White Paper | Check Point SASE: Multilayer Secure Access Architecture

White Paper | Check Point SASE: Multilayer Secure Access Architecture

Learn how Check Point SASE combines Zero Trust Network Access, secure web access, data protection, and cloud-delivered security into a multilayer architecture. Explore strategies for securing remote users, applications, and data while strengthening cyber security and access control.

White Paper | Check Point SASE: Multilayer Secure Access Architecture

Check Point SASE: Multilayer Secure Access Architecture

Practical Use Cases Illustrating How to Protect the Modern Enterprise

MULTILAYER SECURE ACCESS ARCHITECTURE | 2

Executive Summary The modern enterprise runs in the browser. Employees draft documents, access SaaS applications, collaborate in real time, and move between tasks entirely through web-based tools. While this shift has improved productivity and organizational agility, it has also created new security blind spots that traditional network-centric models cannot address.

Most work now takes place outside the traditional perimeter – across home networks, coffee shops, partner environments, and unmanaged contractor devices. The browser itself has become a high-value target, capable of executing code from multiple sources simultaneously. Malicious downloads, embedded scripts, and compromised documents are common entry points for attackers.

Simultaneously, corporate data flows have become more fluid and difficult to control. Users regularly move sensitive information through SaaS interfaces, personal devices, clipboard actions, file uploads, downloads, form fills, and increasingly into generative AI tools – all of which fall outside the visibility of legacy DLP and firewall solutions.

These challenges are top of mind for the security teams tasked with protecting modern distributed workforces. While not exhaustive, the use cases below illustrate the core patterns organizations must address: securing browser-based workflows, controlling data movement, and enabling safe access across both managed and unmanaged devices.

Check Point SASE’s multilayer secure access architecture brings these elements together. Rather than relying solely on network inspection or device agents, the architecture applies controls at multiple points – in the browser, on the device, and across a global cloud security fabric – to deliver consistent protection regardless of where or how users work.

MULTILAYER SECURE ACCESS ARCHITECTURE | 3

The New Enterprise Reality Employees today use the browser as their primary interface with the business. Work that once depended on dedicated applications is now performed inside cloud and SaaS platforms like Google Docs, Salesforce, Monday, Office 365, WebEx, and Adobe Creative Cloud.

This browser-first environment supports flexible, collaborative workflows across distributed teams. A user can draft content, manage a CRM pipeline, join a meeting, upload files, and collaborate on presentations – all without leaving the browser. Remote work amplifies this model, with the browser acting as the bridge between users and corporate resources from any location.

But the browser’s openness introduces substantial risk. Its ability to load and execute content from many sources – ad networks, third-party scripts, embedded documents, and dynamic code – creates fertile ground for sophisticated attacks. Threat actors exploit temporary downloads, malicious JavaScript, and file-based payloads, many of which bypass traditional perimeter defenses.

Meanwhile, unmanaged devices are now part of daily operations. Contractors, freelancers, and BYOD users routinely access corporate applications without the protections found on managed corporate laptops. Organizations often lack visibility into the security posture of these devices, increasing the chances of data leakage or compromise.

These changes have stretched legacy security models beyond their limits. Network appliances cannot see inside the browser. VPNs provide overly broad access. Traditional DLP cannot govern in-browser actions like copy/paste, file uploads, cloud-to-cloud interactions, or form submissions.

Enterprises need a new approach – one that addresses real-world workflows rather than legacy network boundaries.

Managed device

BYOD user

Contractor

Today’s enterprise runs in the browser

MULTILAYER SECURE ACCESS ARCHITECTURE | 4

Fluid Data Movement

Fragmented Security Controls

Data may move from a SaaS app to a local download, into a clipboard, into a personal device, or into an AI tool. Traditional DLP struggles to inspect or control these flows.

Network security, endpoint security, identity systems, and cloud access tools often operate in isolation. Without coordination, gaps emerge between layers.

