This session is for members.

Subscribe or log in to watch every GoSec session.

Subscribe Log in

This recording is not available yet.

Au-delà du périmètre: sécuriser l’entreprise face aux risques externes.

Download resources

About this session

Xavier Bensemhoun, a security engineer and cybersecurity evangelist at Check Point, introduces external risk management (ERM): monitoring threats that originate outside the organization's own network, such as stolen credentials, phishing sites, brand impersonation and supply-chain exposure. He cites a statistic that 83 percent of enterprise risk in 2023 was external, and describes security teams juggling around 45 disconnected tools and manual scripts to cover this ground, wasting time on already-stretched teams. He positions Check Point's Infinity ERM, built on the Cyberint acquisition, as a single cloud platform that continuously scans the internet, dark web and code repositories for exposure, contextualizes each alert, and can act on it, claiming a 98 percent takedown success rate for phishing sites. He walks through five use cases with screenshots: a stolen-credential leak from a client's infected browser, an active phishing site impersonating a brand, exposed vulnerable assets, exposed secrets on GitHub, and threat-actor intelligence tailored to sector and region. A closing Q&A covers integration with Check Point's Harmony Email product, workflow impact of consolidating tools, platform resilience, and MSSP multi-tenant licensing.

Les menaces ne s’arrêtent pas aux frontières de votre infrastructure. Attaques sur la chaîne d’approvisionnement, vulnérabilités chez les partenaires, services SaaS mal configurés… les risques externes sont partout, et souvent invisibles. Venez en savoir plus sur la pratique de gestion des risques externes et découvrez comment Infinity ERM, la solution dédiée de Check Point, vous permet de reprendre le contrôle sur ces zones d’ombre et de renforcer durablement votre posture de sécurité globale.

Key takeaways

  • Assume you do not know your full external attack surface; budget for a discovery capability (shadow IT) rather than assuming your asset inventory is complete.
  • Contextualize every leaked-credential or exposed-secret alert by recency and source before acting; a years-old leak resurfacing for the hundredth time needs different handling than a fresh one.
  • Never let employees, partners or customers store corporate portal credentials in a browser password manager; the presenter's demo traces a real leak to exactly this.
  • Monitor your supply chain's security posture continuously, not just at contract signing; two recent breaches cited (an npm-ecosystem compromise and a Salesforce partner incident) show third-party risk can hit you indirectly within days.
  • Before consolidating from many point tools to one platform, weigh the resilience trade-off explicitly: fewer moving parts reduces maintenance burden and key-person risk from unmaintained scripts, but also removes the redundancy of having other tools still working if one fails.

Speakers

Xavier Bensemhoun
Xavier Bensemhoun
SE et Évangéliste · Check Point
Xavier Bensemhoun est Expert et Évangéliste en cybersécurité chez Check Point. Il intervient régulièrement lors d’événements professionnels pour sensibiliser aux enjeux de la sécurité numérique et promouvoir les bonnes pratiques du secteur. Curieux… Read moreRead less

Xavier Bensemhoun est Expert et Évangéliste en cybersécurité chez Check Point. Il intervient régulièrement lors d’événements professionnels pour sensibiliser aux enjeux de la sécurité numérique et promouvoir les bonnes pratiques du secteur. Curieux de nature et passionné par l’exploration - aussi bien technologique que spatiale - il aime faire le lien entre cybersécurité et innovation, avec une énergie communicative.

Resources

Tags

More from GoSec 2025

Also from Xavier Bensemhoun

On the same topic

This site is registered on wpml.org as a development site. Switch to a production site key to remove this banner.