one place, and security policy can no longer assume they do. A single

business service may begin with internet-facing workloads in one cloud, run business logic in another, depend on

shared services in a third environment, and still connect to sensitive systems or data on-prem. The application

remains one application. The security model often does not.

That is the real problem. Not complexity for its own sake, but fragmented trust. We end up managing one

application across different metadata models, control planes, object types, and assumptions about what should

trust what. The result is inconsistency at exactly the moment consistency matters most. Check Point and Illumio

address that problem from two complementary directions.

• Check Point provides the prevention-first enforcement layer across the hybrid network. It secures major trust

boundaries, implements threat prevention, and provides a single policy and enforcement architecture across

cloud and on-prem environments, leveraging a unified Firewall as a Service, Virtual Firewall, Hyperscale

Firewalls, and SASE.

• Illumio adds two capabilities that materially strengthen that architecture. Illumio Segmentation builds trust

boundaries around application context and workload role, helping contain lateral movement within the

environment, not just at the edge. Illumio Insights turns telemetry and environmental context into a clearer

picture of risky movement, suspicious paths, and policy gaps.

Together, Illumio and Check Point create a more complete security model for hybrid applications: stronger policy at

the network layer, tighter trust at the workload layer, and better clarity when we need to investigate and respond.

Illumio AI Security raph

x xxx

etection

esponse

Incidents, IoCs,

Telemetry

Policy Context

IP-free Contextual

abels for

dynamic policies ogs Events

Threat Prevention

Enforcement

Macro

Segmentation

https://www.checkpoint.com/cyber-hub/network-security/firewall-as-a-service-fwaas/ https://www.checkpoint.com/cloudguard/cloud-network-security/ https://www.checkpoint.com/quantum/maestro-hyperscale-network-security/ https://www.checkpoint.com/quantum/maestro-hyperscale-network-security/ https://sase.checkpoint.com/internet-access https://www.illumio.com/illumio-segmentation https://www.illumio.com/illumio-insights

2

© 2026 Check Point Software Technologies Ltd. All rights reserved.

ILLUMIO & CHECK POINT

SHIFTING OUR FOCUS BACK TO THE TRAFFIC

Shifting Our Focus Back To The Traffic In the world of the Hybrid Mesh Network, security

leaders are no longer protecting a single network. We are

protecting a hybrid estate comprising public cloud,

private cloud, data centers, remote users, partner

connections, shared services, administrative control

planes, and increasingly dynamic application

components.

At the same time, the risk of breach has changed:

• AI is compressing the time between exposure,

discovery, and attempted exploitation.

• AI allows attackers to find and chain zero-days

faster than vendors can patch them.

• A democratized hacking, empowering novice threat

actors to pull off sophisticated attack paths.

Unfortunately, attackers do not need to defeat every control. They need one weakness, one over-trusted path, one

misplaced credential, or one legitimate connection they can abuse once they gain a foothold. And in a world of

heterogeneous environments where everything is connected to everything else, a foothold is all you need.

However, the interconnectness of modern hybrid networks also gives us an opportunity. After all, thanks to AI-

assisted zero-day discovery and vulnerability chaining, we might not know where an attack will come from or how it

will evolve. Still, there’s one thing we can be sure of – no matter the technique or tactic, all attacks ultimately end

up as traffic, turning network security controls into our first and last line of defense.

The Hybrid Mesh Firewall In a world in which applications span the hybrid mesh network,

directly through logic paths or indirectly through access paths, the

traffic itself still has to move from users to services, from services to

data, and from one environment to another. Those paths need to be

consistently controlled, inspected, and protected.

Check Point’s Hybrid Mesh Firewall provides a broad enforcement

layer across cloud and on-prem environments, with a single firewall

deployable in multiple form factors, including a virtual firewall, a

cloud firewall-as-a-service, and a traditional appliance-based

firewall.

In its multi-form-factor configuration, the Hybrid Mesh Firewall

provides a common policy and enforcement model, with advanced

threat-prevention engines covering traffic around and within

networks (N/S E/W), and zero-trust policies utilizing application

Chat PT elease

Claude Code elease

Branch H

Customers

Em loyees

Productivity toolsServices

ata Center

Clouds

3

© 2026 Check Point Software Technologies Ltd. All rights reserved.

