Industry: Healthcare
Challenge: Lack visibility into their external exposure, limited security resources, and legacy systems.
Results: Continuous monitoring, user exposure detection, and support for NIS2 compliance
Landspítali is Iceland's national hospital, operating across 100+ buildings and 16 locations. While relatively small on a global scale, its digital infrastructure is highly complex, covering everything from patient care to administration, all of which require the best cybersecurity possible.
Like many healthcare institutions, Landspítali faces the challenge of clinical staff focusing on patient care with little care for cybersecurity. But ransomware or system failures can impact that care in an instant. Additionally, they heavily rely on digital systems, deal with a lot of sensitive data, and fall under critical infrastructure subject to multiple compliance requirements.
The cybersecurity team, led by Auður Ester Guðlaugsdóttir (Team Lead of Operations and Infrastructure) and Guðjón Hauksson (System Administrator) share with us that, until recently, they had limited resources and budget to conduct critical and comprehensive security assessments across all hospital operations. This resulted in performing external scans manually and inconsistently, leaving them completely “blind” to their external attack surface.
The IT operations and infrastructure team are also responsible for all operations, covering Iceland’s entire hospital needs. In addition to treating patients, these operations include extensive management and administrative functions. They were also dealing with inherited systems—some with poor security practices—active development of web portals and applications, and vulnerable contractor-built sites.
Establishing security partnerships with Syndis for their SOC (security operations center) services and other services from Defend Iceland was a step in the right direction, but it wasn’t enough. They still had limited visibility into their external exposure, including user exposure such as leaked credentials and online account usage.
This left a critical gap in their security coverage.
Their struggles to get internal recognition and funding for security from the top were finally alleviated when a new CTO joined the team in 2022. He introduced them to Aftra and they immediately saw the value. They also found it to be the only product out there that could provide insight both into their external attack surface and user exposure.
Landspítali began to implement Aftra in 2023 and immediately recognized its value in addressing their blind spots. It provided them with:
Choosing Aftra also supported the hospital’s commitment to local innovation.
The team at Landspítali saw immediate benefits and measurable results from implementing Aftra.
They recognize that their cybersecurity journey requires continuous evolution to stay ahead. Achieving 100% cybersecurity is not realistic, instead their goal is to have the most comprehensive coverage possible to make them a less attractive target for hackers.
Aftra enables them to focus on where they stand versus trying to achieve “absolute security” and support them in their on-going effort to reduce their attack surface and keep their footprint as small as possible.
By implementing Aftra, Landspítali successfully transformed their approach to external security management and became proactive. The solution provided unique capabilities that complemented their existing security partnerships, while delivering the visibility and reporting needed to engage C-level leadership and support NIS2 compliance efforts.