
Security Researchers: Digital Fighters Series
Check Point: “We are entering an entirely new phase of the digital arms race”
Avital Leshem, Group Manager of Exposure Management at Check Point, discusses the importance of looking at an organization through the eyes of an attacker, as part of CTech’s Security Researchers series.
“Every time detection capabilities improve, generation capabilities improve alongside them,” says Avital Leshem, Group Manager of Exposure Management at global cybersecurity company Check Point. “We are entering an entirely new phase of the digital arms race – faster than anything we have dealt with before – and figuring out how to keep my team one step ahead is exactly the kind of challenge I enjoy tackling.”
Within Israel’s cyber companies are small, highly specialized teams trained to think like attackers, find vulnerabilities and stay ahead of a threat landscape increasingly accelerated by AI. In this series, we meet the individuals and teams who make up this frontline of cyber: the digital fighters.
1 View gallery


Avital Leshem, Group Manager at Exposure Managementm Check Point.
(Photo: Maxim Dinshtein)
Leshem began her career as a cyber intelligence analyst in Unit 8200. After working across several cyber companies, she joined Cyberint, which was later acquired by Check Point. Today, she oversees a team of 60 threat intelligence professionals. “There is something about our work that can sometimes resemble traditional intelligence operations,” she explains. “We operate under covert identities, enter spaces where attackers communicate with one another, track actors over time and try to connect pieces of information that may not initially appear related.”
You can read the entire interview below.
ID Card
Company name: Check Point
Founders: Gil Shwed, Marius Nacht and Shlomo Kramer
Year of founding: 1993
Current number of employees: 7,000 worldwide, 3,000 in Israel
Company Description:
Check Point is a global cyber security company protecting more than 100,000 organizations worldwide. Its mission is to secure enterprises’ AI transformation. With a prevention-first approach and an open ecosystem architecture, Check Point helps organizations block advanced threats, prioritize exposures, and automate security operations across complex digital environments. The unified architecture simplifies protection across hybrid networks, multi-cloud environments, digital workspaces, and AI systems. Structured around four strategic pillars, Hybrid Mesh Network Security, Workspace Security, Exposure Management, and AI Security, Check Point delivers consistent protection and visibility across multivendor environments.
About Check Point's Security Research Team:
Check Point’s research organization is very broad, with more than 200 researchers and analysts globally. It includes experts specializing in vulnerabilities, malware, threat actors, deep technical research, threat intelligence and other areas.
I lead a team of approximately 60 cyber threat intelligence professionals who joined Check Point following the acquisition of Cyberint. We approach research from a slightly different angle: we are very close to our customers and to what is happening to them in real time.
My teams are made up of multilingual CTI experts, each of whom develops a strong understanding of the threat landscape relevant to the customers they are responsible for. They know which threat actors matter to them, which assets are critical, what could impact their business and what their security teams need to know right now.
That customer-specific view is what makes intelligence actionable. To me, that is one of the most distinctive things about the team. On the one hand, we investigate attackers and highly specialized intelligence sources. On the other, we always have to translate what we find into one very simple question: What does this mean for my customer?
What is your background in cyber, and what led you to specialize in security research?
The military opened the door to cyber security for me. I served in the 8200 intelligence unit, where I worked as a cyber intelligence analyst. In that role, I was exposed to the worlds of technology and vulnerabilities and learned techniques for online investigation and research.
I was completely drawn into the field. I could never have imagined the capabilities that were possible in cyber, and I found it fascinating to learn from brilliant (and sometimes eccentric) researchers and hackers.
Later, while studying International Relations at university, I worked in a variety of intelligence analysis roles, primarily in security, and later also in market and business research. That was also where I was first exposed to working directly with customers.
Eventually, I joined Cyberint, where I grew from a senior analyst to a team manager and ultimately to leading the department, before the company was acquired by Check Point.
What does your security research team look like in action?
On a typical day, we might move between threat actor Telegram groups, Dark Web forums, underground marketplaces, data leaks and new campaigns targeting organizations. We are constantly trying to understand not only what happened, but who is behind it, what motivates them and what they are likely to do next.
