insuranceciooutlook
8 Jan-Feb 2017In my opinionUnderstanding Insurance SecurityBy Sean Murphy, VP & CISO, Premera Blue CrossTraditionally, the healthcare industry has been reluctant to embrace the cloud. In many cases, for good reason. There were unclear supplier obligations under HIPAA along with sketchy access and data control provisions that really slowed adoption. Over the last few years, these concerns have begun to be addressed and, especially in terms of large cloud service providers, I think healthcare organizations have started to embrace the benefits of cloud computing. From a security perspective, cloud actually improves security in some ways over on-premise environments. I find that large cloud computing suppliers can provide more cost-efficient robust physical security controls, better access to highly-qualified security personnel, and best-in-class security assets. Additionally, I can expect better vulnerability management as critical updates are done with improved consistency. Another benefit is in the area of asset and data availability and recovery. In "as a service" (XaaS) models, the cost benefit for business resiliency and disaster recovery are very attractive.The first challenge is in determining real value. Security requirements are most often cited as meeting with resistance from business and even IT decision makers. But candidly, my experience is that many challenges are self-inflicted wounds coming from security technology that promises more than it can deliver. The business remembers these false starts and develops a reluctance to fund every new, shiny security technology without demonstrated value. Therefore, implementation of new security technology must better address the "people, process, technology" triad. Solutions implemented without personnel trained to use them will run inefficiently or sit idle. Security and business processes cannot operate independent of each other. Security must be built into business and IT initiatives. At the same time, security must be savvy about business processes and IT production service levels to facilitate availability and uptime.And last, new security technology and security requirements are a reality of the insurance business, especially healthcare insurance. So, we have to make sure we optimize what we already have. From there, we always need to make sure additions are complementary and measurably reduce risk by maturing our security capabilities.Quick Tips for SecurityIt starts with understanding the business. From there, I would say understand the risk. So, the first step is to know which risks are most important to the insurance sector and address them explicitly.The second step is to innovate around integration of devices or singular "point" solutions. One device that can protect, detect, and recover up and down the entire open systems interconnection (OSI) model is innovation I am interested in seeing. Ultimately, I need to have one view and machine-level learning of the threat intelligence provided by internal and external monitoring and alerting systems. Negotiating APIs with various vendors with niche solutions is a non-starter. Where is Insurance Security Heading?Keeping with the theme of integration, optimization, and cloud adoption, I would expect to see in the near future, better technology around extending and preserving corporate security policies in cloud Sean Murphy
< Page 7 | Page 9 >