Intelligent CISO Issue 101 | Page 17

COVER story

The platform became foundational to our Zero Trust strategy because it gives us continuous visibility and control across both managed and unmanaged assets. We’ re able to identify unmanaged or rogue devices, enforce policy automatically and isolate systems when needed. That level of automation is critical in healthcare because threats move fast and downtime can directly impact patient care.
What’ s also important is the scale of segmentation we’ ve achieved. Many healthcare organisations spend years trying to segment one department or carve out a biomedical network.
With Forescout, we were able to implement true macro segmentation across the enterprise while still maintaining granular control at the department and device level. It allows us to limit lateral movement and isolate issues quickly without disrupting the broader environment.
Ultimately, it changed Zero Trust from a theoretical framework into something operational and measurable across the entire organisation, aligned with a Universal Zero Trust Network Access( UZTNA) approach.
What impact has tighter control over unauthorised vendor-connected devices had on your security posture?
It’ s been a game changer. When I started at St. Luke’ s 12 years ago, vendors had unfettered access. They were constantly making changes and constantly doing things without us knowing. Apps would break, apps would stop working, apps would change fundamentally, data would be deleted and we would never know why. Vendors would lie and say they didn’ t do anything or they didn’ t even know an automated change was being made. That impacted business to the point where millions of dollars were lost. Changing the mindset and the technical controls around access, we now have full control of our environment. No one makes a change without us knowing it and explaining the impact. The frequency of downtimes has gone from 30-40 a month to maybe two to three a quarter, and those downtimes were based on misconfigurations, not vendors making changes without us knowing it.
How has integration with Microsoft Defender and Azure strengthened visibility and response capabilities?
Here is the thing: security today comes down to speed. It’ s about how quickly you can identify a problem, understand the impact, and respond before it turns into something bigger. The integrations between Forescout, Microsoft Defender and Azure have helped us significantly improve that response capability because they allow us to automate many of the lower-level security actions and focus our teams on the areas that really matter.
What those integrations give us is context. Forescout provides the asset intelligence, visibility and risk prioritisation layer, while Microsoft Defender and Azure give us additional telemetry, endpoint insight and cloud awareness. When you combine those together, you get a much more complete understanding of what is happening across the environment in real time.
Instead of having analysts manually jumping between platforms trying to correlate information, we can automate investigation and response workflows. If a device becomes non-compliant, starts behaving abnormally, or creates risk, we can identify it quickly, contain threats and take action faster.
That level of integration also helps reduce operational overhead. Our teams spend less time chasing alerts and more time proactively managing risk, strengthening protections, and ensuring we maintain the highest level of security possible across the organisation.
What benefits have you seen from reducing your risk management toolset from 38 vendors to eight?
For us, reducing 38 vendors down to eight gave us consistency and control. We needed platforms that could integrate together, share intelligence, and give us one operational view of the environment instead of forcing our teams to jump between systems trying to piece things together manually.
Forescout became a central part of that because it gave us visibility into everything connected to the network and allowed us to tie a lot of those controls together. That reduced downtime significantly because we finally had accountability and visibility into what was happening across the environment. Previously, vendors would make changes and nobody knew until something broke. That happened constantly.
Now, changes are controlled, monitored and understood before they impact operations. We spend less time reacting and troubleshooting and much more time being proactive and strategic about risk management and patient safety.
The platform became foundational to our Zero Trust strategy because it gives us continuous visibility and control across both managed and unmanaged assets.
WWW. INTELLIGENTCISO. COM 17