There is something about our work that can sometimes resemble traditional intelligence operations. We operate under covert identities, enter spaces where attackers communicate with one another, track actors over time and try to connect pieces of information that may not initially appear related.
For example, we might identify a new threat actor before they gain wider attention, uncover information stolen from an organization and offered for sale, or connect what appears to be an isolated incident to a much broader attack campaign. And for us, that can simply be a regular Tuesday.
How does the research team influence your company at large?
For me, one of the biggest advantages of being part of Check Point today is that we do not operate in a vacuum. If we identify something interesting in the threat intelligence world, we can connect it with technical researchers, product teams and the enormous volumes of data generated by the company’s security technologies.
Our research organization formed the foundation for Check Point’s Exposure Management business, an entire business unit focused on closing the gap between knowing and doing: identifying external risks, understanding which ones matter most, and helping customers reduce exposure before attackers can act.
We look at an organization from the outside, almost through the eyes of an attacker: What information about it is already publicly exposed? Have its employees’ credentials been compromised? Are there infrastructures impersonating the company? Is someone selling access to its network?
What matters to me is that we do not stop at “we found something interesting.” My analysts speak directly with customers, understand the broader context and help them determine what actually requires action.
For me, the critical point is reducing the time between knowing and acting. The longer an exposure remains open, the more opportunity attackers have to turn intelligence into an incident.
What has been your team’s most significant security discovery to date?
Every researcher on my team conducts threat investigations on a daily basis. But every once in a while an investigation that begins with a single incident develops into a broader exposure of a threat actor, and sometimes even leads to action in the real world.
Over the years, we have used infiltration into threat actor forums, covert identities and Human Intelligence (HUMINT) techniques, meaning intelligence gathered through direct interaction with people and threat actors, to identify hackers and fraudsters, understand how they operate and, in some cases, prevent significant damage to organizations. Some of these investigations have saved organizations millions of dollars.
Over the past two years, for example, there have been several cases in which we were able to obtain evidence proving that attackers who were attempting to extort customers for hundreds of thousands of dollars, claiming they had stolen information as part of a ransomware attack, had in fact never breached the organization at all.
Instead, they were attempting to sell old or recycled information while presenting it as newly stolen data. As a result of our investigation, the organizations were able to avoid paying the ransom.
Who or what is your 'Moby Dick'?
II see this field more as an endless arms race than a pursuit of one ultimate victory. Right now, the area I am most immersed in is AI as an attack vector.
Attackers are already using AI to automate, within minutes, attacks that once required nation-state-level resources and technical expertise available only to the most sophisticated organizations.
That changes the exposure management model as well. If attackers can move from discovery to exploitation much faster, defenders need intelligence, prioritization and remediation to work as one continuous process, not as separate steps handled over days or weeks.
On our side, my team is also using AI: for triage, to correlate intelligence sources more quickly, and to identify clues and insights that once took weeks to uncover.
But every time detection capabilities improve, generation capabilities improve alongside them. That is what makes this period so interesting. We are entering an entirely new phase of the digital arms race – faster than anything we have dealt with before – and figuring out how to keep my team one step ahead is exactly the kind of challenge I enjoy tackling.
How would you characterize the competition between research teams today?
We are all part of the same arms race, and we share common enemies. In cyber security, I have always felt that our real “competition” is against the threat actors.
At the same time, other researchers push us forward, and we learn from them. In threat intelligence specifically, competition often revolves around sources: who has the most exclusive access to underground marketplaces and who is the first to get access to the latest data leak.
What is your take on the future of the human security researcher?
I see AI as a tool with the potential to enhance the person using it, rather than necessarily replace them.
The need to constantly reinvent ourselves has always been part of security. Again, it is the same arms race. It is true that the pace today is unprecedented, but that also creates more opportunities for discovery and allows us to accelerate our own capabilities.
Beyond that, when a customer is dealing with a cyber incident, what they need is someone who can guide them through it and lead them toward a resolution. That need is not going away, and human beings will always remain the ones providing it.













