IT Aduit & Assessment - Case 3

A hospital providing holistic healthcare to patients in Hong Kong
 
Size200 staffs

Service
IT Audit and Assessment with Follow-up Services

Challenge
With a number of 100+ hospitals and clinics in diverse locations, the company has been struggling for many years to centrally manage the information security and to standardize the operation procedures. Due to the lack of resource, hardly can the company spot out the potential vulnerability without regular review mechanism. Therefore, Ringus engaged to perform an one-off and in-depth assessment, and pinpoint improvement areas within the information system.

After the on-site assessment, Ringus identified large amount of security vulnerabilities and operational deficiencies, in which IT Team might not have sufficient resource to fix the problem in the short run.
 

Solution

  • Identified network security vulnerabilities and provided technical recommendations
  • Evaluated and commenced internal and external security controls
  • Provided one-year implementation plan: Document Management System and Workflow System enhancement 
  • Provided project management consultation, including project progress, budget, and timeframe.

Result
Through a series of on-site interviews, our security experts have tailor-made a one-year step-by-step implementation plan for the company to perform remediation actions, along with continuous advisory from Ringus. High-priority risk items have been addressed with appropriate corrective actions to prevent the company from security risk exposure in the short run.

In the long run, to reduce the workload of the IT Team, Ringus not only provided suggestions and alternatives for the companies to consider, but also helped integrate the Information Security Management System into the operational workflow in diverse locations.
 
Follow-up
After the assessment, Ringus has consistently updated the remediation process with the company and continually provide implementation advisory mentioned in the assessment report.
An introduction of the standardized policies and procedures has been brought to ensure appropriate security level of information handling in the daily operation.

Benefit 
The one-year implementation roadmap is embedded in the assessment report in a manner that our client can easily follow the remediation plan according to the severity level assigned.

Our team continues to work closely with our client, providing the best managerial and technical implementations advisory that are in line with clientโ€™s missions and visions.
 

More Updates

Further reading

๐—ฆ๐˜‚๐—บ๐—บ๐—ฒ๐—ฟ ๐—ต๐—ผ๐—น๐—ถ๐—ฑ๐—ฎ๐˜†๐˜€ ๐—ฎ๐—ฟ๐—ฒ ๐—ต๐—ฒ๐—ฟ๐—ฒ! ๐—›๐—ฎ๐˜ƒ๐—ฒ ๐˜†๐—ผ๐˜‚ ๐—ฝ๐—น๐—ฎ๐—ป๐—ป๐—ฒ๐—ฑ ๐˜†๐—ผ๐˜‚๐—ฟ ๐—ป๐—ฒ๐˜…๐˜ ๐˜๐—ฟ๐—ถ๐—ฝ ๐˜†๐—ฒ๐˜?

Whether you are travelling overseas, staying at a hotel, or working remotely while enjoying your vacation, there is one thing many of us rely on every day โ€” ๐—ต๐—ผ๐˜๐—ฒ๐—น ๐—ช๐—ถ-๐—™๐—ถ.After checking in, it is common to connect your laptop or phone to the hotel network without thinking twice. But have you ever wondered:โ€œ๐—–๐—ฎ๐—ป ๐—œ ๐—ฟ๐—ฒ๐—ฎ๐—น๐—น๐˜† ๐˜๐—ฟ๐˜‚๐˜€๐˜ ๐˜๐—ต๐—ถ๐˜€ ๐—ช๐—ถ-๐—™๐—ถ ๐—ป๐—ฒ๐˜๐˜„๐—ผ๐—ฟ๐—ธ?โ€Public Wi-Fi networks are convenient, but they can also become a target for attackers. A compromised hotel Wi-Fi gateway could potentially allow attackers to manipulate network traffic, redirect users to fake login pages, and steal sensitive information such as Microsoft 365 credentials.Some common risks include:๐Ÿ”น Fake Wi-Fi login portals๐Ÿ”น DNS redirection to malicious websites๐Ÿ”น Credential harvesting through fake Microsoft 365 login pages๐Ÿ”น Session hijacking attemptsA few simple steps can greatly reduce the risk:โœ… Avoid accessing sensitive accounts on unknown networksโœ… Use a trusted VPN when connecting through public Wi-Fiโœ… Enable Multi-Factor Authentication (MFA)โœ… Verify the website address before entering credentialsโœ… Avoid installing unexpected certificates or applications requested by public networks

๐—˜๐—ป๐˜๐—ฒ๐—ฟ๐—ฝ๐—ฟ๐—ถ๐˜€๐—ฒ ๐—”๐—œ ๐——๐—ผ๐—ฒ๐˜€๐—ป'๐˜ ๐—ฆ๐˜๐—ฎ๐—ฟ๐˜ ๐˜„๐—ถ๐˜๐—ต ๐—”๐—œ. ๐—œ๐˜ ๐—ฆ๐˜๐—ฎ๐—ฟ๐˜๐˜€ ๐˜„๐—ถ๐˜๐—ต ๐—”๐—ฟ๐—ฐ๐—ต๐—ถ๐˜๐—ฒ๐—ฐ๐˜๐˜‚๐—ฟ๐—ฒ.

