Protecting Corporate Mail
The information provided by Kartos XTI Watchbots enables the hospital to quickly identify the breach and its source and to carry out the necessary corrective measures to protect hospital systems.
CHALLENGE
A hospital is an organisation that belongs to the category of critical infrastructures subject to strict compliance with legal regulations on the protection of confidential patient data as well as business continuity protection. After a period of malfunction and loss of information in some communication systems, the hospital's management team accepts the need to find out, with as much certainty as possible, the existence of security breaches in its IT system. In this way, it ensures that the budget allocation for remediation will be adjusted to the real need of the risk.
Solution
The hospital’s CISO contacts Enthec Solutions and starts using the Kartos XTI Watchbots cyber intelligence and cyber security platform, which is used by the hospital’s CISO:
- It continuously tracks and monitors the Internet, the Dark Web, the Deep Web and Social Networks in real time for breach confirmation.
- Find evidence of the existence of the hospital’s security breach and the leak of institutional data and information.
- Detects the source of the security breach in a corporate email misconfiguration.
- It provides the hospital with the necessary information to carry out vulnerability remediation and risk destruction.
Result
After receiving the report with the results of the analysis performed by the Kartos XTI Watchbots platform, the hospital obtains certain proof of security breaches in its IT system, which are being exploited by cybercrime to steal critical confidential information. Thanks to the information gathered, the hospital takes the necessary actions to resolve the vulnerability and close data leaks of which it was unaware. The analysis also detected the flaw in the configuration of the mail system that had been used as a gateway to the hospital’s information. Thanks to the information detected by Kartos XTI Watchbots, the hospital implemented the following immediate corrective measures:
- Reduction of low encryption.
- Permanent updates of the security system.
- Changes in the internal communication and mailing policy.
- Tightening of the policy on compliance with the requirements of the
- Legal regulations on data protection and systems.
Once the effectiveness of the solution provided by Enthec Solutions has been verified and in order to avoid future security breaches, guarantee the integrity of the confidential information hosted in its system and know at all times the exposure in its external perimeter, the hospital permanently hires Enthec Solutions’ Cyber Intelligence and cybersecurity service. Through the Kartos XTI Watchbots platform, it obtains constant monitoring of hospital exposure on the Web, Deep Web, Dark Web and Social Networks, recurrent and continuous analysis of the hospital’s cybersecurity status and immediate detection of any vulnerability or security breach when it occurs.