security consultant at a tech vendor with 10,001+ employees
Real User
Top 5
Aug 26, 2026
My main use case for Check Point WAF (formerly CloudGuard WAF) is web application API protection in cloud-native, hybrid, and multi-cloud environments, where it provides automated AI-driven threat prevention, comprehensive API security, zero-day and OWASP Top 10 protection, as well as bot protection and DDoS mitigation. As a scenario, I can describe a broken object level authorization attack where an enterprise is running a containerized microservice application deployed via Terraform or Docker. The front end communicates with the back-end service through a REST API, and user authentication is handled by a central identity and access management provider such as OAuth2. The attack vector involved an attacker logging in with valid, low-privilege user credentials, which led them to probe the application's back-end endpoint. After requesting their own authorized record, they deployed a script to iterate through other IDs to scrape sensitive data from other tenants. Since the API calls are perfectly formatted and authenticated, a legacy signature-based WAF would typically allow this traffic through. However, the mitigation flow includes automatic schema enforcement, behavioral baseline, IAM context awareness, and surgical blocking. By applying these techniques, we can shift from static rule maintenance to dynamic, context-aware analysis, which is where Check Point WAF (formerly CloudGuard WAF) applies.
System And Network Administrator at a tech services company with 51-200 employees
Real User
Top 10
Jul 29, 2026
I have found features like Cisco ASA and Firepower most valuable. Secure Firewall is a secure firewall with features like WAF and web applications. We have web filtering applications, secure features, and application controls among other features.
Senior Technical Engineer at a outsourcing company with 1,001-5,000 employees
Real User
Top 20
Jul 22, 2026
We have implemented Check Point WAF (formerly CloudGuard WAF) in our environment. We have been dealing with Check Point WAF (formerly CloudGuard WAF) for three months. We are using Check Point WAF (formerly CloudGuard WAF) for our company only. Currently, we are handling only the L7 part with Check Point WAF (formerly CloudGuard WAF), and we are planning to expand to the APIs and rate-limiting capabilities. We are not handling the network part, as we are only taking care of the security part with Check Point WAF (formerly CloudGuard WAF). We have a team of 15 people who handle Check Point WAF (formerly CloudGuard WAF) and other security aspects. We have only two administrators dedicated to Check Point WAF (formerly CloudGuard WAF).
The main purpose is to have network security through machine learning, which can offer threat detection and intelligence for my endpoints, and I am looking for application security. I am looking for an AI-based solution that can strengthen my cloud-native security, automate security, and better prevent threats. I am looking for an AI-based solution and unified cloud-native security from the SaaS platform to improve my security posture.
I am using Check Point WAF (formerly CloudGuard WAF). I am also using multiple FortiGate products. I am using the product for URL filtering, security, WAF, and VRF. Check Point WAF improves our ability to discover, monitor, and protect APIs.
I typically use Check Point WAF (formerly CloudGuard WAF) for protecting cloud workspaces, which includes cloud applications and websites hosted on cloud platforms, especially Amazon or Azure. My customers are using Check Point WAF (formerly CloudGuard WAF) as a standalone product in the cloud, not in conjunction with any other Check Point products.
Learn what your peers think about Check Point WAF (formerly CloudGuard WAF). Get advice and tips from experienced pros sharing their opinions. Updated: September 2026.
Any cloud-native application is where my clients might be using Check Point WAF (formerly CloudGuard WAF) to secure Layer 7 with low latency. It is one of the best in Layer 7 security.
Security Consultant at a computer software company with 501-1,000 employees
Consultant
Top 10
May 27, 2026
The customers I have worked with were primarily using Check Point WAF (formerly CloudGuard WAF) as an application security solution, mostly leveraging Check Point CloudGuard for various purposes such as protecting their application servers from the top 10 OWASP attacks and for Zero-Day protection. My clients were not working separately with Check Point WAF (formerly CloudGuard WAF); they were receiving a unified platform that included firewall, email security, and endpoint security, so the integration effectively eliminated silos in their environment.
Check Point WAF (formerly CloudGuard WAF) is required by customers who have web resources and assets that are important to them and in production. These resources include internet shops, services, and financial services. Without a web application firewall, the business stops, and customers need to implement this solution. Insurance companies, banks, and similar organizations fall into this category.
I want to protect my application hosted in my cloud by preventing attacks against my top OWASP Top 10 threats. I am enabling Check Point WAF (formerly CloudGuard WAF) as my application firewall. The integration is straightforward because I am hosting in the cloud, so Check Point WAF (formerly CloudGuard WAF) can be hosted in a public location wherever my cloud vendor is located as a service provider, and I can host the application within a change of DNS.
