BeyondTrust > 实例探究 > FFVA Mutual Insurance Company Achieves HIPAA Compliance

FFVA Mutual Insurance Company Achieves HIPAA Compliance

BeyondTrust Logo
公司规模
200-1,000
地区
  • America
国家
  • United States
产品
  • PowerBroker for Windows
  • BeyondInsight
技术栈
  • Windows
实施规模
  • Enterprise-wide Deployment
影响指标
  • Cost Savings
  • Digital Expertise
  • Productivity Improvements
技术
  • 网络安全和隐私 - 应用安全
  • 网络安全和隐私 - 网络安全
适用功能
  • 商业运营
用例
  • 网络安全
服务
  • 软件设计与工程服务
  • 系统集成
关于客户
FFVA Mutual Insurance Company is “the choice for Workers Compensation.” As an A.M. Best A- (Excellent), FSC VIII rated insurance company, FFVA Mutual provides coverage to all business segments, including contractors, manufacturers, retail/wholesale, and service operations. The focus for FFVA Mutual is on controlling workers’ compensation costs through a staff conversant in every facet of workers compensation insurance. A unique combination of prevention-driven loss control and proactive claims management has made FFVA Mutual an industry leader in controlling costs for the insureds they serve. This has allowed continued growth across increasingly larger geographic regions, while maintaining market share and pricing integrity despite the volatility within the workers’ compensation market.
挑战
When Michael Romious joined FFVA Mutual five years ago as senior network systems administrator, users could bring in USB drives from home, install whatever they wanted including games, and otherwise modify their workstations. The consequence was that IT spent considerable time dealing with corrupted operating systems and had substantial expenses replacing machines. Rebuilding systems took “a lot of effort” according to Romious, and inevitably users had files in additional unexpected places, requiring manual efforts to retrieve those files. Users were down for a day or more. These incidents took time away from priority IT initiatives and required 3-24 hours each to identify the issue, mitigate and remediate. Educating users was helpful, but users still couldn’t manage themselves, particularly given increasingly sophisticated social engineering exploits.
解决方案
They initially selected a product that had seemed simple in their trials and it offered to fully automate deployment of software to local and remote employees via an intuitive web interface. It even offered remote access capabilities for remote employees. The results of a trial deployment, however, were much less than expected — important applications could not work without admin rights the way that product was designed. That’s when Romious tested PowerBroker for Windows on his personal PC. “With PowerBroker for Windows I could navigate and discover assets, identify vulnerabilities, and most importantly lock down all applications to implement least privilege and remove all admin rights from users’ PCs,” Romious discovered. And PowerBroker had flexibility in how it could be deployed and managed, which did take some time to decide, but in the end PowerBroker for Windows easily scaled to meet their enterprise needs and allow removal of admin rights from all Windows systems. PowerBroker has solved these challenges.
运营影响
  • Eliminating admin rights across the Windows environment has been a win-win
  • The number of incidents dramatically declined to maybe less than 20% of what they were previously
  • This change has also allowed FFVA Mutual to replace its AV solution with a lighter-weight implementation
  • FFVA Mutual users have the rights they need to run, install and utilize appropriate work-specific applications, and are prevented from installing and running applications that are not pre-authorized without making an explicit request of IT
  • On an application-by-application basis, IT can then review the risk and vulnerabilities associated with the requested application by using the BeyondInsight platform included with PowerBroker for Windows
数量效益
  • Incidents reduced to less than 20% of previous levels

Case Study missing?

Start adding your own!

Register with your work email and create a new case study profile for your business.

Add New Record

相关案例.

联系我们

欢迎与我们交流!
* Required
* Required
* Required
* Invalid email address
提交此表单,即表示您同意 IoT ONE 可以与您联系并分享洞察和营销信息。
不,谢谢,我不想收到来自 IoT ONE 的任何营销电子邮件。
提交

感谢您的信息!
我们会很快与你取得联系。