下载PDF
实例探究 > Health and Social Services Organization Uses Arctic Wolf to Keep Patient Records Safe

Health and Social Services Organization Uses Arctic Wolf to Keep Patient Records Safe

技术
  • 网络安全和隐私 - 端点安全
  • 网络安全和隐私 - 网络安全
  • 网络安全和隐私 - 安全合规
适用行业
  • 医疗保健和医院
  • Professional Service
适用功能
  • 商业运营
  • 质量保证
用例
  • 网络安全
  • 入侵检测系统
  • 监管合规监控
  • 远程资产管理
服务
  • 云规划/设计/实施服务
  • 网络安全服务
  • 系统集成
挑战
The health and social services organization faced several challenges, including ensuring robust HIPAA compliance, executing a comprehensive security strategy in a complex IT environment with limited staff, and demonstrating that PII and ePHI are protected. The organization had a modest IT staff tasked with managing a complex IT environment, which meant its engineers had to assume several roles and had little time for hunting down security alerts generated by point security products deployed in the organization’s IT infrastructure. Cybersecurity was not their forte, but the need to secure patient and client data became increasingly important with the rise of newer threats such as WannaCry ransomware. Recognizing the gap in their expertise, the team weighed adding a managed security service provider (MSSP) solution, such as FireEye, against managing it in-house with Splunk Enterprise Security for security information and event management (SIEM). Their analysis showed they could not feasibly get all the services they needed from a traditional MSSP or an in-house SIEM without significantly increasing their budget and staffing.
关于客户
One of the nation’s oldest health and social services organizations has served children and adults with intellectual and developmental disabilities for more than 100 years. Throughout its history, the organization has pioneered new service models and developed new programs to meet the changing needs of people with disabilities and help them reach their full potential. This non-profit organization has partnered with local governments and communities to provide services across multiple states. In the course of its business, the organization stores and transfers a good deal of confidential data related to patients and others. That’s why it deployed Arctic Wolf’s SOC-as-a-service to protect electronic patient health information (ePHI) and sensitive personal identifiable information (PII) across multiple service facilities.
解决方案
Arctic Wolf’s AWN CyberSOC™ service met the organization's needs by providing a dedicated Concierge Security™ team (CST) that works as an extension of their IT team. The Arctic Wolf CST is their singular point of contact, monitoring their network and directing response to all threats. With years of security experience to draw from, the organization relies heavily on the CST’s expertise in handling its security-related matters and ensuring its data stays safe. The AWN CyberSOC service ingests thousands of daily alerts from the organization’s wide range of security products and highlights only those few that require some sort of remediation. The service combines machine intelligence to correlate incoming alerts with network flow data, behavioral analytics and threat feed subscriptions, and a dedicated CST to perform validation and triage. Additionally, the AWN CyberSOC includes unlimited log collection, so daily triage and forensics are performed across the entire network. The organization’s IT team was impressed by the AWN CyberSOC service and Arctic Wolf’s DNA, especially for the following reasons: a dedicated AWN Concierge Security team that acts as an extension of the organization’s IT staff, and is always available as a trusted security advisor; a predictable, fixed monthly service cost for continuous network monitoring with expertise for threat detection and response, which was far more cost-effective than deploying a SIEM; Arctic Wolf is an engineering-driven company that continually invests in its cloud-based SOC-as-a-service platform to meet customer demands.
运营影响
  • The organization benefited from SOC capabilities and expertise for less than the cost of one full-time employee.
  • Thousands of alerts were reduced to a few actionable incidents per week, significantly reducing alert fatigue.
  • Customized reports were provided to meet HIPAA compliance requirements.
数量效益
  • Thousands of alerts reduced to a few actionable incidents per week.

相关案例.

联系我们

欢迎与我们交流!

* Required
* Required
* Required
* Invalid email address
提交此表单,即表示您同意 IoT ONE 可以与您联系并分享洞察和营销信息。
不,谢谢,我不想收到来自 IoT ONE 的任何营销电子邮件。
提交

Thank you for your message!
We will contact you soon.