Every organisation is asking the same question today:"๐˜๐˜ฐ๐˜ธ ๐˜ค๐˜ข๐˜ฏ ๐˜ธ๐˜ฆ ๐˜ช๐˜ฏ๐˜ต๐˜ณ๐˜ฐ๐˜ฅ๐˜ถ๐˜ค๐˜ฆ ๐˜ˆ๐˜ ๐˜ช๐˜ฏ๐˜ต๐˜ฐ ๐˜ฐ๐˜ถ๐˜ณ ๐˜ฃ๐˜ถ๐˜ด๐˜ช๐˜ฏ๐˜ฆ๐˜ด๐˜ด?"But experienced solution architects often start somewhere else.They ask:"๐˜๐˜ด ๐˜ต๐˜ฉ๐˜ฆ ๐˜ฃ๐˜ถ๐˜ด๐˜ช๐˜ฏ๐˜ฆ๐˜ด๐˜ด ๐˜ด๐˜บ๐˜ด๐˜ต๐˜ฆ๐˜ฎ ๐˜ฅ๐˜ฆ๐˜ด๐˜ช๐˜จ๐˜ฏ๐˜ฆ๐˜ฅ ๐˜ต๐˜ฐ ๐˜ด๐˜ถ๐˜ฑ๐˜ฑ๐˜ฐ๐˜ณ๐˜ต ๐˜ˆ๐˜ ๐˜ง๐˜ณ๐˜ฐ๐˜ฎ ๐˜ต๐˜ฉ๐˜ฆ ๐˜ฃ๐˜ฆ๐˜จ๐˜ช๐˜ฏ๐˜ฏ๐˜ช๐˜ฏ๐˜จ?"That's an important distinction.Modern enterprise platforms such as ๐—ข๐˜‚๐˜๐—ฆ๐˜†๐˜€๐˜๐—ฒ๐—บ๐˜€ now make it possible to build applications, workflows, integrations and AI capabilities within a single development ecosystem.Adding AI is becoming easier than ever.Designing an application that allows AI to deliver reliable business value is the real challenge.Because AI does not work in isolation.It relies on the business systems behind it.Before AI can analyse information, automate decisions or assist users, it depends on a strong enterprise foundation:๐Ÿ”ธ ๐—–๐—น๐—ฒ๐—ฎ๐—ฟ๐—น๐˜† ๐—ฑ๐—ฒ๐—ณ๐—ถ๐—ป๐—ฒ๐—ฑ ๐—ฏ๐˜‚๐˜€๐—ถ๐—ป๐—ฒ๐˜€๐˜€ ๐—ฝ๐—ฟ๐—ผ๐—ฐ๐—ฒ๐˜€๐˜€๐—ฒ๐˜€๐Ÿ”ธ ๐—ฅ๐—ฒ๐—น๐—ถ๐—ฎ๐—ฏ๐—น๐—ฒ ๐—ฎ๐—ป๐—ฑ ๐—ด๐—ผ๐˜ƒ๐—ฒ๐—ฟ๐—ป๐—ฒ๐—ฑ ๐—ฑ๐—ฎ๐˜๐—ฎ๐Ÿ”ธ ๐—ช๐—ฒ๐—น๐—น-๐—ฑ๐—ฒ๐˜€๐—ถ๐—ด๐—ป๐—ฒ๐—ฑ ๐˜€๐˜†๐˜€๐˜๐—ฒ๐—บ ๐—ถ๐—ป๐˜๐—ฒ๐—ด๐—ฟ๐—ฎ๐˜๐—ถ๐—ผ๐—ป๐˜€๐Ÿ”ธ ๐—–๐—ผ๐—ป๐˜€๐—ถ๐˜€๐˜๐—ฒ๐—ป๐˜ ๐—ฏ๐˜‚๐˜€๐—ถ๐—ป๐—ฒ๐˜€๐˜€ ๐—ฟ๐˜‚๐—น๐—ฒ๐˜€๐Ÿ”ธ ๐—”๐—ฝ๐—ฝ๐—ฟ๐—ผ๐—ฝ๐—ฟ๐—ถ๐—ฎ๐˜๐—ฒ ๐˜€๐—ฒ๐—ฐ๐˜‚๐—ฟ๐—ถ๐˜๐˜† ๐—ฎ๐—ป๐—ฑ ๐—ฎ๐—ฐ๐—ฐ๐—ฒ๐˜€๐˜€ ๐—ฐ๐—ผ๐—ป๐˜๐—ฟ๐—ผ๐—น๐˜€These are not "AI features."They are architectural decisions.When these foundations are built into the application from Day One, AI becomes a natural extension of the business rather than an isolated feature.This is why successful enterprise AI projects don't begin with selecting an AI model.They begin with designing an application architecture that allows AI, data, workflows and enterprise systems to work together seamlessly.That's where enterprise low-code platforms like ๐—ข๐˜‚๐˜๐—ฆ๐˜†๐˜€๐˜๐—ฒ๐—บ๐˜€ create long-term value.Not by simply making development faster.But by providing a platform where business applications can continuously evolve as new technologiesโ€”including AIโ€”become part of the organisation's digital journey.Before asking:"๐˜๐˜ฐ๐˜ธ ๐˜ฅ๐˜ฐ ๐˜ธ๐˜ฆ ๐˜ข๐˜ฅ๐˜ฅ ๐˜ˆ๐˜ ๐˜ต๐˜ฐ ๐˜ต๐˜ฉ๐˜ช๐˜ด ๐˜ข๐˜ฑ๐˜ฑ๐˜ญ๐˜ช๐˜ค๐˜ข๐˜ต๐˜ช๐˜ฐ๐˜ฏ?"Perhaps the better question is:"๐˜ˆ๐˜ณ๐˜ฆ ๐˜ธ๐˜ฆ ๐˜ฅ๐˜ฆ๐˜ด๐˜ช๐˜จ๐˜ฏ๐˜ช๐˜ฏ๐˜จ ๐˜ข๐˜ฏ ๐˜ข๐˜ฑ๐˜ฑ๐˜ญ๐˜ช๐˜ค๐˜ข๐˜ต๐˜ช๐˜ฐ๐˜ฏ ๐˜ต๐˜ฉ๐˜ข๐˜ต ๐˜ช๐˜ด ๐˜ณ๐˜ฆ๐˜ข๐˜ฅ๐˜บ ๐˜ต๐˜ฐ ๐˜ฆ๐˜ท๐˜ฐ๐˜ญ๐˜ท๐˜ฆ ๐˜ธ๐˜ช๐˜ต๐˜ฉ ๐˜ˆ๐˜ ๐˜ง๐˜ณ๐˜ฐ๐˜ฎ ๐˜‹๐˜ข๐˜บ ๐˜–๐˜ฏ๐˜ฆ?"Because successful enterprise AI isn't defined by the intelligence of the model.๐—œ๐˜'๐˜€ ๐—ฒ๐—ป๐—ฎ๐—ฏ๐—น๐—ฒ๐—ฑ ๐—ฏ๐˜† ๐˜๐—ต๐—ฒ ๐—ถ๐—ป๐˜๐—ฒ๐—น๐—น๐—ถ๐—ด๐—ฒ๐—ป๐—ฐ๐—ฒ ๐—ผ๐—ณ ๐˜๐—ต๐—ฒ ๐—ฎ๐—ฟ๐—ฐ๐—ต๐—ถ๐˜๐—ฒ๐—ฐ๐˜๐˜‚๐—ฟ๐—ฒ ๐—ฏ๐—ฒ๐—ต๐—ถ๐—ป๐—ฑ ๐—ถ๐˜.

