Regarding specific incidents where Check Point Harmony Email & Collaboration's AI features stopped threats, we receive notifications whenever there is a new alert through email to the admin. Whenever there is an alert, we go to the dashboard to check what kind of alerts it has and proceed with the investigation. The system has a very nice dashboard with a clear layout when investigating incidents, showing email profiles and attack types. In the relationship section, it shows different AI indicators that confirm why a threat was stopped and what AI features are at play, indicating AI threats evident in the email. This helps us during investigations as it is easy to see different indicators and decide whether a threat requires quarantine or whether it's a true positive or false positive.
The first standout feature is that it's an API-based email security solution. It took us hardly half a day to get it deployed and set up, compared to other email securities such as Barracuda Email Security which takes days to fully deploy due to inbound and outbound connector setup requirements. Check Point Harmony Email & Collaboration was protecting our incoming, outgoing, and internal emails within half a day of deployment. Another impressive feature is that it offers API-based inline protection, unlike Trend Micro Email Security which wasn't inline, meaning emails would first go to the inbox before being removed if threats were found.
The incorporated AI capabilities are particularly notable, functioning as AI versus AI. It has protected us from various threats and has a nice dashboard that shows if anything is missed by MS 365. For instance, last week we received an email flagged as safe by Microsoft, but Check Point flagged it. Upon investigation, we found it had a malicious attachment, and Check Point provided a full report highlighting the malicious indicators.
The positive impact includes a clear reduction in threats and improved detection capabilities. The dashboard is impressive, neat, and clean, showing all information about threats on the initial landing page. The analytics are very good, particularly the ability to identify real source IPs, which was a distinguishing factor from Trend Micro.
The URL emulation and real-time on-click protection are impressive features. When we receive a malicious document, it can sanitize the document by removing malicious elements while maintaining benign content. The user-to-admin interaction feature for managing quarantined emails is also noteworthy. We utilize analytics to generate reports, helping us pinpoint types of threats and their origin, which has been instrumental in implementing targeted training programs.