As a large healthcare provider, continuous improvement of cyber security is a critical business driver for Mehiläinen – quite literally a prerequisite for its operations.

“We have a great responsibility to ensure that patient data is securely protected and that healthcare professionals can access patient information in a secure manner. That’s why continuous cyber security development is vital for Mehiläinen, and we have been investing in it for a long time,” says Janne Siltainsuu, Head of Information Security.

Mehiläinen operates 840 locations across four countries, serves 2.1 million customers, and employs 37,000 employees and independent practitioners. The company’s revenue amounted to EUR 1.85 billion in 2023. How does a major social and healthcare services provider keep its cyber security at a top level?

How Mehiläinen prepares for cyber threats? “How we prepare for cyber threats starts with having sufficient and appropriate resources,” Siltainsuu explains.

Seven people work full-time on information security at Mehiläinen. In addition, a significant number of employees across other units have cyber security as part of their role. Alongside its internal resources, Mehiläinen works with cyber security partners such as Elisa’s Cyber Security Center, which provides 24/7 monitoring and incident response for the IT environment across all operating countries.

Mehiläinen also runs a testing programme in which the security of its external applications is regularly tested. “We also use ethical hackers to test our applications and report their findings,” Siltainsuu says.

This ensures that potential security risks are identified early and can be quickly addressed.

Versatile cyber security exercises are essential

Good planning alone is not enough when it comes to responding to threat scenarios – the execution of plans must also be practised. This is something Mehiläinen actively does.

“Continuous training is at the heart of cyber security. I often say that a plan is a beautiful dream that won’t come true unless it is practised. Exercises help identify areas in the plans that need improvement,” Siltainsuu explains.

In addition to smaller cyber security drills, Mehiläinen also conducts larger-scale exercises. In a full-day exercise held in spring 2024, Mehiläinen’s key personnel practised cyber incident response and decision-making together with Elisa’s Cyber Security Center.
“This year, we are also participating in the large-scale Tieto24 exercise,” Siltainsuu says.

Tieto24 is Finland’s largest joint preparedness exercise for critical infrastructure companies and authorities, focusing on large-scale hybrid, cyber and information disruptions.

Modernising monitoring and response capabilities with Elisa

Elisa’s Cyber Security Center became Mehiläinen’s cyber security partner in 2022 following an extensive tendering process. The goal was to improve the level of 24/7 cyber security monitoring and response – and according to Siltainsuu, this goal has been achieved exceptionally well.

“With Elisa’s support, we have developed round-the-clock monitoring and response capabilities based on the latest cyber security technologies. We can now monitor endpoints and the IT environment and respond to alerts much more effectively than before,” Siltainsuu says.

“Elisa had strong long-term experience in operating a cyber security center, solid references, and met all the criteria of a trustworthy partner. In addition, Elisa had expertise in modern cyber security technologies and was able to support us in their deployment,” Siltainsuu explains the reasons behind selecting Elisa as a partner.

Elisa’s Cyber Security Center monitors, among other things, Mehiläinen’s 13,000 endpoints, server infrastructure and network traffic across Finland, Sweden, Estonia and Germany. Elisa’s Cyber Resilience Platform service model enables dynamic monitoring of Mehiläinen’s IT environment and the integration of selected cyber security technologies into the Cyber Security Center’s operations.

“The cooperation with Elisa has been excellent. I’m pleased that our security team now has a partner that helps us get the maximum value out of the technologies we’ve chosen. We now have significantly better tools to monitor and intervene in, for example, phishing emails and situations where users open malicious messages,” Siltainsuu describes the benefits.

Elisa’s service mindset and capabilities receive praise

Siltainsuu particularly praises Elisa’s service attitude and contacts.

“It may not sound like a big thing, but for us it is important that we’ve received excellent support and assistance from Elisa whenever we’ve needed help developing our information security. Elisa has a strong ability to drive development initiatives forward, which supports continuous cyber security improvement. The technology landscape is constantly evolving – if cyber security isn’t continuously developed, you quickly fall behind.” Siltainsuu also commends Elisa’s approach to incident resolution.

“Cyber security technologies are complex and the volumes of monitored data are large, so minor errors are inevitable. Elisa has a straightforward way of informing us about issues before we even notice them, explaining the root causes, how they will be fixed, and even proposing compensation. That kind of service is first-class,” Siltainsuu says.

Thanks to smooth communication between Mehiläinen and Elisa’s Cyber Security Center, a continuous improvement model has been easy to build on a foundation of trust.

“Taking care of cyber security should be a core function of every company today,” Siltainsuu emphasizes to his peers.

​​Learn more about Elisa’s Cyber Security Services

Photo: Mehiläinen

Related articles

​How good collaboration helps Atria to improve cyber security