St. Luke’s University Health Network strengthens Zero Trust security and reduces vendor complexity with Forescout

St. Luke’s University Health Network strengthens Zero Trust security and reduces vendor complexity with Forescout

Healthcare organisations are increasingly strengthening cyber-resilience by improving visibility, reducing risk and adopting Zero Trust security to protect critical systems and patient care. David Finkelstein, CISO at St. Luke’s University Health Network, tells us how the organisation used the Forescout platform, integrated with Microsoft Defender and Azure, to gain real-time visibility across more than 40,000 connected devices, enforce Zero Trust policies, reduce unauthorised vendor access and streamline its cybersecurity operations.

David Finkelstein, CISO at St. Luke’s University Health Network

St. Luke’s University Health Network has strengthened its cybersecurity posture by implementing the Forescout platform to gain complete visibility across its growing estate of Internet of Medical Things (IoMT) devices and network endpoints while supporting its Zero Trust strategy.

The healthcare provider manages approximately 85k nodes. Previously, network assets and devices were tracked using infrequently updated spreadsheets and vendors could connect new devices to the network without authorisation, making it difficult to maintain an accurate view of connected assets and their security status.

By deploying the Forescout platform, which integrates with Microsoft Security Solutions including Microsoft Defender, St. Luke’s now has comprehensive asset intelligence across all device types. The platform enables the organisation to identify every connected asset, enforce security compliance and quarantine non-compliant devices where necessary. It also enhances visibility across its Microsoft Defender and Azure environments, supporting its progress towards HITRUST certification.

David Finkelstein, CISO at St. Luke’s University Health Network, said: “We’ve been able to go from having no idea, having no understanding of who owns the asset, what’s on the device to true visibility… Now, we can say, look, if you don’t meet the security requirement, see you. That’s real Zero Trust.”

The implementation has also enabled St. Luke’s to significantly improve operational efficiency and reduce cyber-risk. The organisation can now identify the location and behaviour of all connected assets in real time, while reducing the number of risk management vendors it relies on from 38 to eight. In addition, the deployment has helped create a stronger security culture, with greater awareness across the organisation of why devices may be restricted from accessing the network when they fail to meet security requirements.

We asked David Finkelstein, CISO at St. Luke’s University Health Network, further questions to find out more about the project.

How did the lack of accurate asset visibility affect security across St. Luke’s network? 


This goes back to one of the age-old statements about security: if you don’t know your assets, you can’t truly understand your risk. Residual risk is what helps you establish your risk tolerance overall, shape your security strategy, and decide where to focus your efforts. Without visibility, you’re essentially operating blind.

For us, asset visibility is the key to making sure that you can truly manage risk. In a healthcare environment, it’s not just laptops and servers. It’s medical devices, imaging systems, IV pumps, third party connections, cloud applications, remote access tools, and now even AI driven systems and agents. You need comprehensive visibility into what is connected to your network, where it is located, who owns it, what it’s doing, why it’s communicating, and what level of access it has.

Before we had that visibility, there were gaps in our understanding of the environment. Vendors were connecting devices without oversight, assets were appearing on the network without anyone knowing, and we couldn’t confidently assess our exposure. You cannot build a mature Zero Trust or risk management strategy on top of incomplete information. If you don’t know your assets, or you can’t identify them accurately via continuous asset discovery and inventory, you’re already behind before you even begin.

What were the biggest risks of relying on spreadsheets to track IoMT devices and endpoints? 


The biggest risks of relying on spreadsheets to track IoMT devices and endpoints is that they create a false sense of confidence. People assume they’re accurate because the information exists somewhere, but in reality, spreadsheets become outdated almost immediately. They rely on manual updates, different teams entering information in different ways, and people remembering to keep them current. In a healthcare environment moving as fast as ours, that simply doesn’t work.


We found that spreadsheets were often inconsistent, duplicated and easily manipulated. Different departments would maintain their own versions, vendors would provide incomplete information, and no one could confidently say which spreadsheet reflected the real environment. That becomes a massive issue when you’re dealing with thousands of IoMT devices and endpoints spread across hospitals, physician practices and clinical environments.


