About Landspítali
Landspítali is Iceland's national hospital, and it runs across more than 100 buildings and 16 locations. It may be small on a global scale, but its digital infrastructure is anything but simple. It reaches from patient care all the way through to administration, and every part of it needs strong cybersecurity.
What Aftra provides
- External vulnerability management
- Employee digital footprint monitoring
- Security campaigns
- Dashboard and executive reports
This story, in short
This is a story about visibility, and about how a hospital that was once blind to its external attack surface came to watch it every single day.
Along the way, you'll hear from two people who lived it: Auður Ester Guðlaugsdóttir, Team Lead of Operations and Infrastructure, and Guðjón Hauksson, System Administrator at Landspítali.
What Landspítali needed help with
The hospital knew it had gaps, but it couldn't actually see them. What it needed was:
- Real visibility into its external attack surface.
- A way to catch leaked credentials and exposed user accounts.
- Security checks that didn't rely on manual, one-off scans.
- Coverage that matched the demands of critical infrastructure and its compliance rules.
What we brought to the table
Landspítali first came across Aftra through a new CTO who joined in 2022. From there, we brought:
- Continuous monitoring of every internet-facing asset.
- Detection of compromised user credentials.
- A replacement for the slow, manual external scans they'd been running.
- Reporting that leadership could actually read and act on.
- A single view of both the external attack surface and user exposure.
The main challenge: seeing the hospital the way an attacker does
The IT operations and infrastructure team at Landspítali carries a heavy load. It runs everything for Iceland's hospital needs, from patient systems to administration and management.
Clinical staff, understandably, spend their days on patient care, so cybersecurity sits far from the front of their minds.
The problem is that ransomware or a system failure can reach patient care in an instant.
Limited visibility and resources
For a long time, the team simply didn't have the budget or resources for proper security assessments. They ran external scans by hand, and only now and then, which left them blind to their own attack surface. To make things harder, they'd inherited systems with poor security practices, alongside live web portals and contractor-built sites that came with their own risks.
A gap in the existing security stack
It's not that Landspítali had no partners. Syndis ran their security operations center, and they used services from Defend Iceland too. Those were real steps forward, but they weren't enough on their own.
The team still had very little insight into their external exposure, including leaked credentials and where staff were using work accounts online, and that turned out to be a critical gap.
The solution: one view of external and user exposure
Things changed when a new CTO joined in 2022. He won the internal recognition and funding that security had been missing, and he introduced the team to Aftra. They saw the value straight away, because Aftra was the only product they could find that showed both their external attack surface and their user exposure in one place. They started rolling it out in 2023.
The work we're proud of
Aftra went straight at the blind spots. It gave Landspítali:
- Comprehensive monitoring of internet-facing assets across their infrastructure
- The ability to identify compromised user credentials
- A proper replacement for those manual scans, all of which lined up neatly with their own vision for comprehensive security.
On a day-to-day basis, these are the few features that do the heavy lifting:
- External vulnerability management finds and assesses internet-facing assets across every domain and account, and flags the vulnerabilities sitting on them.
- Employee digital footprint shows where staff use work accounts online and whether any passwords have leaked.
- Security campaigns help staff understand where they're exposed and why it matters.
- Dashboard reports track the data and show progress to leadership.
Choosing Aftra also backed something the hospital cares about: a commitment to local innovation.
Learning on the go
Landspítali is the first to say the work is never really finished. They don't chase perfect security, because they know 100% security isn't realistic.
Instead, the goal is the widest coverage they can get, so that an attacker looks elsewhere for an easier target.
Aftra keeps them focused on where they stand rather than on some idea of absolute security, and it supports their ongoing effort to shrink their attack surface and keep their footprint small.
Lessons we carry with us
The first is that leadership buy-in changes everything. A security-focused CTO brought both visibility and funding, and without the ear of leadership, none of it would have moved.
The second is to speak the customer's language. Cyber risk only landed once it was framed in healthcare terms, including the very real threat to patient care.
The third is to complement what already works. Aftra sat alongside Syndis and added proactive, continuous coverage instead of tearing anything out.
And the fourth is that partnerships carry the load. The results came from Aftra and Syndis working together, not from any one piece on its own.
From reactive to proactive
By bringing in Aftra, Landspítali changed its whole approach to external security and became proactive. The platform added capabilities its other partnerships didn't cover, and it delivered the visibility and reporting needed to bring C-level leaders in and support the hospital's NIS2 work.
Why Landspítali sticks with Aftra
Aftra filled a gap that nothing else could. It gave the team a single view of their external attack surface and their user exposure, retired the slow manual scans, and produced reporting that leaders could follow.
It's the only product they found that covered both sides at once, and it fit their commitment to local innovation, which made the choice an easy one to stand behind.
In short: here's how we support Landspítali
- A tangible security score: Aftra gives Landspítali a score that benchmarks them against other customers. They sit at 74 today, with a goal of 80.
- Stronger user security: they can see where staff use work email online, catch passwords caught up in breaches, fix the problem, and teach better habits along the way.
- Leadership engagement: they report to management and executives in terms leaders can act on.
- Compliance support: stronger documentation helps them meet requirements, including NIS2.