st lukes

ARIA S.p.A. Secures Healthcare Data for 10M Citizens

The impact of a ransomware attack from a human standpoint would be devastating. It could force facilities to shut down and deprive someone of access to critical, life-saving services. Our partnership with Rubrik has empowered us to protect the sensitive data of 10 million citizens and 32 healthcare institutions, ensuring we are resilient in the face of cyberthreats.

Roberto Nocera
Director of IT Infrastructure & Cloud Transformation Officer, ARIA
By viewing this video, you are providing your express consent that your viewing history has been captured and may be shared with our affiliates or third-party providers that may also combine with other data they collect about you, e.g. your use of their services. We and our third-party providers may use this information to present you with offers, promotions, or other marketing that we think you'll find relevant.
Watch video Download PDF Download PDF (Italian)
masthead

CHALLENGES

As the central IT hub for the healthcare system of the Lombardy Region—Italy’s most populous area—ARIA’s mission is to manage and protect highly sensitive patient data for over 40 healthcare institutions. Recognizing the increasing threat landscape in healthcare, ARIA needed to move beyond a fragmented and reactive legacy setup and adopt a modern cyber resilience strategy. 

ARIA was facing significant risks from:

Vulnerability to Ransomware

Fragmented Legacy Backup Solutions

Risk of Reputational Damage and Penalties

With the security of 10 million citizens’ sensitive health data at stake, ARIA required a comprehensive, unified platform to ensure unwavering operational continuity and regulatory compliance.
 


OUTCOMES

Partnering with Rubrik helped ARIA achieve:

$100k/year TCO Savings

by leveraging Rubrik Cloud Vault for a cost-effective, air-gapped cyber vault with immutable data copies.

5:1 Tool Consolidation Ratio

removed legacy complexity, simplified data security, and significantly reduced administrative overhead and licensing costs. 

80% Enhanced Critical Service Coverage

securing 5 petabytes of sensitive data across 32 out of 40 medical institutions and ensuring continuity for over 10 million citizens.

Flawless Audit Pass and Zero Remediation

by establishing a robust security posture with a “golden copy” of data that aligns with NIST frameworks and meets medical institution protection requirements.

Critical Health Infrastructure and Patient Lives at Risk from Ransomware


For a critical public sector entity like ARIA, downtime is not an option; a cyber incident could halt essential clinical services, directly jeopardizing patient well-being. ARIA faced unacceptable risk because its reliance on a fragmented, complex mix of five legacy backup tools (including Veeam, EMC, Veritas, Commvault, and Acronis) lacked the immutability and centralized control needed to withstand modern threats. As Roberto Nocera, Director of IT Infrastructure & Cloud Transformation Officer, noted, “Our reliance on multiple legacy solutions meant we were flying blind to compliance gaps and couldn’t guarantee a clean recovery point. When patient lives are on the line, that uncertainty is an unacceptable risk.” Without a comprehensive solution, a successful ransomware event could: 

img

Halt life-saving medical services and systems for days.

img

Compromise citizen trust and result in significant financial and reputational damage.

img

Complicate GDPR compliance and expose the region to severe regulatory penalties.

PRODUCTS & SERVICES

  1. Enterprise Data Protection

  2. Cloud Native Protection

  3. Unstructured Data Protection

  4. Rubrik Cloud Vault

  5. Customer Experience Manager

  6. Ransomware Recovery Warranty

TRANSFORMATION WITH RUBRIK

A Proactive Partnership for Unwavering Cyber Resilience

To transform its cybersecurity posture and support its ambitious cloud-first strategy, ARIA partnered with Rubrik to unify data protection across on-prem and cloud environments. This shifted their approach from reactive defense to proactive, business-enabling resilience. This move replaced the complex, fragmented legacy stack with a single, integrated platform designed to deliver immutable backups,  cloud-native protection, and a clear “golden copy” recovery path.

By consolidating legacy tools into one modern platform, ARIA immediately achieved a 5:1 tool consolidation ratio, dramatically simplifying data security and realizing significant cost savings. The implementation of Rubrik Cloud Vault was key, establishing a logically air-gapped, immutable cyber vault.

Rubrik Cloud Vault provides us with an air-gapped, immutable copy of our data, creating a ‘golden copy’ that can’t be compromised. This not only gives us peace of mind but also allows us to move forward with our digital transformation initiatives with confidence.

Roberto Nocera
Director of IT Infrastructure & Cloud Transformation Officer, ARIA

To ensure maximum operational confidence, the partnership included an on-site resident and dedicated customer support, providing peace of mind and assuring stakeholders that critical health data is protected to the highest standards of security.

With Rubrik serving as the backbone of its data security strategy, ARIA established a robust security posture that aligns with NIST frameworks, allowing it to pass its audit with zero remediation. As the first Italian public administration to adopt such a comprehensive solution, ARIA set a powerful precedent for healthcare data security, ensuring the well-being of its 10 million citizens and the continuity of life-saving medical care