ILLUMIO & CHECK POINT

THE HYBRID MESH FIREWALL

control and I awareness, all managed and monitored from a single management console with shared policies.

’ A v

As mentioned, we are now in a world where attackers can find and exploit vulnerabilities at ever-increasing speed

and at scale, and the obvious response to AI-powered threats? AI-powered threat prevention.

Check Point ThreatCloud AI has been doing just that long before the days of Ms. With dozens of AI/M engines

working in tandem and enriched with billions of IoCs collected from all Check Point deployments – from email

security to data center firewalls at Fortune 500 companies, Check Point has achieved threat prevention scores that

are unmatched across the industry across analyst firms - from Mirecom (2025, 2026), Cyber atings, and NSS abs.

Beyond Check Point’s Hybrid Mesh Firewall benchmark scores, its defining capability is to weave itself across

hybrid environments at all major traffic junctions. This is why our infra-agnostic gateway has become the backbone

of threat prevention in the cloud, on-prem, and in between (i.e., multi- and hybrid cloud deployments).

After all, if you can block malicious traffic, spot evasion, and stop exploit attempts of CVEs less than a day after they

are disclosed, your chances of being breached go down dramatically, and even unpatched workloads are virtually

patched.

In addition, features such as application control and identity awareness allow companies to wrap threat prevention

with an additional layer of zero trust – all of which are consistently enforced across the networks that make up the

Hybrid Mesh Network.

That said, there’s a catch…

B f

Most east-west designs start off on the right foot. The Hybrid Mesh Firewall is deployed as a security hub across

environments with network segments acting as spokes. These spokes, or segments, reduce exposure, create order,

and keep unrelated parts of the environment from talking freely to one another.

Miercom Enter rise & Hybrid Mesh Firewall

ero 1 ay First to Block

IPS (BreakingPoint)

NSS Labs Enter rise Firewall

Exploit Evasions esistance

Cyber atings Cloud Network Firewall

Security Effectiveness

Competitors Average

Miercom Hybrid Mesh Network Security

Malware Prevention

Phishing Prevention

https://www.checkpoint.com/2025-miercom-firewall-report/?flz-category=items&flz-item=report--miercom-enterprise--hybrid-mesh-firewall-benchmark-2025 https://engage.checkpoint.com/2026-miercom-hybrid-mesh-network-security-benchmark/items/report--miercom-hybrid-mesh-network-security-competitive-assessment-2026 https://www.checkpoint.com/resources/items/report-cyberratings-cloud-firewall-test-results-q1-2025 https://www.checkpoint.com/resources/items/report-nss-labs-enterprise-firewalls-report-2025

4

© 2026 Check Point Software Technologies Ltd. All rights reserved.

ILLUMIO & CHECK POINT

CLOSING THE GAP WITH ILLUMIO SEGMENTATION

The problem is that firewalls assume implicit trust across these broad segments and are largely blind to traffic

traversing workloads within those segments. This becomes apparent when you consider the heterogeneity within

each segment: A f may contain reverse proxies, web front ends, API gateways, and session

services; may contain internal APIs, worker services, schedulers, AI-driven services, and

administrative interfaces; and a may contain listeners, primary databases, replicas, caches, and

brokers.

In other words, a firewall can correctly separate major segments while still leaving room for lateral movement

within them. Once an attacker gets in, those broad internal segments can give them space to move from one

workload to another, test loose policies, abuse exposed credentials, chain misconfigurations, and eventually blend

into legitimate application paths. That is not a failure of the firewall. It is a sign that the application has outgrown a

purely topology-led trust model, especially now that AI is helping more attackers find and chain those paths faster.

Closing the Ga with Illumio Segmentation Unlike a firewall’s topology-led macro-segmentation, Illumio Segmentation starts with the workloads that make up

the application, the workloads the application serves, and the role each workload plays within the application’s

context.

Instead of defining trust primarily through subnets, zones, or IP ranges, it defines trust around application context.

What is this workload? What service does it belong to? What role does it play? What should it communicate with

and over which protocol, and just as important, what should it never communicate with and how.