I use Check Point CloudGuard WAF for web application and API protection. I can provide a scenario where I used Check Point CloudGuard WAF to defend against an SQL injection attack on a web app. It detects query patterns via machine learning and then blocks requests instantly without needing any rule writing.
Check Point CloudGuard WAF's primary use is protecting web applications and APIs from application layer attacks in the cloud. I also use it to protect public-facing apps.
The major use case is providing application security and API security solutions to the organization. For example, our client was HYG, and they wanted to ensure their applications and API security gets fully secured, which is why I proposed Check Point CloudGuard WAF to their solution.
I use Check Point CloudGuard WAF for CSPM and posture management. In some places, I use native app protection-related management, and in other places, I use it for runtime protection. These are all some of the use cases I have utilized it for. I also use it for CASB in some locations, compliance assessment, adaptive access control, UEBA, policy enforcement, and threat protection. I have performed all of these functions using firewalls. Traditional WAF with Check Point CloudGuard WAF has some features that could be integrated inside the WAF that might be helpful. I normally use a separate tool for API security, and I used to perform OWASP top 10 or 20 assessments. Not everything falls under WAF. However, if it is included, especially in today's market where AI-related features are all integrated, that would be tremendously helpful. AI and modern viruses such as token theft, tool poisoning, command injection, unauthorized access, and prompt injection are all concerns. If you have prompt injection detection in Check Point CloudGuard WAF, that would be the greatest help for the market. I would give you one more thing called a rug pull attack. Prompt injection is critical to address. Today everything is prompt-based and AI-based, and there will definitely be some bots. Those bots will definitely cross this WAF. There are some modern AI-based vulnerabilities such as token theft and tool poisoning. Tool poisoning means that some malicious command will be hidden inside, and then passwords will be saved insecurely. This happens everywhere, sometimes by mistake or unintentionally, but these mistakes are what allow hackers to penetrate. Token theft, tool poisoning, token passthrough, command injection, rug pull attack, unauthenticated access, and prompt injection are all seven major problems for people like me, CISOs.
IT Security & Networks Administrator at a financial services firm with 1,001-5,000 employees
Real User
Top 5
Feb 4, 2026
I am using not only Fortinet, but I am also dealing with other vendors as well, such as Check Point. I am working with email security by Check Point. I have a little bit of experience with Check Point CloudGuard WAF, as we ran a proof of concept here.
I can use Check Point CloudGuard WAF for multiple purposes, as I am using it as our cloud security posture management tool. I have started using it since cloud security posture management was sold to Wiz. Wiz is another product these days. I have started using Check Point CloudGuard WAF along with bot protection and API protection.
Sr. VP of Creative & Development at a non-tech company with 51-200 employees
Real User
Top 5
Nov 22, 2025
Check Point CloudGuard WAF's main use case is protecting web application APIs from external threats. It helps us block common attacks like SQL injections, cross-site scripting, and bot traffic, while also ensuring compliance with the security standards. One unique aspect of our use case for Check Point CloudGuard WAF is how we leverage it to protect customer APIs that are critical to our business. Because we develop and host several in-house applications, we needed a solution that could adapt quickly to new endpoints and traffic patterns. Check Point CloudGuard WAF has been especially helpful here, automatically learning and adjusting protection without requiring constant manual tuning.
IT Support at a security firm with 51-200 employees
Real User
Top 5
Nov 9, 2025
My main use case for Check Point CloudGuard WAF is protecting the public-facing web applications in my company because I need to show different webs to different clients, and I need to protect these web apps. In addition to protecting public-facing web apps and APIs, I also use Check Point CloudGuard WAF for different purposes, such as providing protection to non-production environments, ensuring that vulnerabilities are caught early during deployment and testing, which helps identify misconfiguration or insecure code before it reaches production.
Our main use case for Check Point CloudGuard WAF is to protect web applications and APIs from common threats such as SQL injection, cross-site scripting, and bot attacks. A specific example of how we've used Check Point CloudGuard WAF to protect against SQL injection attempts is that we had a public-facing customer portal hosted on AWS, where CloudGuard WAF detected and logged multiple SQL injection attempts targeting the login page and flagged the attacks in real time. We were able to review detailed logs showing the malicious payload, which ensured the application stayed fully available without any downtime and prevented the exposure of sensitive data, giving our security team confidence that the WAF rules were working efficiently against the OWASP Top 10 threats.
