CGCOM Strengthens Its Cybersecurity with a 24/7 SOC in the Healthcare Sector

The Challenge

CGCOM is the body that brings together, coordinates, and represents all the Official Medical Associations in Spain. In addition, its services include the management of critical processes such as the prescription system and death certificates, which means its cybersecurity requirements must meet the highest standards, both at the regulatory and operational levels.

 

CGCOM, already certified under the ENS and the ISO/IEC 27001 standard, began a process to renew its SOC service in order to strengthen the security of the essential services it provides and the administrative functions delegated to it by various public administrations. The selection process lasted approximately one year and was characterized by high regulatory and operational standards, prioritizing a SIEM recognized in the CCN guidelines (such as Splunk) and a provider capable of meeting particularly demanding SLAs, commensurate with the critical nature of its services.

The Solution

To address this challenge, SIRT designed a comprehensive solution with Splunk Cloud at the core of the platform.

Building on this foundation, a security model was implemented that included:

  • 24/7 monitoring
  • incident response
  • forensic capabilities
  • addition of a new EDR
  • training, consulting, and penetration testing services

 

In addition, SIRT provided the client with specific training and adoption sessions to ensure the effective use of the solution and its ongoing development.

The result

Thanks to the solution implemented, CGCOM strengthened the security of its administrative services and essential functions, establishing a more robust protection model that is aligned with its regulatory framework.

In addition, the implementation of Splunk as a SIEM made it possible to maintain the required cybersecurity levels, ensure sustainable compliance with SLAs, and advance a strategy of continuous improvement.

As a result, SIRT was able to present a value proposition that highlighted its strengths and its ability to provide technological support in critical and regulated environments.

projects