๐—ฆ๐—ฒ๐—ฐ๐˜‚๐—ฟ๐—ถ๐—ป๐—ด ๐˜๐—ต๐—ฒ ๐—–๐—น๐—ผ๐˜‚๐—ฑ ๐˜„๐—ถ๐˜๐—ต ๐—œ๐—ฆ๐—ข/๐—œ๐—˜๐—– ๐Ÿฎ๐Ÿณ๐Ÿฌ๐Ÿฌ๐Ÿญ:๐Ÿฎ๐Ÿฌ๐Ÿฎ๐Ÿฎ

Cloud services have become the backbone of modern business, enabling organisations to operate with greater speed, flexibility, and scalability. However, moving to the cloud does ๐—ป๐—ผ๐˜ transfer all security responsibilities to the cloud provider.Many cloud platforms operate under a ๐˜€๐—ต๐—ฎ๐—ฟ๐—ฒ๐—ฑ ๐—ฟ๐—ฒ๐˜€๐—ฝ๐—ผ๐—ป๐˜€๐—ถ๐—ฏ๐—ถ๐—น๐—ถ๐˜๐˜† ๐—บ๐—ผ๐—ฑ๐—ฒ๐—น, where organisations remain accountable for protecting their data, identities, and cloud configurations. That's why effective cloud security requires more than selecting a trusted providerโ€”it demands clear governance, ongoing monitoring, and practical security controls.Here are three key areas organisations should focus on when securing their cloud environments:โ˜๏ธ ๐Ÿญ. ๐—จ๐—ป๐—ฑ๐—ฒ๐—ฟ๐˜€๐˜๐—ฎ๐—ป๐—ฑ ๐—ฌ๐—ผ๐˜‚๐—ฟ ๐—ฆ๐—ต๐—ฎ๐—ฟ๐—ฒ๐—ฑ ๐—ฅ๐—ฒ๐˜€๐—ฝ๐—ผ๐—ป๐˜€๐—ถ๐—ฏ๐—ถ๐—น๐—ถ๐˜๐˜†A strong cloud security strategy begins with clearly defining responsibilities between your organisation and the cloud service provider.ใƒปClearly define security roles and responsibilities between both parties.ใƒปReview the provider's security certifications, whitepapers, and control documentation.ใƒปEstablish Service Level Agreements (SLAs) covering availability, incident response, and security expectations.ใƒปRegularly evaluate the provider's security performanceโ€”not just during onboarding.๐Ÿ” ๐Ÿฎ. ๐—ฃ๐—ฟ๐—ผ๐˜๐—ฒ๐—ฐ๐˜ ๐—œ๐—ฑ๐—ฒ๐—ป๐˜๐—ถ๐˜๐—ถ๐—ฒ๐˜€ ๐—ฎ๐—ป๐—ฑ ๐——๐—ฎ๐˜๐—ฎProtecting access and sensitive information remains one of the most critical aspects of cloud security.ใƒปEnforce strong authentication, including Multi-Factor Authentication (MFA).ใƒปReview user access regularly and remove unnecessary permissions.ใƒปClassify sensitive data before migrating it to cloud environments.ใƒปEncrypt data both in transit and at rest wherever possible.๐Ÿ“Š ๐Ÿฏ. ๐— ๐—ผ๐—ป๐—ถ๐˜๐—ผ๐—ฟ ๐—ฎ๐—ป๐—ฑ ๐—•๐˜‚๐—ถ๐—น๐—ฑ ๐—ฅ๐—ฒ๐˜€๐—ถ๐—น๐—ถ๐—ฒ๐—ป๐—ฐ๐—ฒCloud security is an ongoing process that requires continuous visibility and preparedness.ใƒปMonitor cloud environments for unusual activities and configuration issues.ใƒปEnsure cloud-specific incident response procedures are clearly defined and tested.ใƒปVerify that backup processes are functioning correctly and can support recovery.ใƒป Regularly test whether critical services can be restored within acceptable recovery timeframes.Cloud security is not a one-time projectโ€”it's an ongoing discipline built on ๐—ฐ๐—น๐—ฒ๐—ฎ๐—ฟ ๐—ผ๐˜„๐—ป๐—ฒ๐—ฟ๐˜€๐—ต๐—ถ๐—ฝ, ๐—ฟ๐—ฒ๐—ด๐˜‚๐—น๐—ฎ๐—ฟ ๐—ฟ๐—ฒ๐˜ƒ๐—ถ๐—ฒ๐˜„, ๐—ฎ๐—ป๐—ฑ ๐—ฐ๐—ผ๐—ป๐˜๐—ถ๐—ป๐˜‚๐—ผ๐˜‚๐˜€ ๐—ถ๐—บ๐—ฝ๐—ฟ๐—ผ๐˜ƒ๐—ฒ๐—บ๐—ฒ๐—ป๐˜.๐—ฅ๐—ฒ๐—บ๐—ฒ๐—บ๐—ฏ๐—ฒ๐—ฟ: Moving to the cloud doesn't transfer your security responsibilitiesโ€”it changes how they should be managed.ISO/IEC 27001:2022 provides organisations with a structured framework to manage cloud-related risks while supporting business growth and digital transformation.