Avalon Healthcare Solutions Secures Deployment with Palo Alto Networks Prt241

Title

AWS re:Invent 2022 - Avalon Healthcare Solutions secures deployment with Palo Alto Networks (PRT241)

Summary

  • Tanya Shastri from Palo Alto Networks and Jesse Webb from Avalon Healthcare Solutions presented their experiences and insights on securing cloud deployments.
  • Avalon Healthcare, a lab insights company, was born in the cloud and has a strong security strategy built from the ground up, leveraging AWS and best practices.
  • The talk covered the importance of next-gen firewalls in the public cloud, using the Log4j attack as an example to illustrate the need for advanced security measures.
  • Avalon's security strategy includes zero trust, hyper-segmentation, HIPAA minimum necessary rule, user access control, defense in depth, and building security into the company culture.
  • Palo Alto Networks has developed a Cloud Next Gen Firewall product, which Avalon uses to secure their environment, resulting in cost savings, increased security manageability, and reduced complexity.
  • The session concluded with a Q&A session and a summary of the benefits of Palo Alto Networks' security updates and threat intelligence capabilities.

Insights

  • Avalon Healthcare Solutions has successfully implemented a cloud-native security strategy, emphasizing the importance of starting with security in mind from day one.
  • The shared responsibility model in cloud security requires customers to manage their own server configurations and security structures, while the cloud provider handles infrastructure security.
  • Next-gen firewalls are essential in the cloud to protect against known and unknown threats, prevent malware downloads, and stop lateral movement within the network.
  • Palo Alto Networks' Cloud Next Gen Firewall is a managed service that integrates with AWS, providing scalability, high availability, and automation capabilities.
  • The partnership between Avalon and Palo Alto Networks demonstrates the effectiveness of combining industry-leading security practices with cloud-native solutions to protect sensitive healthcare data.
  • The session highlighted the ongoing need for robust security measures in the cloud, especially for small to medium-sized businesses that handle sensitive information, such as patient healthcare records.