The real risk is that you lose operational and security awareness. If you don’t know a device exists, you can’t secure it, patch it, segment it, monitor east-west communications, or understand its behaviour. In healthcare, that risk is amplified because many of these devices are tied directly to patient care. We needed real time visibility and automated intelligence, not static documents that were outdated the moment they were created. 

How has the Forescout platform improved your ability to enforce Zero Trust across the organisation?


Forescout allowed us the ability to truly understand our environment at scale. We can see our physical assets, where they’re located, how they’re connected, whether they’re compliant, and whether they should even be on the network in the first place. When you’re managing more than 85,000 nodes across hospitals, physician practices and clinical systems, there’s simply no way to do that manually.


The platform became foundational to our Zero Trust strategy because it gives us continuous visibility and control across both managed and unmanaged assets. We’re able to identify unmanaged or rogue devices, enforce policy automatically and isolate systems when needed. That level of automation is critical in healthcare because threats move fast and downtime can directly impact patient care.


What’s also important is the scale of segmentation we’ve achieved. Many healthcare organisations spend years trying to segment one department or carve out a biomedical network. 


With Forescout, we were able to implement true macro segmentation across the enterprise while still maintaining granular control at the department and device level. It allows us to limit lateral movement and isolate issues quickly without disrupting the broader environment.


Ultimately, it changed Zero Trust from a theoretical framework into something operational and measurable across the entire organisation, aligned with a Universal Zero Trust Network Access (UZTNA) approach. 


What impact has tighter control over unauthorised vendor-connected devices had on your security posture?


It’s been a game changer.  When I started at St. Luke’s 12 years ago, vendors had unfettered access. They were constantly making changes and constantly doing things without us knowing. Apps would break, apps would stop working, apps would change fundamentally, data would be deleted and we would never know why. Vendors would lie and say they didn’t do anything or they didn’t even know an automated change was being made. That impacted business to the point where millions of dollars were lost. Changing the mindset and the technical controls around access, we now have full control of our environment. No one makes a change without us knowing it and explaining the impact. The frequency of down times has gone from 30-40 a month to maybe two to three a quarter, and those downtimes were based on misconfigurations, not vendors making changes without us knowing it.

How has integration with Microsoft Defender and Azure strengthened visibility and response capabilities? 

Here is the thing: security today comes down to speed. It’s about how quickly you can identify a problem, understand the impact, and respond before it turns into something bigger. The integrations between Forescout, Microsoft Defender and Azure have helped us significantly improve that response capability because they allow us to automate many of the lower level security actions and focus our teams on the areas that really matter.

What those integrations give us is context. Forescout provides the asset intelligence, visibility and risk prioritisation layer, while Microsoft Defender and Azure give us additional telemetry, endpoint insight and cloud awareness. When you combine those together, you get a much more complete understanding of what is happening across the environment in real time.


Instead of having analysts manually jumping between platforms trying to correlate information, we can automate investigation and response workflows. If a device becomes non-compliant, starts behaving abnormally, or creates risk, we can identify it quickly, contain threats and take action faster.


That level of integration also helps reduce operational overhead. Our teams spend less time chasing alerts and more time proactively managing risk, strengthening protections, and ensuring we maintain the highest level of security possible across the organisation. 


What benefits have you seen from reducing your risk management toolset from 38 vendors to eight?

For us, reducing 38 vendors down to eight gave us consistency and control. We needed platforms that could integrate together, share intelligence, and give us one operational view of the environment instead of forcing our teams to jump between systems trying to piece things together manually.


Forescout became a central part of that because it gave us visibility into everything connected to the network and allowed us to tie a lot of those controls together. That reduced downtime significantly because we finally had accountability and visibility into what was happening across the environment. Previously, vendors would make changes and nobody knew until something broke. That happened constantly.


Now, changes are controlled, monitored and understood before they impact operations. We spend less time reacting and troubleshooting and much more time being proactive and strategic about risk management and patient safety. 

Browse our latest issue

Intelligent CISO

View Magazine Archive