Back

Customers

Healthdirect

Healthcare

Healthdirect Australia runs the national digital health services that Australians rely on to get trusted health advice, and that mandate comes with a corresponding obligation: the platform has to be provably secure, not just secure in theory. For a cyber security architect operating in that environment, the gap between "we found a misconfiguration" and "we know whether this misconfiguration actually matters" is where most of the risk hides.

Challenge

Healthdirect's security team could detect misconfigurations across its cloud environment, but detection alone didn't tell them much. A finding sitting on its own, without any sense of how it connected to exposed services, identity permissions, or sensitive data, gave no real indication of whether it was exploitable or just noise. Understanding actual risk meant manually piecing together an attack path from the misconfiguration to something that mattered, one finding at a time.

Solution

Healthdirect adopted Plerion largely because of how the platform surfaced information: an interface that made findings usable rather than just visible, paired with a vendor that engaged directly on feature requests and bug fixes rather than filing them away.

"The team is pretty happy with the tool. They like the attack path and how the risk prioritization is more focused. It's not like you've got 2,000 criticals and 10,000 highs, it's like, okay, these 5 or 10 really matter." - Ihab Naguib, Cyber security architect

Key benefits

  • Findings that speak two languages: Risks that used to live in security tooling and security vocabulary can now be explained to both technical and business stakeholders in terms each group can act on, without a translation step in between.
  • Visibility native tools didn't provide: Amazon Inspector, GuardDuty, and Security Hub each showed a slice of the environment, but none connected configuration data to exposure and identity the way Plerion's attack path context does.
  • Prioritization that cuts through volume: Instead of triaging thousands of criticals and highs generated by CVSS scoring, the team now works from a short list of findings confirmed to represent real, exploitable risk.
  • Time back for higher-value work: Automated reporting, remediation guidance, and API-driven workflows removed a projected 163 hours a year of manual effort, concentrated in reporting, vulnerability assessment, and remediation.

Results

The clearest outcome for Healthdirect has been external validation. Stakeholders and funders who require ongoing assurance of the platform's security posture have seen measurable improvement since Plerion went in, and that improvement carried through to a reduction in the organization's cyber insurance premiums.

Manual effort dropped alongside it. A projected 163 hours a year has come back to the team, concentrated in the areas that used to consume the most time:

  • Reporting and data aggregation - 15.2 hrs
  • Vulnerabilities and SBOM - 11.2 hrs
  • Remediation and how-to - 7.0 hrs
  • Asset and identity - 5.4 hrs
  • API and automation - 5.1 hrs

Some of that time back comes from custom automations Plerion built specifically for Healthdirect. When a firewall rule-ordering compliance gap turned up that a major cloud provider's own tooling wouldn't even flag as a bug, Plerion built a fix for it and had it running in Healthdirect's environment within about three weeks. A second one, a cross-account/external account access audit feature, is underway.

"Improvement in Healthdirect's platform security posture that our stakeholders and funders were happy to see as part of ongoing assurance." — Ihab Naguib

Want to learn more? Book a demo and see what it’s like to have real help, not just another dashboard.

Healthdirect

Found it. Fixed it. Done.

Start free. Understand your cloud in under an hour.