The assessment shows that Check Point’s Enterprise and Hybrid Mesh Firewall is designed to help organizations rethink how they handle the most dangerous early phase of attacks—the first 24 hours.
Zero 1 Day malware prevention (first 24 hours):
- Check Point prevented 99.9% of new malware (no more than one day old) across a broad mix of file types: DOCX, XLSX, PDFs, EXEs, PowerShell and Bash scripts, APKs, DLLs, and archives.
- Comparative prevention rates in this Zero 1 Day test:
- Check Point: 99.9% prevention
- Zscaler: 90.9% prevention
- Fortinet: 87.7–87.8% prevention
- Cisco: 67.1% prevention
- Palo Alto Networks: 62.7% prevention
- Some vendors also had a portion of threats in “detect‑only” mode (identified but not blocked). For example, Palo Alto Networks showed 25.2% detect‑only and Fortinet 5.7% detect‑only in the Zero 1 Day test.
This early block capability matters because the report notes that the first 24 hours of a malware campaign are the most dangerous, when attacks can spread quickly and cause operational disruption.
Phishing URL prevention (first 24 hours):
- Check Point achieved a 99.74% prevention rate on newly discovered phishing and malicious URLs, missing only 1 URL in the test set.
- Comparative phishing prevention rates and missed URLs:
- Check Point: 99.74% prevention, 1 missed URL
- Palo Alto Networks: 98.69% prevention, 5 missed URLs
- Fortinet: 97.39% prevention, 10 missed URLs
- Zscaler: 91.12% prevention, 34 missed URLs
- Cisco: 55.87% prevention, 169 missed URLs
How Check Point approaches phishing differently:
- Uses a combination of reputation‑based checks and AI‑driven content analysis.
- AI models analyze elements such as corporate logos, icons, suspicious form fields, irregular spellings, redirects, and other obfuscated components.
- This dual approach is designed to keep up with phishing sites that frequently change IP addresses and domains to evade static reputation lists.
Remote user / SSE malware prevention:
- For Secure Service Edge (SSE) / FWaaS scenarios, Check Point recorded a 99% total block rate for malware targeting remote users.
- Comparative SSE malware block rates:
- Check Point: 99% total block rate
- Cisco: 96% total block rate
- Fortinet: 84% total block rate
- Zscaler: 83% total block rate
- Palo Alto Networks: 74% total block rate
For security and IT leaders, these results suggest that Check Point can help reimagine early‑stage threat handling across both on‑prem and remote user scenarios, with a particular focus on blocking new malware and phishing attempts before they gain a foothold.