PKI Health Check

PKI Health Check (Healthcare)

Project Description

The engagement

Unsung was commissioned by an NHS Trust to assess the current state of the Trust's PKI service to inform and de-risk the planned implementation of a Certificate Lifecycle Management solution. The health check was driven by Trust leadership concerns that limited visibility into the existing PKI technical platform could compromise anticipated benefits.

Specific concerns included risks of prolonged CLM implementation timelines, increased implementation costs, and potential failure to realise operational benefits if underlying PKI health issues were not first addressed.

Why the Trust commissioned a health check before implementing CLM

Certificate lifecycle management platforms discover, inventory and automate against the certificate estate that already exists. They are extremely effective at bringing order to a well-understood environment. They are considerably less effective when deployed onto an environment whose underlying structure is unclear, because the platform inherits whatever it finds. Misaligned certificate templates, gaps in revocation infrastructure, undocumented integrations and unclear ownership do not disappear when a CLM tool is introduced; they surface during implementation, usually as unplanned remediation work on the critical path.

Trust leadership recognised this risk in advance, which is not always the case. The more common pattern is for organisations to procure a CLM platform, begin implementation, and discover the condition of the underlying estate midway through delivery, at which point remediation competes for time and budget already committed. Commissioning an independent assessment first converted an unknown into a scoped, costed and prioritised set of actions before the implementation began.

Why this matters in a healthcare environment

Certificates underpin a great deal of clinical and administrative service delivery: authentication to clinical systems, secure communication between applications, device identity across a broad and varied estate, and protection of data in transit. When a certificate expires unexpectedly in this context, the effect is not an inconvenience to an IT team but a service that clinical staff cannot access. That reality raises the value of visibility considerably, and it is one of the reasons an evidence-led assessment carries weight with clinical and executive stakeholders as well as technical ones.

Trusts also operate under information governance and assurance obligations that require demonstrable control over how identities are issued, managed and revoked. A health check produces the evidence base that supports those obligations, independently of any implementation programme.

What the assessment needed to establish

The Trust's question was a practical one: is this estate ready for a CLM implementation, and if not, what must change first? Answering it required more than a technical audit. It required a view of the platform's condition, the governance surrounding it, the processes operating around it and the organisational capacity to sustain a new operating model once the platform was in place.

Assessments that address only the technical dimension routinely miss the reason CLM implementations disappoint. The platform installs correctly and discovers the estate as intended, but the organisational arrangements needed to act on what it finds are absent: no clear ownership of certificates, no agreed process for handling renewals the platform surfaces, no route to onboard the application teams whose certificates are now visible. Scoping the health check to cover technical and business readiness in equal measure was therefore a deliberate decision, and it shaped both the assessment and the recommendations that followed.

Outcomes & Deliverables

Unsung delivered a focused health check report providing clear visibility of both technical and business readiness for CLM implementation.

A comprehensive report presented findings across dimensions relevant to CLM implementation readiness, with evidence-driven, prioritised recommendations targeting both technical platform improvements and organisational readiness activities. The assessment followed Unsung's established health check methodology, scoped and weighted for the Trust's specific objective of de-risking CLM implementation.

Current state analysis

We established a factual baseline of the PKI service as it actually operated, rather than as documentation described it. This covered certificate authority configuration, Active Directory Certificate Services implementation, Authority Information Access locations, certificate templates, and the mechanisms by which certificates were requested, issued and renewed. Revocation infrastructure was reviewed in detail, including CRL stores, distribution arrangements and the availability of validation services, alongside backup and monitoring capability.

Risk assessment and findings

Vulnerabilities, misconfigurations and process weaknesses were documented and categorised by risk level. Certificate validity periods, expiry tracking and the protection of sensitive material were assessed. Each finding was recorded with its context, its potential impact and a recommended mitigation, so that the Trust could prioritise remediation against its own risk appetite and available resource rather than working from an undifferentiated list of issues.

