# Check Point

> Your whole estate agrees with itself.

Check Point runs your network, your cloud and your people on one policy, enforced the same everywhere.

**Key points**

- Network security from perimeter to segment
- Cloud workloads and the configuration behind them
- Protection that follows the user, not the office

## Three estates, or one

### Network security

Firewalls, segmentation and remote access run as part of one estate rather than as three products that must be talked into agreeing.

### Cloud workloads

The same policy applied to what runs in the cloud, including the configuration mistakes that are the usual way in.

### The people using it

Protection that follows the user rather than the office, which is where the perimeter went.

## One policy, and the places it has to hold

- **The branch that got its own firewall** — Bought in a hurry by whoever was on site, configured by whoever was available, and never compared against the rules at head office. It is one estate or it is a list of exceptions, and the second one is only discovered during an incident.
- **The lift-and-shift** — A workload moved to the cloud keeps the ruleset it had in the rack, and the rack had a perimeter around it. What protected it there does not exist there, and the gap is usually found by somebody enumerating it.
- **The contractor’s laptop** — Not your build, not your patch cycle, and on your network by Tuesday. Access decided by who the user is and what the device is currently in a state to be trusted with, rather than by which cable it is plugged into.
- **The exception nobody removed** — Opened for a migration in March, still open in November because the person who asked for it has left and nobody is certain what breaks if it closes. One policy means one place to find it and one place to answer for it.
- **The audit** — Somebody asks what the rule is for remote access to production. With three estates that is three answers and a week of reconciliation. With one it is a screen.
- **The new office** — The question is how long until it is protected the same way as the others. The policy already exists; what is left is applying it, which is the difference between an estate and a collection.

## FAQ

### We already have a firewall. Why change?

The question is not the box, it is whether one policy holds across the network, the cloud and your remote staff. Most estates have three that disagree quietly.

### Do we have to replace everything at once?

No, and the estates that tried it are the cautionary tales. It goes in where the disagreement is costing you most — usually remote access or a cloud workload — and the rest follows at the pace your renewal dates allow.

### Who runs it once it is in?

We do, if you want that. A licence is not a deployment and a deployment is not an operation; our analysts watch what it reports and answer for it when something goes wrong.

---

Canonical: https://centio.bg/reshenia/check-point