Previously, I described the journey of ASL Roma 1’s Healthcare Operational Protection & Excellence (HOPE) cybersecurity and risk governance framework, which started by overcoming a familiar problem in healthcare cyber-physical systems (CPS) security: visibility.
First, we needed to understand the assets we were managing and which systems were describing the same physical object. That led to the establishment of a canonical asset, a single digital representation of an asset. Once we had the canonical asset, we could agree on what its risk really was. That was the idea behind canonical risk. For a while, I thought this was the natural destination of the architecture. It wasn’t.
The reason is not because we decided to redesign the interface, nor because we wanted another architectural layer. The change came from a much simpler realization: the asset itself was no longer enough to describe what we were trying to protect.
A device can be perfectly identified and still tell us very little about the real security problem around it, such as:
Who can access it
Which vulnerabilities affect it
What events have been observed around it
Which indicators describe its behavior
How does it relate to other systems?
Which governance metrics apply to it?
And, increasingly, which artificial-intelligence component is reasoning about it, enriching it or acting upon its data.
At some point, putting all of this inside a single asset record stops helping. Instead, it starts hiding the structure of the problem.
This was the architectural turning point. Instead of continuing to enlarge the canonical asset indefinitely, we started separating the different kinds of truth surrounding it.
For years, security platforms have organized the world around products and databases. One tool stores devices, while others store vulnerabilities, identities, or events, while another calculates compliance indicators. We then spend enormous effort trying to correlate those databases after the fact.
But the organization does not actually experience security as a collection of databases. It experiences relationships.
A vulnerable medical device is relevant because it belongs to a clinical process. An identity is relevant because it can reach that device. An event matters because it changes our understanding of exposure. An AI-generated recommendation matters because somebody may use it to make a decision.
The interesting object is therefore no longer simply the asset. It is the graph of meaning around the asset. And this is where HOPE because something different from what was originally designed.
We call the layer Aggregated Resource Manager (ARM), and its meaning has expanded considerably.
ARM began as a way to normalize and reconcile information coming from different sources. Today, it is evolving toward a canonical model in which different security domains can preserve their own semantics while still belonging to the same governed system.
Warden can reason about IoMT and cyber-physical assets. Pathfinder can reason about network infrastructure. Sentinel can contribute endpoint and security telemetry. Gatekeeper can represent identity. Guardian can represent exposure and vulnerability. Beacon can transform what the system sees into measurable indicators. Other profiles can observe external signals, audit actions or support AI reasoning.
They no longer need to pretend that all of these things are the same kind of object. They only need to speak the same canonical language.
Cyber-physical environments are probably the best place to see why. In healthcare, the meaning of an object changes continuously depending on who is looking at it.
For the network team, it is an IP address. For biomedical engineering it is a medical device. For the security operations center (SOC), it may be an exposure point. For identity management it may be something accessed by a particular user or service account. For management it may represent a critical clinical dependency. For an auditor it becomes evidence.
All of those interpretations are valid. The mistake is forcing them into a single representation. The new HOPE architecture tries to preserve those perspectives while creating a common space in which they can be related.
That is a very different idea from building a larger CMDB. It is closer to building a security knowledge fabric.
The screenshot above shows only the surface of that change. Behind the canonical dimensions is a much more ambitious question: what happens when a security system no longer thinks primarily in terms of records, but in terms of relationships between governed objects?
Once asset, identity, exposure, event, metric, relationship and AI can become canonical entities, the system can start asking questions that are difficult to express inside traditional security silos.
Not simply: “Which devices are vulnerable?” But: “Which critical clinical assets are exposed, reachable by privileged identities, associated with anomalous events, and currently outside the expected governance threshold?”
That is not a better dashboard query. It is a different way of modelling security. And it may also change how AI operates inside the architecture. Instead of giving an AI a collection of disconnected alerts and asking it to infer the context, we can begin giving it the context itself.
The graph becomes part of the evidence.
I deliberately do not want to explain the whole architecture in this article. Partly because it is still evolving, but mainly because the transformation deserves its own discussion.
The first version of HOPE tried to understand assets. The second tried to understand their risk. The architecture we are building now is trying to understand the relationships that make risk meaningful.
That is a much larger ambition.
And it brings us very close to the next question in this series: if a cybersecurity platform can construct a governed model of assets, identities, exposures, events, relationships and AI itself, can it begin to reason about the environment as a whole rather than as a collection of findings?
That is where HOPE is going next.
And that is the part I am most looking forward to sharing.
Stefano Scaramuzzino is the cybersecurity team leader and network and information systems manager, for ASL Roma 1, Italy's largest local health authority.
A partner at Deloitte Italy Cyber Risk Services, Battelli has 25 years consulting experience with a specific focus on ICT/Cybersecurity where he is well-recognized trusted advisor and subject matter expert in critical infrastructure protection (CIP).