My main use case for Check Point CloudGuard WAF is to protect web applications and APIs from OWASP Top 10, and it has helped to secure cloud workload and prevent unauthorized access to data leaks. I use Check Point CloudGuard WAF to block SQL injection and cross-site scripting attacks, and we protect the API by enforcing strict access, automatically applying a security policy to new applications before deploying in the cloud.
Security Engineer at a tech vendor with 51-200 employees
Real User
Top 5
Aug 22, 2025
My main use case for Check Point CloudGuard WAF is defending from SQL injection or DDoS attacks, and a quick specific example would be that it protects our applications and data from these threats. I don't have anything else to add about my main use case, as there are no stories or examples where it helped my team.
My team and I work with Check Point CloudGuard Code Security and handle all related tasks, including deploying virtual machines and configuring all aspects. Our security team's roles include networking security, and our responsibility is to deploy all firewalls across our organization's sites, both on-premises and in the cloud.
Technical Support Executive at a computer software company with 501-1,000 employees
Real User
Top 5
May 9, 2025
The main use case of Check Point CloudGuard WAF is for application protection. Check Point CloudGuard WAF provides protection from OWASP threats, and secures web applications from common vulnerabilities, such as SQL injection, cross-site scripting, cross-site request forgery, and remote file inclusions.
Director of Security EngineerIng at a financial services firm with 5,001-10,000 employees
Real User
Mar 15, 2024
It was adopted in response to the events of SolarWinds, where API credentials were leaked into Git repositories or other developer tools. We, at the time, had no detective or preventive controls to prevent this sort of disclosure, so CloudGuard Spectral was implemented into the pipelines themselves to detect secrets being disclosed.
Our primary use case involves protecting our internal services hosted within our data center's cloud environment, which includes virtual machines housing critical company resources. Additionally, we safeguard external services used by our customers with Check Point security measures.
Senior Manager Ict & Innovations at Bangalore International Airport Limited
Real User
Top 10
Dec 1, 2023
We have so many applications where the code needs to be verified before it can be transferred to production. This scans the code and all the configurations to detect issues.
Perimeter Security Administrator at a security firm with 51-200 employees
Real User
Top 20
Feb 24, 2023
We were looking for a solution that could perform analysis on variables that we currently have to achieve real-time analysis of response from the organization and the measures that we must mitigate based on our organizational structure. Additionally, we needed a simplification of compliance with internal regulations based on international regulations and standards to allow us to maintain a standard of security in the industry. Our niche market requires a solution that automatically identifies security risks, compliance problems, or bad configurations.
We have tried to find and solve problems when developing applications, encouraging each one of our developers to comply with security standards worldwide based on the best practices published so that each one promotes and exposes a robust line of security. Based on this need to achieve the best security guidelines and try to make the development exponents easy, fast, and scalable, we sought solutions for the company.
Two years ago, the company began migrating to the Azure cloud, taking with it almost 80% of the servers of their respective applications. Due to this, we then thought of making a well-defined strategy to strengthen the security of the company's infrastructure. We needed a strong pillar to maintain robust and secure security against any cyber attack. We began to adopt security tools that provided us with support in the cloud. In addition to that, they are multi-cloud. If we decide to make any change in the future, we can. All the applications that we use and have access to the outside need good filtering and security and Spectral meets the current requirements we have.
There is a great improvement in the security of the organization. Our assets and infrastructure are enhanced by Check Point CloudGuard Spectral. It shields the organization against exposed API keys and confidential credentials against ransomware attacks. It uncovers hidden hiccups in the coding system that can affect our workflow and production ecosystem. Uncovering security blindspots has enabled sectors across the enterprise to plan and set security measures that cannot be compromised easily. This product scans the application configurations to enhance compliance.
In recent years, in search of a new strategy, we have tried to strengthen our security and infrastructure posture. It's one of the fundamental pillars of a large organization. As a result of this situation, we have begun to adapt by using solutions that support us on cloud and on-premise. We have found the solution offers a healthy, strong infrastructure and, above all, is aligned with the legal and regulatory frameworks at an international level.
Currently, our company implements several sites and applications developed in Microsoft Azure. However, in the past, we had some vulnerabilities in identities that were used within the development, which allowed us to understand that we needed help to implement the best security practices for others to protect all the development against attackers that could harm us. The tool has helped us improve and implement improvements for our security.
