Resources - eBooks & On-Demand Webinars - Field Effect

How RWHC cut 1000s of security alerts to 5 per week with Field Effect MDR & AxCel Technology

Written by Field Effect | Aug 25, 2026, 1:27:24 PM

The cooperative

The Rural Wisconsin Health Cooperative (RWHC) is a member-owned cooperative of 45 rural hospitals across Wisconsin. Its mission is simple: ensure smaller facilities aren't left behind by the cost of modern healthcare technology. By pooling resources, RWHC gives its members access to tools and services they couldn't sustain on their own.

RWHC provides managed IT services, hosted applications, and shared infrastructure to member hospitals that connect directly into its environment. Because those hospitals depend on RWHC to keep critical services running, a breach could also disrupt their ability to deliver modern healthcare, making cybersecurity central to everything the cooperative delivers.

The challenge

Supporting 45 member hospitals left RWHC's small IT team with little capacity to spare. And building out a fully staffed security operation internally wasn't feasible; they needed more protection without the overhead.

Over the years, Joe Plonka, Manager of IT at RWHC, tested a range of cybersecurity solutions in search of the right fit. Many demanded heavy time investment and didn’t provide threat disruption that they wanted.

“We were getting thousands and thousands of alerts,” said Plonka. “In four hours, you could maybe get through 250 alerts. We didn’t feel like we were able to stay on top of them enough to deliver a meaningful response.”

Despite having a growing tool stack and thousands of alerts, significant gaps remained. The cooperative had no visibility into internal network traffic or lateral movement and weren’t clear on where they were potentially vulnerable to attack. "We'd had different products that never found anything, and we were never confident whether that was good or bad,” said Plonka.

With cyber risk increasing and cyber insurers raising the bar on acceptable cybersecurity standards, RWHC knew a change was needed.

The solution

RWHC needed a solution that could centralize visibility across its entire environment, reducing risk, stopping attacks and building resiliency, without consuming its lean team’s limited time.

The answer came through RWHC's long-standing partnership with AxCel Technology. AxCel Technology has spent years bringing cutting-edge solutions to the table and this time they brought Field Effect MDR. When Plonka took a closer look, it was clear to him that this solution was different.

Field Effect MDR Complete consolidated everything needed to protect their environment into one solution, backed by a 24/7 SOC. "Everything you need is included, for a great price point," said Plonka. The solution also helped RWHC address critical cyber insurance requirements and made day-to-day security management achievable for their team through Field Effect's AROs (Actions, Recommendations, and Observations), which surface only prioritized, validated alerts.

But what set Field Effect apart was where the analysis happened and how quickly they could detect threats. Rather than funneling logs to the cloud for after-the-fact analysis, Field Effect deploys a sensor directly inside the environment to block threats on the endpoint and in the network in real time. "With cloud-based log analysis, the train may have already left the station," Plonka noted.

The on-site sensor also ingested Fortinet logs natively, creating a meaningful advantage in RWHC's Fortinet-heavy environment, and kept data on-premises.

The results

Field Effect delivered results from day one, giving RWHC the visibility, clarity, and confidence their lean team needed:

  • Gained complete visibility into network and user behavior, identifying vulnerabilities, misconfigurations, and threats across their environment
  • Reduced alert volume from thousands of daily notifications to four to five actionable AROs (Actions, Recommendations, and Observations) per week
  • Automatically gained new protection as threats evolved, including AI Detection and Response (AIDR), at no extra cost

Shortly after deployment, Field Effect uncovered a VLAN misconfiguration that allowed a network segment to silently reach systems it had no business touching. Previous tools had missed it entirely. Plonka noted, "Having something that can identify gaps in your network before an attacker does is invaluable."

Where previous solutions had generated thousands of notifications, Field Effect delivered four to five AROs per week, each one prioritized, contextualized, and warranting attention. Joe and his team knew that when an ARO arrived, it mattered. The ongoing relationship with Field Effect's team made every interaction feel less like processing an alert and more like guidance from a trusted colleague. "It just feels like an extension of your team," Plonka said.

As threats evolved, so did the service. When AI adoption introduced new risks around data exposure, exploitation, and compliance, Field Effect launched AI Detection and Response, included in RWHC's existing subscription at no additional cost. Shadow AI had become a pressing conversation across RWHC's member hospitals, and Field Effect gave Plonka clear visibility into the AI users and tools within their environment. "We just had a big discussion about ways of stopping it, ways of identifying it," said Plonka. "It was a great solution."

For a lean team, Field Effect MDR gave RWHC's lean team what no previous tool could, complete visibility into their environment and the confidence that threats would be stopped any time of day, so they can safeguard the access to critical services for their member hospitals. "I think people would be pleasantly surprised with the bang for the buck," said Plonka. "Everything you need is included, and for the price point, it competes with the biggest names in the industry. I would give Field Effect a serious look."