The group
A hospital group with more than 20 hospitals, supported by its own IT organisation of more than 50 employees.
The starting position
Unlike many remediation projects, the infrastructure itself was not the problem. The sites are soundly built, the networks are stable and the hardware in use is robust. It comprises switches and firewalls from several manufacturers, together with a large number of IT and OT clients from clinical operations.
It is precisely this mix that places demands on the network structure. Workstations, server systems and devices used in clinical operations have different protection requirements and therefore need clear boundaries between the areas they belong to.
The second problem lay one level above: manageability. More than twenty hospitals, several device generations and several manufacturer worlds mean a corresponding number of interfaces, conventions and maintenance cycles. Configuration states were held in different places, and knowledge about individual sites depended on individual people. In a team of this size, staff turnover is normal. Until now, every change meant the loss of operational knowledge that then had to be reconstructed at considerable effort.
Added to this was the administrative side. Keeping track of maintenance dates, licence terms and warranty periods across twenty hospitals is a permanent task with a high risk of error unless it is managed centrally.
The trigger
The initiative came from an audit in the context of NIS2 and KRITIS. Its findings identified two requirements that could not be met with the existing organisation: systematic vulnerability recording across the entire installed base, and central administration that works across both sites and manufacturers.
Both require complete knowledge of which systems are in operation and in what condition. That foundation was exactly what was missing in a landscape that had grown over many years.
The solution
For network segmentation and structural boundaries between areas, the group uses AIMdefense. This gives the transitions between areas a defined point at which rules take effect. In an environment with IT and OT clients, this is the prerequisite for separating the two worlds properly.
Above this sits AIM – Advanced Infrastructure Management as a central management layer across the existing infrastructure. Deliberately without replacing hardware that works: AIM is placed on top of what is already there rather than replacing it.
In practical terms this means:
- Automatic discovery of the switches in use across manufacturer and site boundaries, so the installed base is recorded completely and up to date for the first time
- Vulnerability analysis through the included VAS module, applied directly to the recorded installed base and without an additional third-party solution
- Central configuration backup: device states are backed up automatically, changes are traceable and a defined state can be restored
- Integrated wiki: for every IT workstation and every system, the operational information is held where the work is done rather than in separate repositories
- Maintenance calendar for individual systems, with deadlines for licence renewals and warranties held in one place
One platform therefore covers both requirements from the audit: inventory management and vulnerability recording are built on the same data basis instead of two separately maintained systems.
Implementation
The proof of concept and the first expansion stage were completed after three months. On this basis, the rollout is now being extended to all hospitals and IT workstations in the group.
The result
The network areas now have structural boundaries. Between them sit named transitions at which rules can be reviewed and changed. For an environment in which IT and OT clients operate within the same hospitals, this is the basis for every further security measure.
The first expansion stage also shows where the greatest organisational benefit lies: in handover. When someone changes role or hospital, their successor takes over a documented state instead of a reconstruction task. Staff turnover is therefore no longer an operational risk but an organisational process.
The device inventory is visible centrally, configurations are backed up, vulnerabilities are assessed against the actual installed base and deadlines no longer pass unnoticed. For an environment in which systems must be available around the clock, this shifts the work from reconstruction to planning. It also supports the IT management in providing the evidence that is required in a regulated environment in any case.
Ongoing operations are supported by an IT reseller from the AIM partner network, which monitors the environment around the clock from its Network Operation Center. This structure grows with the rollout.
"A KRITIS infrastructure of this size is under permanent scrutiny. Without the ability to react in real time, that cannot be achieved. The AIM approach has noticeably eased our processes at exactly this point. The proof of concept and the first expansion stage have been completed successfully. We are now moving on to the changeover of all sites and hospitals, and to further infrastructure projects together."
— Managing IT director
Key facts
| Sector | Inpatient care, hospital group |
|---|---|
| Size | more than 20 hospitals |
| Environment | Multi-vendor network, IT and OT clients |
| AIM products | AIMdefense, AIM including VAS module |
| Focus | Central administration, vulnerability analysis, documentation |
| Trigger | Audit in the context of NIS2 / KRITIS |
| IT organisation | In-house team, more than 50 employees |
| Project status | PoC and first expansion stage completed, group-wide rollout in progress |
| Duration to expansion stage 1 | 3 months |
| Follow-on services | 24/7 support from the NOC of an AIM partner |
More about AIMdefense
For the functions available for segmentation, rule sets and transitions between network areas, please see the Features page.