In our company, we use Microsoft Azure, where we carry out developments and applications. Previously, we did not have how to test that they were created with the best security practices in addition to being covered or provided against vulnerabilities that could be the target of cyber attackers. For this reason, we began with the investigation of a tool that could validate how these tools were made up, for which we found Spectral Check Point. We began to use it to generate greater security for the company and the perimeter.
Check Point WAF offers a robust security framework with AI-driven threat detection and seamless integration, protecting applications and APIs in multi-cloud environments.Effective in preemptively blocking threats through AI and machine learning, Check Point WAF reduces false positives and operational workload. Its integration capabilities and threat intelligence provide comprehensive protection against zero-day attacks, while centralized management facilitates cost-effective and insightful...
My main use case for Check Point WAF (formerly CloudGuard WAF) is web application API protection in cloud-native, hybrid, and multi-cloud environments, where it provides automated AI-driven threat prevention, comprehensive API security, zero-day and OWASP Top 10 protection, as well as bot protection and DDoS mitigation. As a scenario, I can describe a broken object level authorization attack where an enterprise is running a containerized microservice application deployed via Terraform or Docker. The front end communicates with the back-end service through a REST API, and user authentication is handled by a central identity and access management provider such as OAuth2. The attack vector involved an attacker logging in with valid, low-privilege user credentials, which led them to probe the application's back-end endpoint. After requesting their own authorized record, they deployed a script to iterate through other IDs to scrape sensitive data from other tenants. Since the API calls are perfectly formatted and authenticated, a legacy signature-based WAF would typically allow this traffic through. However, the mitigation flow includes automatic schema enforcement, behavioral baseline, IAM context awareness, and surgical blocking. By applying these techniques, we can shift from static rule maintenance to dynamic, context-aware analysis, which is where Check Point WAF (formerly CloudGuard WAF) applies.
I have found features like Cisco ASA and Firepower most valuable. Secure Firewall is a secure firewall with features like WAF and web applications. We have web filtering applications, secure features, and application controls among other features.
We have implemented Check Point WAF (formerly CloudGuard WAF) in our environment. We have been dealing with Check Point WAF (formerly CloudGuard WAF) for three months. We are using Check Point WAF (formerly CloudGuard WAF) for our company only. Currently, we are handling only the L7 part with Check Point WAF (formerly CloudGuard WAF), and we are planning to expand to the APIs and rate-limiting capabilities. We are not handling the network part, as we are only taking care of the security part with Check Point WAF (formerly CloudGuard WAF). We have a team of 15 people who handle Check Point WAF (formerly CloudGuard WAF) and other security aspects. We have only two administrators dedicated to Check Point WAF (formerly CloudGuard WAF).
The main purpose is to have network security through machine learning, which can offer threat detection and intelligence for my endpoints, and I am looking for application security. I am looking for an AI-based solution that can strengthen my cloud-native security, automate security, and better prevent threats. I am looking for an AI-based solution and unified cloud-native security from the SaaS platform to improve my security posture.
I am using Check Point WAF (formerly CloudGuard WAF). I am also using multiple FortiGate products. I am using the product for URL filtering, security, WAF, and VRF. Check Point WAF improves our ability to discover, monitor, and protect APIs.
I typically use Check Point WAF (formerly CloudGuard WAF) for protecting cloud workspaces, which includes cloud applications and websites hosted on cloud platforms, especially Amazon or Azure. My customers are using Check Point WAF (formerly CloudGuard WAF) as a standalone product in the cloud, not in conjunction with any other Check Point products.
Any cloud-native application is where my clients might be using Check Point WAF (formerly CloudGuard WAF) to secure Layer 7 with low latency. It is one of the best in Layer 7 security.
The customers I have worked with were primarily using Check Point WAF (formerly CloudGuard WAF) as an application security solution, mostly leveraging Check Point CloudGuard for various purposes such as protecting their application servers from the top 10 OWASP attacks and for Zero-Day protection. My clients were not working separately with Check Point WAF (formerly CloudGuard WAF); they were receiving a unified platform that included firewall, email security, and endpoint security, so the integration effectively eliminated silos in their environment.
Check Point WAF (formerly CloudGuard WAF) is required by customers who have web resources and assets that are important to them and in production. These resources include internet shops, services, and financial services. Without a web application firewall, the business stops, and customers need to implement this solution. Insurance companies, banks, and similar organizations fall into this category.
