Managed solutions, step by step

By Charles Cardine
Published on 07/12/2023
Managed solutions, step by step

Three years ago, Advens positioned itself with a packaged, managed Security Operations Center (SOC) offering for healthcare facilities. Given the success of this approach and the increasing threat landscape, the company renewed its contract this summer with the UniHA (CAIH) network. The protection scope has been further expanded for enhanced security.

PROVIDING 24/7 SERVICE

In 2019, the initiative stemmed from a simple observation. Most workstations in healthcare facilities were then equipped with the Windows 7 operating system, whose support was expiring. “70% of the 150,000 endpoints we were equipping were affected,” emphasizes Thomas Jan, Deputy Managing Director in charge of digital strategy at UniHA (CAIH).

We then considered how to help these facilities mitigate the risk. “To protect them, there was no simple migration option due to the highly heterogeneous application landscape.

So, a suitable solution had to be found. This resulted in a managed Endpoint Detection and Response (EDR) offering, capable of ensuring continued security and providing alerts when needed. Members of the CAIH (French Hospital Information Systems Association) and the RSSI Healthcare (Health Information Systems Security Club) were surveyed to determine which institutions would be potentially interested in combining services to obtain the best prices. “We worked extensively with the field,” emphasizes Thomas Jan. “This allowed us to create a disruptive offering, developed for and with healthcare professionals.”

Hence the choice of a 360° managed services solution that enables alerting, diagnosis, action planning, and first aid.

“Healthcare facilities don’t have the necessary internal resources to ensure their security, neither in terms of availability (24/7) nor in terms of expertise,” observes Jacky Grisey, SOC manager in charge of the run service at Advens. “The idea was therefore to democratize managed emergency response by providing a solution adaptable to each facility’s maturity and needs, and at low prices because we operate on a large scale.”

The offering is indeed highly modular. Structured around numerous work units, it is implemented through purchase orders, which are very easy for hospitals to set up. “We’re not selling a solution, we’re selling a service,” emphasizes Thomas Jan.

The formula quickly found its audience. Currently, 40% of hospital groups (GHTs) use this market. Subscriptions accelerated in 2022 and 2023, driven by the attacks and increased government support, particularly with the France Relance recovery plan. “We went from 90 to 150 clients in two years,” says Jacky Grisey. Building on this success, market players opted for renewal last July.

TOWARDS EVEN GREATER PROTECTION

The novelty of this secondary market lies in the expansion of its scope, which we will discuss later. But the fundamentals remain the same: the solution’s agnostic nature and its sovereignty.

The Réunion Hospital Group (GHT) opted for a managed SOC solution with a managed EDR in 2020. For its CISO, Stéphane Duchesne, the agnostic aspect of the approach is essential. “It’s in my best interest that the solution not be dependent on the SOC, and vice versa.” On this issue, Advens is very open. If they happen not to cover certain solutions, they are not closed to it. I submit the case to them, and they react very quickly.” This is a real advantage for healthcare facilities, which therefore have a choice of solutions and are not dependent on a single vendor. “We must be able to offer the most suitable solution to the client, according to their level of maturity and the functionalities they are looking for,” adds Frédéric Descamps, Market Manager for Public & Healthcare.

The issue of sovereignty, meanwhile, has always been an expectation of the healthcare sector, which has intensified in recent years. GDPR, European NIS directives, certification—numerous criteria are driving the adoption of sovereign solutions. The “Shared Healthcare SOC by CAIH operated by Advens” formula fully meets these expectations, and in particular the criteria of the national CARE plan (Cybersecurity, Acceleration, and Resilience of Healthcare Facilities, led by the French Digital Health Agency).

But it is now within its own scope that it is going further. With this second contract, new service units are being introduced. NDR (Network Detection and Response), mobile protection, vulnerability management, email protection—the scope is even broader. A CSIRT (Cyber Incident Response Team) is also being established to handle crises. It can deploy resources on-site if needed. “This second contract significantly expands the range of services offered,” explains Ivan Paturel, Technical Director and CISO of Grenoble-Alpes University Hospital and the Alpes Dauphiné Hospital Group. “Network probes, perimeter equipment—it incorporates more comprehensive monitoring of detection. This is how we can ultimately limit the impact of attacks.”

A TWO-STAGE DEPLOYMENT

In Grenoble, as in Réunion, it was the end of Windows 7 support that triggered the change. “We then moved from using a security solution to a monitoring service,” summarizes Stéphane Duchesne. “There was a whole change management process to undertake. Advens had everything planned for this.” Brochures, support, and packages for independent uninstallation and installation, workstation by workstation.

The deployment itself took place in two phases. For nearly six months, Grenoble first deployed the solution across all 8,500 workstations and 1,400 servers in “detection” mode. This mode aims to make adjustments based on false positives. The EDR (End Detection and Response) system reports abnormal behavior, but no protective measures are implemented. This is because the behavior may, in fact, be normal, related to the activity of certain applications. Advens’ teams, in collaboration with the University Hospital teams, continuously adjust and qualify the alerts to optimize the EDR (Electronic Data Repository) settings. As a result, false positives decrease, and the “protection” mode can be activated. The entire network is then protected, and a quarantine is implemented if an anomaly is detected on a workstation. “The key advantage here is that by pooling the experience of all its clients, the SOC (Security Operations Center) has in-depth knowledge of the evolution of healthcare applications (to detect false positives) and attacks (to block them as early as possible),” emphasizes Ivan Paturel. The proof (although in this area, one should never declare victory too soon): no major attack has affected the institution. Only a few P2-type alerts were detected and stopped promptly.

In Réunion, the deployment was carried out in stages. First, the 6,500 workstations at the University Hospital were covered, then the servers (in “detection” mode), and finally all the facilities within the Hospital Group. Now, the entire PC fleet is covered, and the server fleet is partially covered. In addition to EDR’s managed service, the facilities have switched to XDR (Extended Detection and Response). Changes to Active Directory and firewall activity are also scrutinized. “The more traces and events we analyze, the faster and more effective our detection will be.” Following this logic, the coverage area should expand further. Monitoring NDR probes (which analyze network traffic) will soon add a new dimension to the cybersecurity of Réunion’s healthcare facilities. “The market, as it’s structured, allows us to move forward step by step,” explains the CISO. “It’s modular because it’s designed in building blocks. We will continue to gradually expand its scope because we don’t have the necessary resources internally.” We need to rely on these teams of experts, available 24/7.

Marion BOIS

Learn more: Advens / CAIH Managed SOC

[pdf-embedder url=“https://www.sih-solutions.fr/wp-content/uploads/2023/12/014SIHMAG_v12p36-37.pdf”]