Isle of Wight NHS Trust increases cyber resilience with a 360-degree view of managed and unmanaged assets from ITHealth and Axonius

Isle of Wight NHS Trust is somewhat unique in that it is the only integrated acute, community, mental health and ambulance health care provider in England, serving an isolated offshore population of 140,000. Established in April 2012, the Trust employs some 4,400 staff and operates around 3,850 endpoints, with just over 300 servers.
Key Challenges
The Trust lacked endpoint and server compliance and had very limited visibility and reporting of devices. It then discovered a striking gap between managed and unmanaged assets – ‘a black hole’ representing almost a third of the physical hosts on the Trust’s network.
One of the major issues that hit us straight out of the blocks was that we had very limited reporting and visibility of our devices.
The Situation
In 2019, Jake Gully, Digital Operations Manager at Isle of Wight NHS Trust, had been newly appointed and readily understood that the immediate priority for the Trust was to address server and endpoint compliance and onboarding all devices into MDE. It was quickly apparent that the Trust had very limited visibility and reporting on its devices. With an old and broken SCCM 2007 installation and a poorly maintained and unreliable ITSM for asset management, the Trust knew that it needed greater asset visibility to achieve compliance and efficiently manage its upgrade programme.
Initial Solution
To fill the visibility gap, the Trust purchased an initial year of a ITHealth Dashboard in February 2020; it gave the Trust the visibility it needed to better manage endpoint and server compliance and provided reliable information so it could plan its upgrade and rolling replacement programs. The ITHealth Dashboard assisted the Trust to complete its Windows 10 migration programme, including the replacement of almost all its legacy server estate.
Closing the Gap
An early finding from the ITHealth Dashboard’s reporting was the striking gap between managed devices, for which IT were responsible - some 6,500 hosts - and unmanaged devices (IoT/IoMT), of which there were 2,000. “There was very little information or reporting on these unmanaged devices”, said Gully. “A black hole representing almost a third of the physical hosts on our network”. This presented a significant unmanaged attack surface for the Trust, affecting some of its most critical medical, infrastructure and security equipment.
The Trust quickly embarked on a review of the market to identify an IoT/ IoMT security provider. Four leading vendors were identified, including Axonius – all of which were invited to conduct demonstrations and a mini tender. Although the process was IT-led, demonstrations and scoring were handled jointly by colleagues from IT, Medical Electronics, Radiology, Pathology, Pharmacy and Estates teams. “Tendering was competitive, but Axonius was chosen as they demonstrated real commitment to developing the product at pace for the UK NHS market”, said Gully.
With Axonius, the Trust now has complete IoMT/IoT visibility and reporting to address device hardening and north-south segmentation; it can also prioritise risk by criticality and automate mitigation at scale.
Some Axonius favourites of the Isle of Wight NHS Trust include:
Asset risk prioritised based on impact (Patient Safety, Patient Confidentiality, and Service Disruption)
Classification of assets by device type and risk exposure per group
Actionable DSPT and Cyber Alert Dashboards for IoMT/IoT
The engagement from Axonius was excellent with fast delivery of the collectors, onboarding and training of staff in IT, Medical Electronics, Estates, Pathology, Radiology and Pharmacy. We ordered October 2022 – by the end of November, it was delivered, set-up and we were all trained!
Results
With ITHealth and Axonius for Healthcare, the Trust now benefits from granular, 360-degree security visibility of all assets – both managed and unmanaged. Jointly, ITHealth and Axonius is a key thread to helping the Trust improve cyber resilience, reduce risk and respond to evolving cyber threat – greatly assisting the Trust’s journey to achieve compliance with:
NHS Digital’s Data Security and Protection Toolkit (DSPT)
The National Cyber Security Centre’s (NCSC) Cyber Assessment Framework (CAF)
particularly to objectives A1-A3 (Managing Security Risk: Governance, Risk Management and Asset Management), B1 (Defending against cyber-attack: Service protection policies and processes) and C1 (Detecting cyber security events: Security monitoring)
National Institute of Standards and Technology (NIST) Cyber Security Framework
substantially to ‘identify’, ‘protect’ and ‘detect’

Get Started
Discover what’s achievable with a product demo, or talk to an Axonius representative.