Continuous visibility
Attained continuous visibility into new assets and vulnerabilities within the ever-evolving attack surface
Health data platform gains a continuous attack surface map that shows exposed assets and critical attack vectors
Download the PDF
Attained continuous visibility into new assets and vulnerabilities within the ever-evolving attack surface
Empowered the security teams to rapidly identify, prioritize, and remediate critical issues
Gained comprehensive reporting used to support business case for adding additional resources
Security is paramount for Human API because their platform places a consumer at the center of managing their healthcare data and sharing their health data with doctors, labs, pharmacies, and other health care businesses.
Traditional assessments are point-in-time and, as a software company using Agile and DevOps methodologies, Human API understands very well that âsecurity has to be a continuous process,â adds Bell.
The business challenge for Human API is how to deliver the highest levels of security with their limited security resources, while meeting customer expectations around legacy testing approaches.
âThe CyCognito platform helps us efficiently monitor security. There are thousands of threats out there; even an army of security staff canât address them all. CyCognito helps us focus our efforts on whatâs critical.â
Megan Bell ă» Chief Privacy and Security Officer
âWe chose CyCognito because it delivers a continuous approach and focuses us on the critical security issues most likely to take place,â says Bell.
CyCognito helps Human API understand not just where they are potentially exposed, but provides them with an attack surface map showing them what assets and critical attack vectors are exposed. The clear prioritization and identification of risks by the CyCognito platform helps the security operations team be more efficient and get a greater return on investment from their security efforts.
âThe CyCognito platform helps us efficiently monitor security. There are thousands of threats out there; even an army of security staff canât address them all. CyCognito helps us focus our efforts on whatâs critical,â says Bell.
CyCognito platform benefits for Human API to-date include:
One of the ways that Human API uses CyCognito is to validate security controls, configurations and third-party partners. The Human API IT ecosystem is cloud-based, and one of the benefits of todayâs virtualized infrastructure is that a lot of security is built-in by default. But the model is also one of shared security responsibilities, and the enterprise owns proper configuration. âIn these environments, dealing with a mountain of configurations is challenging, and misconfigurations can be a primary source of vulnerability,â says Bell.
The CyCognito platform provides Human API with new insights, identifying risks not previously been known or examined, including risks with third-party partners. Those findings have helped facilitate conversations with third-party providers about the security of their interactions.
âThe CyCognito platform helps my team be more efficient because we are working from our threats to the specific assets,â says Bell. âIt delivers a first line of understanding of what needs to be considered and evaluated and possibly mitigated and/or remediated. Otherwise, we could be chasing corner cases all day.â
âThe CyCognito platform helps me figure out how to distill an overwhelming amount of information and determine what is a risk for our business.â
Megan Bell ă» Chief Privacy and Security Officer
Another use case for CyCognito at Human API is to set the context for penetration testing, which improves the benefit and quality of penetration testing. Bell notes, âThere are thousands of risks and threat vectors for any organization small or large, and the challenge is to knowwhatâs most likely to be targeted.â Penetration tests donât give you that. And, they donât provide the continuous view needed for security operations; they provide a point-in-time snapshot. According to Bell, the question becomes, âHow does one tailor a pen test? You cannot reasonably cover everything. Using CyCognito to understand the risks that are present informs how to scope a pen test and even select the methodologies.â
And Bell says that the clear identification of risks and priorities helps her justify requests for additional resources. âThe information CyCognito provides helps us prioritize our investments,â Bell says, âand thatâs always a good thing.â
Get a free scan of your attack surface and gain valuable insight into your organization's risk posture by allowing CyCognito to discover, contextualize, and test externally.
Request a Scan