NHS Blood & Transplant builds long-term relationship with Integralis for proactive, practical Information Security Management

The range of security challenges NHSBT faces, particularly in the areas of governance, risk, compliance and confidentiality led the security team to seek advisors with the broadest knowledge of the information security landscape – a partner that could offer advice and assess requirements at all levels within the organisation, deliver practical solutions and provide proactive ongoing maintenance.

Business Overview

NHSBT is a Special Health Authority in the NHS. Its main responsibilities include encouraging people to donate blood, organs, tissues and stem cells, optimising the safety and supply of these life-saving products, and raising the quality, effectiveness and efficiency of blood and transplant services. It collected nearly 2 million units of blood and 3,516 organ transplants in 2009.

NHSBT has 6,000 employees, multiple sites for blood collection, research and manufacturing as well as managing the mobile blood donation service and an active web recruitment programme.

Challenge

NHSBT’s mission to “Save and Improve Lives” emphasises the critical nature of its work. Retaining public confidence in data protection whilst offering new and innovative ways to engage with potential blood and organ donors, places information security and regulatory compliance at the centre of NHSBT’s continuous improvement of group systems. The range of security challenges

NHSBT faces, particularly in the areas of governance, risk, compliance and confidentiality led the security team to seek advisors with the broadest knowledge of the information security landscape – a partner that could offer advice and assess requirements at all levels within the organisation, deliver practical solutions and provide proactive ongoing maintenance.

Solution

NHSBT has worked with Integralis since 2008. Over time, the relationship has developed as Integralis has successfully supported NHSBT with multiple information security projects – delivered on time and on budget at business and operational levels.

These projects include:

  • Hard disk and email encryption
  • ID and access management
  • User awareness and education
  • Penetration and web application testing
  • Secure Remote Access
  • Policy writing and management
  • Web filtering
  • Email security and encryption

NHSBT uses Integralis’s end-to-end services from gap analysis, vendor assessment and audit solutions to technology implementation and proactive maintenance through Integralis’s Support Services.

Benefits

“Integralis has added value at every level, as we continuously seek to enhance our security policies and operational practices. We trust their consultants’ impartial advice based upon their strong technology foundation,” says Adam Ataar.

Reducing cost of implementation
NHSBT has benefited from Integralis’ vendor relationships to lower the cost of implementation of best in class solutions.

Building workforce flexibility through secure remote access
Integralis has worked with NHSBT to create a secure infrastructure for remote workers to access critical business information

On time delivery
Working with Integralis to deliver projects consistently on time and to budget has inspired confidence which underpins ongoing investment

Commitment to Compliance
NHSBT continues to work with Integralis to maintain regulatory compliance consistent with business objectives and its integrated governance structures

Spam reduction
The consolidation of web and email management has not only enabled efficiencies with elements of the SaaS solution hosted within the cloud, but also reduced spam

Secure foundation for innovation
Using Integralis to advise on online projects such as the organ donor recruitment website, enables NHSBT to undertake innovative campaigns securely

Future

NHSBT as part of its commitment to efficiency and improved customer experience, is examining ways to offer a swifter, digital approach to registering blood donors’ details at mobile units.

Making Security Work

Integralis makes security work. By asking the right questions, our consultants resolve complex security, risk and compliance issues. This insight is essential to provide a complete end-to-end service – one designed to meet specific business objectives, not merely address individual security components.

Integralis’s proven track record gives our customers the confidence to make security decisions based on expert advice at business, management and operational levels.