Healthcare
Protect patient data without taking clinical systems down.
You cannot patch a clinical device during a procedure, and you cannot block a clinician mid-shift. Security has to work around uptime that genuinely matters.
- HIPAAEvidenced
- NIST CSF 2.0Scored
- CIS Controls v8Scored
- ISO/IEC 42001Scored
The pressure
Pressures specific to this sector
Every sector has pressures. These are the ones that change what a security programme is allowed to do here.
Clinical systems that cannot be patched inside a normal maintenance window.
A severity ranking that ignores when you are allowed to act produces a queue nobody can work.
Patient data spread across systems with very different controls.
The boundary drawn on the architecture diagram is not where the data actually is.
Staff using whatever tool is fastest, including AI tools nobody approved.
The fastest tool during a shift is rarely the one that went through review.
Breach notification timelines that leave no room for slow scoping.
The clock starts before you know the blast radius, not after.
The constraint
The constraint
You cannot patch a clinical device during a procedure, and the procedure does not move.
Frameworks
What you are measured against, and what we actually do about it.
Two states, and they are not the same thing. The cards say which is which rather than listing every framework at the same weight.
HIPAA
EvidencedNo agent assesses it. What the platform gives a notification timeline is scoping speed and a complete record of who accessed and who was told.
NIST CSF 2.0
ScoredAll 106 controls across six functions, with identity, logging and asset-inventory controls answered from connected tools rather than a questionnaire.
CIS Controls v8
Scored153 safeguards across 18 controls, scoped to the implementation group you are actually held to before anything is scored.
ISO/IEC 42001
ScoredCoverage computed from what AI Guardian actually detects in usage telemetry, not from an answered questionnaire. It attests only what telemetry can satisfy.
Scored means an agent assesses that framework control by control and produces a maturity score and a gap register. Evidenced means no agent assesses it: what the platform contributes is the audit trail and the control evidence a reviewer asks to see. Neither is a compliance certification, and framework mapping is a control-evidence aid rather than a legal opinion.
The answer
How the platform works around it.
Three movements, in order. The constraint above is restated in each of them, because it is what makes this sector's version different.
See
Where the data actually is
Sensitive data detected in content rather than assumed from a system boundary, including what staff paste into external models at the egress boundary.
Decide
Risk weighed against uptime
Reachability and asset criticality weighted so a fix is scheduled against a change window rather than forced through one, with freeze windows honoured rather than overridden.
Act
Contained, then scoped fast
Containment on approval, with the blast radius established quickly enough for a notification timeline and reversibly enough to undo if the verdict was wrong.
Who does the work
The agents this sector leans on.
You can turn one on and add the others later. A connector configured for one is available to the rest.
- Detect and RespondAI GuardianShows you which AI tools your staff use, what they send to them, and gives you the controls to do something about it.
- Detect and RespondPhishing RemediationTakes a reported message from any source, works out who else got it, and removes it everywhere, once an analyst says go.
- Protect and HardenVERA Vulnerability RemediationRanks exposures on real exploit signal, writes the remediation as code against your own patterns, and drives it through your orchestrator reversibly.
- Assess and ComplyCIS Controls v8 AssessmentAssesses all 153 safeguards against CIS Controls v8, scoped to your implementation group, with the automatable ones checked automatically.
Questions
The things this sector asks first.
Will it try to patch something mid-procedure?
No. Change-freeze windows are merged from ServiceNow and your own calendars, and work that hits a freeze is held rather than forced. Autonomy is set per environment and severity, so a clinical environment can sit at manual while a corporate one does not.
How fast can we actually scope a breach?
For an email incident, Microsoft Graph enumerates every mailbox that received the message directly rather than inferring spread, and Advanced Hunting correlates who clicked. For AI usage, raw payloads archive within five minutes and are retained, so a prompt sent last quarter is still scopeable.
Does it find patient data, or just assume where it is?
It detects sensitive data in content. Prompt inspection runs Presidio and GLiNER at the egress boundary and highlights the detected entities, redacted by default. That is the opposite of assuming data is wherever a system boundary says it should be.
Can we block AI tools without blocking clinicians?
Policy is set per tool, per group and per data class, not as a blanket domain block, and a rule can allow, warn, quarantine or block. Discovery comes first: the inventory catalogues what is in use before anything is enforced.
The other sectors
- Financial servicesRegulatory pressure, high-value identity targets, and reporting that has to hold up.
- Public sectorMandated frameworks, procurement scrutiny, and constrained headcount.
- Technology and SaaSCloud-native estates, fast shipping, and customers who ask hard security questions.
- Manufacturing and OTComing soonProduction uptime, flat networks, and equipment that predates the security model.
