BeyondTrust > Case Studies > FFVA Mutual Insurance Company Achieves HIPAA Compliance

FFVA Mutual Insurance Company Achieves HIPAA Compliance

BeyondTrust Logo
Company Size
200-1,000
Region
  • America
Country
  • United States
Product
  • PowerBroker for Windows
  • BeyondInsight
Tech Stack
  • Windows
Implementation Scale
  • Enterprise-wide Deployment
Impact Metrics
  • Cost Savings
  • Digital Expertise
  • Productivity Improvements
Technology Category
  • Cybersecurity & Privacy - Application Security
  • Cybersecurity & Privacy - Network Security
Applicable Functions
  • Business Operation
Use Cases
  • Cybersecurity
Services
  • Software Design & Engineering Services
  • System Integration
About The Customer
FFVA Mutual Insurance Company is “the choice for Workers Compensation.” As an A.M. Best A- (Excellent), FSC VIII rated insurance company, FFVA Mutual provides coverage to all business segments, including contractors, manufacturers, retail/wholesale, and service operations. The focus for FFVA Mutual is on controlling workers’ compensation costs through a staff conversant in every facet of workers compensation insurance. A unique combination of prevention-driven loss control and proactive claims management has made FFVA Mutual an industry leader in controlling costs for the insureds they serve. This has allowed continued growth across increasingly larger geographic regions, while maintaining market share and pricing integrity despite the volatility within the workers’ compensation market.
The Challenge
When Michael Romious joined FFVA Mutual five years ago as senior network systems administrator, users could bring in USB drives from home, install whatever they wanted including games, and otherwise modify their workstations. The consequence was that IT spent considerable time dealing with corrupted operating systems and had substantial expenses replacing machines. Rebuilding systems took “a lot of effort” according to Romious, and inevitably users had files in additional unexpected places, requiring manual efforts to retrieve those files. Users were down for a day or more. These incidents took time away from priority IT initiatives and required 3-24 hours each to identify the issue, mitigate and remediate. Educating users was helpful, but users still couldn’t manage themselves, particularly given increasingly sophisticated social engineering exploits.
The Solution
They initially selected a product that had seemed simple in their trials and it offered to fully automate deployment of software to local and remote employees via an intuitive web interface. It even offered remote access capabilities for remote employees. The results of a trial deployment, however, were much less than expected — important applications could not work without admin rights the way that product was designed. That’s when Romious tested PowerBroker for Windows on his personal PC. “With PowerBroker for Windows I could navigate and discover assets, identify vulnerabilities, and most importantly lock down all applications to implement least privilege and remove all admin rights from users’ PCs,” Romious discovered. And PowerBroker had flexibility in how it could be deployed and managed, which did take some time to decide, but in the end PowerBroker for Windows easily scaled to meet their enterprise needs and allow removal of admin rights from all Windows systems. PowerBroker has solved these challenges.
Operational Impact
  • Eliminating admin rights across the Windows environment has been a win-win
  • The number of incidents dramatically declined to maybe less than 20% of what they were previously
  • This change has also allowed FFVA Mutual to replace its AV solution with a lighter-weight implementation
  • FFVA Mutual users have the rights they need to run, install and utilize appropriate work-specific applications, and are prevented from installing and running applications that are not pre-authorized without making an explicit request of IT
  • On an application-by-application basis, IT can then review the risk and vulnerabilities associated with the requested application by using the BeyondInsight platform included with PowerBroker for Windows
Quantitative Benefit
  • Incidents reduced to less than 20% of previous levels

Case Study missing?

Start adding your own!

Register with your work email and create a new case study profile for your business.

Add New Record

Related Case Studies.

Contact us

Let's talk!
* Required
* Required
* Required
* Invalid email address
By submitting this form, you agree that IoT ONE may contact you with insights and marketing messaging.
No thanks, I don't want to receive any marketing emails from IoT ONE.
Submit

Thank you for your message!
We will contact you soon.