Success Story

Northeast Georgia Health System: Regional Healthcare Provider Sees Nearly 50% Reduction in SecOps Workload

Omdia Logo
NGHS logo

Industry

Healthcare

Employees

213

Region

United States

IT Environment

Multi-cloud

  • 60% reduction in the amount of time spent investigating false positives.
  • Nearly 50% reduction in the team’s SecOps workload.
  • 20% improvement in mean time to respond.
  • 28% risk reduction in 12-month period.
  • More efficient audits to satisfy regulatory compliance.
  • Simplified board of directors (BoD) reporting.

INTRODUCTION

Northeast Georgia Health System (NGHS) is a regional healthcare delivery provider. Operating as a not-for-profit community health system, it’s anchored by five hospital campuses, collectively with more than 1,000 beds and more than 1,500 medical staff members representing over 60 specialties.

Supporting this diverse, highly distributed environment are information systems and technology used for every aspect of care delivery and administration. This dependency puts cybersecurity on the critical path to success as a healthcare delivery provider.

It was vital for NGHS to architect and operate a secure 24/7 solution to meet the needs of its critical operating environment. This led to the healthcare provider choosing Trend Vision One™ to secure its rapidly growing hospital system’s critical data and infrastructure.

Laptop

“The last thing I want our providers to worry about is IT. I want them focused on delivering patient care.”

A LAPSE IN SECURITY CAN COMPROMISE PATIENT CARE

The complexity involved in healthcare can create more opportunities for successful cyberattacks. Aging service delivery systems and highly distributed operational environments challenge security teams to identify assets, vulnerabilities, and risks—before mitigating these risks without disrupting care. Regulatory requirements add to further challenges, as systems are often operating with protected healthcare information (PHI) data, with strict limitations on access control.

While the fundamentals of cybersecurity frameworks apply within healthcare, cybersecurity program development and management are particularly challenging for healthcare delivery providers. Despite a wellthought- out incident command center and thorough downtime procedures, the impact of a major incident could disrupt care at multiple levels.

“I’m very curious. I will advocate for my team to get the best. For us, having the right partners was key to our journey.

Stuart Samples

CTO, Northeast Georgia Health System

“I was impressed with the commitment, honesty, and delivery demonstrated by Trend Micro.”

Stuart Samples

CTO, Northeast Georgia Health System

BEFORE TREND VISION ONE

Prior to implementing this cybersecurity platform, NGHS experienced many challenges that touched multiple business areas, such as the technical environment, resourcing, and culture. These challenges included:

Fragmented visibility. As a health system, one of the core challenges reported is ensuring full visibility across the many thousands of endpoints and end users that must be properly secured and protected. Monitoring multiple platforms to gather consistent data on alerts, logs, and anomalies was a key issue. This fragmented approach made it difficult and timeconsuming to correlate security signals from different systems to get a comprehensive view of the security landscape.

Inefficient threat detection. This labor-intensive approach also made it challenging to detect and respond to malicious activities promptly, leading to delayed response times and increasing the risk of potential successful incidents. Therefore, an initial, primary objective was to improve visibility and response times.

Operational complexity. Managing multiple systems for identifying and addressing issues requires significant manual effort. Security personnel had to switch between different point products to manually piece together information, delaying investigations. The high frequency of false positives further exacerbated the problem, consuming valuable time and diverting attention from genuine threats.

Talent resource allocation. Without a centralized system, it was difficult to allocate and train security resources effectively. Multiple teams had to be notified of each alert, leading to frequent personnel overlap and inefficiencies.

BEFORE TREND VISION ONE

Prior to implementing this cybersecurity platform, NGHS experienced many challenges that touched multiple business areas, such as the technical environment, resourcing, and culture. These challenges included:

Fragmented visibility. As a health system, one of the core challenges reported is ensuring full visibility across the many thousands of endpoints and end users that must be properly secured and protected. Monitoring multiple platforms to gather consistent data on alerts, logs, and anomalies was a key issue. This fragmented approach made it difficult and timeconsuming to correlate security signals from different systems to get a comprehensive view of the security landscape.

Inefficient threat detection. This labor-intensive approach also made it challenging to detect and respond to malicious activities promptly, leading to delayed response times and increasing the risk of potential successful incidents. Therefore, an initial, primary objective was to improve visibility and response times.

Operational complexity. Managing multiple systems for identifying and addressing issues requires significant manual effort. Security personnel had to switch between different point products to manually piece together information, delaying investigations. The high frequency of false positives further exacerbated the problem, consuming valuable time and diverting attention from genuine threats.

Talent resource allocation. Without a centralized system, it was difficult to allocate and train security resources effectively. Multiple teams had to be notified of each alert, leading to frequent personnel overlap and inefficiencies.

“I was impressed with the commitment, honesty, and delivery demonstrated by Trend Micro.”

Stuart Samples

CTO, Northeast Georgia Health System

Trend Micro is a trusted advisor— not just a product or service provider. It’s a partnership.

Stuart Samples

CTO, Northeast Georgia Health System

Stuart Samples

SEEKING A SECURE, 24/7, SCALABLE SOLUTION

Stuart Samples, NGHS’s CTO, joined the organization in 2022 and began by examining its entire operating environment and security strategy. Among the first questions he asked was, “Are we leveraging our tools effectively?”

“I don’t want to assume that I’m secure…I have to know,” Samples says.

After a detailed assessment of the then-current security strategy, Samples realized that there were many prospects for improving the overall program in terms of efficacy and efficiency.

Samples saw an opportunity to think differently about securing NGHS—to strengthen his security posture and consolidate multiple security tools into a more integrated security architecture that could grow and scale with the operation. NGHS continues to expand organically and by acquisition, requiring the team to quickly secure and consolidate new systems on a continual basis.

