From EDR to securing Active Directory at the heart of hospitals' cybersecurity concerns

By Charles Cardine
Published on 07/06/2023
From EDR to securing Active Directory at the heart of hospitals' cybersecurity concerns

Dozens of attacks a day. That’s what hospitals in France are facing. Intrusions into information systems remain rare, but last December, the South Val d’Oise Hospital Group (GHT Sud Val d’Oise) was the victim of such an attack. The hospital filed a complaint with the Public Prosecutor in Pontoise, even though the impact remained limited. More than ever, robust security tools are essential to maintain patient care.

Focus on Active Directory and EDR

According to the GHT’s CIO, Thierry-Alain Kervella, the services are facing a real paradox. “You have to be both schizophrenic and paranoid. Because the current trend requires us to move towards ever greater sharing and openness of information, while simultaneously increasing security.” A challenge made even more pressing by the institutions. The French National Cybersecurity Agency (ANSSI) has strengthened the CERT-FR control points around Active Directory. This critical element centralizes the management of accounts, resources, and permissions and can be a gateway for a takeover. The ANSSI website states that “analysis of the methods used in recent attacks highlights a resurgence in the targeting of Active Directory directories, given their role as the cornerstone of most information systems. Consequently, the low level of security of these directories endangers information systems as a whole and poses a systemic risk to organizations. ANSSI’s observations reveal a critical and recurring lack of maturity in the security of Active Directory directories.” This is why the agency is placing this element at the heart of its control points.

Another sensitive area is Endpoint Detection and Response (EDR). Antoine Guillot, CISO at the South Val d’Oise Hospital Group, observes, “Until now, EDR solutions were not very widespread. But we see that all the institutions that are attacked (Dax, South Francilien Hospital Center, Versailles, etc.) are adopting them. Their deployment has been significant lately.” This is why the South Val d’Oise Hospital Group chose to implement an EDR solution. SentinelOne’s Endpoint Security Platform protects the 6,400 workstations and 300 servers across the Group’s five sites. For the organization, relying solely on antivirus solutions that work by malware signature detection was not an option. “This strategy is only effective after the fact,” laments the CIO. “It requires constant updates. It’s like a race against time.” The dynamic behavioral analysis offered by SentinelOne therefore appealed to the teams.

The question of EDR deployment and operation remains. “The deployment was very simple and took place overnight,” recalls Antoine Guillot. “Because this solution continuously analyzes behavior, we were concerned about having too many false positive alerts, but this was quickly addressed. And on the operational side, updates are simple, performed from the central console without requiring a workstation restart.” To go even further, the service is currently being considered for a managed SOC (Security Operations Center). “SentinelOne will be able to help bring all weak signals to the console,” explains Thierry-Alain Kervella. “To do this, it needs to be integrated with the rest of the security tools.” The organization has acquired the necessary licenses for such a configuration and will be able to quickly transition to this new strategy. Aware of the lack of resources and capabilities in healthcare facilities, the SentinelOne Singularity XDR solution is a unified and centralized platform that protects endpoints, the cloud, and identity. It boasts complete and continuous scalability, enabling the automation of a range of remediation actions, hence the importance of making a strategic choice to avoid multiplying administration consoles. Even though many healthcare facilities are equipped with an EDR, several issues remain to be addressed, including securing Active Directory, a complex subject that remains the weak link and a perennial challenge for IT systems, explains Rachida Majeri, Sales Manager for the public sector. Privileged accounts carry sensitive patient data. Following last year’s acquisition of Attivo Networks, our Ranger AD solution can analyze and verify your Active Directory’s compliance with best practices and recommend actions to quickly correct any excessive privileges, reduce your attack surface, fix security vulnerabilities, and optimize your long-term security approach. Deployable as needed in SaaS or on-premises mode with minimal resources, Ranger AD requires only a single endpoint/agent for continuous auditing and no privileged access.

Marion Bois