Back to Customer Stories
Healthcare
2min read
September 11, 2022

Growing Health Technology Firm Supplements its VPN with Certificates and Wi-Fi with RADIUS

The company first spoke with SecureW2’s sales team at the beginning of the summer of 2022. As a burgeoning biotech company that had just received funding, they were in the early stages of establishing their structure – including their network and its security.

The Challenge: To guard against credential theft and misconfigured BYODs, the biotech firm looked for a modern approach to secure VPN and Wi-Fi access.

Deployment Timeline

This biotech customer contacted our sales team in March of 2022. With the steadily growing number of cyber-attacks leading to devastating data breaches in the industry, they knew they needed a solution that would protect both their VPN and Wi-Fi as soon as possible.

Fortunately, SecureW2 has experience rapidly deploying our solutions. The customer was able to deploy Cloud RADIUS, our onboarding solution, and our PKI within a month.

Challenges

Biotech companies like this one pave the way toward a healthier future. But the research necessary to produce innovative products takes time, and during that time, any IP developed by the company is uniquely vulnerable to cyber threats.

Our customer knew it was just a matter of time before their growing organization was exposed to such a risk – especially since, with locations in three different countries, a lot of sensitive data had to be accessed remotely.

On top of that, many of their employees use BYODs/unmanaged devices. BYODs can be a huge risk to an organization’s network because administrators must rely on the end-user to configure them properly and keep them compliant.

Quote Icon
"We had already been working on making our network efficient by moving to cloud-based infrastructure like Azure, the next step was ensuring that our BYODs, our VPN, and our Wi-Fi were secure."
TOMI, SENIOR NETWORK SECURITY ENGINEER

Every day, the company’s employees accessed sensitive company data by logging into a VPN. Each employee had their own password for the VPN, but their IT department increasingly worried that these passwords could be stolen. The potential for misconfigured BYODs only made this possibility likelier.

Solution

Having worked with many other organizations that handle sensitive data, including healthcare organizations, SecureW2 understands the importance of protecting that data. Our solutions were made with the need for discretion and security in mind.

We began by working with the customer to deploy our Public Key Infrastructure (PKI). That way, the company would be able to create certificates for their employees to log into the VPN with, as opposed to using insecure credentials. However, each employee used their own devices, and that meant the customer needed a way to equip each of those unmanaged devices with their certificates.

Fortunately, we have a top-rated solution for this problem, too: SecureW2’s easy-to-use JoinNow MultiOS, which is a dissolvable client. From an employee’s perspective, it’s as effortless as navigating to the portal, following a few simple steps, and then their device is properly configured for certificate-based authentication. JoinNow MultiOS prevents the danger of misconfiguration before it can occur and allows users to install certificates on their devices in mere minutes.

Quote Icon
"Each employee has their own level of technical skill; some might have been fine getting the certificates on their own, but we couldn’t expect that for everyone. JoinNow MultiOS gives me the peace of mind of knowing that everyone, regardless of skill, can easily configure their device for certificates"
TOMI, SENIOR NETWORK SECURITY ENGINEER

There was one more piece of the puzzle remaining, though: what would the company use to authenticate their newly installed certificates? The answer to that question is Cloud RADIUS. Cloud RADIUS is a cloud-based authentication server that was created to be used for certificate-based authentication.

Thanks to its Identity Lookup feature, Cloud RADIUS can communicate with the company’s Identity Provider, Azure AD, in real-time during authentication. That means the most up-to-date network access policies from Azure AD can be extended to their VPN and even their Wi-Fi.

Evaluating Success

The company made a lot of changes beyond simply moving from Active Directory to Azure. With our PKI, onboarding application, and Cloud RADIUS, their movement to ironclad VPN security was stunningly smooth.

As a result, all of their employees can now access the VPN remotely without having to enter in frustrating passwords each time. And of course, this also means that there’s no chance of a VPN password being stolen by a malicious third party. Their IP is safeguarded by the robust security of digital certificates.

Although they’re much more secure than before, their cybersecurity goals don’t end here. The company is strongly considering utilizing an MDM in the future, alongside SecureW2’s gateway APIs, which make it possible to deploy certificates to managed devices automatically.

Quote Icon
"This is just the beginning for us. In the future, we look forward to even easier certificate deployment with the SecureW2 gateways and the MDM of our choice"
TOMI, SENIOR NETWORK SECURITY ENGINEER

Learn More About SecureW2

Explore SecureW2's trust model, dive into our platform and product details or read more success stories.

Why SecureW2

Establish continuous trust with Dynamic PKI and Cloud RADIUS. Enforce access based on live identity, device posture, and risk context.

  • Passwordless authentication that can’t be phished
  • Works with your IdP, MDM, and security stack
  • Real-time policy engine for dynamic access control
Explore the Platform

Get the essentials on the products that power continuous enforcement.

Knowledge Base Articles

Explore practical guidance from engineers and admins deploying SecureW2.

  • Setup and configuration tutorials
  • Integration best practices with IdPs and MDMs
  • Troubleshooting guides for PKI and RADIUS