HomeCases

Cases

As an insurance underwriting firm, technology plays a critical factor in the underwriting process. Everything from artificial intelligence and machine learning (AI) to the utilization of technology to model risk and exposure – technology and a solid plan for the future is paramount. This major underwriter enlisted the expertise of Digital Forge to lead a strategic planning initiative for the technology over the next several years.

Digital Forge conducted many surveys and performed targeted technology research on the most effective modern technology toolsets and the talent and executive sponsorship needed to ensure success. Most importantly, this engagement delivered the Digital Forge assurance promise; the promise that we stand behind our research, our recommendations, and the strategic planning that comes from it. If a plan was discovered to have flaws during implementation, Digital Forge would return to the table at no additional cost to ensure that the plan would execute, and any course corrections could be made in a timely fashion.

After several months of meetings, committee discussions, and research a formal plan was created that detailed the path moving forward for approval by the governing Board of Directors. The plan was unanimously accepted, and immediate implementation approved. Twelve months into the initiative the organization saw a tremendous return on investment (ROI) and was able to detect financial abnormalities in its underwriting and was quickly able to take corrective actions to ensure the organization continued to maintain profitability.

Startups in the modern era have an uphill battle from the very start. Compliance concerns, Cybersecurity concerns, business climate, and staff retention are all common factors. If you are a technology startup, those factors multiply substantially as your SaaS services are the target of today’s Threat Actors and Cyber Criminals.

Startups in the modern era have an uphill battle from the very start. Compliance concerns, Cybersecurity concerns, business climate, and staff retention are all common factors. If you are a technology startup, those factors multiply substantially as your SaaS services are the target of today’s Threat Actors and Cyber Criminals. This startup had several obstacles to overcome including Payment Card Compliance (PCI) and ensuring compliance with HIPAA and NIST security standards. Their primary market partner also required all SaaS vendors to maintain HITRUST Attestation. Engaging with Digital Forge, the goals were to provide a baseline strategy for the SaaS platform and how to handle PCI DSS Compliance, HIPAA Compliance, and NIST Compliance. Recognizing the benefits and need for HITRUST, Digital Forge was able to provide the needed frameworks and certification services in order for this startup to be PCI DSS certified as well as HITRUST Certified.

The ability for this startup to attain was greatly enhanced by having a single point of compliance accountability in Digital Forge as well as a Compliance and Cybersecurity program that was organized to work well together. The attainment of HITRUST CSF Certification enabled them to certify against the HIUTRUST CSF framework and check the box on compliance with HIPAA, NIST, and ISO all in one clean framework from HITRUST. Enabling this startup to assess and certify on a graduated scale with HITRUST ensured they could grow and scale their compliance and cybersecurity program as they grew in size. The engagement was also structured financially to ensure that a startup’s great concern, cash flow, was not impacted with traditional upfront expenses associated with Compliance and allowed Digital Forge to craft the engagement into a predictable long-term expense that could be budgeted and remained predictable.

As a prominent Health System today, the greatest threats to operations are those which are unseen or remain undetected for some time. That data is a valuable asset that Cyber Criminals want. Such is the case with Cyber threats like Ransomware. Digital Forge was engaged to provide incident and breach response, as well as provide overall incident management.

Digital Forge deployed various tools and engaged proven methodologies to ultimately combat the threat and threat actors, assess data exfiltration, and determine the best approach to ensure compliance. Digital Forge worked with various Legal Counsels involved, the Cyber Liability Insurance Providers, and the Federal Bureau of Investigations (FBI). Digital deployed information gathering security sensors (SEIM), Endpoint Detection and Response (EDR) software and thoroughly provided deep learning forensics to ensure data was protected and that all endpoints and data points were secured. Mobile Devices were immediately secured and given a clean bill of health to ensure that patient and continuity of care could continue.

Various aspects of incident management were enacted including utilizing the Public Relations team of Digital Forge, created specifically to handle Cybersecurity Public Relations and enable tight communication protocols to ensure the mass media was being provided with the correct information in order to fulfill public reporting obligations as well as ensure the privacy and data integrity of the organization was maintained through the incident. Working together with Law Enforcement, Legal Teams, and the Executive and Management staff of the Health System, data was ultimately never exfiltrated, Digital Forge assisted with the reporting protocols needed for the US Health and Human Services and continues to assist the FBI with ongoing data for this case.

As a health provider across multiple states, the Health system faced the enormous task of undertaking Digital Transformation away from paper-based charting to paperless. This initiative required the IT Department to undertake. A serious inventory of skills and capabilities to ensure it could meet the challenges of the user base in this new environment of paperless charting.

The Director of Talent and Recruitment engaged with Digital Forge to provide oversight and guidance in reviewing the existing IT Talent and mapping a pathway to enhance the existing talent base and potential expansion of talent. Assessment tools were utilized to measure skill sets and match them accordingly to the goals of the organization. After a detailed inventory of skills and requirements were compiled, Digital Forge set forth a plan to ensure the team had the needed education and forward-thinking foundation to ensure success while recommending that additional talent be utilized to cover the gaps in short and long-term goals and ensure the most forward-thinking approach to compliance with HIPAA and modern HIT Privacy Practices.

Employee and Clinician assessments were also performed to assess the knowledge requirements needed for a successful transition to digital clinical records. Teams were excited for the ability to voice their opinions on the transformation and voice their concerns over training and adoption. The results were quantifiable; a successful migration to a leading-edge Patient Health Record system with a well-qualified team of professionals on the frontline of the IT Department prepared to take on the requirements of the organization’s forward-trajectory in Digital Transformation.

With the more recent uptick in Cybercriminal activity in the last five years, the State of New York took a very proactive approach to cybersecurity and enacted its own minimum standards and protocols for ensuring that any business operating in or within the State of New York maintains a proactive minimum-security posture.

New York 23 NYCRR 500 creates a very tight compliance requirement for cybersecurity.  As a financial company underwriting major financial transactions, the complexity of Compliance and Cybersecurity is exponentially multiplied. Digital Forge was enlisted to assist in a complete assessment and renovation of the organization’s Compliance and Cybersecurity program including the interim maintenance and management of Compliance and Cybersecurity during the transformation and deployment of the new program.

Digital Forge rolled out a complete Cybersecurity renovation from Network to Endpoint and all policy and protocols to exceed standards.Digital Forge performed a NIST and ISO evaluation utilizing the HITRUST CSF Framework as a standard and produced a compliance program focused around a leading-edge HITRUST framework which allowed for a robust program to ensure compliance.  Applying the foundations of that framework allowed for the organization’ to easily adapt protocols to ensure PCI DSS Compliance and continue to carry out its financial operations.

7 Jan HITRUST Announces

A Collaboration Effort With AWS And Microsoft Azure

FBI Warning: Email Scam to Steal Your Direct Deposit Paycheck

Over the years, cloud service providers have supported various types of shared responsibility models. Over the years they have also faced challenges that come with supporting that model; many shared responsibility models are loosely defined and vary based on the solution.

Click here to Read the Official Press Release.

https://hitrustalliance.net/press_release/hitrust-collaborates-with-aws-and-microsoft-azure-to-enhance-the-shared-responsibility-approach-for-cloud-security/

Digital Forge is a respected HITRUST CSF Assessor Firm with offering a unique approach to HITRUST CSF Attestation for organizations across a broad spectrum of industry and vertical markets.