The Gaps Security Teams Must Address Despite their investments in network inspection, identity security, and endpoint tools, organizations still face four persistent gaps:

Blind Spots Inside the Browser

Most security tools struggle to see or govern the actions users take inside the browser – where sensitive data is copied, pasted, uploaded, downloaded, or moved between applications.

Unmanaged and Semi-Managed Devices

Contractors, third parties, and BYOD users frequently access corporate resources using devices without corporate controls. Agent deployment is often impossible or impractical.

MULTILAYER SECURE ACCESS ARCHITECTURE | 5

Use Case #1: Securing Corporate Employees Across SaaS & Cloud Corporate employees rely heavily on SaaS applications and web-based tools to complete daily work. Even with managed devices, most of their activity still takes place inside the browser, where traditional network or endpoint security has limited visibility. Remote and hybrid work amplify this with users connecting over networks outside the organization’s control.

Challenges

• Most workflows now occur in SaaS or web applications accessed through the browser • Need consistent protection and performance across distributed locations • On-device threats such as ransomware, keyloggers, or zero-day exploits • Limited visibility into browser-level actions even on managed devices • Growing risks from AI-augmented SaaS features and browser-embedded GenAI tools

Solution Approach

Combine device-level prevention, browser-level governance, and cloud-delivered inspection to protect all user activity across SaaS, web, and internal applications.

Capabilities Supporting This Use Case

Outcome

Corporate employees gain fast, reliable access to cloud applications with comprehensive protection across device, browser, and network layers – without impacting productivity.

Device Agent

Prevents ransomware, keyloggers, and zero-day threats at the endpoint

Global Cloud PoPs

Ensure fast, secure connectivity to SaaS and corporate applications

Browser Controls

Enforce safe search settings, rate search results, and monitor sensitive actions within SaaS sessions

ThreatCloud AI

Blocks malicious downloads, websites, and embedded scripts in real time

GenAI Data Controls

Prevent inadvertent sharing of corporate data into AI- driven fields or prompts

MULTILAYER SECURE ACCESS ARCHITECTURE | 6

Outcome

Unmanaged users – contractors and BYOD employees alike – gain secure, frictionless access to only the resources they need. Organizations maintain visibility and data control inside the browser while keeping sensitive applications isolated from riskier unmanaged devices.

Device Posture Check

Verifies whether an unmanaged device meets required security conditions, even without installing a persistent agent

Agentless ZTNASecure Enterprise Browser

A secure web portal that provides per-application access – such as to internal servers or building systems – without granting broad network visibility

A hardened workspace for contractors requiring elevated or regulated access

Use Case #2: Securing Unmanaged Devices (Contractors & BYOD) Contractors and employees using their own devices access corporate applications from environments that the organization does not control. These unmanaged devices introduce similar types of risks: no endpoint agent, no visibility into system posture, and no reliable way to enforce data-handling policies.

Challenges

• Need for precise, application-specific access for contractors or temporary workers • No ability to deploy or trust endpoint agents on personal or contractor devices • Data exposure through copy/paste, uploads and downloads • Risk of compromised or risky devices connecting to corporate applications

Solution Approach

Create an isolated, controlled browser workspace or deliver access through cloud-delivered controls on any device, without an agent. This ensures unmanaged devices can safely reach approved applications without exposing the broader environment.

Capabilities Supporting This Use Case

MULTILAYER SECURE ACCESS ARCHITECTURE | 7

Outcome

Organizations gain visibility and control over sensitive data across all browser-based workflows, preventing accidental or intentional leakage into SaaS, AI tools, or unmanaged environments.

Browser DLP

Governs file transfers, clipboard actions, and data handling inside SaaS applications

Secure Enterprise Browser

Adds restrictive workspace controls, including screenshot blocking and print protections

Clipboard & Form Fill Protection

Identifies sensitive information before it leaves the browser

GenAI Governance

Prevents users from pasting or submitting confidential data into generative AI services or AI-augmented SaaS interfaces

ThreatCloud AI

Analyzes web content and file activity to prevent malicious or unsafe actions

Use Case #3: Data Protection & Governance in the Browser Modern workflows involve constant data movement through the browser, such as copying, pasting, uploading, downloading, filling forms, and interacting with cloud applications. Traditional DLP tools cannot see or control many of these in-browser actions, leaving gaps in data governance across SaaS environments.