I want to protect my application hosted in my cloud by preventing attacks against my top OWASP Top 10 threats. I am enabling Check Point WAF (formerly CloudGuard WAF) as my application firewall. The integration is straightforward because I am hosting in the cloud, so Check Point WAF (formerly CloudGuard WAF) can be hosted in a public location wherever my cloud vendor is located as a service provider, and I can host the application within a change of DNS.
I have been using Check Point WAF (formerly CloudGuard WAF) on a public cloud.
I use Check Point CloudGuard WAF for web application and API protection. I can provide a scenario where I used Check Point CloudGuard WAF to defend against an SQL injection attack on a web app. It detects query patterns via machine learning and then blocks requests instantly without needing any rule writing.
Check Point CloudGuard WAF's primary use is protecting web applications and APIs from application layer attacks in the cloud. I also use it to protect public-facing apps.
The major use case is providing application security and API security solutions to the organization. For example, our client was HYG, and they wanted to ensure their applications and API security gets fully secured, which is why I proposed Check Point CloudGuard WAF to their solution.
I use Check Point CloudGuard WAF for CSPM and posture management. In some places, I use native app protection-related management, and in other places, I use it for runtime protection. These are all some of the use cases I have utilized it for. I also use it for CASB in some locations, compliance assessment, adaptive access control, UEBA, policy enforcement, and threat protection. I have performed all of these functions using firewalls. Traditional WAF with Check Point CloudGuard WAF has some features that could be integrated inside the WAF that might be helpful. I normally use a separate tool for API security, and I used to perform OWASP top 10 or 20 assessments. Not everything falls under WAF. However, if it is included, especially in today's market where AI-related features are all integrated, that would be tremendously helpful. AI and modern viruses such as token theft, tool poisoning, command injection, unauthorized access, and prompt injection are all concerns. If you have prompt injection detection in Check Point CloudGuard WAF, that would be the greatest help for the market. I would give you one more thing called a rug pull attack. Prompt injection is critical to address. Today everything is prompt-based and AI-based, and there will definitely be some bots. Those bots will definitely cross this WAF. There are some modern AI-based vulnerabilities such as token theft and tool poisoning. Tool poisoning means that some malicious command will be hidden inside, and then passwords will be saved insecurely. This happens everywhere, sometimes by mistake or unintentionally, but these mistakes are what allow hackers to penetrate. Token theft, tool poisoning, token passthrough, command injection, rug pull attack, unauthenticated access, and prompt injection are all seven major problems for people like me, CISOs.
I am using not only Fortinet, but I am also dealing with other vendors as well, such as Check Point. I am working with email security by Check Point. I have a little bit of experience with Check Point CloudGuard WAF, as we ran a proof of concept here.
I can use Check Point CloudGuard WAF for multiple purposes, as I am using it as our cloud security posture management tool. I have started using it since cloud security posture management was sold to Wiz. Wiz is another product these days. I have started using Check Point CloudGuard WAF along with bot protection and API protection.
Check Point CloudGuard WAF's main use case is protecting web application APIs from external threats. It helps us block common attacks like SQL injections, cross-site scripting, and bot traffic, while also ensuring compliance with the security standards. One unique aspect of our use case for Check Point CloudGuard WAF is how we leverage it to protect customer APIs that are critical to our business. Because we develop and host several in-house applications, we needed a solution that could adapt quickly to new endpoints and traffic patterns. Check Point CloudGuard WAF has been especially helpful here, automatically learning and adjusting protection without requiring constant manual tuning.
My main use case for Check Point CloudGuard WAF is protecting the public-facing web applications in my company because I need to show different webs to different clients, and I need to protect these web apps. In addition to protecting public-facing web apps and APIs, I also use Check Point CloudGuard WAF for different purposes, such as providing protection to non-production environments, ensuring that vulnerabilities are caught early during deployment and testing, which helps identify misconfiguration or insecure code before it reaches production.
Our main use case for Check Point CloudGuard WAF is to protect web applications and APIs from common threats such as SQL injection, cross-site scripting, and bot attacks. A specific example of how we've used Check Point CloudGuard WAF to protect against SQL injection attempts is that we had a public-facing customer portal hosted on AWS, where CloudGuard WAF detected and logged multiple SQL injection attempts targeting the login page and flagged the attacks in real time. We were able to review detailed logs showing the malicious payload, which ensured the application stayed fully available without any downtime and prevented the exposure of sensitive data, giving our security team confidence that the WAF rules were working efficiently against the OWASP Top 10 threats.
