Cybersecurity Renewal in a Healthcare-Adjacent SME through ISO 27001-Aligned Practices
Runola, Aleksi (2025-06-18)
Cybersecurity Renewal in a Healthcare-Adjacent SME through ISO 27001-Aligned Practices
Runola, Aleksi
(18.06.2025)
Julkaisu on tekijänoikeussäännösten alainen. Teosta voi lukea ja tulostaa henkilökohtaista käyttöä varten. Käyttö kaupallisiin tarkoituksiin on kielletty.
suljettu
Julkaisun pysyvä osoite on:
https://urn.fi/URN:NBN:fi-fe2025062473323
https://urn.fi/URN:NBN:fi-fe2025062473323
Tiivistelmä
This thesis investigates the cybersecurity renewal of a Finnish SME subcontractor providing digital room reservation systems for use in healthcare facilities. Despite not processing patient data directly, the company’s systems operated in regulated environments, prompting heightened expectations from clients and regulators alike. Motivated by both internal assessments and external requirements, particularly the demand to align eventually with ISO/IEC 27001, the company undertook a comprehensive renewal process of its infrastructure and security. Through qualitative case study methodology, the thesis investigates and demonstrates the integration of international standards, national tools, and regulatory requirements into development workflows, infrastructure management, and organizational policy. It evaluates the outcomes of the renewal with a focus on technical controls, risk reduction, and alignment with maturity frameworks, while also addressing challenges such as resource constraints and the absence of dedicated security personnel. The findings contribute a transferable model for other SMEs navigating compliance and cybersecurity demands in regulated environments.