What is our primary use case?
Check Point Harmony Email & Collaboration serves as my main protection platform for Office 365 SaaS platforms, including email, OneDrive, SharePoint, and I utilize some training features. In my daily work, Check Point Harmony Email & Collaboration has become our number one protection platform; it reviews all information that passes through our Office 365 and makes the final decision on whether something poses a risk to the organization. Every day, we review each of the alerts regarding user interactions at the spam, phishing, malware levels and analyze the threat behavior our organization is receiving, including which departments face the most attacks, what is the number one target, and what types of attacks we receive daily, such as phishing, graymail, spam, malware, etc.
What is most valuable?
The process of reviewing alerts in Check Point Harmony Email & Collaboration is automatic; the tool executes the entire process we have configured, checking and taking actions to block anything suspicious automatically, without any action from us. Essentially, we connect to check if the actions taken are correct and whether there are any false positives; otherwise, the tool operates 100% automatically based on the parameters we have configured in each rule.
When Check Point Harmony Email & Collaboration detects something suspicious, it runs a certain number of intelligence engines that analyze the data source, the domain's reputation, and the current interaction of that domain with our platform. If it is the first time an email arrives from that domain, it alerts the user; if the email contains content that could be malicious, the user is also alerted, and a score is assigned to the email. If the score exceeds the thresholds we have set, it is classified as a low, medium, or high threat, resulting in automatic blocking and alerting the user about the action taken, allowing the user to interact with the platform and report false positives if they believe the email is valid.
Additionally, I utilize Check Point Harmony Email & Collaboration as a training tool; its new Security Training module allows us to conduct department-specific training on phishing, controlled tests, and provides a score for our organization, along with further training to raise awareness within the security department. Other very specific use cases involve user engagement, as we strive to provide as many actionable reports to users as possible to help them be aware of the risks they face daily and how these risks could affect the organization as a whole.
In my opinion, the best feature of Check Point Harmony Email & Collaboration is its ease of integration with platforms like Office and Google Cloud, allowing for automatic integration that results in a robust platform that makes decisions based on your organization with just a couple of steps. The most used features include email tracking, which allows us to easily follow up on emails and conversations, helping us understand what is happening within the organization when an alert is detected, providing more context rather than simply blocking an email due to detecting something malicious. Its intelligence engines also review how interactions occur within the platform, and the integration with inspection engines and our infrastructure knowledge at the email level makes it one of its best features.
Those integrations definitely help me save time and improve security, as we no longer need to manually review each alert and are less concerned about false positive reviews. The tool operates automatically, making our workload easier, while also significantly enhancing our overall security.
Since acquiring Check Point Harmony Email & Collaboration, we have seen an increase in the blocking of Business Email Compromise, phishing, and spam emails, drastically reducing our exposure to email security risks. We have noticed a reduction in accepted phishing attempts since we started using Check Point Harmony Email & Collaboration compared to the protection of Microsoft 365. We have graphs showing that Microsoft 365 detects approximately 65% of threats, while Check Point processes the rest of that 65%, thus providing better protection than traditional solutions.
What needs improvement?
To improve Check Point Harmony Email & Collaboration, one notable enhancement would be to fully integrate the DMARC and SPF protections they have; once this is correctly implemented, I believe it will further improve internal email protection outcomes.
We have only encountered some false positives that required us to whitelist certain third-party domains, mostly due to their poor email configuration preventing DMARC or SPF alerts. Frankly, the platform performs very well, and we have not experienced any other issues since we began using it.
Currently, I believe that no further improvements are needed for Check Point Harmony Email & Collaboration.
For how long have I used the solution?
I have used Check Point Harmony Email & Collaboration for seven or eight years.
What do I think about the stability of the solution?
The platform is very stable; we have not encountered any downtime or stability-related issues, so I would say we have had 100% uptime.
What do I think about the scalability of the solution?
The scalability of Check Point Harmony Email & Collaboration is very straightforward; we experience an annual growth rate of about 10 to 15%, and scaling up is simple, as we only increase licensing, and the rest happens automatically. User synchronization and administration detect user license activation, and protection begins from day one.
How are customer service and support?
I have not needed to open any support cases with Check Point Harmony Email & Collaboration, which indicates that my experience with support has been very good.
How would you rate customer service and support?
Which solution did I use previously and why did I switch?
Before using Check Point Harmony Email & Collaboration, we were utilizing Microsoft 365 with Defender for email protection.
We switched from Microsoft Defender to Check Point Harmony Email & Collaboration because we had an event where Defender failed to detect a threat, allowing phishing and spam emails to reach our directors. We chose Check Point Harmony Email & Collaboration because we felt it has better security engines and a more detailed administration of internal security and event management. It also provides graphs and statistics to illuminate how these events occur within the organization, allowing us to identify which departments require closer monitoring or which ones are the main targets for threats, such as directors, purchasing, and HR. We evaluated various tools before choosing Check Point Harmony Email & Collaboration, including Proofpoint, but ultimately, we decided to go with Check Point.
How was the initial setup?
I would advise others considering using Check Point Harmony Email & Collaboration to conduct a proof of concept directly with Check Point to set up the initial configuration and see the platform working at full capacity before making a decision, and that they can compare the detection parameters provided by Check Point with any other email tools they are evaluating.
What about the implementation team?
We are customers and do not have any relationship with the vendor or partner.
What was our ROI?
We have seen a return on investment with Check Point Harmony Email & Collaboration; specifically, we have drastically reduced the time it takes to detect and stop a threat, which has been cut by over 2 hours from detection to the automatic blocking of the threat.
What's my experience with pricing, setup cost, and licensing?
My experience with pricing, setup costs, and licensing for Check Point Harmony Email & Collaboration is quite good; the pricing is based on the number of users. There are three types of licenses that range from basic to advanced, with a Complete version offering DLP characteristics, but if you do not plan to create detection or data protection policies, I believe that the Advanced license is sufficient. It is a very straightforward licensing approach, done per user and for periods of 1 to 5 years.
What other advice do I have?
I have given this review a rating of 10.
Which deployment model are you using for this solution?
Private Cloud
If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?
Microsoft Azure