Governance and compliance review

Certificate Policy, Certificate Practice Statement and supporting operational documentation were assessed for completeness, accuracy and alignment to the compliance frameworks the Trust operates under. We looked beyond whether documents existed to whether the procedures they described were implemented in practice, which is where the more consequential gaps usually sit. Sound governance reduces audit burden and supports consistent operation, and it is a prerequisite for delegating certificate operations to an automated platform with confidence.

Operational efficiency evaluation

Manual processes and performance constraints were identified, with recommendations covering automation, tooling and workflow changes that reduce the scope for human error and improve service reliability. This element of the assessment fed directly into the CLM business case, since it established which manual activities the platform would displace and where the operational benefit would actually be realised.

Strategic alignment and CLM readiness

We assessed how well the existing PKI supported the Trust's wider technology roadmap and security strategy, and what would be required for the planned CLM implementation to succeed. Findings addressed both technical platform improvements and organisational readiness, including ownership, process and the operating model that would need to be in place for the platform to deliver sustained value rather than an initial burst of discovery followed by drift.

The report

The final report was written to be accessible to technical and executive audiences alike, containing detailed observations, prioritised actions and practical recommendations. Prioritisation was the key output: it gave Trust leadership a clear view of what needed to be addressed before CLM implementation, what could be addressed in parallel, and what could reasonably follow, converting an open-ended concern into a sequenced plan.

What this gave the CLM programme

The health check addressed the three specific risks Trust leadership had raised at the outset. On implementation timelines, remediation requirements were identified and sequenced in advance, so that work which would otherwise have emerged mid-implementation could be planned rather than absorbed as delay. On cost, the scope of preparatory work was established before commitments were made, allowing the implementation to be budgeted against a known position rather than an assumed one. On benefit realisation, the assessment established which operational benefits the platform could deliver against the estate as it stood, and which depended on prior remediation or on organisational change within the Trust.

Independence was a meaningful part of the value here. An assessment carried out by a party with no stake in the subsequent implementation can report the estate as it is, including findings that make the implementation look harder than initially assumed. That is precisely the information a leadership team needs before committing to a programme, and it is the information least likely to surface from an assessment conducted by the eventual implementer.

Challenges

Constrained resource availability

Resource availability to support health check activities was constrained by competing operational priorities. Unsung addressed these constraints through deployment of scripted methods to interrogate PKI platform components and extract critical data automatically.

This constraint is close to universal in healthcare, where the teams who hold the necessary knowledge are the same teams keeping clinical services running. An assessment approach that depends heavily on stakeholder availability will either extend indefinitely or return incomplete findings. By scripting the collection of configuration and certificate data directly from the platform, we substantially reduced the demand placed on Trust staff and improved the quality of the evidence base at the same time, since data gathered directly from the environment is not subject to the recall limitations of interview-based discovery.

Working from limited documentation

Where documentation was incomplete, findings were derived from the environment itself and validated with the Trust rather than inferred. This matters for a report intended to support investment decisions: recommendations carry weight only where the evidence behind them is traceable, and an assessment that cannot show its working is difficult for leadership to act upon with confidence.

Producing findings that served two audiences

The report needed to give technical teams sufficient detail to act, while giving Trust leadership a clear view of risk, cost and sequencing. These are different documents in most organisations. Structuring findings so that each recommendation carried both its technical substance and its business consequence allowed a single report to serve both, which kept the technical and executive views of the programme aligned as it progressed.

Working within a live clinical environment

Assessment activity had to proceed without introducing any risk to services in use. Scripted interrogation was read-only and scoped to configuration and certificate data, scheduled in agreement with the Trust so that collection did not coincide with periods of operational sensitivity. Engagements of this kind depend on the assessor understanding that the environment under review is carrying live clinical load, and adjusting method accordingly rather than expecting the environment to accommodate the assessment.

Technologies Used

Microsoft ADCS, DigiCert Trust Lifecycle Manager Unsung's health check methodology is vendor-neutral and applies across certificate authority platforms and CLM tooling. Assessment findings and recommendations are driven by the Trust's requirements, risk position and existing estate, not by any commercial relationship.