Seville, Spain
Seville, Spain
+(34) 624 816 969
In the fast-paced world of cybersecurity, where attackers use artificial intelligence to automate their campaigns, defense teams are overwhelmed by a flood of alerts that are mostly false positives or theoretical risks that have not been exploited. Aware of this problem, Check Point Software has taken a decisive step by strengthening its alliance with OpenAI, integrating next-generation cyber reasoning models into its platform. The result is Daybreak, a suite of capabilities that promises to transform the way companies manage their security posture, moving from endless lists of alerts to validated and actionable risks at a speed that exceeds attackers' exploitation capabilities.

To understand the scope of this innovation, we spoke with Jonathan Zanger, CTO of Check Point Software, who had already shared with us in Paris the company's vision for the future of cybersecurity. Now, Zanger delves into how Daybreak not only automates repetitive tasks but also incorporates a reasoning capability that mimics the cognitive process of a senior analyst. "Reasoning involves following a chain of logic through several steps: understanding what a patch actually fixes, determining whether a vulnerability can be reached given the configuration of a particular environment, connecting a credential event with an endpoint event and an email event to form a picture of what has happened," he explains.
This reasoning capability is crucial because, as Zanger points out, "models alone are not sufficient for this. They need our security context, our telemetry, and our enforcement capabilities to be useful." That combination, he clarifies, "is what we are building." In other words, Daybreak is not a simple AI assistant but a system that integrates deep knowledge from the Check Point platform with the power of OpenAI models, creating a synergy that allows security teams to focus on what really matters: mitigating demonstrated risks.
Table of contents [Show]
One of Daybreak's main contributions is Agentic Exposure Validation, a feature designed to verify which attack paths are actually exploitable in an organization's specific environment, not just theoretically possible. This approach drastically reduces the noise that consumes analysts' time, who are often overwhelmed by findings that, although technically true, are not reachable due to network segmentation, existing controls, or current configuration.
Zanger is blunt on this point: "The issue in exposure management is not about finding problems; scanners produce more findings than any team can process, ranked by severity scores that do not consider whether the issue is reachable in your environment." To address this, Daybreak's multi-agent architecture "separates real, exploitable risk from theoretical findings." That is, it analyzes whether an attacker could actually reach the vulnerable component given existing controls, segmentation, and configuration.
At this point, the collaboration with OpenAI becomes tangible. "We are now piloting OpenAI's frontier cyber models within that system," Zanger explains. "Their reasoning is applied to attack path analysis, combined with our security context and evidence." The result for the security team is a much shorter list, where each item includes the reasoning behind its importance, allowing remediation efforts to be directed at demonstrated risk rather than whatever scored highest. Although still in pilot phase with design partners, this capability promises to revolutionize vulnerability management.
Another key piece in the Daybreak ecosystem is Keystone, which advances attack path investigation and recommendation of mitigation actions. Traditionally, managing security rules has been a manual process: someone writes the rules, someone maintains them, and someone cleans up those that are no longer necessary. Keystone reverses this scheme by allowing the customer to define their security intent (what should be allowed and what should be protected), and the system automatically calculates how controls should be configured to meet it.
"The customer defines their security intent, and the system calculates how controls should be configured to fulfill it," details the CTO. This involves continuously understanding the environment, rather than waiting for someone to notice that something has changed. Incorporating frontier cyber reasoning into this process means the system can investigate: "It can analyze a possible attack path, understand what makes it viable, and identify what change would close it. The intent remains in the customer's hands; what changes is the amount of analysis and translation into policies that the system itself can assume," Zanger adds.

This automation not only saves time but also reduces human error and ensures that security policies are always aligned with business intent, even in dynamic environments where changes are constant. For companies, this represents a significant improvement in their security posture, as configurations proactively adapt to new threats and infrastructure changes.
The third highlighted tool is NexPloit, an AI solution that Check Point Research uses to stay ahead of threat actors, who are constantly evolving. "NexPloit transforms vulnerability information into verified attack material that drives our own automated development of protections. It is research infrastructure for building defenses and remains within our environment," Zanger explains.
The problem NexPloit addresses is the time gap between vulnerability disclosure and the availability of functional protection. During that period, customers are exposed. "Historically," he adds, "closing that gap meant waiting for public exploit code or doing manual analysis. We do neither: we work from vulnerability information and the patch."
OpenAI's frontier models play a crucial role here, helping with the slow parts of research: understanding what the vulnerable code does, what the patch changes, and which exploitation paths are realistic. "That allows us to reach a verified result faster. For customers, this means protection against newly disclosed vulnerabilities arrives sooner," Zanger states. Importantly, "nothing produced by this process is published openly," ensuring that competitive advantage and customer security are not compromised.
The Daybreak announcement not only represents a technological advance but also a strengthening of the strategic alliance between Check Point and OpenAI. Both companies share the vision that global cyber defense requires a collective effort. Proof of this is Check Point's support for the A call for collective action on cyber defense, launched by OpenAI at the end of August and already supported by more than 130 organizations.
Zanger emphasizes that "we protect more than 100,000 organizations, and our threat intelligence sees a broad portion of what actually happens, rather than what is theoretically possible. Advanced reasoning is most useful when grounded in that kind of context and connected to something that can act on the conclusion." This philosophy is reflected in Daybreak, which not only analyzes but also acts, closing the loop between detection and response.

For companies, the arrival of Daybreak represents a paradigm shift. It is no longer about managing alerts but understanding real risk and making informed decisions. Integrating next-generation reasoning models with Check Point's telemetry and security context allows defense teams to stay one step ahead of attackers, reducing the attack surface and optimizing resources. At a time when generative AI is transforming all sectors, as we analyzed in our article on GPT-6 Astra and the Mirage of AGI, it is crucial that security solutions evolve at the same pace.
Check Point's bet on cyber reasoning is not a mere incremental improvement but a qualitative leap that redefines how organizations should approach cybersecurity in the AI era. As Zanger rightly points out, the goal is not just to automate but to equip systems with the ability to think and act like the best analysts, but at a scale and speed impossible for humans. This trend toward AI fluency is what will mark the difference between organizations that thrive and those that fall behind in the race for digital resilience.
If you want to delve deeper into how to implement generative AI solutions in your security workflows, we recommend our step-by-step technical guide. And do not forget that the adoption of these technologies must be accompanied by an ethical and social framework, as the government proposes in its plan for a fair distribution of technology, a debate that also affects the field of cybersecurity.
Original source: ComputerWorld. Analysis and adaptation by ForgeNEX.