My main use case for Check Point CloudGuard WAF is to protect web applications and APIs from OWASP Top 10, and it has helped to secure cloud workload and prevent unauthorized access to data leaks. I use Check Point CloudGuard WAF to block SQL injection and cross-site scripting attacks, and we protect the API by enforcing strict access, automatically applying a security policy to new applications before deploying in the cloud.
My main use case for Check Point CloudGuard WAF is defending from SQL injection or DDoS attacks, and a quick specific example would be that it protects our applications and data from these threats. I don't have anything else to add about my main use case, as there are no stories or examples where it helped my team.
My team and I work with Check Point CloudGuard Code Security and handle all related tasks, including deploying virtual machines and configuring all aspects. Our security team's roles include networking security, and our responsibility is to deploy all firewalls across our organization's sites, both on-premises and in the cloud.
The main use case of Check Point CloudGuard WAF is for application protection. Check Point CloudGuard WAF provides protection from OWASP threats, and secures web applications from common vulnerabilities, such as SQL injection, cross-site scripting, cross-site request forgery, and remote file inclusions.
The primary use case for Check Point CloudGuard WAF is for protecting web applications and APIs. We use it for web apps and APIs we want to protect.
The primary use case of this solution is to detect vulnerabilities, prevent breaches, accelerate development, and improve code quality.
It was adopted in response to the events of SolarWinds, where API credentials were leaked into Git repositories or other developer tools. We, at the time, had no detective or preventive controls to prevent this sort of disclosure, so CloudGuard Spectral was implemented into the pipelines themselves to detect secrets being disclosed.
Our primary use case involves protecting our internal services hosted within our data center's cloud environment, which includes virtual machines housing critical company resources. Additionally, we safeguard external services used by our customers with Check Point security measures.
We have so many applications where the code needs to be verified before it can be transferred to production. This scans the code and all the configurations to detect issues.
In our company, we deployed a firewall in the office. The office has around 200 to 300 people. We're using it to control the Internet access.
We were looking for a solution that could perform analysis on variables that we currently have to achieve real-time analysis of response from the organization and the measures that we must mitigate based on our organizational structure. Additionally, we needed a simplification of compliance with internal regulations based on international regulations and standards to allow us to maintain a standard of security in the industry. Our niche market requires a solution that automatically identifies security risks, compliance problems, or bad configurations.
We have tried to find and solve problems when developing applications, encouraging each one of our developers to comply with security standards worldwide based on the best practices published so that each one promotes and exposes a robust line of security. Based on this need to achieve the best security guidelines and try to make the development exponents easy, fast, and scalable, we sought solutions for the company.
Two years ago, the company began migrating to the Azure cloud, taking with it almost 80% of the servers of their respective applications. Due to this, we then thought of making a well-defined strategy to strengthen the security of the company's infrastructure. We needed a strong pillar to maintain robust and secure security against any cyber attack. We began to adopt security tools that provided us with support in the cloud. In addition to that, they are multi-cloud. If we decide to make any change in the future, we can. All the applications that we use and have access to the outside need good filtering and security and Spectral meets the current requirements we have.
There is a great improvement in the security of the organization. Our assets and infrastructure are enhanced by Check Point CloudGuard Spectral. It shields the organization against exposed API keys and confidential credentials against ransomware attacks. It uncovers hidden hiccups in the coding system that can affect our workflow and production ecosystem. Uncovering security blindspots has enabled sectors across the enterprise to plan and set security measures that cannot be compromised easily. This product scans the application configurations to enhance compliance.
In recent years, in search of a new strategy, we have tried to strengthen our security and infrastructure posture. It's one of the fundamental pillars of a large organization. As a result of this situation, we have begun to adapt by using solutions that support us on cloud and on-premise. We have found the solution offers a healthy, strong infrastructure and, above all, is aligned with the legal and regulatory frameworks at an international level.
Currently, our company implements several sites and applications developed in Microsoft Azure. However, in the past, we had some vulnerabilities in identities that were used within the development, which allowed us to understand that we needed help to implement the best security practices for others to protect all the development against attackers that could harm us. The tool has helped us improve and implement improvements for our security.
In our company, we use Microsoft Azure, where we carry out developments and applications. Previously, we did not have how to test that they were created with the best security practices in addition to being covered or provided against vulnerabilities that could be the target of cyber attackers. For this reason, we began with the investigation of a tool that could validate how these tools were made up, for which we found Spectral Check Point. We began to use it to generate greater security for the company and the perimeter.