Em loyees

contractors

shared on rem

services

Customers Users

SaaS PIs

Public Cloud ata CenterPrivate Cloud

N S Traffic N S Traffic

B segment (spoke)App segment (spoke)Web segment (spoke)

E and Connectivity enforcement threat revention and ero Trust

Security Hub

Firewall as a Service Physical Firewall irtual Cloud Firewall

Application A

orkloads Traffic

Flow ogic Context

Application

orkloads Traffic

Flow ogic Context

Public Cloud ata CenterPrivate Cloud

Web segment (spoke) App segment (spoke) B segment (spoke)

https://www.illumio.com/illumio-segmentation

5

© 2026 Check Point Software Technologies Ltd. All rights reserved.

ILLUMIO & CHECK POINT

CLOSING THE GAP WITH ILLUMIO SEGMENTATION

That is what makes Illumio different. Its value is not simply a finer-grained policy. Its value is tighter control over

attacker movement once something has already gone wrong. The practical outcome is straightforward. If an

attacker compromises a single workload, Illumio helps prevent that foothold from expanding into broader lateral

movement. Communication remains limited to the paths the application actually needs and traffic that consumes

the application’s service. Everything else is denied by design.

Put simply, with Illumio, micro-segmentation becomes breach containment. It limits lateral movement between

workloads rather than between network segments. This reduces the blast radius, protects critical systems, and

gives the organization a better chance of preventing a single incident from evolving into a larger business event.

The obvious question is how Illumio can enforce rules on workloads based on application rather than traditional IP

addresses.

u u L

Illumio does this by building a detailed model of workload communication across the environment. It observes how

workloads connect, which services they expose, which systems depend on them, and which paths are normal for

the application. From there, it gives security teams a practical way to describe each workload using labels.

abels are the foundation of the Illumio model. They describe the workload in terms humans understand:

application, role, environment, location, and other business or security context. A workload might be part of the

Payments application, running in production, acting as an API tier, and hosted in a specific cloud or data center.

That identity is more durable than an IP address, and much closer to how application and security teams actually

think.

This label-driven model is what allows Illumio policy to follow the application rather than the network map. When a

workload moves, scales, or is rebuilt, the trust model does not need to be recreated from scratch. The policy

remains tied to what the workload is and how it should behave, not only to where it happens to sit today. Which

brings us to how these labels become useful outside Illumio, and how Check Point can use them to make firewall

policy more application-aware.

Ingress Egress

( evices, Appliances, Services)

B workloads segment

App workloads segment

Web workloads segment

v u

B

B

L

A

A

orkload Level Segmentation

orkload Level Segmentation

orkload Level Segmentation

orkload Level Segmentation

Context Labeling

ative etadata cloud

Inventory Conte t on-prem

raffic Patterns

abeling ules

AI-Assisted Classification.

1

2

3

4

Shared-Service ole ump-Host Environment Production

Location H Ex osure Privileged

Shop ole Environment Production

Location atacenter Ex osure egulated

ole istener

Shop ole App

Environment Production Location A ure Ex osure Internal

ole AI ole CP

Shop ole eb Environment Production

Location A S Ex osure E ternal

6

© 2026 Check Point Software Technologies Ltd. All rights reserved.

ILLUMIO & CHECK POINT

FIREWALL POLICY CONSISTENCY AND REPEATABILITY

Firewall Policy Consistency and e eatability Thanks to our new product coupling motion, Check Point can now use Illumio’s workload-durable identity to

generate firewall policies that are more accurate, more repeatable, and less dependent on static network

assumptions and tedious configurations.

Illumio labels describe what a workload is, which application it belongs to, its role, location, etc., and Check Point

uses that context in access and threat prevention policies across cloud and on-prem enforcement points.

That is where the value compounds. Illumio makes the trust model more accurate. Check Point makes it

enforceable across the wider hybrid environment. Together, they help teams build firewall policies that are more

application-aware, more stable over time, and harder for attackers to exploit through over-trust, stale rules, or

fragmented control. Therefore:

• Policies become easier to understand because they describe applications rather than the network.

• Check Point controls can be applied around trust boundaries defined by workload role and application context,

rather than treating every system within a large segment as if it carries the same risk or requires the same

access.

