Download PDF
BeyondTrust > Case Studies > FFVA Mutual Insurance Company Achieves HIPAA Compliance
BeyondTrust Logo

FFVA Mutual Insurance Company Achieves HIPAA Compliance

Technology Category
  • Cybersecurity & Privacy - Application Security
  • Cybersecurity & Privacy - Network Security
Applicable Functions
  • Business Operation
Use Cases
  • Cybersecurity
Services
  • Software Design & Engineering Services
  • System Integration
The Challenge
When Michael Romious joined FFVA Mutual five years ago as senior network systems administrator, users could bring in USB drives from home, install whatever they wanted including games, and otherwise modify their workstations. The consequence was that IT spent considerable time dealing with corrupted operating systems and had substantial expenses replacing machines. Rebuilding systems took “a lot of effort” according to Romious, and inevitably users had files in additional unexpected places, requiring manual efforts to retrieve those files. Users were down for a day or more. These incidents took time away from priority IT initiatives and required 3-24 hours each to identify the issue, mitigate and remediate. Educating users was helpful, but users still couldn’t manage themselves, particularly given increasingly sophisticated social engineering exploits.
About The Customer
FFVA Mutual Insurance Company is “the choice for Workers Compensation.” As an A.M. Best A- (Excellent), FSC VIII rated insurance company, FFVA Mutual provides coverage to all business segments, including contractors, manufacturers, retail/wholesale, and service operations. The focus for FFVA Mutual is on controlling workers’ compensation costs through a staff conversant in every facet of workers compensation insurance. A unique combination of prevention-driven loss control and proactive claims management has made FFVA Mutual an industry leader in controlling costs for the insureds they serve. This has allowed continued growth across increasingly larger geographic regions, while maintaining market share and pricing integrity despite the volatility within the workers’ compensation market.
The Solution
They initially selected a product that had seemed simple in their trials and it offered to fully automate deployment of software to local and remote employees via an intuitive web interface. It even offered remote access capabilities for remote employees. The results of a trial deployment, however, were much less than expected — important applications could not work without admin rights the way that product was designed. That’s when Romious tested PowerBroker for Windows on his personal PC. “With PowerBroker for Windows I could navigate and discover assets, identify vulnerabilities, and most importantly lock down all applications to implement least privilege and remove all admin rights from users’ PCs,” Romious discovered. And PowerBroker had flexibility in how it could be deployed and managed, which did take some time to decide, but in the end PowerBroker for Windows easily scaled to meet their enterprise needs and allow removal of admin rights from all Windows systems. PowerBroker has solved these challenges.
Operational Impact
  • Eliminating admin rights across the Windows environment has been a win-win
  • The number of incidents dramatically declined to maybe less than 20% of what they were previously
  • This change has also allowed FFVA Mutual to replace its AV solution with a lighter-weight implementation
Quantitative Benefit
  • Incidents reduced to less than 20% of previous levels

Related Case Studies.

Contact us

Let's talk!

* Required
* Required
* Required
* Invalid email address
By submitting this form, you agree that IoT ONE may contact you with insights and marketing messaging.
No thanks, I don't want to receive any marketing emails from IoT ONE.
Submit

Thank you for your message!
We will contact you soon.