Challenges

• Sensitive data movement through uploads, downloads, clipboard activity, and form entries • Cloud-to-cloud transfers that bypass traditional DLP • Browser-based interactions invisible to network-only or endpoint-only controls • User-initiated data exposure through GenAI tools or AI-powered SaaS features • Need for consistent policy enforcement across managed and unmanaged devices

Solution Approach

Apply data loss prevention policies directly in the browser – where sensitive actions occur – and reinforce them with cloud inspection and device-level controls.

Capabilities Supporting This Use Case

MULTILAYER SECURE ACCESS ARCHITECTURE | 8

Outcome

Users gain secure, role-appropriate access to internal systems without exposing the broader environment, while data and in-app actions remain governed at the browser level.

GenAI Data Controls

Governance over sensitive data being copied or pasted into generative AI tools

Agentless ZTNA

Secure, browser‑based access for unmanaged devices when agents can’t be deployed

Per‑Application Zero Trust Access

Granular, identity‑aware access to internal apps without exposing the broader network

Browser‑Level Visibility & Control

Monitoring and governance of copy/paste, uploads, downloads, and form actions inside internal applications

Secure Enterprise Browser

Hardened workspace for regulated or high‑risk roles requiring stronger protections

Use Case #4: Zero Trust Access to Internal Applications Internal applications are critical to business operations, yet traditional access controls often fall short. Legacy VPNs provide overly broad connectivity, increasing the chance of lateral movement, while identity-only controls lack sufficient context for secure access.

Challenges

• Legacy VPNs expose more of the network than necessary • BYOD and contractor devices cannot install agents • Need per-app segmentation and role-based control • Browser-based actions inside internal apps remain unmonitored • Possibility of internal data being copied into external GenAI tools

Solution Approach

Deliver per-application Zero Trust access for managed and unmanaged devices while governing in- browser actions to prevent data leakage or unauthorized behavior.

Capabilities Supporting This Use Case

MULTILAYER SECURE ACCESS ARCHITECTURE | 9

Book a demo to discover how Check Point SASE’s multilayer secure access architecture can provide consistent protection wherever your users work.

Worldwide Headquarters 5 Shlomo Kaplan Street, Tel Aviv 6789159, Israel | Tel: +972-3-753-4599 U.S. Headquarters 100 Oracle Parkway, Suite 800, Redwood City, CA 94065 | Tel: 1-800-429-4391 www.checkpoint.com

Pulling the Use Cases Together – A Unified Architecture Across these scenarios, several patterns emerge:

• Browser-level protection is essential, as this is where most user activity occurs. • On-device capabilities strengthen security for managed endpoints. • Cloud-delivered inspection ensures global consistency, performance, and policy enforcement. • Identity- and context-based controls drive effective Zero Trust.

This unified model applies security policies consistently – including controls that prevent sensitive information from flowing into external AI systems – regardless of device, network, or application.

Unified Operations Through the Check Point Portal The Check Point Portal centralizes visibility and control across all protection layers, allowing administrators to monitor browser activity, device posture, and cloud traffic from a single interface. This makes scaling – to new users, locations, or applications – effortless thanks to the cloud-delivered model.

Why Check Point • Deep protection inside the browser through both an extension and Enterprise Secure Browser • Full threat prevention powered by ThreatCloud AI • Flexible secure access options for managed, unmanaged, and BYOD devices • Global PoPs for optimized connectivity and low latency • Unified policy management across all access and data protection layers

Work happens in the browser, on every type of device and across a wide mix of apps and cloud services. Protecting this reality means using security that fits how people actually work today, not relying on outdated, network-centric assumptions.

https://sase.checkpoint.com/demo?utm_content=WPR&utm_medium=PDF&utm_campaign=Multilayer-architecture

Button 2:


Item Type: pdf