下载PDF
BeyondTrust > 实例探究 > FFVA Mutual Insurance Company Achieves HIPAA Compliance
BeyondTrust Logo

FFVA Mutual Insurance Company Achieves HIPAA Compliance

技术
  • 网络安全和隐私 - 应用安全
  • 网络安全和隐私 - 网络安全
适用功能
  • 商业运营
用例
  • 网络安全
服务
  • 软件设计与工程服务
  • 系统集成
挑战
When Michael Romious joined FFVA Mutual five years ago as senior network systems administrator, users could bring in USB drives from home, install whatever they wanted including games, and otherwise modify their workstations. The consequence was that IT spent considerable time dealing with corrupted operating systems and had substantial expenses replacing machines. Rebuilding systems took “a lot of effort” according to Romious, and inevitably users had files in additional unexpected places, requiring manual efforts to retrieve those files. Users were down for a day or more. These incidents took time away from priority IT initiatives and required 3-24 hours each to identify the issue, mitigate and remediate. Educating users was helpful, but users still couldn’t manage themselves, particularly given increasingly sophisticated social engineering exploits.
关于客户
FFVA Mutual Insurance Company is “the choice for Workers Compensation.” As an A.M. Best A- (Excellent), FSC VIII rated insurance company, FFVA Mutual provides coverage to all business segments, including contractors, manufacturers, retail/wholesale, and service operations. The focus for FFVA Mutual is on controlling workers’ compensation costs through a staff conversant in every facet of workers compensation insurance. A unique combination of prevention-driven loss control and proactive claims management has made FFVA Mutual an industry leader in controlling costs for the insureds they serve. This has allowed continued growth across increasingly larger geographic regions, while maintaining market share and pricing integrity despite the volatility within the workers’ compensation market.
解决方案
They initially selected a product that had seemed simple in their trials and it offered to fully automate deployment of software to local and remote employees via an intuitive web interface. It even offered remote access capabilities for remote employees. The results of a trial deployment, however, were much less than expected — important applications could not work without admin rights the way that product was designed. That’s when Romious tested PowerBroker for Windows on his personal PC. “With PowerBroker for Windows I could navigate and discover assets, identify vulnerabilities, and most importantly lock down all applications to implement least privilege and remove all admin rights from users’ PCs,” Romious discovered. And PowerBroker had flexibility in how it could be deployed and managed, which did take some time to decide, but in the end PowerBroker for Windows easily scaled to meet their enterprise needs and allow removal of admin rights from all Windows systems. PowerBroker has solved these challenges.
运营影响
  • Eliminating admin rights across the Windows environment has been a win-win
  • The number of incidents dramatically declined to maybe less than 20% of what they were previously
  • This change has also allowed FFVA Mutual to replace its AV solution with a lighter-weight implementation
数量效益
  • Incidents reduced to less than 20% of previous levels

相关案例.

联系我们

欢迎与我们交流!

* Required
* Required
* Required
* Invalid email address
提交此表单,即表示您同意 IoT ONE 可以与您联系并分享洞察和营销信息。
不,谢谢,我不想收到来自 IoT ONE 的任何营销电子邮件。
提交

Thank you for your message!
We will contact you soon.