COVER story
We needed real time visibility and automated intelligence, not static documents that were outdated the moment they were created.
How did the lack of accurate asset visibility affect security across St. Luke’ s network?
This goes back to one of the age-old statements about security: if you don’ t know your assets, you can’ t truly understand your risk. Residual risk is what helps you establish your risk tolerance overall, shape your security strategy, and decide where to focus your efforts. Without visibility, you’ re essentially operating blind.
For us, asset visibility is the key to making sure that you can truly manage risk. In a healthcare environment, it’ s not just laptops and servers. It’ s medical devices, imaging systems, IV pumps, third party connections, cloud applications, remote access tools, and now even AI driven systems and agents. You need comprehensive visibility into what is connected to your network, where it is located, who owns it, what it’ s doing, why it’ s communicating, and what level of access it has.
Before we had that visibility, there were gaps in our understanding of the environment. Vendors were connecting devices without oversight, assets were appearing on the network without anyone knowing, and we couldn’ t confidently assess our exposure. You cannot build a mature Zero Trust or risk management strategy on top of incomplete information. If you don’ t know your assets, or you can’ t identify them accurately via continuous asset discovery and inventory, you’ re already behind before you even begin.
What were the biggest risks of relying on spreadsheets to track IoMT devices and endpoints?
The biggest risks of relying on spreadsheets to track IoMT devices and endpoints is that they create a false sense of confidence. People assume they’ re accurate because the information exists somewhere, but in reality, spreadsheets become outdated almost immediately. They rely on manual updates, different teams entering information in different ways, and people remembering to keep them current. In a healthcare environment moving as fast as ours, that simply doesn’ t work.
We found that spreadsheets were often inconsistent, duplicated and easily manipulated. Different departments would maintain their own versions, vendors would provide incomplete information, and no one could confidently say which spreadsheet reflected the real environment. That becomes a massive issue when you’ re dealing with thousands of IoMT devices and endpoints spread across hospitals, physician practices and clinical environments.
The real risk is that you lose operational and security awareness. If you don’ t know a device exists, you can’ t secure it, patch it, segment it, monitor eastwest communications, or understand its behaviour. In healthcare, that risk is amplified because many of these devices are tied directly to patient care. We needed real time visibility and automated intelligence, not static documents that were outdated the moment they were created.
How has the Forescout platform improved your ability to enforce Zero Trust across the organisation?
Forescout allowed us the ability to truly understand our environment at scale. We can see our physical assets, where they’ re located, how they’ re connected, whether they’ re compliant, and whether they should even be on the network in the first place. When you’ re managing more than 85,000 nodes across hospitals, physician practices and clinical systems, there’ s simply no way to do that manually.
16 WWW. INTELLIGENTCISO. COM