Looking at the security vendors in use, Samples discussed prior experiences and options with his team, which led them to explore potential solution offerings with Trend. One of the first decisions made was to move from an on-premises security architecture to a cloud-delivered security strategy. He also made an early decision to consolidate security tools. These decisions ultimately resulted in committing to the Trend Vision One cybersecurity platform. Samples was impressed with the solution’s early measurable results and the commitment, honesty, and delivery delivered by Trend. These factors resulted in Samples further engaging with Trend to expand its deployment to multiple modules in Trend Vision One.

TREND VISION ONE PLATFORM IN ACTION

NGHS reports that the adoption of Trend Vision One has enabled it to secure its rapidly growing systems and data sets within its hybrid, multi-cloud operating environment. Trend Vision One is used in support of both proactive and reactive security strategies, including attack surface reduction, monitoring and assessing risk, and mitigating active threats. The Trend Vision One platform protects the network, endpoint, and email using proactive attack surface risk management (ASRM) and reactive detection and response capabilities—including extended detection and response (XDR)—to support security operations.

NGHS reports that Trend Vision One XDR capabilities have helped improve the team’s efficiency, providing centralized visibility and management across protection layers. NGHS reports previously employing six engineers to manage multiple siloed tools and now managing them with three. This equates to a 50% reduction in the team’s workload, enabling them to train on more advanced capabilities. NGHS also reports a 60% reduction in the amount of time spent investigating false positives.

NGHS further utilizes the Trend Vision One risk index within ASRM to evaluate itself holistically, including its performance against best practices and security, as well as its performance against other healthcare systems around the world. This enables NGHS to identify areas where it might have gaps or where it is particularly strong, assisting the company to focus on improving the areas most in need.

BUSINESS IMPACT

NGHS reports significant improvements fueled by Trend Vision One across the entire security program, including:

Visibility advances. Samples reports drastic improvements in asset and threat visibility from the initial implementation of Trend Vision One. Instead of occasional updates on security posture, the Trend platform provides real-time visibility into the state of the overall security program, including the top 10 threats, the current state of risk and vulnerabilities, and where to focus first.

Moving to cloud ASRM provides better visibility for endpoints, server infrastructure (virtualized), and the NGHS cloud infrastructure in AWS and Azure. It reportedly helps NGHS focus on the right alerts and prioritize the most important issues.

Risk reduction. In a 12-month period, NGHS’s risk score was reduced by 28%. “Risk reduction is our goal. We must manage the risk, but the risks are both internal and external to us, and the risks are going up,” adds Samples. “Both our organization AND our attack surface is growing in size. Our job is to react quickly to threats and risks. Visibility and management of risk is, therefore, core to our program.”

Employee retention. Samples reports spending less time replacing people on his team and less money on recruiting, enabling funding to shift

Before Trend Vision One, alert fatigue was a significant problem for Samples. But since employing the platform, the overwhelming noise has been reduced, enabling his team to prioritize and focus on what truly matters. ”Since the implementation of Trend Vision One, my team operates with a new level of energy—more engaged and more empowered to protect the organization,” says Samples. “Trend Vision One has literally made people’s lives easier.”

Faster response. “Trend Vision One is helping our team react and respond faster, improving response times by more than 20%. We’ve improved our ability to go from detection to action. In many cases we can detect and mitigate in a single step. This makes the process both faster and more efficient.”

Tools consolidation. “We evaluated tools overlap. We wanted to know, if we were to further invest in or optimize licensing, whether we would operate more efficiently. With our move to Trend Vision One, we’ve reduced the number of security tools from more than 20 to 5 or 6, reduced the complexity in both managing tools and using them, and improved the quality for our engineers. This all translates into real cost savings by preventing staff burnout and attrition.”

Compliance. “We are better equipped, today, for meeting our compliance objectives. The effort that’s required to maintain compliance is far less because we have the ability to generate high-quality data and reporting on demand.”

Executive support. “We report to the board of directors and C-suite at least quarterly, and our leaders are extremely bright and engaged. Cybersecurity is a top concern for all of us. We share healthcare-specific threats to our environment and also share industry-wide cyber threats from our Trend platform with this team.” This helps all levels of leadership visualize the ongoing risks and opportunities to more effectively fight them. “We utilize the Trend Vision One risk index to share our security posture with our leadership team, which is very powerful. Personally, I enjoy getting in front of the thought leaders of the organization. I want them to have actionable insights so that they understand how our security program is progressing.”

CONCLUSION

While the fundamentals of cybersecurity frameworks apply within healthcare, the level of diversity, third-party systems and solutions, strictly protected data requirements, and 24/7 operating environments make cybersecurity program development and management particularly challenging for healthcare delivery providers.

Security leaders supporting this environment, therefore, need all the help they can get to see, protect, and defend this diverse attack surface. Trusted partnerships with cybersecurity solution providers such as Trend are helping support security program growth and sustainability to strengthen security posture, simplify security operations, and ease program management.

The deep and trusted relationship between NGHS and Trend continues to grow, enabling NGHS to focus on patient care while operating a secure, complex environment that serves the needs of patients and care providers.

ABOUT TREND MICRO

Trend Micro, a global cybersecurity leader, helps make the world safe for exchanging digital information. Fueled by decades of security expertise, global threat research, and continuous innovation, the Trend Vision One enterprise cybersecurity platform harnesses AI to protect hundreds of thousands of organizations and millions of individuals across clouds, networks, devices, and endpoints. TrendMicro.com

Ready to transform your cybersecurity approach?