What is our primary use case?
Check Point Harmony Endpoint is used in this company to connect users from different endpoints and locations, such as users working from home or users working in other countries. The main way this tool is used is to monitor all devices and all endpoints that connect to the enterprise network.
Check Point Harmony Endpoint is used in this company because some employees travel around Latin America and constantly move to different countries. For example, the CEO travels to Colombia, Guatemala, and Panama and needs to connect to the enterprise network. This tool is used to verify that the person connecting to the enterprise network is the correct person.
Threat prevention has been centralized, and Check Point Harmony Endpoint unifies multiple layers of protection, including malware, ransomware, exploit prevention, and behavior analysis in a single agent. This helps reduce complexity and ensure consistent security policies across all devices. Strong ransomware protection is one of the main use cases, as Check Point Harmony Endpoint prevents ransomware attacks and monitors for suspicious encryption. Posture management and visibility are also key use cases, as the platform provides detailed visibility into endpoint health, missing patches, vulnerabilities, and policy compliance.
What is most valuable?
Posture management for vulnerabilities, patches, compliance alerts, and endpoint status is valuable. The tool monitors device compliance, checks for missing patches, and detects vulnerable software. It identifies missing patches for remediation before the issue escalates and ensures that protection policies have been applied correctly.
Additional valuable features include anti-phishing and web protection, sandbox emulation, threat emulation, threat extraction, endpoint firewall for device control, centralized logs and reporting, and automated incident response.
Check Point Harmony Endpoint has significantly strengthened the defense against malware, ransomware, phishing, and zero-day threats, and the unified agent ensures consistent protection across all endpoints. Greater visibility and control have been achieved through the centralized console, which provides real-time insight into endpoint health, vulnerabilities, patches, and compliance. This has made it much easier to detect issues early and take corrective action before they turn into real risks. Operational complexity has been reduced by having multiple protection layers in a single lightweight agent, which has simplified management. The solution provides strong protection for remote users, ensuring that wherever users are—on-site or on a remote device—they receive the same level of protection.
What needs improvement?
The management console is powerful, but some sections can be complex or require too many clicks. The reporting and dashboard could be improved by offering more popular formats with customizable dashboards that are easier to export.
Check Point Harmony Endpoint could have lighter resource usage on endpoints. The agent is generally efficient, but deploying a scan can use a lot of CPU. Faster or more intuitive policy creation would be beneficial, along with more integration with third-party tools, such as additional native integration with a
SIEM, ticket system, or device management.
Additional improvements could include faster single agent update propagation, better offline protection workflows, improved mobile device alignment, or clearer module dependency mapping.
For how long have I used the solution?
Check Point Harmony Endpoint has been used for about two years in this company. Previous work with this tool at other companies brings the total experience using Check Point and different tools from Check Point to six years.
What do I think about the stability of the solution?
Check Point Harmony Endpoint has been stable in this environment with no problems.
What do I think about the scalability of the solution?
The scalability for Check Point Harmony Endpoint is good and supports very large deployments according to the vendor documentation. Check Point
Harmony supports managing endpoints on a single management infrastructure. The single agent works for multiple operating systems and endpoint types, providing elastic growth and reducing the overall number of components.
How are customer service and support?
Customer support varies depending on the person handling the case. Some support staff are effective, while others are not as strong. Overall, the support quality is intermediate.
How would you rate customer service and support?
Which solution did I use previously and why did I switch?
Fortinet was used previously, but the switch to Check Point Harmony Endpoint was made because Fortinet did not evolve significantly. Fortinet remained the same with no evolution for the market and did not represent a revolution in security tools.
What was our ROI?
Independent tests conducted in the company to calculate the investment have shown a return on investment.
What's my experience with pricing, setup cost, and licensing?
Check Point Harmony Endpoint uses a licensing model based on a license per endpoint, with licenses typically sold as annual subscription packages. Different license packages are available depending on whether the basic, advanced, or complete version is used. The price is common or inexpensive in the market for these types of tools, and the licensing approach is flexible.
Which other solutions did I evaluate?
Different options were evaluated, including
Cloudflare and Fortinet, to update the license. Check Point Harmony Endpoint was chosen because the license is not expensive and it offers more tools for security. Check Point is always evolving in security.
What other advice do I have?
A reduction in security incidents has been observed, with a noticeable drop in malware and phishing. Check Point Harmony Endpoint blocks many threats before they reach the user, which has reduced the number of tickets the team needs to handle. Less time is spent on remediation, as the incident response is faster because the solution automates containment, such as isolating a device and stopping the malicious process. Tool complexity has been reduced because the multiple protection layers are consolidated into the agent, resulting in less time spent managing or updating tools. Improvements are measured primarily through a noticeable reduction in security incidents, faster remediation time, fewer support tickets, and improved endpoint compliance. Check Point Harmony Endpoint has helped save time by blocking threats.
Check Point Harmony Endpoint should be evaluated by taking full advantage of the unified agent, integrating it with existing workflows, and planning policies carefully from the beginning. Posture management should be used as a proactive feature, the team should be trained on the console, and the solution should be rolled out to a large environment.
Overall, Check Point Harmony Endpoint is a solid and reliable security solution. Its biggest strengths are the unified protection layer, strong ransomware defense, and comprehensive posture management. It brings together the tools needed into one platform. This review has been rated a 10 out of 10.
Which deployment model are you using for this solution?
Public Cloud
If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?