• With Illumio labels feeding into Check Point policy, rulesets remain tied to the workload’s role in the

application, even as the underlying infrastructure changes, without requiring policy tweaks and cleanups work,

and with no risk of drift, conflicting policies, and policy gaps.

x

x

x

xIngress Egress

( evices, Appliances, Services)

B workloads segment

App workloads segment

Web workloads segment

v u

B

B

L

A

A 1

2

3

4

Shared-Service ole ump-Host Environment Production

Location H Ex osure Privileged

Shop ole Environment Production

Location atacenter Ex osure egulated

ole istener

Shop ole App

Environment Production Location A ure Ex osure Internal

ole AI ole CP

Shop ole eb Environment Production

Location A S Ex osure E ternal

Workloads abel- riven Segment

Workloads abel- riven Segment

Workloads abel- riven Segment

7

© 2026 Check Point Software Technologies Ltd. All rights reserved.

ILLUMIO & CHECK POINT

UNTANGLING THE HYBRID MESS

Untangling the Hybrid Mess You cannot defend what you cannot see. And in a hybrid mesh network, visibility is rarely clean.

Traffic moves across clouds, data centers, shared services, remote access paths, administrative tools, and

application dependencies. Under pressure, it can look less like a network map and more like a knot of sessions,

logs, alerts, and partial views.

While Illumio Segmentation helps define and enforce workload-level trust, Illumio Insights helps security teams

understand risky movement across the hybrid environment. In the Check Point integration, firewall and session

telemetry can be enriched with asset, traffic, and environment context, making suspicious behavior easier to

investigate and prioritize.

The point is not another dashboard; it’s clarity. Instead of forcing analysts to rebuild the story from disconnected

logs, Insights helps show how risky traffic, suspicious protocols, compromised resources, remote management

abuse, malicious IP activity, and potential exfiltration paths relate to their environment. It helps teams see not only

that something happened, but where it happened, what it touched, and why it matters. After all, detection without

context is noise, and context is what turns firewall telemetry into action.

By connecting firewall telemetry with workload and environment context, teams identify where policies are too

broad, where trust paths are being abused, which resources may need isolation, and where containment should

occur first.

That is how the loop closes Check Point enforces across the broader network, Illumio Segmentation limits

workload movement, and Illumio Insights helps security teams understand what needs attention before a

suspicious path becomes a bigger problem.

Network- evel Enforcement and Threat Prevention

Ingress Egress

( evices, Appliances, Services)

x

Ingress Egress

( evices, Appliances, Services)

Ingress Egress

( evices, Appliances, Services)

x

B workloads segment Ingress Egress

( evices, Appliances, Services)

x

App workloads segment Ingress Egress

( evices, Appliances, Services) Web workloads segment

x

Workload- evel Segmentation, etection, and esponse

Contextual abels

Telemetry Policy Context

isk Policy Insights Incident Context Smart Prioriti ation Click to uarantine Fine Tune Policies

8

© 2026 Check Point Software Technologies Ltd. All rights reserved.

ILLUMIO & CHECK POINT

CONCLUSION

Conclusion Hybrid applications have changed faster than most security architectures. They now span multiple environments,

rely on inconsistent metadata, and create trust paths that are too important to leave to coarse topology alone. At

the same time, attackers are moving faster, and the cost of getting containment wrong is too high.

Check Point and Illumio address that reality from both sides. Check Point secures the broad network paths the

business depends on and applies prevention across the hybrid estate. Illumio Segmentation builds workload-

centric trust boundaries that reduce lateral movement and limit blast radius inside those paths. Illumio Insights

turns telemetry into clearer visibility, better prioritization, and more informed response.

Together, this is more than another “better together” integration. It is a practical hybrid security architecture:

prevent what you can, contain what gets through, and respond with confidence when it matters most

qu

5 Shlomo Kaplan Street, Tel Aviv 6789159, Israel | Tel: 972-3-753-4599

U. . qu

100 Oracle Parkway, Suite 800, edwood City, CA 94065 | Tel: 1-800-429-4391

. .

© 2026 Check Point Software Technologies td. All rights reserved.

http://www.checkpoint.com/


Item Type: pdf