- +44 1252 917000
- info@bluefort.com
Cody Technology Park,
Farnborough,
GU14 0LX
X (Twitter) Icon
LinkedIn Icon
- +44 1252 917000
- info@bluefort.com
Cody Technology Park,
Farnborough,
GU14 0LX
© Copyright BlueFort Security Ltd.
Cloud security is the practice of protecting data, applications, and systems hosted in the cloud.
Platform and Enterprise Security solutions to protect all your human and non-human identities.
OT security focuses on protecting the specialised systems that control industrial operations.
Enable your organisation to embrace AI securely.
These programs provide structured ways for ethical hackers and researchers to report security flaws.
API security involves securing the interfaces that allow software systems to communicate with each other.
From darkness to defence: Mapping your attack surface for ultimate visibility.
Secure access for every user, device and location without compromising control or visibility.
As phishing, BEC, and supply-chain attacks evolve beyond legacy defences, learn how AI based email protection can block threats before they hit inboxes.
Customer Story
The hospital’s IT team had been running a long-term project around Active Directory (AD) hygiene, identifying and closing gaps in one of the areas most targeted by external threat actors. It was also looking ahead to the Cyber Assessment Framework (CAF), and thinking about the steps it would need to take to meet new compliance requirements.
Developed by the National Cyber Security Centre (NCSC) to help organisations both achieve and demonstrate cyber resilience, NHS trusts and many other organisations in the UK healthcare industry are now subject to CAF requirements, which focus on organisations subject to the Network and Information (NIS) regulations, those within the UK’s critical national infrastructure (CNI), and those managing cyber risks related to essential services and public safety.
CAF, which now aligns with the Data Security and Protection Toolkit (DSPT), puts identity front and centre, and several directive policy requirements are prescriptive about multi-factor authentication (MFA) and identity and access management (IAM) policies. With CAF coming down the line, and being mindful of the recent Synnovis breach, the team knew it needed to take steps to put stronger identity processes in place.
All of this took place within the context of an already stretched IT security team. BlueFort Security was mindful that the last thing this NHS trust wanted, or needed, was to add another cybersecurity tool that could increase their workload.
BlueFort Security deployed Silverfort’s advanced multi-factor authentication (MFA) protection capabilities, replacing its legacy MFA solution. Working closely together, the combined team’s objective was to protect patient services and enable the stretched trust’s IT team to implement the new solution quickly and effectively, without impacting their day-to-day activity.
The new Silverfort solution gave the hospital’s IT team the ability to deploy MFA everywhere and to every account. As any NHS trust dealing with the challenge of securing identities will know, this is a big deal. The Silverfort solution also provided the ability to discover and protect service accounts (or ‘non-human identities’) to remove the threat of lateral movement within the organisation’s IT environment.
Securing privileged users is a big focus area in CAF, and historically, one that is hard to put protections around. The Silverfort deployment enabled the trust to extend MFA coverage across its privileged users, and to services that were previously unprotected, allowing for more granular controls and protection around privileged users for tools such as PowerShell and CLI.
Silverfort worked closely with BlueFort and the hospital’s IT team to replace all VPN users in one go, rather than replacing users in small increments over time, and prioritising user and service accounts with the greatest risk potential. As well as avoiding any disruption to users, which is always an inherent risk in any large-scale IT infrastructure upgrade project, the solution reduced threats to patient services without impacting the limited IT team resources.
While the project was focused on implementing an MFA solution, the trust’s IT team quickly realised the Silverfort solution would also provide the visibility they needed to solve the ongoing challenge they had been addressing around AD hygiene.
With this project, BlueFort proved that it’s possible to deploy, configure, and optimise a new MFA solution fast and without disrupting the end-user experience. Working alongside the trust’s IT team, BlueFort delivered the Silverfort rollout in just under three weeks (over the Christmas period), replacing the legacy MFA tool, and successfully migrating 88% of users over to the new system to ensure everything was up and running when staff returned in January. A single email was all it took to complete the switchover; simple, seamless, and secure.
This was made easier by BlueFort’s strategic partnership with the trust’s IT Manager and his cybersecurity team at the hospital: the driving force behind the success of the project. As Silverfort’s leading UK partner, no one was better positioned than BlueFort Security to deliver expert deployment, configuration, and continuous optimisation, ensuring maximum return on investment and significantly enhancing their cybersecurity resilience.
The architecture of the Silverfort solution was central to delivering the project quickly and successfully across so many users at once. Silverfort provides a slick end-user experience, and the speed and efficiency of the deployment meant the IT team could see tangible value from the solution immediately, without having to allocate significant additional time to achieve it.
One of the unexpected but highly valuable outcomes of selecting Silverfort was the exceptional visibility their Identity Threat Detection and Response (ITDR) provided, within the trust’s AD. The depth and clarity of the data delivered by the solution has proven to be a significant benefit, offering value well beyond the original scope of the project.
The NHS hospital trust’s IT team needed to ensure it had adequate funding available to support the implementation of the new technologies it knew it needed to meet the broader requirements outlined in CAF. As a guidelines-based framework, CAF moves away from the more prescriptive elements of DSPT towards an outcomes-focused assessment of compliance. This means teams need to be able to demonstrate the deployment, policies, and results around the controls that have been put in place, rather than simply checking a box.
While currently CAF is a guideline, the new outcomes-focused format makes compliance more complex, and this means that many trust IT departments are looking ahead, combining all potential areas of funding to meet the new standards over time. With the challenges facing the NHS trust’s IT team, and the solutions needed to meet compliance, the team needed to put a strong business case together to deliver the project.
This NHS trust funded the project with a combination of budgeted renewal funds, capital underspend, and a portion of centralised funding:
BlueFort is the UK’s leading independent Security Solutions Partner (SSP). A unique combination of people and technology focused on simplifying your cyber journey. With a curated suite of tools, products, and skills, BlueFort partners with CISOs and SecOps teams to simplify, consolidate, optimise, and transform their cybersecurity environments. Driven by industry-standard methodologies including NIST, ISO 27001, CyberEssentials+ and CTEM, BlueFort’s tightly integrated security disciplines deliver complete solutions that ensure continuous discovery, validation, and control for your organisation.
BlueFort Security is a trusted cybersecurity partner and G-Cloud 14 supplier.
Silverfort secures every dimension of identity. They are the first to deliver an end-to-end identity-security platform that is easy to deploy and won’t disrupt business operations, resulting in better security outcomes with less work. Discover every identity across every environment, analyse exposures to reduce your attack surfaces, and enforce security controls inline to stop lateral movement, ransomware, and other identity threats.
© Copyright BlueFort Security Ltd.